Multi-agent cooperative defense and evaluation method

By collecting data and generating weighted evaluation evidence through intelligent agents, the problem of heterogeneous asynchronous information fusion in multi-agent collaborative defense is solved, and efficient global threat consensus and rapid response are achieved.

CN121333713APending Publication Date: 2026-01-13STATE GRID HENAN INFORMATION & TELECOMM CO +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511548055.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-28
Publication Date
2026-01-13

Smart Images

  • Figure CN121333713A_ABST
    Figure CN121333713A_ABST
Patent Text Reader

Abstract

The invention relates to the field of network security, and particularly discloses a multi-agent cooperative defense and evaluation method, which comprises the following steps of: independently acquiring original data in a monitoring range and generating local evaluation evidences through a plurality of agents deployed at different nodes; in order to solve the problem that evidence sources are different in credibility, an honor sub-mechanism is introduced to carry out weighted discount on local evaluation evidences. Meanwhile, a selective broadcasting strategy is designed, and broadcasting is carried out only when evidences meet the importance or variability threshold value. After all weighted and screened evidences are collected, heterogeneous and asynchronous evaluation information from different local perspectives is aggregated into a unified and reliable global consensus result through global evidence fusion and a consensus decision mechanism. And finally, the defense coordinator generates and issues a defense instruction according to the consensus result, so that the technical problem that accurate global threat cognition is difficult to quickly form due to view angle limitation, model heterogeneity and communication overhead in the traditional method is effectively solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cybersecurity, and more specifically, to a multi-agent collaborative defense and evaluation method. Background Technology

[0002] With the deep integration of information technology and physical systems, critical infrastructure represented by new power systems and the Industrial Internet of Things is developing towards large-scale, distributed, and intelligent directions. In such systems, the widespread deployment of massive heterogeneous terminal devices and edge nodes dramatically increases the attack surface. Traditional security strategies that rely on centralized analysis and perimeter protection are proving inadequate in dealing with increasingly complex and collaborative cyberattacks.

[0003] However, in existing multi-agent collaborative defense technologies, how to enable a distributed group of agents to reach a consensus on the global threat situation efficiently and accurately remains a pressing technical problem. This problem mainly stems from the inherent complexity of the collaborative process: First, each agent is deployed on different nodes, and its perception range is naturally limited, only able to observe local fragments of the attack chain. These scattered, isolated events may not seem like high-threat events individually, leading to misjudgments or omissions of the overall attack intent. Second, different agents may use heterogeneous detection models and data sources, resulting in different formats, semantics, and credibility of their evaluation results, making direct quantitative comparison and effective fusion difficult, thus affecting the accuracy of consensus. Furthermore, the asynchronous nature of attack behavior in time and space, coupled with network and processing delays, leads to different reporting times for each agent's findings, making the information set used to reach consensus at any given moment potentially incomplete. To overcome these difficulties, frequent full-scale information broadcasting would trigger massive communication storms, not only consuming valuable network resources but also potentially delaying the transmission of critical threat information due to congestion, creating an irreconcilable contradiction between real-time performance and system overhead. In summary, existing technologies generally lack a mechanism that can efficiently integrate distributed, heterogeneous, asynchronous, and uncertain local security assessment information and quickly reach a reliable consensus on the global threat level. This restricts the practical effectiveness of multi-agent collaborative defense systems.

[0004] Therefore, an optimized multi-agent cooperative defense and evaluation scheme is desired. Summary of the Invention

[0005] To address the aforementioned technical problems, this application is proposed. Embodiments of this application provide a multi-agent cooperative defense and evaluation method.

[0006] According to one aspect of this application, a multi-agent cooperative defense and evaluation method is provided, comprising: Each intelligent agent continuously collects raw data within its monitoring range; Each agent uses its built-in threat model to segment the raw data to obtain local evaluation evidence: Each agent performs evidence weighting and selective broadcasting on local evaluation evidence based on its current honor score to obtain weighted evaluation evidence; Global evidence fusion and consensus decision-making are performed on the weighted evaluation evidence set to obtain a consensus result; Based on the consensus results, the defense coordinator generates specific defense instructions according to the contingency plan and assigns them to the corresponding agents for execution.

[0007] Compared with existing technologies, this application provides a multi-agent collaborative defense and assessment method. This method utilizes multiple agents deployed on different nodes, each independently collecting raw data within its monitoring range and generating standardized local assessment evidence. To address the issue of inconsistent evidence source credibility, a honor score mechanism is introduced to weight and discount local assessment evidence. Simultaneously, to avoid communication congestion, a selective broadcast strategy is designed, broadcasting only when evidence meets importance or variability thresholds. After all weighted and filtered evidence is aggregated, a global evidence fusion and consensus decision-making mechanism integrates heterogeneous and asynchronous assessment information from different local perspectives into a unified and reliable global consensus result. Finally, the defense coordinator generates and issues defense commands based on this consensus result, effectively solving the technical problem in traditional methods where limited perspectives, heterogeneous models, and communication overhead make it difficult to quickly form accurate global threat perception. Attached Figure Description

[0008] The above and other objects, features, and advantages of this application will become more apparent from the more detailed description of the embodiments of this application in conjunction with the accompanying drawings. The drawings are provided to further illustrate the embodiments of this application and form part of the specification. They are used together with the embodiments of this application to explain this application and do not constitute a limitation thereof. In the drawings, the same reference numerals generally represent the same components or steps.

[0009] Figure 1 This is a flowchart of a multi-agent cooperative defense and evaluation method according to an embodiment of this application; Figure 2 This is a schematic diagram of data flow in the multi-agent cooperative defense and evaluation method according to an embodiment of this application; Figure 3 A flowchart for generating the local evaluation evidence based on a propensity score set in the multi-agent cooperative defense and evaluation method according to embodiments of this application; Figure 4This is a flowchart illustrating how each agent in the multi-agent collaborative defense and evaluation method according to an embodiment of the present application performs evidence weighting and selective broadcasting on local evaluation evidence based on its current honor score to obtain weighted evaluation evidence. Figure 5 This is a flowchart illustrating the process of performing global evidence fusion and consensus decision-making on a weighted evaluation evidence set to obtain a consensus result, according to the multi-agent collaborative defense and evaluation method of this application. Detailed Implementation

[0010] Hereinafter, exemplary embodiments according to this application will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of this application, and not all embodiments of this application. It should be understood that this application is not limited to the exemplary embodiments described herein.

[0011] As indicated in this application and claims, unless the context clearly indicates otherwise, the words "a," "an," "an," and / or "the" are not specifically singular and may include plural forms. Generally speaking, the terms "comprising" and "including" only indicate the inclusion of explicitly identified steps and elements, which do not constitute an exclusive list, and the method or apparatus may also include other steps or elements.

[0012] While this application makes various references to certain modules of the systems according to embodiments of this application, any number of different modules can be used and run on user terminals and / or servers. The modules described are merely illustrative, and different aspects of the systems and methods may use different modules.

[0013] Flowcharts are used in this application to illustrate the operations performed by the system according to embodiments of this application. It should be understood that the preceding or following operations are not necessarily performed in exact order. Instead, various steps can be processed in reverse order or simultaneously as needed. Furthermore, other operations can be added to these processes, or one or more steps can be removed from them.

[0014] Hereinafter, exemplary embodiments according to this application will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of this application, and not all embodiments of this application. It should be understood that this application is not limited to the exemplary embodiments described herein.

[0015] Current multi-agent collaborative defense technologies face a core challenge in dealing with distributed attacks: due to the limited perspectives of each agent, heterogeneous evaluation models, and asynchronous observations, it is difficult to quickly and accurately fuse fragmented information to form a unified global threat perception. This lack of consensus efficiency and accuracy severely restricts the response speed and decision-making quality of the entire defense system. To address the above technical problems, this application proposes a multi-agent collaborative defense and evaluation method. Specifically, agents deployed in various locations first continuously collect raw data within their monitoring range and process it into structured local evaluation evidence through a built-in threat model. This process includes characterizing the raw data using monitoring indicators to obtain feature vectors, then inputting the vectors into the threat model for multi-dimensional propensity scoring, and finally generating local evaluation evidence that can quantify uncertainty. Next, to ensure the reliability of the evidence entering the decision-making stage and optimize communication efficiency, each agent discounts the local evaluation evidence based on its current honor score, forming weighted evaluation evidence, and selectively broadcasts it according to broadcast trigger conditions such as importance or degree of change. Then, the collected weighted evaluation evidence set is globally fused and consensus-based decision is made. This process involves structured embedding encoding of each weighted evaluation piece of evidence to obtain a unified set of embedding representations. Then, a feature aggregation network based on causal emergence constraints is used for deep fusion of the core evidence, generating an integrated core evidence representation. Finally, feature classification and regression are performed on this core evidence representation to output the final global consensus result. The defense coordinator uses this result to generate and distribute defense commands, enabling a rapid and coordinated response to threats.

[0016] Figure 1 This is a flowchart of a multi-agent cooperative defense and evaluation method according to an embodiment of this application. Figure 2 A schematic diagram of the data flow of the multi-agent cooperative defense and evaluation method according to an embodiment of this application is shown below. Figure 1 and Figure 2 As shown, the multi-agent collaborative defense and evaluation method according to an embodiment of this application includes: S100, each agent continuously collects raw data within its monitoring range; S200, each agent uses its built-in threat model to segment the raw data to obtain local evaluation evidence; S300, each agent performs evidence weighting and selective broadcasting on the local evaluation evidence based on its current honor score to obtain weighted evaluation evidence; S400, performs global evidence fusion and consensus decision-making on the weighted evaluation evidence set to obtain a consensus result; S500, based on the consensus result, the defense coordinator generates specific defense instructions according to the plan and assigns them to the corresponding agents for execution.

[0017] Specifically, in step S100, each intelligent agent continuously collects raw data within its monitoring range. It should be understood that because threat indicators arising from complex coordinated attack behaviors are often dispersed across multiple layers of the cyber-physical system and dynamically evolve over time, single, discontinuous data collection methods are insufficient to obtain comprehensive, real-time attack evidence. Therefore, each intelligent agent continuously collects raw data within its monitoring range to uninterruptedly capture the underlying data streams reflecting the system's operational status from different dimensions, such as the network layer, host layer, and application layer. This establishes a complete and blind-spot-free data foundation for subsequent threat assessment, ensuring that any minute anomalies are included in the analysis, thereby improving the sensitivity and accuracy of threat detection.

[0018] More specifically, in a concrete example of this application, the data acquisition process is embodied as a multi-layered, concurrently executed data acquisition flow. First, on the gateway device at the network boundary, a network agent uses a packet capture library to mirror and capture all network traffic flowing through the device in real time, thereby obtaining raw network packets. Simultaneously, on the web application server, a host agent monitors system calls, process activity, and the usage of resources such as CPU and memory by attaching a probe to the operating system kernel, and synchronously reads the access logs and error logs of the web service, forming raw data at the host layer and application middleware layer. On the backend database server, a database agent accesses the database's built-in auditing interface to obtain all executed SQL queries, connection information, and response times in real time, constituting raw data at the database application layer. These three types of agents execute the above operations in parallel and continuously, using the network packets, system activity records, and database interaction logs they acquire as raw data within their monitoring scope, providing multi-dimensional, high-fidelity input for subsequent analysis.

[0019] Specifically, in step S200, each agent uses its built-in threat model to segment the raw data to obtain local evaluation evidence. It should be understood that, due to the diverse formats and massive volume of the raw data collected by each agent, and the fact that the threat information contained within is not readily apparent, directly fusing and analyzing these heterogeneous raw data is not feasible. Therefore, in the technical solution of this application, the built-in threat model of each agent is further utilized to analyze the raw data to obtain local evaluation evidence. This allows for dimensionality reduction and feature extraction of massive amounts of raw data at the data source, transforming unstructured data streams into structured evidence capable of quantifying threat tendencies and uncertainties. This solves the standardization problem of multi-source heterogeneous data, providing a unified and computable input for subsequent global evidence fusion and consensus decision-making, making the local discoveries of different types of agents comparable and fusionable.

[0020] More specifically, in a specific example of this application, each agent uses its built-in threat model to segment the raw data to obtain local evaluation evidence, including: characterizing the raw data with monitoring indicators to obtain monitoring indicator feature vectors; inputting the monitoring indicator feature vectors into the threat model to perform multi-dimensional propensity scoring to obtain a propensity score set; and generating the local evaluation evidence based on the propensity score set.

[0021] Accordingly, the raw data is characterized by monitoring indicators to obtain monitoring indicator feature vectors; these feature vectors are then input into a threat model for multi-dimensional propensity scoring to obtain a set of propensity scores. It should be understood that due to differences in structure, format, and semantics, the raw data stream cannot be directly used as input to the analysis model, and a single threat judgment result cannot reflect the ambiguity and uncertainty of the early stages of an attack. Therefore, in the technical solution of this application, the raw data is further characterized by monitoring indicators to obtain monitoring indicator feature vectors, and these feature vectors are then input into a threat model for multi-dimensional propensity scoring to obtain a set of propensity scores. This transforms the diverse raw data into a unified, quantifiable numerical vector, and then the analysis model evaluates the correlation strength between this vector and multiple preset threat levels. This process transforms unstructured data into standardized model input and produces an unnormalized raw assessment result that initially reflects the current state's potential tendency towards multiple threat levels, providing a necessary prerequisite for generating assessment evidence containing uncertainty.

[0022] More specifically, the monitoring metric feature vector includes: packet rate, byte rate, connection flow rate, average packet length, protocol share, TCP flag combination count, source IP address entropy, destination port entropy, CPU utilization, memory usage, disk I / O rate, number of active processes, system call frequency, number of login failures, HTTP response code distribution, API request rate, request parameter anomaly score, number of slow queries, query complexity, and deviation of feature values ​​from historical baselines. In a specific example of this application, firstly, monitoring metric featureization is performed. For example, the network agent parses network packets captured over a period of time, statistically calculates a series of metrics such as packet rate, source IP address entropy, and protocol share, and combines these metric values ​​into a numerical vector. Next, multi-dimensional propensity scoring is performed. This numerical vector is input into its built-in threat model, which contains multiple parallel evaluation functions, each corresponding to a threat level, such as low, medium, and high. Each evaluation function calculates a propensity score based on the characteristics of the input vector. For example, a higher packet rate might result in evaluation functions for medium and high threats outputting scores of 0.8 and 0.6, respectively. Simultaneously, the host agent inputs a vector of features it has calculated, such as CPU utilization and login failure counts, into its threat model to obtain a set of propensity scores for the host state. Finally, each agent outputs a set of propensity scores containing the raw scores for all possible threat levels.

[0023] Accordingly, the local assessment evidence is generated based on the propensity score set. It should be understood that since the propensity score set obtained in the previous step is a set of unnormalized and independent raw scores, it does not constitute a mathematically rigorous evidence structure that can express uncertainty, and therefore cannot be directly used for subsequent evidence fusion calculations. Therefore, in the technical solution of this application, the local assessment evidence is further generated based on the propensity score set. This is used to map the raw score set into a basic probability allocation function that conforms to the evidence theory framework through a series of transformations such as aggregation calculation, normalization, confidence generation, and belief allocation. This produces a standardized local assessment evidence that not only clearly defines the degree of trust in each specific threat level but also explicitly quantifies the magnitude of uncertainty in the current judgment, providing a uniformly formatted and comprehensive input for subsequent reputation-weighted and cross-agent global evidence fusion.

[0024] Figure 3 This is a flowchart illustrating the generation of local evaluation evidence based on a propensity score set in the multi-agent cooperative defense and evaluation method according to embodiments of this application. (See flowchart for example.) Figure 3As shown, the local assessment evidence is generated based on the propensity score set, including: S210, performing threat intensity aggregation calculation on the propensity score set to obtain an aggregate score; S220, normalizing the threat propensity of the propensity score set based on the aggregate score to obtain a normalized threat propensity distribution; S230, generating a confidence factor based on the aggregate score and sensitivity parameter; S240, assigning a specific belief quantity to the normalized threat propensity distribution based on the confidence factor to obtain a belief quantity vector; and S250, constructing the local assessment evidence based on the belief quantity vector and the confidence factor.

[0025] Specifically, in step S210, a threat intensity aggregation calculation is performed on the propensity score set to obtain an aggregate score. It should be understood that since the propensity score set contains independent scores for multiple different threat levels, it lacks a single indicator that can measure the overall abnormality of the currently observed event or the total strength of evidence. Therefore, in the technical solution of this application, a threat intensity aggregation calculation is further performed on the propensity score set to obtain an aggregate score. This integrates the discrete multi-dimensional scores into a scalar value that comprehensively reflects all threat propensities through summation. In this way, a key intermediate parameter quantifying the current overall threat intensity can be generated. This parameter is directly related to the confidence level of the assessment and serves as the direct input for subsequently generating confidence factors.

[0026] More specifically, in a concrete example of this application, the aggregation calculation is performed independently within each agent. Taking a network agent as an example, its obtained set of propensity scores contains multiple numerical scores corresponding to different levels such as no threat, low threat, medium threat, and high threat. The threat strength aggregation calculation is performed by arithmetically summing all the numerical scores in this set. The result of this summation is a single scalar value, the aggregation score, which comprehensively reflects the total strength of all current threat propensities. Simultaneously, the host agent also performs the same arithmetic summation operation on another set of propensity scores it generates internally. After this process, each agent holds an aggregation score representing the total strength of evidence it has observed, for use in the next stage of processing.

[0027] Specifically, in step S220, the threat tendency normalization of the bias score set is performed based on the aggregated score to obtain a threat tendency normalized distribution. It should be understood that since each score in the bias score set is an absolute value, its magnitude may fluctuate significantly due to differences in the model and input, making the relative importance between different threat levels unclear and unsuitable as a direct proportional basis for assigning beliefs. Therefore, in the technical solution of this application, the threat tendency normalization of the bias score set is further performed based on the aggregated score to obtain a threat tendency normalized distribution, thereby converting each independent absolute score into a relative proportion in the total strength of evidence. This generates a probability distribution whose sum of elements is one, clearly revealing the proportion of evidence among different threat level hypotheses under the current observation, providing precise weights for subsequent proportional allocation of the total confidence of the system.

[0028] More specifically, in a particular example of this application, the calculation of the normalized distribution immediately follows the calculation of the aggregate score. The network agent uses its obtained aggregate score as a baseline divisor and each score in its propensity score set as the dividend. The normalization process is performed by dividing each individual score in the propensity score set by the aggregate score. This operation generates a new value for each threat level, representing the relative proportion of the propensity score for that threat level in the total strength of evidence. All these newly generated proportions together constitute a distribution that sums to one, namely the threat propensity normalized distribution. This normalization process is performed in parallel in all other agents, each using its own aggregate score and propensity score set to generate a unique normalized distribution.

[0029] Specifically, in step S230, a confidence factor is generated based on the aggregate score and sensitivity parameter. It should be understood that since the aggregate score is an unbounded numerical value representing the total strength of evidence, it cannot be directly used as a basis for distinguishing between certainty and uncertainty; a standardized metric is needed to define the overall credibility of this assessment. Therefore, in the technical solution of this application, a confidence factor is further generated based on the aggregate score and sensitivity parameter. This converts the unbounded aggregate score into a scalar value representing the total confidence of the system within the interval of 0 to 1 through a nonlinear mapping function. The sensitivity parameter is used to adjust the response rate of the confidence level as the strength of evidence changes. In this way, a clear confidence factor is produced, which quantifies the total amount of belief that can be assigned to a specific threat level in this assessment and provides a quantitative boundary for subsequently distinguishing between the certain and uncertain parts.

[0030] More specifically, in a concrete example of this application, the confidence factor is generated using a non-linear exponential function. The function is input to the aggregate score obtained in the previous step, and a preset sensitivity parameter used to adjust the response rate. The calculation process involves first multiplying the sensitivity parameter by the aggregate score, then taking the negative of the product as the exponent of the natural constant e to calculate the power value. Finally, the power value is subtracted from 1, and the difference is the final confidence factor. This calculation process is executed in parallel across all agents, including the network agent and the host agent. Each agent uses the same sensitivity parameter but substitutes its own different aggregate score. After calculation, each agent receives a scalar value between 0 and 1, which is the confidence factor characterizing its current assessment of the overall credibility, used for subsequent belief allocation.

[0031] Specifically, in steps S240 and S250, a specific belief quantity is allocated to the threat propensity normalized distribution based on the confidence factor to obtain a belief quantity vector; based on the belief quantity vector and the confidence factor, the local assessment evidence is constructed. It should be understood that since the confidence factor and the threat propensity normalized distribution are two independent intermediate results, the former defines the total distributable belief quantity, and the latter defines the allocation ratio, but the process of specifically assigning beliefs to each threat level has not yet been completed, nor has the remaining uncertainty been explicitly calculated. Therefore, in the technical solution of this application, a specific belief quantity allocation is further performed on the threat propensity normalized distribution based on the confidence factor to obtain a belief quantity vector, and based on the belief quantity vector and the confidence factor, the local assessment evidence is constructed to proportionally allocate the total confidence to each individual threat level, while the difference between the total probability 1 and the confidence factor is used as uncertainty, ultimately assembling a complete basic probability allocation function that conforms to the evidence theory framework. In this way, a structured and comprehensive local assessment evidence can be generated, which not only includes the judgment of specific threats, but also quantifies the uncertainty of the judgment, providing standardized input for subsequent collaborative defense processes.

[0032] More specifically, in a concrete example of this application, the construction process integrates two steps: belief allocation and final assembly. First, specific belief quantities are allocated, utilizing the confidence factor and threat propensity normalized distribution generated in the previous step. Specifically, the confidence factor, as the total belief quantity, is multiplied by each proportion value in the normalized distribution. This operation calculates a precise belief quantity for each specific threat level, and all these belief quantities together constitute a belief quantity vector. Next, local assessment evidence is constructed. This process first calculates the belief quantity representing uncertainty by subtracting the confidence factor from 1. Then, the individual specific belief quantities contained in the belief quantity vector obtained in the previous step are combined with the uncertainty belief quantity calculated here. Finally, this combination forms a complete set of local assessment evidence that includes beliefs about all specific threat levels and beliefs about overall uncertainty.

[0033] Specifically, in step S300, each agent performs evidence weighting and selective broadcasting on its local evaluation evidence based on its current honor score to obtain weighted evaluation evidence. It should be understood that due to differences in the evaluation capabilities and historical performance of different agents, the locally evaluated evidence they generate has different levels of credibility. Furthermore, if all agents broadcast each of their evaluation results indiscriminately, it would generate enormous communication overhead and potentially overwhelm crucial threat intelligence. Therefore, in the technical solution of this application, each agent further performs evidence weighting and selective broadcasting on its local evaluation evidence based on its current honor score to obtain weighted evaluation evidence. This first discounts the belief in the evidence through the honor score, quantifying the agent's historical reliability in its evidence influence. Based on this, broadcasting trigger conditions are set, and evidence is only broadcast when it meets an importance or variability threshold. This ensures that all evidence entering the global fusion stage has undergone credibility weighting and importance screening, thereby improving the robustness of the final consensus decision while reducing network communication load and ensuring the timeliness of key threat evidence transmission.

[0034] Figure 4 This is a flowchart illustrating how each agent in the multi-agent cooperative defense and evaluation method according to embodiments of this application performs evidence weighting and selective broadcasting based on its current honor score to obtain weighted evaluation evidence. For example... Figure 4 As shown, step S300 includes: S310, applying a belief discount to the local evaluation evidence based on the current honor score to obtain weighted evaluation evidence; S320, evaluating the weighted evaluation evidence for broadcast trigger conditions based on the broadcast threshold set and the previous broadcast evidence to obtain a broadcast decision; S330, broadcasting the weighted evaluation evidence in response to the broadcast decision being true.

[0035] Specifically, in step S310, the local evaluation evidence is discounted based on the current honor score to obtain weighted evaluation evidence. It should be understood that due to differences in the historical evaluation accuracy and stability of various agents, the credibility of their generated local evaluation evidence is not equivalent. If these are used directly for global fusion without distinction, the accuracy of the final consensus may be affected by interference from low-credibility evidence. Therefore, in the technical solution of this application, the local evaluation evidence is further discounted based on the current honor score to obtain weighted evaluation evidence. This utilizes the honor score as a quantitative indicator to proportionally reduce the beliefs pointing to specific conclusions in the local evaluation evidence, and transforms the reduced credibility difference into uncertainty. In this way, a weighted evaluation evidence with the source credibility internalized in its structure can be generated, ensuring that evidence from high-credibility agents can play a greater role in subsequent fusion processes, thereby improving the robustness of decision-making.

[0036] More specifically, in a concrete example of this application, the belief discounting process is implemented through specific mathematical operations. Assume the network agent possesses a high honor score, and its local assessment evidence indicates a clear belief in medium and high threats, while retaining some uncertainty. The belief discounting operation first uses the agent's honor score as a discount factor, multiplying it by all belief quantities in its local assessment evidence pointing to specific threat levels. The result of this operation is that the belief quantities originally allocated to each specific threat level are proportionally reduced, the reduction depending on the honor score. Subsequently, the uncertainty beliefs are recalculated. The new uncertainty consists of two parts: one is the reputation gap due to insufficient honor score, and the other is the remaining portion of the original uncertainty beliefs after honor score discount. Adding these two parts yields the updated uncertainty belief quantity. Finally, the specific belief quantities adjusted by the above operations, together with the updated uncertainty belief quantity, constitute a complete weighted assessment evidence, ready to enter the subsequent broadcast judgment process.

[0037] Specifically, in step S320, a broadcast trigger condition evaluation is performed on the weighted evaluation evidence based on the broadcast threshold set and the previous broadcast evidence to obtain a broadcast decision. It should be understood that if each agent unconditionally broadcasts every generated weighted evaluation piece of evidence to the network, it would generate a large amount of redundant communication, wasting network resources and potentially delaying the transmission of critical threat intelligence due to information congestion, thus affecting the timeliness of collaborative response. Therefore, in the technical solution of this application, a broadcast trigger condition evaluation is further performed on the weighted evaluation evidence based on the broadcast threshold set and the previous broadcast evidence to obtain a broadcast decision, thereby establishing a dynamic evidence screening checkpoint. This checkpoint judges newly generated evidence from two dimensions: importance and variability. A broadcast action is only triggered when the evidence itself reveals a sufficiently high threat level, or when its content has significantly changed compared to the previously broadcast evidence. This effectively suppresses the spread of low-value and repetitive information, ensuring that critical threat evidence can be shared in a timely manner while also reducing the communication overhead and computational load of the entire collaborative defense network.

[0038] More specifically, in a specific example of this application, a broadcast trigger condition evaluation is performed on weighted evaluation evidence based on a broadcast threshold set and the previous broadcast evidence to obtain a broadcast decision. This includes: evaluating the importance of the weighted evaluation evidence to obtain an importance belief value; calculating the difference between the previous broadcast evidence and the weighted evaluation evidence to obtain an evidence change value; determining whether the importance belief value is greater than an importance belief threshold and whether the evidence change value is greater than a change threshold; if the importance belief value is greater than the importance belief threshold or the evidence change value is greater than the change threshold, the broadcast decision is determined to be true.

[0039] Accordingly, the weighted assessment evidence is evaluated for importance to obtain an importance belief value; the difference between the previously broadcast evidence and the weighted assessment evidence is calculated to obtain an evidence change value. It should be understood that since a single criterion cannot comprehensively determine whether assessment evidence is worth broadcasting, it is necessary to consider both immediate evidence revealing high-risk situations and trend evidence reflecting significant changes in the state. Therefore, in the technical solution of this application, the weighted assessment evidence is further evaluated for importance to obtain an importance belief value, and the difference between the previously broadcast evidence and the weighted assessment evidence is calculated to obtain an evidence change value. This quantifies the broadcast value of the weighted assessment evidence from two orthogonal dimensions: absolute severity and relative novelty. This generates two independent decision-making reference indicators, providing a data foundation for implementing a more refined broadcasting strategy that can both respond to sudden high-risk events and capture the evolution of potential threats.

[0040] More specifically, in a concrete example of this application, this evaluation process comprises two parallel computational steps. First, an importance assessment is performed. This process analyzes a weighted assessment of evidence, summing the belief values ​​assigned to all propositions related to the high threat level. For example, the belief values ​​assigned to the single proposition "high threat," as well as those assigned to composite propositions such as "medium" or "high threat," are summed, and the total sum is the importance belief value of the evidence. Simultaneously, a difference calculation is performed. This process treats the current weighted assessment evidence and the stored evidence from the last broadcast as high-dimensional vectors and uses an evidence distance function to calculate the difference between them. This calculation retrieves the belief values ​​corresponding to the same proposition for each pair of evidence, calculates the square of their difference, and summarizes and mathematically transforms the squared differences for all propositions to ultimately derive a scalar value quantifying the degree of difference between the two, namely, the evidence change value.

[0041] Accordingly, it is determined whether the importance belief value is greater than the importance belief threshold and whether the evidence change value is greater than the change threshold. If either the importance belief value or the evidence change value is greater than the change threshold, the broadcast decision is determined to be true. It should be understood that since the importance belief value and evidence change value generated in the previous step are independent quantitative indicators, a clear judgment rule is needed to integrate these two indicators and ultimately form a broadcast instruction that is either true or false. Therefore, in the technical solution of this application, it is further determined whether the importance belief value is greater than the importance belief threshold and whether the evidence change value is greater than the change threshold. If either the importance belief value or the evidence change value is greater than the change threshold, the broadcast decision is determined to be true. This applies a logical or threshold judgment to ensure that broadcasting is triggered regardless of whether a threat of high absolute severity or a threat whose state has significantly evolved is detected. In this way, a clear Boolean broadcast decision is ultimately generated, which balances sensitivity to sudden high-risk events and dynamically evolving threats, ensuring the effectiveness and comprehensiveness of information filtering.

[0042] More specifically, in a concrete example of this application, the decision-making process is completed within an agent. First, the agent presets two thresholds: an importance belief threshold and a change threshold. Then, it compares the importance belief value calculated in the previous step with the importance belief threshold, and simultaneously compares the evidence change value with the change threshold. The results of these two comparisons are input into a logic OR gate. If either or both comparisons are true—that is, if the importance belief value exceeds its threshold, or the evidence change value exceeds its threshold—then the output of the logic OR gate is true. This output is then determined as the final broadcast decision, used to decide whether to execute the subsequent broadcast action.

[0043] Specifically, in step S330, in response to the broadcast decision being true, the weighted evaluation evidence is broadcast. It should be understood that since the broadcast decision generated in the preceding steps is only an internal logical state, if it is not transformed into an actual communication action, the evaluation evidence, after layers of filtering and weighting, will remain stuck at its source and cannot provide information support for global collaborative defense. Therefore, in the technical solution of this application, in response to the broadcast decision being true, the weighted evaluation evidence is further broadcast to execute a conditionally triggered data distribution operation. The weighted evaluation evidence, determined by the local intelligent agent to have broadcast value, is sent to other members in the collaborative defense system via a network communication protocol. In this way, local, critical threat insights can be transmitted to the fusion node responsible for global situational awareness, completing a crucial step from individual perception to group sharing, and providing necessary input data for subsequent consensus decisions.

[0044] More specifically, in a concrete example of this application, the broadcast action is a decision-driven communication process. The broadcast process is triggered when the internal broadcast decision state of an agent, such as a network agent, is determined to be true. First, the weighted evaluation evidence data structure containing specific belief values ​​and uncertain belief values ​​stored internally by the network agent is serialized into a byte stream. Subsequently, this byte stream is encapsulated in one or more network data packets and sent to other members of the collaborative defense network, such as host agents and database agents, through a preset multicast or unicast address list. After the broadcast action is completed, the network agent also updates the evidence content of this broadcast to its internally stored previous broadcast evidence for calculating the degree of change in the next evaluation cycle.

[0045] Specifically, in step S400, global evidence fusion and consensus decision-making are performed on the weighted evaluation evidence set to obtain a consensus result. It should be understood that since multiple weighted evaluation evidences from different agents are gathered in the collaborative defense network, each piece of evidence only reflects a local aspect of the system state and may be inconsistent or even conflicting. Therefore, a high-level fusion decision-making mechanism is needed to integrate this fragmented information. Therefore, in the technical solution of this application, global evidence fusion and consensus decision-making are further performed on the weighted evaluation evidence set to obtain a consensus result. This allows for in-depth analysis and aggregation of all evidence, uncovering the inherent connections between different pieces of evidence, enhancing consistency judgments, and resolving conflicting judgments. This refines and elevates multiple local, uncertain views into a unified, global, and more confident understanding of the system state. This overcomes the limitations of a single agent's perspective, generating a final consensus result that represents the collective wisdom of the entire agent group, providing a clear and reliable decision-making basis for subsequent precise and coordinated defense responses.

[0046] Figure 5 This is a flowchart illustrating the construction of a dynamic health cost function based on the current damage potential index in the multi-agent cooperative defense and evaluation method according to an embodiment of this application. Figure 5 As shown, step S400 includes: S410, performing structured embedding encoding on each weighted evidence in the weighted evaluation evidence set to obtain a weighted embedding representation set for each piece of evidence; S420, performing deep fusion of core evidence on each set of weighted embedding representations to obtain an integrated core evidence representation; S430, performing feature classification regression on the integrated core evidence representation to obtain the consensus result.

[0047] Specifically, in step S410, each weighted piece of evidence in the weighted evaluation evidence set is subjected to structured embedding encoding to obtain a set of weighted embedding representations for each piece of evidence. It should be understood that since weighted evaluation evidence is structured data containing a mapping relationship between propositions and belief values, its format cannot be directly utilized by deep neural network models designed to process numerical vectors, hindering subsequent high-level feature aggregation and analysis. Therefore, in the technical solution of this application, each weighted piece of evidence in the weighted evaluation evidence set is further subjected to structured embedding encoding to obtain a set of weighted embedding representations for each piece of evidence. This maps each piece of structured weighted evaluation evidence into a high-dimensional, dense numerical vector, i.e., an embedding representation, through an encoding network. In this way, all evidence from different sources and with varying content can be uniformly converted into a standardized vector format that can be processed by subsequent deep fusion networks, making it possible to use neural network models to mine complex relationships and deep patterns among the evidence.

[0048] More specifically, in a concrete example of this application, the encoding process is performed within the agent responsible for fusion decision-making. Upon receiving a weighted evaluation evidence from the network agent, it is first preprocessed into vectors. This preprocessing extracts the belief values ​​corresponding to each proposition in the evidence, arranged in a predetermined order, such as no threat, low threat, medium threat, high threat, and uncertainty, forming an initial low-dimensional numerical vector. Subsequently, this low-dimensional vector is input into an embedding encoder constructed from a multilayer perceptron. Inside this encoder, the vector undergoes layer-by-layer transformation through multiple fully connected neural network layers and nonlinear activation functions. The output of the last layer of the encoder is a dense vector with higher dimension and richer feature representation; this vector is the structured embedding encoding of the weighted evaluation evidence. This process is performed independently for each received weighted evaluation evidence, ultimately forming a set of weighted embedding representations of evidence composed of multiple high-dimensional vectors, used for the next stage of deep fusion.

[0049] Specifically, in step S420, the weighted embedding representation sets of each piece of evidence undergo deep fusion of core evidence to obtain an integrated core evidence representation. It should be understood that since the weighted embedding representation sets of each piece of evidence obtained in the previous step are composed of multiple independent vectors, simply merging or averaging them would lose the complex interaction information and correlations between the vectors, failing to effectively extract the core features reflecting the global situation. Therefore, in the technical solution of this application, the weighted embedding representation sets of each piece of evidence undergo further deep fusion of core evidence to obtain an integrated core evidence representation. This is achieved by using a deep neural network designed for processing aggregated data, such as a feature aggregation network based on causal emergence constraints, to perform end-to-end nonlinear transformation and aggregation of all evidence vectors, thereby learning and extracting the most decisive integrated features from a global perspective. This generates a single integrated core evidence representation vector that condenses the essence of all local evidence and reflects their inherent correlations. Compared to any single piece of evidence or simple combination, this vector has stronger generalization and discriminative power regarding the global threat state, providing high-quality feature input for the final accurate decision-making.

[0050] More specifically, in a specific example of this application, core evidence deep fusion is performed on each set of weighted embedded representations of evidence to obtain an integrated core evidence representation, including: inputting each set of weighted embedded representations of evidence into a baseline feature convergence network to obtain a global evidence baseline aggregation code; calculating the causal association-based implicit modulation factor of each individual evidence weighted embedded representation in each set of weighted embedded representations relative to the global evidence baseline aggregation code to obtain a set of weighted evaluation evidence based on causal association implicit modulation factors; and performing modulation optimization on the global evidence baseline aggregation code based on the set of weighted evaluation evidence based on causal association implicit modulation factors to obtain an integrated core evidence representation.

[0051] Accordingly, the weighted embedding representation sets of each piece of evidence are input into the baseline feature convergence network to obtain the global evidence baseline aggregation code. This is expressed by the following formula: in, Weighted embedding representation set for each piece of evidence, For each piece of evidence, a weighted embedded representation is generated within the weighted embedded representation set. for Architecture, It is the number of weighted embedded representations of a single piece of evidence in each set of weighted embedded representations of evidence. For example, the feature transformation function. It contains one or more non-linear activation layers. For example, the transformation function after aggregation. It contains one or more non-linear activation layers. for Encoder, This is used for global evidence baseline aggregation encoding.

[0052] It is understandable that, since the weighted embedding representations of each piece of evidence contain a set of micro-states from multiple observation points across different dimensions, such as the network and the host, forming a global judgment requires a preliminary information compression process to create a macro-level overview of all discrete evidence. A simple statistical summary cannot distinguish the heterogeneity of the contributions of each micro-evidence to this macro-level representation. Therefore, in the technical solution of this application, the weighted embedding representations of each piece of evidence are further input into a baseline feature aggregation network to obtain a global evidence baseline aggregation code, thereby performing a basic representation synthesis stage. In this stage, all independent evidence vectors are input together into a primary feature aggregation network capable of processing aggregated inputs. This network maps multiple discrete micro-inputs into a unified latent space through depth transformation, completing a preliminary global information compression. This generates a global evidence baseline aggregation code as the initial feature aggregation code vector. This code can be considered a preliminary, macro-level statistical summary of the entire evidence set, capturing the overall distribution characteristics exhibited by all evidence and providing a necessary macro-level reference benchmark for subsequent investigation of the causal contribution of each micro-evidence.

[0053] Accordingly, the causal association-based implicit modulation factor of each evidence-weighted embedded representation in the set of evidence-weighted embedded representations is calculated relative to the global evidence baseline to obtain the set of causal association-based implicit modulation factors for weighted evaluation evidence. This is expressed by the following formula: in, for and The conditional probability distribution between them For marginal probability distribution, for divergence, For causal constraint multilayer perceptron, This is a vector concatenation operation. For causal information gain, It is the Sigmoid activation function. for The corresponding weighted evaluation evidence is based on implicit modulation factors of causal relationships.

[0054] It is understandable that the global evidence baseline aggregation encoding generated in the previous step is only a preliminary, macro-level statistical summary of all micro-evidence. It has not yet distinguished the heterogeneity of the contributions of each independent micro-evidence, such as traffic anomaly evidence from network agents or login failure evidence from host agents, to the macro-representation. Therefore, in the technical solution of this application, the causal association-based implicit modulation factor of each individual evidence weighted embedded representation in the weighted embedded representation set relative to the global evidence baseline aggregation encoding is further calculated to obtain a set of causal association-based implicit modulation factors for weighted evaluation evidence. This allows for a deeper exploration of the intrinsic dynamics of macro-representation formation. Through an end-to-end learned implicit weight, the causal contribution or informational influence of each micro-evidence in this emergent process from part to whole is quantified. In this way, a set of constraint factors corresponding one-to-one with the original evidence vector can be obtained. These factors profoundly reveal which input evidence is the key driving force constituting the current macro-threat representation, and which is redundant or noisy information, providing key modulation signals for subsequent guided refinement and adjustment of the macro-representation.

[0055] Accordingly, based on the set of implicit modulation factors for causal relationships in the weighted evaluation evidence, modulation optimization is performed on the global evidence baseline aggregation coding to obtain an integrated core evidence representation. This is expressed by the following formula: in, For gated multilayer sensing, for Activation function As the gating factor, For positional product, To refine the multilayer perceptron for residuals, For residual refining term factors, It is an integrated core evidence representation.

[0056] It is understandable that, since the global evidence baseline aggregation code generated in the previous step is only a preliminary statistical summary, and the set of modulation factors quantifying the causal contribution of each micro-level piece of evidence has not yet been used to optimize this macro-level representation, the signals of key evidence have not been strengthened in the final representation. Therefore, in the technical solution of this application, the global evidence baseline aggregation code is further modulated and optimized based on a set of implicit modulation factors for weighted evaluation of evidence to obtain an integrated core evidence representation, thereby performing a process of constraint modulation and representation refinement. In this process, using the obtained set of causal emergence constraint factors, a guided, non-linear fine adjustment is made to the initially formed macro-level representation through complex gating mechanisms or attention weighting, thereby amplifying the influence of evidence features with high causal contribution in the final representation, while suppressing evidence features with low contribution. In this way, an integrated core evidence representation constrained and optimized by causal structure can be produced. This representation is no longer a simple statistical mixture, but a structured and more robust deep representation. It not only summarizes the appearance of the global threat, but also reflects how this appearance is shaped by key local evidence, providing input with higher information density and clearer internal logic for downstream classification tasks.

[0057] Specifically, in step S430, feature classification regression is performed on the integrated core evidence representation to obtain the consensus result. It should be understood that since the integrated core evidence representation generated in the previous step is a dense vector in a high-dimensional feature space, it is still an abstract, machine-readable feature representation, rather than a clear conclusive judgment that can be directly used to guide defense actions. Therefore, in the technical solution of this application, feature classification regression is further performed on the integrated core evidence representation to obtain the consensus result. This allows a final decision network to map the deeply fused complex feature patterns onto predefined threat levels or risk scores with clear business implications. In this way, the final analysis result of the entire collaborative assessment process can be transformed into a specific and actionable consensus conclusion, providing a clear and unambiguous instruction basis for the defense coordinator to formulate and execute response strategies.

[0058] More specifically, in a concrete example of this application, this process is implemented through a classification network. First, the integrated core evidence representation vector obtained in the previous step is input into a classifier composed of a multilayer perceptron. The output layer of this classifier is configured with the same number of neurons as the preset threat levels, for example, corresponding to four levels: no threat, low threat, medium threat, and high threat, and employs the Softmax activation function. After the representation vector flows through this classifier, the Softmax function outputs a probability distribution vector, where each element corresponds to the probability that the global situation described by the representation vector belongs to each threat level. Finally, the threat level corresponding to the element with the highest probability value in this probability distribution vector is selected as the final consensus output.

[0059] Specifically, in step S500, based on the consensus result, the defense coordinator generates specific defense instructions according to the pre-plan and assigns them to the corresponding intelligent agents for execution. It should be understood that since the consensus result generated in the preceding steps is only a high-level judgment of the global threat state, it is not itself a directly executable defense action. It must be transformed into explicit instructions that can be implemented on specific device nodes to achieve effective closed-loop threat handling. Therefore, in the technical solution of this application, based on the consensus result, the defense coordinator further generates specific defense instructions according to the pre-plan and assigns them to the corresponding intelligent agents for execution, thereby initiating an automated response process. This combines the abstract consensus conclusion with the pre-programmed defense strategy to generate machine instructions that can be parsed and executed by specific intelligent agents, and routes them to intelligent agents with the corresponding execution capabilities. This ensures the complete integration of the entire collaborative defense system from perception and decision-making to control, transforming the crystallization of collective wisdom into rapid, accurate, and collaborative actual defense actions, truly implementing closed-loop automated defense.

[0060] More specifically, in a concrete example of this application, the execution process is driven by a defense coordinator. Upon receiving the consensus result from the previous stage, such as a determination of a high-level distributed denial-of-service attack, the defense coordinator immediately queries its internally stored defense contingency plan library and matches it with the corresponding handling plan. This plan may include multiple operations, such as blocking malicious source IP addresses and enabling traffic scrubbing on the target server. Based on this, the defense coordinator generates two specific defense instructions: the first instruction updates the firewall access control list to include a list of IP addresses that need to be blocked; the second instruction enables traffic rate limiting on a specific port. Subsequently, the defense coordinator distributes the instructions according to the functional roles of each agent, sending the first instruction to the firewall agent deployed at the network boundary with network access control capabilities, and sending the second instruction to the host agent deployed on the web server with host network stack management capabilities.

[0061] In summary, the multi-agent collaborative defense and evaluation method according to the embodiments of this application is explained. It utilizes multiple agents deployed on different nodes, each independently collecting raw data within its monitoring range and generating standardized local evaluation evidence. To address the issue of inconsistent reliability of evidence sources, a honor score mechanism is introduced to weight and discount the local evaluation evidence. Simultaneously, to avoid communication congestion, a selective broadcast strategy is designed, broadcasting only when evidence meets importance or variability thresholds. After all weighted and filtered evidence is aggregated, a global evidence fusion and consensus decision-making mechanism integrates heterogeneous and asynchronous evaluation information from different local perspectives into a unified and reliable global consensus result. Finally, the defense coordinator generates and issues defense commands based on this consensus result, effectively solving the technical problem in traditional methods where limited perspectives, heterogeneous models, and communication overhead make it difficult to quickly form accurate global threat perception.

[0062] As described above, the multi-agent collaborative defense and evaluation method according to the embodiments of this application can be implemented in various network and computing devices, such as edge security gateways, data center servers, smart network interface cards, or cloud computing platforms. In one possible implementation, the multi-agent collaborative defense and evaluation method according to the embodiments of this application can be integrated into the network security protection system as a software module or hardware module. For example, the multi-agent collaborative defense and evaluation method can be an independent security analysis application running on a server, or a collaborative decision-making function plug-in module of a network intrusion detection system or security situation awareness platform, or an application programming interface deployed on a cloud platform that provides consensus decisions to various distributed agents through the network; of course, the core evidence fusion calculation and feature aggregation network inference module in this method can also be embedded in hardware such as a data processing unit (DPU), application-specific integrated circuit (ASIC), or field-programmable gate array (FPGA), as one of the real-time analysis or security function offloading hardware modules of the network security protection system.

[0063] The various embodiments of this disclosure have been described above. These descriptions are exemplary and not exhaustive, nor are they limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terminology used herein is chosen to best explain the principles, practical application, or improvement of the technology in the market, or to enable others skilled in the art to understand the embodiments disclosed herein.

Claims

1. A multi-agent cooperative defense and evaluation method, characterized in that, include: Each intelligent agent continuously collects raw data within its monitoring range; Each agent uses its built-in threat model to segment the raw data to obtain local evaluation evidence: Each agent performs evidence weighting and selective broadcasting on local evaluation evidence based on its current honor score to obtain weighted evaluation evidence; Global evidence fusion and consensus decision-making are performed on the weighted evaluation evidence set to obtain a consensus result; Based on the consensus results, the defense coordinator generates specific defense instructions according to the contingency plan and assigns them to the corresponding agents for execution.

2. The multi-agent cooperative defense and evaluation method according to claim 1, characterized in that, Each agent uses its built-in threat model to segment the raw data to obtain local evaluation evidence, including: The raw data is characterized by monitoring indicators to obtain the feature vector of the monitoring indicators; The feature vectors of the monitoring indicators are input into the threat model to perform multi-dimensional propensity scoring to obtain a set of propensity scores; The local evaluation evidence is generated based on the propensity score set.

3. The multi-agent cooperative defense and evaluation method according to claim 2, characterized in that, The monitoring metric feature vectors include: packet rate, byte rate, connection flow rate, average packet length, protocol percentage, TCP flag combination count, source IP address entropy, destination port entropy, CPU utilization, memory usage, disk I / O rate, number of active processes, system call frequency, number of login failures, HTTP response code distribution, API request rate, request parameter anomaly score, number of slow queries, query complexity, and deviation of feature values ​​from historical baselines.

4. The multi-agent cooperative defense and evaluation method according to claim 2, characterized in that, Based on the propensity score set, the local assessment evidence is generated, including: Threat intensity aggregation calculation is performed on the propensity score set to obtain an aggregate score; Based on the aggregated scores, the threat tendency set is normalized to obtain the threat tendency normalized distribution; Confidence factors are generated based on aggregate scores and sensitivity parameters; Based on the confidence factor, a specific belief quantity is assigned to the threat propensity normalization distribution to obtain the belief quantity vector. The local evaluation evidence is constructed based on the belief vector and confidence factor.

5. The multi-agent cooperative defense and evaluation method according to claim 1, characterized in that, Each agent performs evidence weighting and selective broadcasting on its local evaluation evidence based on its current honor score to obtain weighted evaluation evidence, including: Belief discounting is applied to local assessment evidence based on current honor points to obtain weighted assessment evidence; Based on the broadcast threshold set and the previous broadcast evidence, the broadcast trigger condition is evaluated on the weighted evaluation evidence to obtain the broadcast decision. In response to the broadcast decision being true, the weighted evaluation evidence is broadcast.

6. The multi-agent cooperative defense and evaluation method according to claim 5, characterized in that, Based on the broadcast threshold set and previous broadcast evidence, broadcast trigger conditions are evaluated on the weighted evaluation evidence to obtain a broadcast decision, including: The weighted evidence is assessed for importance to obtain importance belief values; Calculate the difference between the previous broadcast evidence and the weighted assessment evidence to obtain a value for the degree of evidence change; Determine whether the importance belief value is greater than the importance belief threshold and whether the evidence change value is greater than the change threshold. If the importance belief value is greater than the importance belief threshold or the evidence change value is greater than the change threshold, then the broadcast decision is determined to be true.

7. The multi-agent cooperative defense and evaluation method according to claim 1, characterized in that, Global evidence fusion and consensus decision-making are performed on the weighted evaluation evidence set to obtain a consensus result, including: Structured embedding encoding is performed on each weighted piece of evidence in the weighted evaluation evidence set to obtain a weighted embedding representation set for each piece of evidence; The core evidence is deeply fused into the weighted embedding representations of each piece of evidence to obtain an integrated core evidence representation; The consensus results are obtained by performing feature classification regression on the integrated core evidence representation.

8. The multi-agent cooperative defense and evaluation method according to claim 7, characterized in that, The core evidence is deeply fused from the weighted embedding representations of each piece of evidence to obtain an integrated core evidence representation, including: The weighted embedding representation set of each piece of evidence is input into the baseline feature convergence network to obtain the global evidence baseline aggregation code; Calculate the causal association-based implicit modulation factor of each evidence weighted embedding representation in the set of evidence weighted embedding representations relative to the global evidence baseline to obtain the set of causal association-based implicit modulation factors for weighted evaluation evidence; Based on the set of implicit modulation factors for weighted evaluation evidence and causal association, the global evidence baseline aggregation coding is modulated and optimized to obtain an integrated core evidence representation.