A Multimodal AI Content Security Risk Tracing and Identification System

By constructing a multimodal AI content security risk tracing and identification system, the problem of difficulty in tracing the authenticity of content in existing technologies has been solved. This system enables full-chain tracing and detection of multimodal content, thereby improving the trustworthiness of digital content and the health of the information ecosystem.

CN120832695BActive Publication Date: 2025-12-02NAT CERTIFICATION TECH (HANGZHOU) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511324183.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-17
Publication Date
2025-12-02
Estimated Expiration
2045-09-17

AI Technical Summary

Technical Problem

Existing technologies lack end-to-end verifiable mechanisms for content creation and distribution, making it difficult to trace and confirm the authenticity of content. In particular, in cross-modal collaborative tampering scenarios, there is a lack of verification mechanisms for consistency between modalities, making it impossible to effectively trace the source of tampered content and the responsible party.

Method used

A multimodal AI content security risk tracing and identification system is constructed. Through multi-source data acquisition, feature fingerprint construction, cross-modal consistency analysis, tracing map construction, and risk identification verification, the system enables the tracing and detection of security risks in the entire process of multimodal content creation, editing, distribution, and presentation.

Benefits of technology

It enables comprehensive and accurate analysis of multimodal content, effectively identifies synthetic and tampered content, provides a complete chain of evidence for tracing the source, enhances the effectiveness of digital judicial evidence collection, locks down the source and dissemination path of deepfake content, and improves the platform's content governance capabilities and credibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120832695B_ABST
    Figure CN120832695B_ABST
Patent Text Reader

Abstract

This invention belongs to the field of digital content security technology. It discloses a multimodal AI content security risk tracing and identification detection system. By acquiring multi-source heterogeneous data from the entire content creation, editing, distribution, and presentation chain, it constructs a full-chain feature fingerprint of the content, achieving cross-modal consistency analysis and chain continuity verification. This invention introduces source mapping graph construction, using potential tampering points as graph nodes. It quantifies content risk through tampering probability weights and risk transmission intensity, accurately identifying the source and propagation path of tampering. This invention is comprehensive and accurate, capable of in-depth analysis and risk assessment of multimodal content, and effectively identifying synthetically tampered content.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of digital content security technology, and more specifically, to a multimodal AI content security risk tracing and identification system. Background Technology

[0002] With the rapid development of deep learning and generative AI technologies, AI-generated content (AIGC) has entered a stage of large-scale application. Currently, multimodal generative models such as DALL-E, Midjourney, and Stable Diffusion can create highly realistic images; the GPT series can generate fluent and natural text; technologies like Sora and Runway support high-quality video synthesis; and audio synthesis technology has achieved millisecond-level sound cloning. These technologies have demonstrated immense value in creative design and content creation, but they have also brought unprecedented content security challenges.

[0003] However, existing technologies generally lack end-to-end verifiable mechanisms for content creation and distribution, making it difficult to trace and confirm the authenticity of content. Specifically, traditional detection methods focus only on the superficial features of content presented on the terminal, ignoring the complete lifecycle of content from its creation source to user reception. In practical applications, when a video is forwarded and edited multiple times across multiple platforms, the traces of operations in the intermediate stages are often completely erased, forming a "black box of authenticity." For example, after an original news video is modified by AI tools by replacing faces and altering audio content and then disseminated on social media, existing technologies struggle to reconstruct the timeline of content changes, determine the specific stages of the alteration, the tools and techniques used, and trace the original source of the alteration and the responsible party. This broken link means that content tracing systems can only provide fragmented evidence, not a complete chain of evidence, severely limiting the effectiveness of digital forensics. More importantly, existing technologies are particularly vulnerable in cross-modal collaborative alteration scenarios—when text, images, audio, and video are collaboratively modified to construct a consistent false narrative, the lack of a verification mechanism for inter-modal consistency allows altered content to easily evade single-modal detection. This lack of traceability not only hinders judicial evidence collection and news fact verification, but also provides a cover for the large-scale dissemination of deepfake content, posing a serious threat to information security.

[0004] In view of this, the present invention proposes a multimodal AI content security risk tracing and identification detection system to solve the above problems. Summary of the Invention

[0005] To overcome the aforementioned deficiencies of the prior art and to achieve the above objectives, the present invention provides the following technical solution: a multimodal AI content security risk tracing and identification detection system, comprising:

[0006] The multi-source data acquisition module is used to acquire multi-source heterogeneous data of the multimodal content to be detected throughout the entire creation and distribution chain. The multi-source heterogeneous data includes metadata in the content generation stage, operation logs in the editing stage, network transmission characteristics in the distribution stage, and user interaction behavior data in the terminal presentation stage.

[0007] The feature fingerprint construction module is used to construct the full-link feature fingerprint of content based on the spatiotemporal distribution characteristics of data at each stage in multi-source heterogeneous data. The full-link feature fingerprint of content includes modal coupling features in the generation stage, operation sequence patterns in the editing stage, topology propagation features in the distribution stage, and behavioral response patterns in the terminal presentation stage.

[0008] The consistency analysis module is used to extract potential tampering points and risk propagation paths by analyzing the cross-modal consistency and link continuity of features at each stage in the full-link feature fingerprint of the content.

[0009] The source map construction module is used to construct a multimodal content source map based on the distribution characteristics of potential tampering points and risk propagation paths. The multimodal content source map includes the tampering probability weights between nodes and the risk transmission strength between paths.

[0010] The risk identification and verification module is used to identify synthetic tampering risks in the content chain based on the multimodal content traceability map and the multimodal content security risk classification model, and output the integrity verification results of the traceability chain.

[0011] Preferably, a content end-to-end feature fingerprint is constructed, including:

[0012] Modal decomposition is performed on the metadata in the generation stage to extract the generator parameter distribution characteristics of multimodal data such as text, image, audio, and video, and modal coupling characteristics are determined by calculating the mutual information of parameters between modalities.

[0013] The operation logs during the editing phase are serialized and modeled to identify non-linear jump patterns in the operation sequence. The operation sequence patterns are extracted through periodic fluctuation analysis of operation timestamps.

[0014] The network transmission characteristics during the distribution phase are topologically embedded to construct a dynamic propagation graph of the distribution network, and the topological propagation characteristics are extracted through propagation delay between nodes and data packet integrity verification.

[0015] Behavioral clustering is performed on user interaction behavior data during the terminal presentation stage to identify time-series anomalies in the interaction behavior, and behavioral response patterns are extracted based on the contextual correlation strength of the anomalies.

[0016] By aligning modal coupling features, operation sequence patterns, topology propagation features, and behavioral response patterns across stages, a full-link feature fingerprint of the content is generated.

[0017] Preferably, the extraction of potential tampering points and risk propagation paths includes:

[0018] Cross-modal consistency checks are performed on the features at each stage of the content end-link feature fingerprint, the cosine similarity of feature vectors between modes is calculated, and cross-modal inconsistency regions are identified by the local extrema of the similarity.

[0019] Link continuity analysis is performed on cross-modal inconsistency regions, and potential tampering points are identified by the jump frequency of feature fingerprints on the time axis and the distribution dispersion on the spatial axis.

[0020] Based on the location distribution of potential tampering points, a risk propagation path map is constructed. The risk propagation path map determines the risk propagation path by weighting the propagation direction and propagation intensity between potential tampering points.

[0021] The stability of risk propagation paths is verified by introducing path reconstruction errors after random perturbation, eliminating unstable paths and retaining high-confidence risk propagation paths.

[0022] Preferably, constructing a multimodal content tracing map includes:

[0023] Potential tampering points are treated as graph nodes, and directed edges between nodes are constructed based on the feature similarity and temporal relationship between nodes.

[0024] The tampering probability weight is assigned to the directed edge. The tampering probability weight is calculated based on the joint probability of the distribution difference of the feature vectors between nodes and the link jump frequency.

[0025] The risk transmission intensity of the risk propagation path is quantified by the normalized ratio of the cumulative tampering probability weight of each node on the path to the path length.

[0026] Based on the tampering probability weight and risk transmission intensity, a multimodal content tracing map is constructed, and through connectivity analysis of the map, isolated tampering areas and high-risk propagation areas in the link are identified.

[0027] Preferably, identifying synthetic tampering risks in the content chain includes:

[0028] A security risk classification model for multimodal content is constructed. The security risk classification model takes the full-link feature fingerprint of the content as input, extracts graph features through a multi-layer graph convolutional network, and combines an attention mechanism to weight high-risk nodes.

[0029] Risk propagation simulation was performed on the multimodal content tracing map, and the tampering and diffusion probability of each node in the map was calculated by using a random walk algorithm;

[0030] Based on the output of the tampering diffusion probability and security risk classification model, synthetic tampering risks in the content chain are identified, and the main modal sources of tampering are determined through modal contribution analysis of tampering risks.

[0031] The risk level of synthetic tampering is classified, and the risk level and corresponding traceability evidence chain are output by weighted combination of tampering diffusion probability and tampering impact range.

[0032] Preferably, the method for extracting modal coupling features includes:

[0033] High-dimensional embedding is performed on the generator parameter distribution features of each modality data to generate modal parameter feature vectors;

[0034] Highly coupled parameter pairs between modes are identified by calculating the mutual information matrix between the eigenvectors of modal parameters.

[0035] The coupling weights of highly coupled parameter pairs are dynamically weighted by determining the coupling weights of each parameter pair based on the consistency of fluctuations within the generation time window.

[0036] Based on coupling weights, the feature vectors of highly coupled parameter pairs are weighted and fused to generate modal coupling features.

[0037] Preferably, the method for determining potential tampering points includes:

[0038] Wavelet transform is performed on the time axis jump frequency of the content full-link feature fingerprint to extract the high-frequency and low-frequency components of the jump frequency;

[0039] By comparing the local peak density of high-frequency components with the trend smoothness of low-frequency components, abrupt change points on the time axis are identified.

[0040] Spatial distribution analysis of jump anomalies is performed, and the distribution anomaly regions on the spatial axis are determined by the ratio of the spatial dispersion of the feature fingerprint to the spatial cluster radius.

[0041] The intersection of abrupt change anomalies and distribution anomaly regions is used as potential tampering points, and false alarms are eliminated by using the consistency of the contextual features of the anomalies.

[0042] Preferably, the method for assigning values ​​to the tampered probability weights includes:

[0043] Kernel density estimation is performed on the differences in feature vector distributions between nodes, and the KL divergence of the distribution differences is calculated as a measure of feature differences.

[0044] Entropy analysis is performed on the link hopping frequency between nodes. The link discontinuity metric is determined by the ratio of the distribution entropy of the hopping frequency to the average hopping interval.

[0045] The normalized results of the feature difference measure and the link discontinuity measure are weighted and fused to generate the joint probability between nodes;

[0046] Based on the joint probability, the tampering probability weights between nodes are generated through mapping using the softmax function.

[0047] Preferably, the method for simulating risk propagation includes:

[0048] Graph embedding is performed on the multimodal content tracing graph to generate low-dimensional feature vectors for the graph nodes;

[0049] Based on low-dimensional feature vectors, multiple propagation paths are generated through a random walk algorithm, and the access frequency of each node on the path is recorded.

[0050] Path entropy analysis is performed on the propagation path, and the propagation stability of the path is determined by the ratio of path entropy to path length.

[0051] Based on propagation stability and access frequency, the tampering and diffusion probability of each node in the graph is calculated, and high-risk propagation subgraphs in the graph are identified by the spatial distribution characteristics of the diffusion probability.

[0052] Preferably, the system further includes:

[0053] Construct a content full-chain traceability and verification database, which includes the original feature fingerprints of multimodal content, the distribution characteristics of tampering points, and the statistical characteristics of risk propagation paths;

[0054] By using a content full-chain traceability and verification database, new input multimodal content can be quickly traced and matched to identify historical tampering patterns in the content chain.

[0055] Based on the matching results of historical tampering patterns, the node weights and path strengths of the multimodal content tracing graph are dynamically adjusted to optimize the real-time performance and accuracy of the tracing graph.

[0056] The optimized results of the source tracing map are combined with the detection results of content security risks to provide a report on the integrity of the content chain.

[0057] The technical effects and advantages of the multimodal AI content security risk tracing and identification detection system of this invention are as follows:

[0058] This invention establishes an end-to-end verifiable mechanism for content creation and distribution, effectively restoring the complete facts of content tampering. This traceability capability enhances the effectiveness of digital judicial evidence collection, accurately pinpointing the source of deepfake content, tracing its dissemination path, and clarifying the responsible parties, thus providing crucial evidentiary support for combating information fraud and online misinformation. This invention helps build a content authenticity verification defense line, preventing the generation and dissemination of fake news and misleading content, and improving the platform's content governance capabilities and credibility. The cross-modal consistency verification mechanism of this invention can effectively identify carefully designed composite modal fake content, maintaining the health and purity of the information ecosystem. This invention can promptly detect and trace improper use. By rebuilding the trust chain of digital content, this invention provides a technical foundation for building a transparent and reliable digital information environment. Attached Figure Description

[0059] Figure 1 This is a schematic diagram of a multimodal AI content security risk tracing and identification detection system according to the present invention;

[0060] Figure 2 This is a diagram illustrating the method for determining potential tampering points in this invention. Detailed Implementation

[0061] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0062] This application provides a multimodal AI content security risk tracing and identification system. The system's execution entities include, but are not limited to, content review platforms, media security monitoring centers, digital forensics systems, and multimodal content analysis platforms, which can be considered general computing nodes in this application. The security detection system includes, but is not limited to, at least one cloud-based security risk analysis engine, a distributed content tracing system, and an intelligent tampering detector.

[0063] This invention provides a multimodal AI content security risk tracing and identification system. Through end-to-end multi-source data acquisition, feature fingerprint construction, cross-modal consistency analysis, tracing graph construction, and risk identification verification, it achieves security risk tracing and detection throughout the entire process of multimodal content creation, editing, distribution, and presentation. It is comprehensive and accurate, capable of in-depth analysis and risk assessment of multimodal content, effectively identifying synthetic and tampered content, and providing a complete chain of tracing evidence.

[0064] Please see Figure 1In this embodiment of the invention, a multimodal AI content security risk tracing and identification system includes:

[0065] The multi-source data acquisition module is used to acquire multi-source heterogeneous data from the entire creation and distribution chain of the multimodal content to be detected. This multi-source heterogeneous data includes key information such as metadata from the content generation stage, operation logs from the editing stage, network transmission characteristics from the distribution stage, and user interaction behavior data from the terminal presentation stage. This data is acquired in real-time through a multi-channel data acquisition interface. The metadata from the content generation stage records basic information such as the content creation time, the generation tools used, and parameter settings. The operation logs from the editing stage record the entire sequence of operations involved in content modification. The network transmission characteristics from the distribution stage reflect the path and method of content dissemination. The user interaction behavior data from the terminal presentation stage records the patterns of user interaction with the content. This data provides comprehensive raw material for subsequent analysis, ensuring the completeness and accuracy of source tracing and detection.

[0066] The feature fingerprint construction module is used to construct a full-link feature fingerprint of content based on the spatiotemporal distribution characteristics of data at each stage in multi-source heterogeneous data. The full-link feature fingerprint of content includes modal coupling features in the generation stage, operation sequence patterns in the editing stage, topology propagation features in the distribution stage, and behavioral response patterns in the terminal presentation stage. Modal coupling features describe the correlation and consistency between different modalities of content, operation sequence patterns reflect the behavioral characteristics of the editing process, topology propagation features reflect the propagation rules of content in the network, and behavioral response patterns quantify the user's interaction characteristics with the content. These multi-dimensional features together constitute the "digital DNA" of the content, providing a foundation for subsequent consistency analysis and risk identification.

[0067] The consistency analysis module is used to extract potential tampering points and risk propagation paths by analyzing the cross-modal consistency and link continuity of features at each stage of the content's end-to-end feature fingerprint. This module first performs cross-modal consistency checks on the feature fingerprint to identify inconsistencies between modalities. Then, through link continuity analysis, it locates anomalous jumps on the timeline and discrete regions in spatial distribution, accurately determining potential tampering points. Based on these tampering points, it constructs risk propagation paths, providing crucial input for building the source tracing map.

[0068] The source tracing graph construction module is used to construct a multimodal content source tracing graph based on the distribution characteristics of potential tampering points and risk propagation paths. The multimodal content source tracing graph includes tampering probability weights between nodes and risk transmission strengths between paths. This module treats tampering points as graph nodes, constructs directed edges through feature similarity and temporal relationships, assigns tampering probability weights to nodes, and allocates risk transmission strengths to paths, forming a complete source tracing network structure. This visually displays the source, scope, and impact of content tampering, providing a graph foundation for risk identification and verification.

[0069] The risk identification and verification module is used to identify synthetic tampering risks in the content chain based on a multimodal content source map and a multimodal content security risk classification model, and output the integrity verification results of the source chain. This module constructs a specialized security risk classification model, extracts graph features through graph convolutional networks, performs weighted analysis on high-risk nodes using an attention mechanism, simulates the risk propagation process to calculate the tampering diffusion probability, and ultimately identifies synthetic tampering risks in the content. Based on the risk level and propagation scope, it generates a detailed risk assessment report and a complete source evidence chain.

[0070] The modules are connected via wired and / or wireless means to enable data transmission between them.

[0071] In this embodiment of the invention, the detailed implementation steps for constructing a content end-to-end feature fingerprint include:

[0072] Modal decomposition is performed on the metadata generated during the generation stage to extract the generator parameter distribution features of multimodal data such as text, images, audio, and video. Modal coupling features are determined through mutual information calculation of intermodal parameters. Modal decomposition is a fundamental step in feature extraction, separating complex content into independent modal layers for refined analysis. The decomposition process employs a deep neural network encoder architecture, with dedicated feature extraction modules designed for different modalities; for example, a BERT-like model is used for text, a CNN variant for images, and a spectral analysis network for audio. Generator parameter distribution features include key indicators such as noise level, color consistency, text semantic features, and audio spectral envelope. Mutual information calculation, based on information entropy theory, quantifies the statistical dependencies between different modal parameters, using the following formula:

[0073] ;in, For modality and mutual information, For joint probability distribution, and For marginal probability distribution, Indicates the first mode The parameter values ​​or values ​​of a specific dimension in the feature vector (such as text). Indicates the second mode The parameter values ​​or values ​​of a specific dimension in the feature vector of an image (such as an image).

[0074] A higher mutual information value indicates a stronger correlation between modes. The modal coupling characteristics are obtained through principal component analysis of the mutual information matrix, providing a benchmark for the consistency between modes in subsequent analysis.

[0075] Serialization modeling is performed on the operation logs during the editing phase to identify nonlinear jump patterns in the operation sequence. Periodic fluctuation analysis of operation timestamps is then used to extract operation sequence patterns. Serialization modeling is a crucial step in capturing the characteristics of editing behavior, transforming discrete operations into analyzable temporal patterns. The modeling process employs an improved sequence coding technique, mapping each operation to a feature vector containing operation type, parameters, duration, and contextual information. Nonlinear jump patterns are identified through Markov chain analysis, calculating the operation transition probability matrix to highlight anomalous state transitions. Periodic fluctuation analysis uses wavelet transform to decompose the frequency components of the timestamp sequence, identifying periodic patterns at different scales. These features collectively constitute the operation sequence patterns, reflecting the behavioral characteristics of the content editing process and providing a basis for identifying differences between manual editing and automatically generated content.

[0076] This paper describes a method for topologically embedding network transmission characteristics during the distribution phase to construct a dynamic propagation graph of the distribution network. Topological propagation features are extracted through propagation delay between nodes and data packet integrity verification. Topological embedding is an effective method for analyzing network propagation patterns, mapping complex network structures to a low-dimensional feature space. The embedding process is based on graph neural network technology, representing propagation nodes as high-dimensional vectors while preserving the topological relationships and propagation dynamics between nodes. The dynamic propagation graph is constructed using a time-series graph model to capture the spatiotemporal evolution of content propagation. Propagation delay is calculated using the time difference between nodes, and data packet integrity is evaluated using hash verification; these two indicators together reflect the reliability and consistency of the propagation process. Topological propagation features include key dimensions such as propagation rate, path diversity, node centrality, and community structure, providing a network perspective for tracing the content propagation chain.

[0077] Behavioral clustering is performed on user interaction data during the terminal presentation phase to identify time-series outliers in the interaction behaviors. The behavioral response patterns are then extracted based on the contextual correlation strength of these outliers. Behavioral clustering is a fundamental method for understanding user interaction patterns, grouping similar behaviors into meaningful categories. The clustering process employs the density-based clustering algorithm DBSCAN, automatically determining the number and range of categories based on the similarity of behavioral features. Time-series outliers are identified using the Local Outlier Factor (LOF) method, calculating the relative density difference between each interaction behavior and its neighborhood to identify points that significantly deviate from the normal pattern. Contextual correlation strength is calculated using the conditional probability of preceding and following behaviors to quantify the coherence between anomalous behaviors and surrounding behaviors. The behavioral response patterns ultimately include dimensions such as user attention distribution, interaction depth, emotional response intensity, and social sharing intention, providing a user perspective for content influence assessment.

[0078] By aligning modal coupling features, operation sequence patterns, topology propagation features, and behavioral response patterns across stages, a full-link feature fingerprint of the content is generated. Feature alignment is a crucial step in integrating features from multiple stages, ensuring consistency of features across different stages in both time and semantic dimensions. The alignment process employs the Dynamic Time Warping (DTW) algorithm to handle the temporal scaling of feature sequences from different stages, achieving timeline alignment; simultaneously, a cross-modal attention mechanism is used to calculate semantic relationships between features, achieving semantic-level alignment. The final generated full-link feature fingerprint is a high-dimensional feature tensor, with each dimension corresponding to a point in time and feature dimension in the content lifecycle, completely recording the digital features of the entire process from content creation to presentation, providing a comprehensive feature foundation for subsequent consistency analysis and risk identification.

[0079] In this embodiment of the invention, the detailed implementation steps for extracting potential tampering points and risk propagation paths include:

[0080] Cross-modal consistency testing is performed on features at each stage of the content end-to-end feature fingerprint. Cosine similarity between modal feature vectors is calculated, and local extrema of the similarity are used to identify inconsistencies across modalities. Cross-modal consistency testing is a crucial step in discovering intermodal contradictions, revealing potential tampering by comparing the similarity of features from different modalities. The testing process first maps each modal feature vector to a shared feature space through projection transformation, and then calculates the cosine similarity between modal pairs. The formula is:

[0081] ;in, and For feature vectors of different modalities, For vector dot product, and It is the vector norm.

[0082] The similarity value ranges from [-1, 1], with values ​​closer to 1 indicating higher consistency between modalities. Local extrema are identified using one-dimensional signal processing techniques. When the similarity curve shows a significant decrease, the corresponding time point is marked as a potential inconsistency region. These regions typically indicate logical or temporal contradictions between different modal contents, serving as important clues for potential tampering.

[0083] Link continuity analysis is performed on cross-modal inconsistency regions. Potential tampering points are identified by the frequency of feature fingerprint jumps on the time axis and the dispersion of their distribution on the spatial axis. Link continuity analysis is a core step in accurately locating tampering sites, revealing anomalies by evaluating the continuity of features in both time and space. The analysis process first calculates the inter-frame differences of feature vectors on the time axis to identify time periods with abnormally high jump frequencies; then, it calculates the distribution dispersion in the feature space to quantify the degree of clustering of feature distributions. The formula for calculating jump frequency is:

[0084] ;in, Time period The frequency of the transition. For the first The feature vector of the frame, For indicator functions, For the jump threshold, The number of frames.

[0085] Distribution dispersion is calculated as the ratio of the standard deviation to the mean of the eigenvector, reflecting the relative dispersion of the feature distribution. When both the jump frequency and distribution dispersion exceed the threshold, the corresponding region is identified as a potential tampering point, providing a foundational node for subsequent risk propagation path analysis.

[0086] Based on the location distribution of potential tampering points, a risk propagation path graph is constructed. This graph determines the risk propagation path by weighting the propagation directionality and intensity between potential tampering points. The risk propagation path graph is a network model describing the diffusion of tampering impact, reflecting the causal relationships and impact transmission between tampering points. The construction process first treats potential tampering points as nodes in the graph, then establishes directed edges based on temporal sequence and feature correlation to form an initial path graph. Propagation directionality is determined by timestamps and the gradient direction of feature changes, while propagation intensity is calculated by the amplitude of feature changes and the scope of impact. The formula for calculating propagation intensity is:

[0087] ;in, For the node To the node The intensity of transmission, For the node To the node The characteristic variation range, For the node To the node Scope of influence and These are the weighting coefficients, and .

[0088] The intensity of propagation, as the weight of an edge, directly affects the priority of risk propagation paths. The higher the propagation intensity, the more important the corresponding path, and the more likely it is to be the main risk propagation channel.

[0089] The stability of risk propagation paths is verified by introducing random perturbations into the path reconstruction error. Unstable paths are eliminated, and high-confidence risk propagation paths are retained. Path stability verification is a key step in improving the reliability of risk propagation paths, screening out truly important paths by assessing their sensitivity to noise. The verification process uses Monte Carlo simulation, repeatedly adding random perturbations to the original feature data, reconstructing the propagation path, and calculating the path recurrence rate. The path reconstruction error is calculated using Jaccard distance to quantify the difference between the original and reconstructed paths. The stability score is calculated using the following formula:

[0090] ;in, For path Stability score, The original path With the Secondary Restructuring Path Jaccard distance, For the number of simulations.

[0091] The stability score ranges from [0,1], with higher values ​​indicating more stable paths. Setting an appropriate threshold (typically 0.7-0.8) eliminates low-stability paths while retaining high-confidence risk propagation paths, ensuring the accuracy and reliability of subsequent risk analysis.

[0092] In this embodiment of the invention, the detailed implementation steps for constructing a multimodal content tracing map include:

[0093] Potential tampering points are treated as nodes in a graph. Directed edges are constructed between nodes based on feature similarity and temporal sequence. Graph node construction is a fundamental step in the source tracing graph, organizing discrete tampering points into a network structure. The construction process first maps each potential tampering point to a node in the graph, attaching attributes such as timestamp, location information, feature vector, and influence range to each node. Then, directed edges are established based on the relationships between nodes, forming a connected graph structure. Feature similarity is calculated using cosine similarity or Euclidean distance, and temporal sequence is determined by comparing timestamps. The establishment of directed edges follows the principle of causality, pointing from earlier nodes to later nodes, and the rationality of the relationships is verified by the coherence of feature changes. This edge construction method based on spatiotemporal relationships and feature similarity ensures the rationality and interpretability of the source tracing graph structure.

[0094] Tamper probability weights are assigned to directed edges, calculated based on the joint probability of the distribution differences of feature vectors between nodes and the link jump frequency. Weight assignment is a crucial step in quantifying the strength of node relationships, reflecting the credibility of the causal relationship between tampered points. The assignment process first calculates the feature distribution differences between nodes, quantifying the distance between feature vector distributions; then analyzes the link jump frequency to assess the degree of abrupt feature changes; finally, it integrates these two factors through a joint probability model to derive the final tamper probability weights. Feature distribution differences are calculated using KL divergence, and link jump frequency is evaluated using entropy analysis. The KL divergence calculation formula is:

[0095] ;in, For distribution Compared to KL divergence, For events / states in the first probability distribution The probability value, For the same event / state in the second probability distribution The probability value.

[0096] The entropy calculation of the link hopping frequency reflects the complexity and uncertainty of the hopping mode. The final tampering probability weight is mapped to the [0,1] interval through the softmax function, which intuitively represents the credibility of the tampering relationship between nodes.

[0097] The risk transmission intensity of a path is quantified by using the ratio of the cumulative tampering probability weights of each node along the path to the normalized path length. Path risk transmission intensity is a key indicator for assessing the scope of tampering impact, reflecting the ability of risk to propagate along a specific path. The quantification process first calculates the sum of the tampering probability weights of all nodes along the path to obtain the original cumulative value; then, considering the path length factor, normalization is used to eliminate the influence of length differences; finally, the risk transmission intensity is derived and used for path importance ranking. The formula for calculating risk transmission intensity is:

[0098] ;in, For path The intensity of risk transmission, For path The tampering probability weight of the edge from node i to node j. For path The length.

[0099] The square root term in the formula acts as a normalization factor, balancing the differences between long and short paths and allowing for a fair comparison of paths of different lengths. The intensity of risk transmission directly affects the simulation and prediction of risk propagation; paths with higher intensity are more likely to be the primary risk propagation channels.

[0100] Based on tampering probability weights and risk transmission intensity, a multimodal content tracing graph is constructed. Through connectivity analysis of the graph, isolated tampering regions and high-risk propagation regions within the tampering chain are identified. The multimodal content tracing graph is a comprehensive visualization model for tampering analysis, intuitively displaying the source, scope, and impact of content tampering. The construction process integrates nodes, directed edges, tampering probability weights, and risk transmission intensity to form a complete graph structure. Connectivity analysis is a crucial step in graph interpretation, identifying special regions by evaluating connection patterns between nodes. Isolated tampering regions are identified through weak connectivity component analysis, representing independent tampering unrelated to the main tampering chain; high-risk propagation regions are identified through centrality indicators and community detection algorithms, representing key areas where tampering impact is concentrated or spread. The identification of these special regions provides a structured perspective for risk assessment, helping analysts quickly locate key risk points and propagation paths, and providing a graph-based foundation for subsequent risk identification and verification.

[0101] In this embodiment of the invention, the detailed implementation steps for identifying synthetic tampering risks in the content chain include:

[0102] A multimodal content security risk classification model is constructed. This model takes the full-link feature fingerprint of the content as input, extracts graph features through a multi-layer graph convolutional network, and weights high-risk nodes using an attention mechanism. The risk classification model is a core component for automatically identifying tampering types, transforming complex graph features into clear risk categories. The construction process first designs a multi-layer graph convolutional network (GCN) architecture, capturing high-order relationships between nodes through a message passing mechanism; then, an attention mechanism is introduced to adaptively adjust the importance weights of different nodes and features; finally, a fully connected layer and a softmax classifier output the risk category probability. The core calculation formula of GCN is:

[0103] ;in, For the first The node feature matrix of the layer, To add self-loops to the adjacency matrix, This is the corresponding degree matrix. The weight matrix is ​​a learnable matrix. It is a non-linear activation function.

[0104] The attention mechanism enhances the model's sensitivity to high-risk regions by calculating feature importance scores, highlighting the influence of key nodes and edges. Model training utilizes a large-scale labeled dataset containing various known tampered samples, and parameters are optimized using the cross-entropy loss function to achieve accurate identification of multiple tampering types.

[0105] Risk propagation simulation is performed on a multimodal content tracing graph, calculating the tampering diffusion probability of each node in the graph using a random walk algorithm. Risk propagation simulation is a dynamic method for assessing the scope of tampering impact, predicting the diffusion trend of tampering risk through computational simulation. The simulation process is based on random walk theory, treating tampering risk as a random walk process on the graph, and calculating the probability of each node being visited through multiple simulations. Specifically, a biased random walk algorithm is used, where the transition probability of an edge is proportional to the tampering probability weight, reflecting the actual tendency of risk propagation. The formula for calculating the tampering diffusion probability of a node is:

[0106] ;in, For nodes The probability of tampering and diffusion. For nodes The total number of times the device is visited in M ​​random walks. The number of steps taken in each movement. To simulate the total number of times.

[0107] The diffusion probability directly reflects the importance and degree of influence of nodes in the risk propagation process, providing a probabilistic basis for the quantitative assessment of tampering risks.

[0108] Based on the output of the tampering propagation probability and security risk classification model, this system identifies synthetic tampering risks in the content chain and determines the main modal sources of tampering through modal contribution analysis of these risks. Tampering risk identification is the core function of the system, determining the authenticity and security of content by integrating multiple pieces of evidence. The identification process first combines the output category and confidence level of the security risk classification model to initially determine the risk type of the content; then, it integrates the tampering propagation probability to assess the scope of the risk's impact; finally, it identifies the main source modalities of tampering through modal contribution analysis. Modal contribution is determined by calculating the influence weight of each modal feature on the final risk judgment, using model interpretability techniques such as SHAP value analysis. This multi-dimensional risk identification method considers both the risk type and the scope of impact, while simultaneously locating the main risk sources, providing a comprehensive basis for security decisions.

[0109] The risk of synthetic tampering is classified into risk levels. A weighted combination of the probability of tampering propagation and the scope of tampering impact is used to output the risk level and the corresponding chain of evidence for tracing the source. Risk level classification is the final output of risk assessment, transforming technical analysis results into actionable decision-making criteria. The classification process first determines the risk scoring formula, comprehensively considering the probability of tampering propagation (reflecting the risk's ability to spread) and the scope of tampering impact (reflecting the proportion of affected content), and derives a comprehensive risk score through a weighted combination. Then, based on preset level thresholds, the score is mapped to different risk levels, typically divided into three levels (low, medium, and high) or a more detailed five-level classification. The risk level calculation formula is:

[0110] ;in, For content Risk level score, To maximize the probability of tampering and diffusion, In order to alter the scope of influence, These are the weighting coefficients.

[0111] It should be noted that the scope of the impact of the alteration is... It is a quantitative indicator used to calculate the degree to which content has been altered; the specific calculation formula is:

[0112] ;in, This refers to the scope of the alteration, with values ​​ranging from [0,1]. It is the set of all nodes in the content source map. It is a node The probability of tampering and diffusion. It is the probability threshold for determining tampering (usually set to 0.3-0.5). It is an indicator function; it takes the value 1 when the condition inside the parentheses is true, and 0 otherwise. It is a node The importance weight is usually based on the content coverage or visual salience of a node.

[0113] The source tracing evidence chain is generated by tracing the source path of high-risk nodes, including the time, location, characteristic changes and related evidence of key tampering points, forming a complete risk tracing report, providing detailed basis for security decision-making and evidence collection analysis.

[0114] In this embodiment of the invention, the detailed implementation steps of the modal coupling feature extraction method include:

[0115] The generator parameter distribution features of each modality's data are embedded in high dimensions to generate modal parameter feature vectors. High-dimensional embedding is a crucial step in mapping complex parameter distributions to a unified feature space, facilitating subsequent cross-modal analysis. The embedding process employs a deep autoencoder architecture, inputting the original parameter distribution features into the encoder and compressing them into a low-dimensional dense representation through multiple nonlinear transformations while preserving key information. Different modalities utilize dedicated encoder structures; for example, a Transformer-based encoder is used for text parameters, a CNN encoder for image parameters, and a waveform analysis encoder for audio parameters. Encoder training employs reconstruction loss and contrastive learning objectives to ensure that the embedded vectors retain the internal structure of the modality while maximizing the expressive power of cross-modal information. The final generated feature vectors are typically 128-512 dimensions, providing a unified feature representation for inter-modal mutual information analysis.

[0116] Highly coupled parameter pairs between modalities are identified by calculating the mutual information matrix between modal parameter feature vectors. The mutual information matrix is ​​an effective tool for discovering key associations between modalities, quantifying the statistical dependence between parameter pairs. The calculation process first constructs the joint probability distribution and marginal probability distribution of each dimension of the feature vectors, then approximates the probability density using kernel density estimation or histogram methods, and finally calculates the mutual information value. For high-dimensional feature vectors, a block-based calculation strategy is adopted, dividing the vector into semantically related sub-blocks to reduce computational complexity. By setting an appropriate threshold (usually the upper quartile of the mutual information distribution), parameter pairs with significantly higher-than-average mutual information values ​​are selected and marked as highly coupled parameter pairs. These parameter pairs reflect the strong correlation characteristics between different modalities and are a key manifestation of modal coupling, providing important clues for tamper detection.

[0117] Dynamic weighting is applied to highly coupled parameter pairs, and the coupling weight of each pair is determined by the consistency of its fluctuations within the generation time window. Dynamic weighting is an important method for evaluating coupling stability, distinguishing stable coupling from accidental correlations through consistency analysis over time. The weighting process first tracks the temporal trajectory of each highly coupled parameter pair within the generation time window; then, it calculates the fluctuation consistency to quantify the degree of synchronization of the parameter pair's changes; finally, it assigns weights based on the consistency level, with higher consistency resulting in greater weights. The formula is:

[0118] ;in, For parameter pairs and The consistency of fluctuations and For time window The parameter timing segment within, The Pearson correlation coefficient is... This represents the total time duration. This refers to the window size.

[0119] The consistency value ranges from [0,1]. A higher value indicates that the parameters are more synchronized with each other and the coupling is more stable. The coupling weights are normalized to ensure that the sum of all weights is 1, providing a reasonable importance allocation for subsequent feature fusion.

[0120] Based on coupling weights, the feature vectors of highly coupled parameter pairs are weighted and fused to generate modal coupling features. Weighted fusion is the final step in integrating cross-modal information, combining scattered parameter pairs into a unified coupling feature representation. The fusion process employs a combination of attention mechanisms and weighted averaging, considering both global information and highlighting the contributions of key parameter pairs. First, the feature vectors of each highly coupled parameter pair are mapped to a shared feature space through a linear transformation; then, a weighted sum is calculated based on the coupling weights; finally, a nonlinear activation function is used to further extract feature relationships, resulting in the final modal coupling feature vector. This feature vector comprehensively reflects the dependencies and coupling patterns between different modalities, providing a cross-modal perspective for subsequent consistency analysis. It helps identify unnatural associations or breaks between modalities and is an important indicator for detecting AI-synthesized content.

[0121] like Figure 2 The diagram shown illustrates a method for determining potential tampering points. In this embodiment of the invention, the detailed implementation steps of the method for determining potential tampering points include:

[0122] Wavelet transform is applied to the time-axis jump frequencies of the content's end-to-end feature fingerprint to extract high-frequency and low-frequency components. Wavelet transform is an effective tool for analyzing the multi-scale characteristics of time series, capable of simultaneously capturing local details and global trends. The transform process uses the Daubechies wavelet basis, decomposing the original jump frequency sequence into sub-signals of different frequency bands through multi-level decomposition. High-frequency components reflect abrupt changes and abnormal fluctuations in features, typically corresponding to editing operations or content replacement; low-frequency components reflect long-term trends and slow changes in features, typically corresponding to the natural evolution of content. The number of decomposition levels is dynamically adjusted according to the sequence length, typically [number missing]. ,in The sequence length is given. The key advantage of wavelet transform is its ability to accurately locate outliers in time series while preserving both time and frequency information, providing a multi-scale perspective for subsequent jump analysis.

[0123] By analyzing the local peak density of high-frequency components and the trend smoothness of low-frequency components, abrupt changes on the timeline are identified. These abrupt changes are potential indicators of tampering in the time dimension, reflecting unnatural changes in content characteristics. The identification process first analyzes the high-frequency components, calculating the density distribution of local peak points to identify time periods with concentrated peak anomalies; then, it evaluates the low-frequency components, calculating trend smoothness through curve fitting to identify regions of abnormal trend changes; finally, by combining these two indicators, abrupt changes on the timeline are located. The formula for calculating local peak density is:

[0124] ;in, For time points peak density, For the first The time location of each peak point For indicator functions, The radius of the time window. This represents the total number of peak points.

[0125] Trend smoothness is assessed using the variance of the second derivative of the fitted curve; a larger value indicates a more drastic trend change. When the peak density is significantly higher than the background level and the trend smoothness is abnormally low, the corresponding time point is marked as anomaly, providing temporal location for spatial distribution analysis.

[0126] Spatial distribution analysis is performed on jump anomalies. The ratio of spatial dispersion to spatial cluster radius of the feature fingerprint is used to identify anomalous distribution regions on the spatial axis. Spatial distribution analysis is a key step in identifying tampering from the feature space dimension, discovering anomalous patterns by evaluating the geometric characteristics of the feature distribution. The analysis process first projects the feature vectors corresponding to the jump anomalies into a low-dimensional space, using dimensionality reduction techniques such as t-SNE or UMAP to preserve local structure. Then, spatial dispersion is calculated to quantify the dispersion of feature points; simultaneously, the spatial cluster radius is estimated to reflect the natural clustering trend of features. Finally, the ratio of these two indicators is used to identify regions with anomalous feature distribution. Spatial dispersion is calculated using the average distance from the feature point to the centroid, and the spatial cluster radius is estimated using the optimal parameters of a density clustering algorithm. When the ratio of dispersion to cluster radius is significantly higher than normal, the corresponding region is marked as an anomalous distribution region, indicating that the feature distribution does not conform to the statistical regularity of natural content and may contain traces of human tampering or synthesis.

[0127] The intersection of abrupt change anomalies and regions with abnormal distribution is considered as potential tampering points, and false alarms are eliminated through the consistency of contextual features of the anomalies. The final determination of potential tampering points is the result of dual temporal and spatial verification, considering both the anomalousness of temporal changes and the assessment of unnatural patterns in feature distribution. The determination process first calculates the intersection of temporal and spatial anomalies to initially identify highly suspicious regions; then, contextual feature consistency analysis further verifies the rationality of the anomalies. Contextual consistency analysis examines the coherence of features before and after the anomaly point, assessing the naturalness of the change by calculating the similarity gradient of forward and backward features. The consistency score is calculated using the following formula:

[0128] ;in, For point Context consistency score, For point eigenvectors, For similarity function, For time step.

[0129] Points with abnormally low consistency scores were retained as potential tampering points, while points with normal consistency were discarded as false alarms. This multi-dimensional method for identifying tampering points significantly improves detection accuracy, reduces false positives, and provides a reliable basis for subsequent risk assessment.

[0130] In this embodiment of the invention, the detailed implementation steps of the method for assigning values ​​to the tampering probability weights include:

[0131] Kernel density estimation is performed on the differences in feature vector distributions between nodes, and the KL divergence of these differences is calculated as a measure of feature difference. Kernel density estimation is an effective method for fitting parameterless distributions, accurately capturing the complex forms of feature distributions. The estimation process first selects an appropriate kernel function (usually a Gaussian kernel) and bandwidth parameter, then constructs a probability density function based on feature vector samples, and finally calculates the KL divergence between distributions. For high-dimensional features, dimensionality reduction preprocessing and piecewise estimation strategies are used to reduce computational complexity. KL divergence, as a classic measure in information theory, intuitively reflects the degree of dissimilarity between two distributions; a larger value indicates a more significant distribution difference. The KL divergence calculation uses the Monte Carlo integration method for approximation. The feature difference measure directly reflects the degree of change in content features between nodes, providing an important basis for assessing the probability of tampering from a distributional perspective.

[0132] Entropy analysis is performed on the link hopping frequency between nodes. The ratio of the distributed entropy of the hopping frequency to the average hopping interval is used to determine the measure of link discontinuity. Entropy analysis is a classic method for evaluating signal complexity and uncertainty; its application to link hopping frequency effectively quantifies the irregularity of content changes. The analysis process first treats link hopping events as a time series and calculates the statistical distribution of hopping intervals; then, it calculates the distributed entropy, reflecting the complexity of the hopping pattern; simultaneously, it calculates the average hopping interval, reflecting the overall frequency of hopping; finally, the ratio of the two is used to derive the measure of link discontinuity. For discrete distributions, the formula is:

[0133] ;in, For distribution The entropy value, For the event The probability, It is a distribution Specific events in the text.

[0134] Discontinuity measures directly reflect the degree of abnormality in content changes. A combination of high entropy and low interval usually indicates unnatural and frequent changes, which may suggest tampering behavior and provide key information from a temporal perspective for tampering probability assessment.

[0135] The normalized results of feature difference measures and link discontinuity measures are weighted and fused to generate the joint probability between nodes. Weighted fusion is a key step in synthesizing multidimensional evidence, integrating information from different perspectives through reasonable weight allocation. The fusion process first normalizes the feature difference measures and discontinuity measures to eliminate dimensional differences and map them to a unified [0,1] interval; then, weight coefficients are set according to content type and analysis objectives to reflect the relative importance of different measures in a specific scenario; finally, the joint probability is calculated through weighted averaging. Normalization typically uses Min-Max or Z-score methods, while weight settings are based on prior knowledge or cross-validation optimization. The formula for calculating the joint probability is:

[0136] ;in, The joint probability among nodes. The normalized KL divergence, As a measure of discontinuity after normalization, and These are the weighting coefficients, and .

[0137] The joint probability integrates anomalous information from both the distribution and temporal dimensions, providing a comprehensive basis for the final quantification of the tampering probability.

[0138] Based on the joint probability, tampering probability weights between nodes are generated through a softmax function mapping. The softmax mapping is the final step in transforming the joint probability into standardized weights, ensuring a reasonable weight distribution with probabilistic interpretability. The mapping process first applies the softmax function to the joint probability of all outgoing edges of each node, converting the original values ​​into a probability distribution within the interval [0,1] with a sum of 1; then, global scaling is performed to adjust the overall weight distribution range, ensuring that high-probability edges are significantly distinguished from low-probability edges. The formula for calculating the softmax function is:

[0139] ;in, For the node To the node The probability weight of tampering For the corresponding joint probability, Temperature is a parameter that controls the steepness of the probability distribution. Traversing nodes All outgoing target nodes.

[0140] Temperature parameters Typically set between 1 and 5, the larger the value, the more concentrated the weight distribution is on high-probability edges, which is more conducive to highlighting the main tampering paths. The final tampering probability weights intuitively reflect the credibility of the tampering relationship between nodes, providing a quantitative basis for the construction and analysis of the source tracing graph.

[0141] In this embodiment of the invention, the detailed implementation steps of the risk propagation simulation method include:

[0142] Graph embedding is performed on a multimodal content tracing graph to generate low-dimensional feature vectors for graph nodes. Graph embedding is an effective dimensionality reduction technique for handling complex graph structures, compressing high-dimensional graph information into computationally pleasing vector representations. The embedding process employs Graph Neural Network (GNN) techniques, such as GraphSAGE or GAT, which learn the contextual information and structural features of nodes through a message-passing mechanism. Specifically, node features are first initialized using original node attributes such as timestamps, location information, and feature vectors. Then, feature propagation and aggregation are performed through multiple layers of GNNs, with each layer incorporating neighborhood information to update the node representation. Finally, the embedding quality is optimized through multi-task learning objectives, while maintaining node similarity and graph structural integrity. The embedding dimension is typically set to 64-256, dynamically adjusted according to the graph size and complexity. The low-dimensional feature vectors preserve the semantic information of the nodes and encode the topological relationships of the graph structure, providing an efficient computational foundation for subsequent random walks.

[0143] Based on low-dimensional feature vectors, multiple propagation paths are generated using a random walk algorithm, and the visit frequency of each node along the path is recorded. Random walk is a classic method for simulating risk propagation, reflecting the randomness and tendency of risk diffusion through probabilistic path generation. The walk process starts from the high-risk source node, and the probability of the next transition is determined based on the tampering probability weight of the outgoing edges, simulating the path of risk propagation along the network. To improve the accuracy of the simulation, a second-order random walk strategy is adopted, considering the joint influence of the current position and the previous position to better capture the inertia and directionality of propagation. The number of walk steps is usually set to 3-5 times the graph diameter to ensure coverage of the main propagation range; the number of repetitions is set to 10-20 times the number of nodes to ensure the reliability of the statistical results. After each walk, the visit status of each node along the path is recorded, and the accumulated visit frequency statistics are used to intuitively reflect the participation and importance of nodes in the risk propagation process.

[0144] Path entropy analysis is performed on propagation paths to determine their propagation stability by using the ratio of path entropy to path length. Path entropy analysis is an important method for assessing the regularity of propagation, quantifying the structural characteristics and change patterns of the path through information theory. The analysis process first treats each propagation path as a sequence of nodes, calculating the conditional entropy of the node transition probabilities to reflect the uncertainty and complexity of the path; then, it considers the path length factor, eliminating the influence of length differences by using the ratio of entropy to length; finally, it derives a propagation stability index to assess the predictability and consistency of risk propagation. The formula for calculating path entropy is:

[0145] ;in, For path The entropy value, For the path Middle node Followed by nodes The conditional probability, This represents the path length.

[0146] Propagation stability is inversely proportional to path entropy. Paths with high stability are usually characterized by low entropy and high regularity, and are the main channels for risk propagation. They have higher reference value for calculating the probability of tampering and diffusion.

[0147] Based on propagation stability and access frequency, the tampering propagation probability of each node in the graph is calculated, and high-risk propagation subgraphs are identified through the spatial distribution characteristics of the propagation probability. Tampering propagation probability is a core indicator of risk assessment, directly reflecting the likelihood and extent to which a node is affected by tampering. The calculation process first comprehensively assesses the importance of a node in risk propagation based on its access frequency and the stability of the paths it participates in; then, through normalization, the original scores are converted into standardized probability values; finally, the propagation probability distribution of all nodes in the graph is formed. The calculation formula is:

[0148] ;in, For nodes The probability of tampering and diffusion. For access frequency, For containing nodes The set of all paths For path Stability score, This refers to all nodes in the graph.

[0149] Based on the diffusion probability distribution, connected regions with probability values ​​significantly higher than the background level were identified through community detection algorithms and density threshold analysis, and marked as high-risk propagation subgraphs. These subgraphs are key areas where tampering impact is concentrated, typically reflecting the scope and propagation pattern of specific types of tampering, providing a structured perspective for subsequent risk classification and intervention strategies.

[0150] In this embodiment of the invention, the system further includes:

[0151] A comprehensive content traceability and verification database is constructed, comprising original feature fingerprints of multimodal content, tampering point distribution characteristics, and statistical characteristics of risk propagation paths. This database is a core component of the system's knowledge accumulation, continuously learning and updating to improve detection capabilities. The construction process first designs a multi-layered data structure, including a bottom-level original feature storage layer, a middle-level tampering feature index layer, and a top-level propagation pattern summary layer. Then, through an online learning mechanism, new results from system analysis are continuously integrated into the database, forming a dynamically growing knowledge base. Simultaneously, regular cleaning and optimization are implemented to ensure the database's accuracy and efficiency. Feature fingerprints are stored using compressed encoding, tampering point distribution is organized using spatial indexing technology, and propagation paths are managed through a graph database. The database not only stores detailed features of known tampering cases but also includes typical patterns and evolutionary trends of various tampering techniques, providing a rich reference foundation for rapid traceability and matching.

[0152] By using a content end-to-end source tracing verification database, new input multimodal content is rapidly source-traced and matched to identify historical tampering patterns within the content chain. Rapid source tracing and matching is a key technology for improving detection efficiency, quickly locating possible tampering types and sources through pattern matching. The matching process first extracts the feature fingerprints of new content, then performs multi-level searches in the database, gradually narrowing the candidate range from coarse-grained type matching to fine-grained pattern comparison; finally, similarity calculations identify the degree of matching with historical cases, determining possible tampering patterns. The search employs hierarchical indexing and an approximate nearest neighbor algorithm, significantly improving query efficiency for large-scale databases. Matching results include the most similar historical cases, matching scores, and suggestions for possible tampering types, providing valuable prior information for subsequent analysis, accelerating the source tracing process, and improving detection accuracy and efficiency.

[0153] Based on the matching results of historical tampering patterns, the node weights and path strengths of the multimodal content tracing graph are dynamically adjusted to optimize the real-time performance and accuracy of the tracing graph. Dynamic graph adjustment is an adaptive mechanism to improve tracing accuracy, guiding current analysis through historical experience. The adjustment process first identifies feature regions in the current content similar to historical patterns based on the matching results; then, based on the confidence level of the matching, the weights of relevant nodes and path strengths in the tracing graph are adjusted, strengthening the importance of high-confidence regions and weakening the influence of uncertain regions; finally, the key indicators of the graph are recalculated to ensure that the adjusted graph structure better reflects actual tampering situations. The adjustment strategy employs a Bayesian update framework, using historical matching as prior information and combining it with current observational evidence to obtain more accurate posterior estimates. This dynamic optimization mechanism enables the system to continuously learn and adapt to new tampering techniques and patterns, maintaining the advanced nature and effectiveness of its detection capabilities.

[0154] The optimized source map results are combined with the content security risk detection results to provide a content chain integrity verification report. This integrity verification report is the system's final output, comprehensively showcasing the content's security status and source tracing evidence. The report generation process first integrates the optimized source map with risk detection results to form a unified security assessment view. Then, based on different user needs, multi-level report content is generated, ranging from a concise risk level overview to detailed technical analysis evidence. Finally, visualization technology is used to intuitively display the complex map structure and risk distribution, facilitating understanding and decision-making. The report content includes key information such as content authenticity scoring, tampering area marking, risk propagation path analysis, tampering technology determination, and risk level recommendations, providing comprehensive technical support for content review, digital forensics, and security decision-making. The report output supports multiple formats and interfaces, facilitating integration with other security systems to form a complete content security protection system.

[0155] This invention achieves end-to-end security risk tracing and detection of multimodal AI content through multi-source data acquisition, feature fingerprint construction, consistency analysis, source mapping construction, and risk identification and verification. The graph-based source tracing method of this invention can accurately locate the source of tampering and the propagation path, effectively identify the security risks of synthetic content, and provide a systematic solution for verifying the authenticity of digital content.

[0156] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

[0157] It should be noted that all formulas in this manual are calculated by removing dimensions and taking their numerical values. The formulas are derived from software simulations based on a large amount of collected data to obtain the most recent real-world results. The preset parameters and thresholds in the formulas are set by those skilled in the art according to the actual situation.

[0158] Although embodiments of the invention have been shown and described, those skilled in the art will understand that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the claims and their equivalents.

Claims

1. A multimodal AI content security risk tracing and identification system, characterized in that, include: The multi-source data acquisition module is used to acquire multi-source heterogeneous data of the multimodal content to be detected in the entire chain of creation and distribution. The multi-source heterogeneous data includes metadata in the content generation stage, operation logs in the editing stage, network transmission characteristics in the distribution stage, and user interaction behavior data in the terminal presentation stage. The feature fingerprint construction module is used to construct a content full-link feature fingerprint based on the spatiotemporal distribution characteristics of data at each stage in the multi-source heterogeneous data. The content full-link feature fingerprint includes modal coupling features of the generation stage, operation sequence patterns of the editing stage, topology propagation features of the distribution stage, and behavioral response patterns of the terminal presentation stage. The consistency analysis module is used to extract potential tampering points and risk propagation paths by analyzing the cross-modal consistency and link continuity of features at each stage in the full-link feature fingerprint of the content. The source map construction module is used to construct a multimodal content source map based on the distribution characteristics of the potential tampering points and risk propagation paths. The multimodal content source map includes the tampering probability weights between nodes and the risk transmission intensity between paths. The risk identification and verification module is used to identify synthetic tampering risks in the content chain based on the multimodal content tracing map and the multimodal content security risk classification model, and output the integrity verification results of the tracing chain.

2. The multimodal AI content security risk tracing and identification system according to claim 1, characterized in that, The constructed content full-link feature fingerprint includes: Modal decomposition is performed on the metadata in the generation stage to extract the generator parameter distribution characteristics of multimodal data, and modal coupling characteristics are determined by calculating the mutual information of parameters between modes. The operation logs during the editing phase are serialized and modeled to identify non-linear jump patterns in the operation sequence. The operation sequence patterns are extracted through periodic fluctuation analysis of operation timestamps. The network transmission characteristics during the distribution phase are topologically embedded to construct a dynamic propagation graph of the distribution network, and the topological propagation characteristics are extracted through propagation delay between nodes and data packet integrity verification. Behavioral clustering is performed on user interaction behavior data during the terminal presentation stage to identify time-series anomalies in the interaction behavior, and behavioral response patterns are extracted based on the contextual correlation strength of the anomalies. The modal coupling features, operation sequence patterns, topology propagation features, and behavioral response patterns are aligned across stages to generate a content full-link feature fingerprint.

3. The multimodal AI content security risk tracing and identification system according to claim 1, characterized in that, The extraction of potential tampering points and risk propagation paths includes: Cross-modal consistency checks are performed on the features at each stage of the full-link feature fingerprint of the content, the cosine similarity of the feature vectors between modes is calculated, and cross-modal inconsistency regions are identified by the local extrema of the similarity. Link continuity analysis is performed on the cross-modal inconsistency region, and potential tampering points are identified by the jump frequency of the feature fingerprint on the time axis and the distribution dispersion on the spatial axis. Based on the location distribution of the potential tampering points, a risk propagation path map is constructed. The risk propagation path map determines the risk propagation path by weighting the propagation directionality and propagation intensity between potential tampering points. The path stability of the risk propagation path is verified by introducing path reconstruction error after random perturbation, eliminating unstable paths and retaining high-confidence risk propagation paths.

4. The multimodal AI content security risk tracing and identification system according to claim 1, characterized in that, The construction of the multimodal content tracing map includes: The potential tampering points are used as graph nodes, and directed edges between nodes are constructed based on the feature similarity and temporal relationship between nodes. The directed edge is assigned a tampering probability weight, which is calculated based on the joint probability of the distribution difference of feature vectors between nodes and the link jump frequency. The risk propagation path is quantified by measuring the risk transmission intensity of the path. The risk transmission intensity between paths is determined by the normalized ratio of the cumulative tampering probability weight of each node on the path to the path length. Based on the aforementioned tampering probability weights and risk transmission intensity, a multimodal content tracing map is constructed, and through connectivity analysis of the map, isolated tampering regions and high-risk propagation regions in the link are identified.

5. The multimodal AI content security risk tracing and identification system according to claim 1, characterized in that, The risks of synthetic tampering in the content identification chain include: A security risk classification model for multimodal content is constructed. The security risk classification model takes the full-link feature fingerprint of the content as input, extracts graph features through a multi-layer graph convolutional network, and combines an attention mechanism to weight high-risk nodes. Risk propagation simulation was performed on the multimodal content tracing map, and the tampering and diffusion probability of each node in the map was calculated by a random walk algorithm; Based on the output of the aforementioned tampering diffusion probability and security risk classification model, synthetic tampering risks in the content chain are identified, and the main modal sources of tampering are determined through modal contribution analysis of tampering risks. The risk level of the synthetic tampering is classified, and the risk level and the corresponding traceability evidence chain are output by weighted combination of the tampering diffusion probability and the tampering impact range.

6. The multimodal AI content security risk tracing and identification system according to claim 2, characterized in that, The method for extracting the modal coupling features includes: High-dimensional embedding is performed on the generator parameter distribution features of each modality data to generate modal parameter feature vectors; Highly coupled parameter pairs between modes are identified by calculating the mutual information matrix between the eigenvectors of modal parameters. The highly coupled parameter pairs are dynamically weighted, and the coupling weight of each parameter pair is determined by the consistency of the fluctuations of the parameter pairs within the generation time window. Based on the coupling weights, the feature vectors of highly coupled parameter pairs are weighted and fused to generate modal coupling features.

7. The multimodal AI content security risk tracing and identification system according to claim 3, characterized in that, The method for determining potential tampering points includes: Wavelet transform is performed on the time axis jump frequency of the full-link feature fingerprint of the content to extract the high-frequency and low-frequency components of the jump frequency; By comparing the local peak density of high-frequency components with the trend smoothness of low-frequency components, abrupt change points on the time axis are identified. Spatial distribution analysis is performed on the jump anomalies, and the distribution anomaly regions on the spatial axis are determined by the ratio of the spatial dispersion of the feature fingerprint to the spatial clustering radius. The intersection of the jump anomaly points and the distribution anomaly regions is taken as potential tampering points, and false alarm points are eliminated by the consistency of the context features of the anomaly points.

8. The multimodal AI content security risk tracing and identification system according to claim 4, characterized in that, The method for assigning the tampering probability weights includes: Kernel density estimation is performed on the differences in feature vector distributions between nodes, and the KL divergence of the distribution differences is calculated as a measure of feature differences. Entropy analysis is performed on the link hopping frequency between nodes. The link discontinuity metric is determined by the ratio of the distribution entropy of the hopping frequency to the average hopping interval. The normalized results of the feature difference measure and the link discontinuity measure are weighted and fused to generate the joint probability between nodes; Based on the joint probability, the tampering probability weights between nodes are generated through a softmax function mapping.

9. A multimodal AI content security risk tracing and identification system according to claim 5, characterized in that, The method for simulating risk propagation includes: Graph embedding is performed on the multimodal content tracing graph to generate low-dimensional feature vectors for the graph nodes; Based on the low-dimensional feature vector, multiple propagation paths are generated using a random walk algorithm, and the access frequency of each node on the path is recorded. Path entropy analysis is performed on the propagation path, and the propagation stability of the path is determined by the ratio of path entropy to path length. Based on the propagation stability and access frequency, the tampering and diffusion probability of each node in the graph is calculated, and the high-risk propagation subgraphs in the graph are identified by the spatial distribution characteristics of the diffusion probability.

10. The multimodal AI content security risk tracing and identification system according to claim 1, characterized in that, The system also includes: Construct a content full-chain traceability and verification database, which includes the original feature fingerprints of multimodal content, the distribution characteristics of tampering points, and the statistical characteristics of risk propagation paths; By using the content full-link traceability and verification database, new input multimodal content can be quickly traced and matched to identify historical tampering patterns in the content link; Based on the matching results of historical tampering patterns, the node weights and path strengths of the multimodal content tracing graph are dynamically adjusted to optimize the real-time performance and accuracy of the tracing graph. The optimized results of the source tracing map are combined with the detection results of content security risks to provide a report on the integrity of the content chain.

Citation Information

Patent Citations

  • False news detection method fusing propagation features and multi-modal content features

    CN118377974A

  • Network content propagation method and system based on fusion cognitive understanding and intelligent treatment

    CN119939229A