A distributed data security early warning method

By constructing a spoofing path generation and structural offset identification mechanism, the problem that consensus mechanisms in distributed data systems cannot identify consistency spoofing errors is solved, and dynamic identification and scheduling control of potential abnormal paths are realized, thereby improving the robustness and policy controllability of the system.

CN120880876BActive Publication Date: 2026-01-23北京晟达伟华信息科技有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511074510.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-01
Publication Date
2026-01-23
Estimated Expiration
2045-08-01

AI Technical Summary

Technical Problem

The consensus mechanism of existing distributed data processing systems cannot identify errors in the consistency of node results, leading to dangerous states remaining latent for a long time and affecting the stability of task scheduling and control response.

Method used

By constructing a mechanism for generating spoofed paths, identifying structural offsets, and determining consensus paths, the system proactively identifies path outcomes that are structurally consistent but behaviorally spoofed. This bypasses the traditional judgment method that relies on differences in outcomes. By employing techniques such as path feature fragment sets, spoofed input-induced modeling, adversarial path generation, and path acceptance state recognition, the system generates a structural offset index matrix and a path behavior response evolution diagram, enabling dynamic identification and scheduling control of potentially abnormal paths.

Benefits of technology

It enables the identification of structural consistency errors, improves the accuracy of risk state modeling and the robustness of distributed task execution, enhances the dynamic identification of potential abnormal paths, and ensures the stability of task scheduling and the controllability of strategies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120880876B_ABST
    Figure CN120880876B_ABST
Patent Text Reader

Abstract

The application discloses a kind of distributed data security early warning methods, specifically related to distributed data early warning technical field, including obtaining the task instruction sequence execution structure extraction operation in distributed data node and carrying out structure generation processing, generates path expression graph, carries out fragment frequency statistics and structure position aggregation operation to path expression graph, outputs path characteristic fragment set;Based on the path characteristic fragment set executes camouflage input induction modeling operation and then carries out the operation of generating the path of confrontation, outputs camouflage path set, combined with path expression graph executes path input combination construction operation, outputs task execution path input combination;By constructing camouflage path generation, structure deviation identification and consensus path determination mechanism, the path result of active identification structure consistency but behavior camouflage, bypass traditional only rely on the judgment mode of result difference, to solve the problem that consensus mechanism cannot identify potential consistency camouflage error in background art.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of distributed data early warning, more specifically, the present application relates to a distributed data security early warning method. BACKGROUND

[0002] The error detection mechanism in the current distributed data processing system generally adopts a result consistency judgment method based on a consensus model. Paxos, Raft and PBFT type algorithms reach an agreement through majority voting of multiple nodes to confirm the validity of the data state and the stability of the system state.

[0003] The majority voting principle is based on the assumption that consistency is reliable. If the results obtained by multiple nodes independently performing the same task remain consistent, the system will determine that there is no abnormal state and enter the normal writing, execution or dispatch process. The consensus mechanism error detection relies on the difference in node results to trigger the response operation. When the results have deviations, omissions, sequence disorders or feedback timeouts, the system starts the retransmission, arbitration or fault tolerance module to repair or block the processing.

[0004] Therefore, in the current consensus mechanism design, errors are equivalent to "inconsistency of results between nodes" or "partial node failure to participate in consensus". The danger prediction technology requires the system to perceive the error trend and potential risk source in advance. In multi-source high-collaboration scenarios such as financial transaction networks, intelligent transportation infrastructure, weather simulation platforms, multiple nodes may be induced to load consistent initial data, accept uniform synchronization timing or respond to similar input disturbances, thereby independently producing completely consistent error outputs without communication negotiation.

[0005] The consensus mechanism only checks the consistency of node results and does not analyze the node execution path, input logic or timing response structure. Therefore, the system will still output a high-confidence judgment of "consensus" in a highly consistent error field. The danger prediction algorithm often relies on error evolution, trend deviation, statistical outliers and other signals to trigger risk judgment. Independent error results will not meet the deviation condition and will not activate any abnormal judgment mechanism. The system does not show observable abnormalities in the output logic, state feedback and control response link. The dangerous state will be long-term latent in the consensus path with "zero abnormality characteristics", which will eventually affect the stability of task scheduling, strategy deployment and control closed loop.

[0006] As can be seen, the consensus mechanism constructs error detection logic based on result consistency, does not verify the behavior source of result consistency, does not analyze the execution structure of the consensus path, and when nodes independently produce consistent error results, the system will identify the error as a normal state. The danger prediction mechanism cannot perceive the consensus camouflage behavior, and the error enters the unforecastable deep execution link. SUMMARY

[0007] In order to overcome the above-mentioned defects of the prior art, embodiments of the present application provide a distributed data security early warning method, which actively identifies path results with consistent structure but behavior camouflage by constructing a camouflage path generation, structure deviation identification and consensus path determination mechanism, bypassing the traditional judgment method which only relies on result difference, to solve the problem that the consensus mechanism in the background art cannot identify potential consistent camouflage errors.

[0008] To achieve the above object, the present application provides the following technical scheme: a distributed data security early warning method, comprising:

[0009] S1: obtaining the task instruction sequence in the distributed data node, performing structure generation processing after the structure extraction operation, generating a path expression graph, performing fragment frequency statistics and structure position aggregation operations on the path expression graph, and outputting a path feature fragment set;

[0010] S2: performing camouflage input induction modeling operation based on the path feature fragment set to generate an anti-path, outputting a camouflage path set, combining the path expression graph to perform path input combination construction operation, and outputting a task execution path input combination;

[0011] S3: performing path acceptance state identification operation and camouflage path extraction operation on the task execution path input combination, outputting the accepted camouflage path set, combining the path expression graph to perform structure comparison analysis, generating a structure deviation index matrix, and performing matrix fusion operation with the path determination response set to output a consistency structure response matrix;

[0012] S4: performing structure camouflage path identification and credibility analysis operation on the consistency structure response matrix, combining the path expression graph to perform structure matching operation, outputting a path behavior response evolution graph, and performing joint judgment on the path behavior response evolution graph to judge whether the current path result is available or not;

[0013] S5: performing path sorting priority modeling operation on the path with the judgment result of available and the path behavior response evolution graph to construct a path control structure, and outputting a path control execution structure.

[0014] In a preferred embodiment, in S1, the task instruction sequence in the distributed data node is obtained, the task instruction sequence includes state transition trajectory, input trigger chain and jump sequence, the structure extraction operation is performed on the task instruction sequence, and the path information set is output, the path information set includes behavior jump distribution, input segment response structure and state evolution fragment;

[0015] The structure generation processing is performed on the path information set, and the path expression graph is output, the path expression graph includes structure expression layer, jump chain layer and response flow layer;

[0016] The fragment frequency statistics and structure position aggregation operation is performed on the path expression graph to output a path feature fragment set, and the path feature fragment set includes a jump repeat fragment, a synchronous trigger sub-path, and an input stream segmentation chain.

[0017] In a preferred embodiment, the fragment frequency statistics and structure position aggregation operation in S1 further includes performing frequency statistics in the full path range on the jump sequence with a frequency higher than a preset threshold based on the jump chain layer in the path expression graph, marking the jump structure fragment that repeatedly appears in different task paths, and outputting the jump repeat fragment.

[0018] The aggregation operation is performed based on the trigger precondition and position distribution characteristics of the jump structure fragment to identify a path fragment group with a common trigger mode and extract a synchronous trigger sub-path from the path fragment group.

[0019] The structure classification and function screening operation is performed on the common structure fragment involving the input segment behavior in the input segment response structure to screen out a typical input stream structure with reorganization value in task control, and output an input stream segmentation chain.

[0020] The jump repeat fragment, the synchronous trigger sub-path, and the input stream segmentation chain are combined to form the path feature fragment set.

[0021] In a preferred embodiment, in S2, the camouflage input induction modeling operation is performed based on the path feature fragment set to output a perturbation input mapping group, and the perturbation input mapping group includes an input induction position, a structure rearrangement section, and a behavior perturbation trigger point.

[0022] The adversarial path generation operation is performed on the perturbation input mapping group to output a camouflage path set.

[0023] The path input combination construction operation is performed on the camouflage path set and the path expression graph to output a task execution path input combination.

[0024] In a preferred embodiment, the adversarial path generation operation in S2 further includes constructing a camouflage path based on the perturbation input mapping group, establishing a structure perturbation generator model, embedding the input induction position, the structure rearrangement section, and the perturbation trigger point into the structure perturbation generator model as a perturbation vector, performing a perturbation path construction modeling at the input level, and outputting a preliminary camouflage path set.

[0025] The path expression graph is taken as a real path reference set, the structure feature parameters of the structure expression layer and the jump chain layer are extracted, and a path structure discriminator is trained.

[0026] The structure disturbance generator model is associated with the path structure discriminator to construct a path-level generative adversarial network, the structure disturbance generator model disturbance strategy is optimized through multiple rounds of adversarial optimization, and a set of camouflage paths with consistent structure and consistent judgment is output.

[0027] In a preferred embodiment, in S3, distributed data consensus judgment is performed on the task execution path input combination, and a path admission state identification operation is performed to output a path judgment response set;

[0028] The path judgment response set is subjected to a camouflage path extraction operation to output an accepted camouflage path set;

[0029] The accepted camouflage path set is subjected to a structure comparison analysis with the path expression graph to output a structure deviation index matrix;

[0030] The structure deviation index matrix is subjected to a matrix fusion operation in combination with the path judgment response set to output a consistent structure response matrix.

[0031] In a preferred embodiment, the structure comparison analysis in S3 further includes a multi-layer structure feature alignment process performed on the accepted camouflage path set from the distributed data consensus judgment and the path expression graph, based on which a graph embedding representation of the camouflage path set and the path expression graph is output, the graph embedding representation being based on structure expression layer and jump chain layer extracted node nesting order, jump mode and state response sequence, and other structure features.

[0032] The graph embedding representation of the camouflage path set and the path expression graph is subjected to training sample construction to generate a graph comparison training sample set, a graph structure comparison neural network model is initialized, a structure alignment encoder and a multi-dimensional similarity discrimination function are constructed, the graph comparison training sample set is subjected to model training based on the structure alignment encoder and the multi-dimensional similarity discrimination function, and a graph structure comparison neural network model is output, which is used to perform a difference judgment operation on the camouflage path set and the path expression graph to generate a structure deviation index matrix.

[0033] In a preferred embodiment, in S4, a structure camouflage path identification and credibility analysis operation is performed on the consistent structure response matrix to output a path credibility weakening identification set;

[0034] The path credibility weakening identification set is subjected to a structure matching operation with the path expression graph to output a path behavior response evolution graph, the path behavior response evolution graph including state change trend, control response difference and input behavior deviation trajectory.

[0035] In a preferred embodiment, S4 further includes jointly judging the path behavior response evolution graph in the distributed data task execution background, judging whether the state change trend exceeds the preset state change trend threshold, whether the control response difference exceeds the preset control response difference threshold, and whether the input behavior offset trajectory exceeds the preset input behavior offset trajectory threshold, as three judgment conditions;

[0036] If the three conditions all meet the corresponding judgment conditions, it is determined that the current path result is not available, the path elimination processing is performed, and the path input combination construction operation is re-executed, otherwise it is determined that the current path result is available.

[0037] In a preferred embodiment, in S5, the path with a determination result of being available is subjected to path ranking priority modeling operation with the path behavior response evolution graph, and a path execution priority graph is output, the path execution priority graph including a trusted path ranking structure, a reduced weight path record, and a strategy rollback parameter;

[0038] The path execution priority graph is subjected to path control structure construction operation, and a path control execution structure is output.

[0039] Technical effects and advantages of the present application:

[0040] 1. The scheme introduces a camouflage path mixing and structure offset analysis mechanism in a distributed data environment, breaks through the technical limitation of equating errors to node result inconsistencies in the consensus mechanism, and realizes the identification ability of structural consistent errors;

[0041] 2. The structural offset index matrix is constructed based on multi-layer structure alignment and graph embedding fusion operation, the structural variation degree of the camouflage path is described, and the accuracy of risk state modeling is improved;

[0042] 3. The behavior situation awareness of the risk path is realized through the joint construction of the trustworthiness weakening identifier and the behavior evolution feature, and the dynamic identification ability of the potential abnormal path is enhanced;

[0043] 4. Based on the construction of the path execution priority graph and the scheduling control structure, the path scheduling robustness and strategy controllability of the distributed task execution are improved. BRIEF DESCRIPTION OF DRAWINGS

[0044] Figure 1 The method step framework flowchart of the present application;

[0045] Figure 2 The path graph generation flowchart of the present application;

[0046] Figure 3 The camouflage path construction flowchart of the present application;

[0047] Figure 4A structure deviation modeling flowchart for the present application;

[0048] Figure 5 A trustworthiness determination flowchart for the present application;

[0049] Figure 6 A path scheduling control flowchart for the present application. DETAILED DESCRIPTION

[0050] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative work fall within the protection scope of the present application.

[0051] With reference to the drawings in the description Figures 1-6 A distributed data security early warning method according to an embodiment of the present application includes:

[0052] S1: After a structure generation process is performed on a task instruction sequence execution structure extraction operation in a distributed data node, a path expression graph is generated, a path feature fragment set is output by performing a fragment frequency statistics and structure position aggregation operation on the path expression graph;

[0053] S2: After a pseudo input induction modeling operation is performed based on the path feature fragment set, an adversarial path is generated, a pseudo path set is output, a path input combination construction operation is performed in combination with the path expression graph, and a task execution path input combination is output;

[0054] S3: A path admission state recognition operation and a pseudo path extraction operation are performed on the task execution path input combination, an accepted pseudo path set is output, a structure comparison analysis is performed in combination with the path expression graph, a structure deviation index matrix is generated, a matrix fusion operation is performed in combination with a path determination response set, and a consistency structure response matrix is output;

[0055] S4: After a structure pseudo path recognition and trustworthiness analysis operation is performed on the consistency structure response matrix, a structure matching operation is performed in combination with the path expression graph, a path behavior response evolution graph is output, and a joint determination is performed on the path behavior response evolution graph to determine whether a current path result is unusable or usable;

[0056] S5: After a path sorting priority modeling operation is performed on the path with a determination result of being usable and the path behavior response evolution graph, a path control structure is constructed, and a path control execution structure is output.

[0057] In S1, a task instruction sequence in a distributed data node is acquired, the task instruction sequence includes a state transition trajectory, an input trigger chain and a jump sequence, a structure extraction operation is performed on the task instruction sequence, and a path information set is output, the path information set includes a behavior jump distribution, an input segment response structure and a state evolution segment, wherein the structure extraction operation refers to performing item-by-item analysis and structured processing on the state transition trajectory, the input trigger chain and the jump sequence recorded in the task instruction sequence, identifying instruction jump patterns, input response logic and state change nodes in the task execution process, extracting a path information set composed of the behavior jump distribution, the input segment response structure and the state evolution segment, the path information set is used to reflect the structural characteristics of the task execution process, and serves as an original basis for constructing a behavior chain structure in danger prediction;

[0058] A structure generation process is performed on the path information set, and a path expression graph is output, the path expression graph includes a structure expression layer, a jump chain layer and a response flow layer, wherein the structure generation process refers to taking the behavior jump distribution, the input segment response structure and the state evolution segment in the path information set as input, performing structure mapping, level merging and segment division operations according to the topological characteristics of the jump chain, the boundary mode of the input response section and the timing rules of the state change paragraph respectively, and generating three layers of structure, namely the structure expression layer, the jump chain layer and the response flow layer, the three layers of structure together constitute a path expression graph with unified format, which is used to express the overall form of the task execution process in terms of structural organization, control flow path and input response flow, and serves as a path structure basis for establishing a camouflage identification reference standard in danger prediction;

[0059] A segment frequency statistics and structure position aggregation operation is performed on the path expression graph, and a path feature segment set is output, the path feature segment set includes a jump repetition segment, a synchronous trigger sub-path and an input flow segmentation chain.

[0060] The segment frequency statistics and structure position aggregation operation in S1 further includes that based on the jump chain layer in the path expression graph, a frequency statistics is performed on a jump sequence with a frequency higher than a preset threshold in a full path range, a jump structure segment repeatedly appearing in different task paths is marked, and a jump repetition segment is output.

[0061] An aggregation operation is performed based on trigger precondition and position distribution characteristics of the jump structure segment, a path segment group with a common trigger mode is identified, and a synchronous trigger sub-path is extracted from the path segment group;

[0062] A structure classification and function screening operation is performed on a common structure segment of the input segment behavior in the input segment response structure, a typical input flow structure with reorganization value in task control is screened out, and an input flow segmentation chain is output.

[0063] The jump repeat segment, the synchronous trigger sub-path and the input stream segment chain are combined to form a path feature segment set as a structural reorganization basis for constructing a camouflage path in risk prediction.

[0064] In S2, a camouflage input induction modeling operation is performed based on the path feature segment set, and a perturbation input mapping group is output, the perturbation input mapping group including an input induction position, a structural rearrangement segment and a behavior perturbation trigger point. The camouflage input induction modeling operation refers to, after obtaining the path feature segment set, analyzing the trigger precondition, input timing mode and response state change of the corresponding task for each jump repeat segment, synchronous trigger sub-path and input stream segment chain of the path, constructing an input construction rule that triggers a similar structural response but has a perturbation feature, generating a mapping relationship set, establishing a mapping relationship between the segments in the path feature segment set and the input induction position, structural rearrangement segment and perturbation trigger point, and forming a perturbation input mapping group for realizing structural interference at the input level and result camouflage in the camouflage path generation.

[0065] An adversarial path generation operation is performed on the perturbation input mapping group, and a camouflage path set is output.

[0066] A path input combination construction operation is performed on the camouflage path set and the path expression graph, and a task execution path input combination is output. The path input combination construction operation refers to recombining and fusing the input perturbation strategy in the camouflage path set with the real input structure in the path expression graph to generate a task execution path input set for identifying the risk of accepting a camouflage path in distributed data consensus judgment.

[0067] The adversarial path generation operation in S2 further includes constructing a structural disturbance generator model by performing a camouflage path construction on the perturbation input mapping group, embedding the input induction position, structural rearrangement segment and perturbation trigger point into the structural disturbance generator model as a disturbance vector, performing input-level disturbance path construction modeling, and outputting a preliminary camouflage path set.

[0068] The path expression graph is used as a real path reference set to extract structural feature parameters of the structural expression layer and the jump chain layer, and a path structure discriminator is trained to determine whether the path is consistent with the real path structure.

[0069] The structural disturbance generator model and the path structure discriminator are combined to construct a path-level adversarial generation network, the disturbance strategy of the structural disturbance generator model is optimized through multiple rounds of adversarial optimization, and a camouflage path set with structural deviation but consistent determination is output, which is used to simulate the structural camouflage mixing behavior in the distributed data task execution process in risk prediction.

[0070] It should be noted that for the formula structure involved in the present scheme, the dimensionless term can be used as a proportional or structural adjustment factor. When combined with quantities with units, it only plays a numerical scaling role and does not introduce new physical dimensions, so it will not change or confuse the unit system of the overall expression; Such combination of "dimensionless term and quantity unit term" can be understood as a composite structure expression commonly used in mathematical and physical modeling, which conforms to the principle of dimensional consistency and has a clear physical interpretation basis;

[0071] Secondly, in the formula structure of the present scheme, if it involves multiple variable terms with different physical units, including but not limited to time, mass or energy variables, their joint occurrence is to express the cooperative modeling relationship of multiple physical mechanisms. Each variable can be mapped by a function, combined by a ratio, or adjusted by a normalization to form a unified structure. The unit is clear and the meaning is clear. The overall expression conforms to the principle of dimensional consistency and the common norm of engineering modeling;

[0072] In the present scheme, if a constant, weight, adjustment factor, threshold parameter, proportion coefficient, etc. are designed, they are all adjustable control parameters for different application environments. Their values depend on the target device configuration, data input characteristics and performance optimization goals. In the implementation phase, they are set within a reasonable range through model verification, performance constraints or engineering calibration; Although such parameters do not have a unique value, they have a clear adjustment logic and calculation path, and belong to the deterministic setting process in engineering implementation. The purpose of such setting is to ensure that the scheme has both general adaptability and reproducibility and operability, without affecting its technical clarity and implementability;

[0073] In S3, distributed data consensus judgment is performed on the task execution path input combination, and path admission state identification operation is performed, and a path judgment response set is output, wherein the distributed data consensus judgment and the path admission state identification operation refer to in a distributed data environment, according to the consensus mechanism of each task node, the task execution path input combination is sent to multiple task nodes for synchronous execution, the consistent structure judgment results fed back by each task node are summarized, it is identified whether each task input path is accepted by the system as an execution path consistent in structure with the real task path in the global range, and a path judgment response set for representing the path admission state is output as the basis for the identification of the camouflage path and the analysis of the structural deviation;

[0074] The path judgment response set is subjected to a camouflage path extraction operation, and an accepted camouflage path set is output, wherein the camouflage path extraction operation refers to filtering out the camouflage paths that are mistakenly accepted as consistent paths in the consensus judgment from the path judgment response set, for structural deviation analysis;

[0075] The accepted camouflage path set is subjected to structural comparison analysis with the path expression atlas, and a structural deviation index matrix is output;

[0076] define a structure offset index matrix S Δ :

[0077]

[0078]

[0079] wherein ε (w) denotes the graph embedding vector set obtained by the path set under the structure expression layer and the jump chain layer executing the graph embedding generation operation; ε (r) denotes the graph embedding vector set obtained by the path atlas under the structure expression layer and the jump chain layer executing the graph embedding generation operation; w denotes the path set identifier; r denotes the path atlas identifier; Ω(·) denotes a graph contrast training sample construction function; Φ(·) denotes a structure alignment feature set; denotes the graph structure representation of the path set under the structure expression layer and the jump chain layer; denotes the graph structure representation of the path atlas under the structure expression layer and the jump chain layer; Θ(·) is the output tensor of the graph structure contrast neural network, and Θ(·) denotes the structure difference vector between the camouflage path and the real path; Λ(·) denotes a structure difference output fusion function, and Λ(·) is used to output a multi-dimensional structure difference score; Γ(·) denotes a graph embedding function, and Γ(·) is used to encode the graph structure into an embedding vector set; n denotes the number of structure fragment pairs in the camouflage path; m denotes the number of structure fragment pairs in the real path; denotes the graph embedding representation of the i-th structure fragment pair in the camouflage path in the path set; denotes the graph embedding representation of the j-th structure fragment pair in the real path in the path atlas; f enc (·) denotes a structure alignment encoder function; μ(·,·) denotes a multi-dimensional similarity discrimination function, and μ(·,·) is used to compare the structure correspondence between two embedding structure alignment encoder functions; y label denotes the structure consistency supervision label of the current structure fragment pair; f sim (·,·) denotes a similarity prediction function of the graph structure contrast neural network; denotes a training loss function, which is used to measure the deviation between the predicted score of the graph contrast and the real structure relationship; denotes the gradient update process performed on the model parameters of the graph structure contrast neural network; W k denotes the weight matrix of the k-th layer in the structure alignment encoder; Θ k denotes the input structure feature representation of the k-th layer in the structure alignment encoder; b krepresents the bias vector of the k-th layer in the structure alignment encoder; ReLU(·) represents a linear rectifier activation function; softmax(·) represents a multi-classification normalization function; Ψ(·) represents a structure shift index scoring function; δ1…δ m represents the structure shift strength of all camouflage paths and real paths; T represents a vector transposition operation; δ p represents the structure shift strength between the p-th camouflage path and the real path; represents the distance value of the node-level nested order difference in the p-th path; α1 represents a structure proportion control parameter corresponding to the node nested structure shift feature represents the difference measurement value of the jump topology structure in the p-th path; α2 represents a structure proportion control parameter corresponding to the jump topology structure shift feature; represents the matching deviation value of the state response sequence in the p-th path in terms of timing and structure; α3 represents a structure proportion control parameter corresponding to the state response sequence shift feature;

[0080] performing a matrix fusion operation on the structure shift index matrix and the path determination response set to output a consistent structure response matrix, wherein the matrix fusion operation refers to corresponding joint of the structure shift index matrix and the path determination response set according to the path dimension, and the structure shift degree and the acceptance state are integrated to generate a consistent structure response matrix for credibility judgment.

[0081] The structure comparison analysis in S3 further includes that the set of camouflage paths accepted from the distributed data consensus judgment is subjected to multi-layer structure feature alignment processing with the path expression graph, and node nested order, jump mode and state response sequence are extracted based on the structure expression layer and the jump chain layer to output graph embedding representation of the set of camouflage paths and the path expression graph.

[0082] The graph embedding representation of the set of camouflage paths and the path expression graph is subjected to training sample construction to generate a graph comparison training sample set, a graph structure comparison neural network model is initialized, a structure alignment encoder and a multi-dimensional similarity discrimination function are constructed, the graph comparison training sample set is subjected to model training based on the structure alignment encoder and the multi-dimensional similarity discrimination function, and a graph structure comparison neural network model is output for performing a difference judgment operation on the set of camouflage paths and the path expression graph to generate a structure shift index matrix for quantifying the structure camouflage depth of the camouflage paths and providing input basis for credibility judgment in danger prediction;

[0083] The graph structure comparison neural network model includes a GSimCNN model or a Graph Matching Network (GMN) model.

[0084] In the present scheme, if the GSimCNN model is applied to the graph structure comparison neural network model, the graph embedding representation of the camouflage path set and the path expression graph can be input as a graph pair, the structure similarity matching mechanism based on the convolution kernel matrix in GSimCNN is used to perform graph alignment coding operation and local structure interaction modeling, and output a structure offset index matrix, which can quantify the multi-dimensional structure camouflage degree of the camouflage path in the structure expression layer and the jump chain layer, and is used to construct the judgment basis for the weakening of path credibility in danger prediction.

[0085] In the present scheme, if the Graph Matching Network (GMN) model is applied to the graph structure comparison neural network model, the camouflage path set and the path expression graph can be embedded into node representation sequences and structure connection weight graphs respectively, the attention weighting mechanism and the learnable matching function in the GMN model are used to construct the mapping relationship between paths, and the node-level alignment scoring operation is performed on the structure of the camouflage path and the real path, and a structure offset index matrix is output, which is used as a key input before constructing a consistent structure response matrix, to assist in determining the structure consistency mismatch degree of the camouflage path.

[0086] In S4, structure camouflage path identification and credibility analysis operation is performed on the consistent structure response matrix, and a path credibility weakening identification set is output, wherein the structure camouflage path identification and credibility analysis operation refers to performing structure abnormal feature extraction and credibility score calculation on each camouflage path in the consistent structure response matrix formed in the distributed data environment, identifying the path with structure camouflage characteristics by analyzing the structure consistency deviation of the path in the structure expression layer, the jump chain layer and the response flow layer, and generating the path credibility weakening identification set combining the structure offset degree and the acceptance state, which is used to filter potential abnormal paths in danger prediction;

[0087] Performing structure matching operation on the path credibility weakening identification set and the path expression graph, and outputting a path behavior response evolution graph, wherein the path behavior response evolution graph includes state change trend, control response difference and input behavior offset trajectory, and the structure matching operation refers to performing structure level matching between each camouflage path in the path credibility weakening identification set and the corresponding real path in the path expression graph, performing sequence comparison on the state node evolution path through the structure expression layer, extracting the state change trend, comparing the control instruction jump relationship through the jump chain layer, extracting the control response difference, and performing differential extraction on the response sequence of the input segment through the response flow layer, input behavior offset trajectory, forming a path behavior response evolution graph containing three types of dynamic behavior characteristics of state change trend, control response difference and input behavior offset trajectory, which provides a data basis for abnormal trajectory judgment in danger prediction.

[0088] S4 also includes a joint judgment on the path behavior response evolution graph under the background of distributed data task execution, judging whether the state change trend exceeds the preset state change trend threshold, whether the control response difference exceeds the preset control response difference threshold, and whether the input behavior offset trajectory exceeds the preset input behavior offset trajectory threshold, as three judgment conditions.

[0089] If all three conditions are met, the current path result is determined to be unusable, path removal is performed, and the path input combination construction operation is re-executed; otherwise, the current path result is determined to be usable.

[0090] In S5, the path ranking priority modeling operation is performed on the paths determined to be usable and their path behavior response evolution graphs, outputting a path execution priority graph. The path execution priority graph includes a reliable path ranking structure, de-weighted path records, and policy fallback parameters. The path ranking priority modeling operation refers to performing a structural feature analysis operation on the paths determined to be usable and their path behavior response evolution graphs, extracting the structural offset strength, behavior evolution stability, and historical execution performance of each path, setting the path priority order based on the degree of structural offset, and forming a reliable path ranking structure. For path records with slight abnormal features but not meeting the elimination criteria, a de-weighting labeling operation is performed to generate de-weighted path records. Combining the fallback execution trajectory of historical abnormal paths with the scheduling relationship of alternative paths, policy fallback parameters are constructed. The reliable path ranking structure, de-weighted path records, and policy fallback parameters together constitute the path execution priority graph, which is used to support the construction of task path scheduling strategies.

[0091] The path execution priority graph is used to construct a path control structure, which outputs the path control execution structure. The path control structure construction operation refers to performing priority mapping, weight adjustment and fallback path derivation operations based on the trusted path sorting structure, de-weighted path records and policy fallback parameters in the path execution priority graph. The path control execution structure is used to construct a path control execution structure for task execution control. The path control execution structure sets the scheduling order of trusted paths, reduces the execution priority of de-weighted paths, and configures fallback paths and alternative strategies for potential spoofed paths, so as to realize the scheduling management and risk isolation of task execution paths in the distributed data environment.

[0092] It should be noted that, including but not limited to, the consensus mechanisms widely used in current distributed data systems, which use the majority voting principle as the basis for judgment, only verify the consistency of node results, but do not verify the behavioral path, execution structure or response chain of the result source;

[0093] This makes it possible for the system to output a consistent judgment with high confidence even if the execution path is severely disguised or disturbed, forming a deep-level error mixing problem with zero action characteristics;

[0094] The deep-level error mixing problem cannot be identified by traditional consistency detection mechanisms or detected by risk prediction methods based on statistical outliers or error mutations, resulting in no warning before system failure, which seriously threatens the stability and accuracy of scheduling;

[0095] Therefore, the present scheme proposes to take structural path difference and credibility response as the core clues, from the five dimensions of path expression structure, disguise construction, structural deviation modeling, credibility judgment and path control reconstruction, to build a complete safety warning process covering identification, modeling, judgment, sorting and scheduling, breaking through the limitations of result consistency, forming a structural tracing and risk response system for disguised paths;

[0096] The present scheme includes a path atlas generation stage:

[0097] Obtain the task instruction sequence from the distributed data nodes, sequentially analyze the state transition trajectory, input trigger chain and jump sequence, perform structure extraction operation, generate path information set containing behavior jump distribution, input segment response structure and state evolution segment, and perform structure merging, level and segmentation operation, build three-layer synthetic path expression atlas of structure expression layer, jump chain layer and response flow layer, count jump frequency, input position and structure co-occurrence, extract jump repeated segment, synchronous trigger sub-path and input flow segmentation chain, and output path feature segment set;

[0098] This path atlas generation stage provides standard structure templates and repeatedly appearing structure segments for the structural construction of disguised paths, ensuring that the disguise simulation has a structural reference basis;

[0099] The present scheme includes a disguised path construction stage:

[0100] Based on the path feature segment set, identify disturbance position, structure rearrangement segment and behavior trigger point, build disturbance input mapping group, call structure disturbance generator model, reorganize the disturbance, generate disguised path set, determine the structure consistency through the path structure discriminator, and form a path-level generative adversarial network, realize multi-round optimization and structure deception enhancement of the disguised path, combine the disguised path and the real path, and output the task execution path input combination;

[0101] This disguised path construction stage simulates the process of mixing in disguised paths with similar structural features but potential risks, tests the structural discrimination ability of the system and constructs disguised attack samples;

[0102] The present scheme includes a structural deviation modeling stage:

[0103] The task execution path input combination is sent to multiple nodes, a synchronous admission judgment is performed according to a consensus mechanism, a path judgment response set is output, a false path that is falsely admitted is filtered out from the path judgment response set, a multi-layer structure feature alignment and graph embedding expression with a path expression graph are performed, a graph comparison training sample set is constructed, a graph structure comparison neural network model is initialized, the training is completed and the graph structure comparison neural network model is output through a structure alignment encoder and a multi-dimensional similarity discrimination function, a difference calculation of the false path and the real path is performed by the graph structure comparison neural network model, a structure offset index matrix is output, and the structure offset index matrix and the path judgment response set are fused to generate a consistency structure response matrix;

[0104] This structure offset modeling stage is used to quantify the structure camouflage depth of the false path and the risk degree of being admitted by the system, and to construct a unified scoring matrix that can be used for credibility judgment;

[0105] The present scheme includes a credibility judgment stage:

[0106] With the consistency structure response matrix as input, a structure abnormal path is extracted, and the structure offset strength and the admission state are analyzed to generate a path credibility weakening identification set. The path credibility weakening identification set and the path expression graph are subjected to a structure matching operation, and through three comparisons of the structure expression layer, the jump chain layer and the response flow layer, the state change trend, the control response difference and the input behavior offset trajectory are extracted respectively to construct a path behavior response evolution graph. Three joint judgments are performed on the path behavior response evolution graph to judge that the current path result is unavailable and the current path result is available.

[0107] The credibility judgment stage filters out the risk individuals in the false path by combining the structure and behavior perspectives, and provides behavior dynamic feature support for path priority ranking;

[0108] The present scheme includes a path scheduling control stage:

[0109] With the path whose judgment result is available and the path behavior response evolution graph as input, the structure offset strength, the behavior evolution stability and the historical execution performance are extracted to construct a credible path ranking structure. The path with slight abnormalities is subjected to a weight reduction annotation and recorded as a weight reduction path. The historical execution trajectory and scheduling redundancy are combined to form a strategy rollback parameter. The three together constitute a path execution priority graph. Based on the path execution priority graph, a path control structure construction operation is performed, a path control execution structure is formed relying on priority mapping, weight adjustment and rollback derivation, and scheduling control and risk avoidance are realized.

[0110] The path scheduling control stage is used for ensuring that a trusted path can be called in priority in task execution, avoiding a potential risk path, and realizing path scheduling optimization and safety control in a distributed environment.

[0111] The above merely describes the preferred embodiments of the present application and is not used to limit the present application, and any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A distributed data security early warning method, Includes, characterized in that: S1: After obtaining the task instruction sequence from the distributed data nodes and performing the structure extraction operation, perform structure generation processing to generate a path representation map. Perform segment frequency statistics and structure position aggregation operations on the path representation map and output a set of path feature segments. S2: After performing camouflage input-induced modeling based on the path feature fragment set, adversarial path generation is performed, and a camouflage path set is output. Combined with the path representation graph, a path input combination construction operation is performed, and the task execution path input combination is output. S3: Combine the task execution path input with the path acceptance status recognition operation and the disguised path extraction operation, output the set of accepted disguised paths, perform structural comparison analysis with the path representation graph, generate the structural offset index matrix, and perform matrix fusion operation with the path judgment response set to output the consistent structural response matrix; S4: After performing structural camouflage path identification and credibility analysis on the consistent structural response matrix, perform structural matching operation in combination with the path expression graph, output the path behavior response evolution graph, and perform joint judgment on the path behavior response evolution graph to determine whether the current path result is unusable or the current path result is usable; S5: After performing path sorting priority modeling operations on the paths that are deemed usable and the path behavior response evolution graph, construct the path control structure and output the path control execution structure.

2. The distributed data security early warning method according to claim 1, characterized in that: In S1, the task instruction sequence in the distributed data node is obtained. The task instruction sequence includes the state transition trajectory, input trigger chain and jump sequence. The structure extraction operation is performed on the task instruction sequence to output the path information set, which includes the behavior jump distribution, input segment response structure and state evolution fragment. Perform structure generation processing on the path information set to output a path representation graph, which includes a structure representation layer, a jump chain layer, and a response flow layer. Perform frequency statistics and structural position aggregation operations on the path representation graph, and output a set of path feature fragments, which includes jump repeating fragments, synchronous triggering sub-paths and input stream segment chains.

3. The distributed data security early warning method according to claim 2, characterized in that: S1 also includes the segment occurrence frequency statistics and structural position aggregation operation. Based on the jump chain layer in the path representation map, frequency statistics are performed on the jump sequence with a frequency higher than a preset threshold across the entire path range to mark the jump structure segments that appear repeatedly in different task paths and output the jump repetition segments. Based on the triggering preconditions and location distribution characteristics of jump structure fragments, an aggregation operation is performed to identify path fragment groups with common triggering patterns and extract synchronous triggering sub-paths from the path fragment groups. Perform structural classification and functional filtering operations on common structural fragments involving input segment behavior in the input segment response structure, filter out typical input stream structures with reorganization value in task control, and output input stream segment chain; The jump repeating segments, synchronous trigger sub-paths, and input stream segment chains are combined to form a set of path feature segments.

4. The distributed data security early warning method according to claim 3, characterized in that: In S2, a dummy input inducement modeling operation is performed based on the set of path feature segments, and a perturbation input mapping group is output. The perturbation input mapping group includes the input inducement position, the structural rearrangement segment, and the behavioral perturbation trigger point. Perform adversarial path generation on the perturbation input mapping group and output a set of spoofed paths; Perform a path input combination construction operation on the camouflaged path set and the path representation graph, and output the task execution path input combination.

5. A distributed data security early warning method according to claim 4, characterized in that: S2 also includes the adversarial path generation operation, which constructs a camouflage path on the perturbation input mapping group, establishes a structural perturbation generator model, embeds the input induction position, structural rearrangement segment and perturbation trigger point as perturbation vectors into the structural perturbation generator model, performs input-level perturbation path construction modeling, and outputs a preliminary camouflage path set; Using the path representation graph as the real path reference set, structural feature parameters of the structural representation layer and the jump chain layer are extracted to train a path structure discriminator. By combining the structure perturbation generator model with the path structure discriminator, a path-level adversarial generative network is constructed. The perturbation strategy of the structure perturbation generator model is optimized through multiple rounds of adversarial interaction, and a set of dummy paths with structural deviations but consistent judgments is output.

6. A distributed data security early warning method according to claim 5, characterized in that: In S3, a distributed data consensus judgment is performed on the combination of task execution path inputs, and a path acceptance status identification operation is performed to output a path judgment response set. Perform a fake path extraction operation on the path determination response set and output the set of accepted fake paths; Perform a structural comparison analysis between the accepted set of camouflaged paths and the path representation graph, and output the structural offset index matrix; The structural offset index matrix and the path decision response set are combined and subjected to a matrix fusion operation to output a consistent structural response matrix.

7. A distributed data security early warning method according to claim 6, characterized in that: S3 also includes the structural comparison analysis, which aligns the set of fake paths accepted from the distributed data consensus judgment with the path expression graph through multi-layer structural feature processing. Based on the structural expression layer and the jump chain layer, it extracts the structural features of node nesting order, jump mode and state response sequence, and outputs the graph embedding representation of the set of fake paths and the path expression graph. Training samples are constructed by combining the camouflaged path set with the graph embedding representation of the path representation graph to generate a graph comparison training sample set. The graph structure comparison neural network model is initialized, and a structure alignment encoder and a multidimensional similarity discriminant function are constructed. Based on the structure alignment encoder and the multidimensional similarity discriminant function, the model is trained on the graph comparison training sample set, and the graph structure comparison neural network model is output. This model is used to perform difference judgment operations on the camouflaged path set and the path representation graph to generate a structure offset index matrix.

8. A distributed data security early warning method according to claim 7, characterized in that: In S4, structural camouflage path identification and credibility analysis are performed on the consistent structural response matrix, and a set of path credibility weakening identifiers is output. Perform a structure matching operation between the set of path credibility weakening identifiers and the path representation map to output a path behavior response evolution map, which includes state change trends, control response differences, and input behavior offset trajectories.

9. A distributed data security early warning method according to claim 8, characterized in that: S4 also includes a joint judgment on the path behavior response evolution graph under the background of distributed data task execution, judging whether the state change trend exceeds the preset state change trend threshold, whether the control response difference exceeds the preset control response difference threshold, and whether the input behavior offset trajectory exceeds the preset input behavior offset trajectory threshold, as three judgment conditions. If all three conditions are met, the current path result is determined to be unusable, path removal is performed, and the path input combination construction operation is re-executed; otherwise, the current path result is determined to be usable.

10. A distributed data security early warning method according to claim 9, characterized in that: In S5, the path ranking priority modeling operation is performed on the path that is determined to be usable and the path behavior response evolution graph, and the path execution priority graph is output. The path execution priority graph includes the trusted path ranking structure, the de-weighted path record and the policy backoff parameter. Perform path control structure construction operations on the path priority graph and output the path control execution structure.

Citation Information

Patent Citations

  • Artificial intelligence early warning system

    CN109447048A

  • Periodic mean constant false alarm-based voltage disturbance detection threshold design method

    CN113742951A