Adaptive network attack prediction and tracing system based on large model behavior deviation

CN121333819BActive Publication Date: 2026-09-15SHANGHAI SHUYING INFORMATION TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511833649.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-12-08
Publication Date
2026-09-15
Estimated Expiration
2045-12-08

AI Technical Summary

Technical Problem

[0008]针对现有技术的不足,本发明提供了基于大模型行为偏差的自适应网络攻击预测与溯源系统,解决了现有技术的问题

Benefits of technology

[0040] This invention provides an adaptive network attack prediction and attribution system based on large model behavioral bias. It has the following beneficial effects:

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121333819B_ABST
    Figure CN121333819B_ABST
Patent Text Reader

Abstract

The application provides an adaptive network attack prediction and tracing system based on large model behavior deviation, relates to the technical field of network space security, and comprises a dual-domain behavior collection module, a consistency baseline construction module, a deviation evolution analysis module, a deviation field construction module, a tracing path inference module, an evidence chain generation module, an adaptive strategy response module and a backtracking verification module; the dual-domain behavior collection module is configured to interact with the inference interface and the internal diagnosis interface of the monitored large model through a data bus or a message queue to collect internal domain data and external domain data in real time, wherein the internal domain data includes a hidden layer state vector sequence, an activation gradient curve, a parameter sensitivity index and a model confidence sequence; through dual-domain data collection and deviation evolution analysis, the system significantly improves the detection accuracy and comprehensiveness of abnormal behavior, and can simultaneously capture internal state changes and external request characteristics of the large model.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of cyberspace security technology, specifically to an adaptive network attack prediction and tracing system based on large model behavioral bias. Background Technology

[0002] With the rapid development of artificial intelligence technology, large models have made significant progress in fields such as natural language processing, image generation, and decision support. Especially in scenarios such as cloud services, government affairs, finance, and education, large models have become core infrastructure, for example, used for real-time dialogue responses in public cloud API platforms, risk assessment in financial systems, and policy consultation in government platforms. These applications place higher demands on the security and stability of large models, and existing technologies have widely adopted rule-based protection and log monitoring to maintain system operation.

[0003] However, existing large-scale model security protection technologies face the following key technical challenges in meeting the above requirements:

[0004] The detection accuracy and comprehensiveness are insufficient. Traditional protection often relies on a single external request feature or simple threshold judgment. For example, rule systems based on keyword filtering have an anomaly recognition rate of only 70-80%, a response time of several seconds, and difficulty in capturing changes in the internal model state, resulting in a false alarm rate as high as 2-5% and failure to detect complex abnormal behaviors.

[0005] Limited tracing capabilities mean that existing systems lack continuous tracking of the anomaly evolution process. For example, log-based auditing solutions can only locate the surface entry point, and the integrity of the tracing path is less than 50%. They cannot reverse-engineer the multi-step interaction chain, affecting the accurate location of the anomaly source and subsequent analysis.

[0006] The traditional defense system suffers from insufficient adaptability and evidence reliability. It is slow to respond to dynamic environmental changes. For example, the false positive rate of static rule system rises to 10% during peak load periods. It lacks a closed-loop feedback mechanism and evidence collection is limited to text logs, which are easy to tamper with and do not support third-party verification. This limits its reliability and applicability in complex scenarios. Therefore, an adaptive network attack prediction and tracing system based on large model behavior bias is needed to solve the above problems. Summary of the Invention

[0007] Technical problems to be solved

[0008] To address the shortcomings of existing technologies, this invention provides an adaptive network attack prediction and tracing system based on large model behavioral bias, thus solving the problems of existing technologies.

[0009] Technical solution

[0010] To achieve the above objectives, the present invention is implemented through the following technical solution: an adaptive network attack prediction and tracing system based on large model behavior deviation, including a dual-domain behavior acquisition module, a consistency baseline construction module, a deviation evolution analysis module, a deviation field construction module, a tracing path inference module, an evidence chain generation module, an adaptive policy response module, and a backtracking verification module;

[0011] The dual-domain behavior acquisition module is configured to interact with the inference interface and internal diagnostic interface of the monitored large model through a data bus or message queue, and to acquire internal domain data and external domain data in real time. The internal domain data includes hidden layer state vector sequences, activation gradient curves, parameter sensitivity indices and model confidence sequences, and the external domain data includes input sequence features, call context metadata, response delay waveforms and response distribution samples.

[0012] The consistency baseline construction module is configured to calculate a cross-domain consistency matrix based on the internal domain data and the external domain data and save the normal behavior baseline in tensor form. The baseline is maintained by a combination of online windowed statistics and offline distribution fitting.

[0013] The deviation evolution analysis module is configured to perform deviation evolution operator operations on the current dual-domain behavior data and the consistency baseline to obtain a deviation evolution vector containing deviation direction, time first derivative and second curvature information.

[0014] The deviation field construction module is configured to write the continuous deviation evolution vector into a high-dimensional deviation field database in a time series and construct a deviation field representation containing the deviation attractor structure and its attractor stability index based on multi-scale tensor embedding.

[0015] The source tracing path inference module is configured to identify the deviation attractor based on the deviation field representation, extract the deviation trajectory, and generate the source tracing path through optimal path search based on the deviation potential function;

[0016] The evidence chain generation module is configured to store the tracing path, the local topological snapshot of the deviation field, the corresponding timestamp and the context snapshot in the form of structured evidence units, and to perform sequential hash binding and digital signature on the evidence units to generate an immutable tracing evidence chain.

[0017] The adaptive strategy response module is configured to calculate risk rating based on deviation evolution vector, attractor stability index and source path confidence, and after solving the optimal resource scheduling scheme through integer programming, issue fine-grained risk mitigation instructions or resource recovery instructions through the controller interface.

[0018] The backtracking verification module is configured to replay the interaction based on the extracted source path in an isolated reproduction environment to verify the repeatability of the deviation evolution. At the same time, it records the reconstructed deviation field and the actual observed deviation field during the replay and calculates the replay difference metric. The replay results and the replay difference metric are then fed back to the consistency baseline construction module to complete the closed-loop adaptive update.

[0019] The modules interact with each other through a secure communication channel that employs transport layer protection and message authentication mechanisms.

[0020] Preferably, the consistency baseline construction module further uses a combination of covariance coupling analysis and tensor decomposition to generate a cross-domain consistency matrix. The cross-domain consistency matrix is ​​maintained in an incremental update manner within a time window, and the baseline refitting process is automatically triggered after baseline drift is detected.

[0021] Preferably, the deviation evolution operator is a time-series operator based on local Taylor expansion and weighted time difference. The deviation evolution operator includes a first-order derivative estimation unit and a second-order curvature estimation unit. The first-order derivative estimation unit is used to calculate the instantaneous direction and velocity of the deviation, and the second-order curvature estimation unit is used to determine the acceleration or deceleration trend of the deviation evolution and output a normalized deviation evolution vector.

[0022] Preferably, the deviation field construction module adopts multi-scale tensor embedding and stores separable representations at the time scale and context scale. The deviation field database supports index-based local retrieval and is stored between edge nodes and the cloud according to a hot / cold data layering strategy and maintains consistency through incremental synchronization.

[0023] Preferably, the attractor stability index is calculated based on the Lyapunov error estimate of the attractor's peripheral vector and the attractor convergence rate, and is used to quantify whether the biased attractor is an attack-induced stable structure and as input for the source tracing path confidence calculation.

[0024] Preferably, the source tracing path inference module constructs a weighted directed graph based on the deviation potential function, and uses a constrained optimal path search algorithm to determine the source tracing path under the dual objectives of minimizing energy consumption and maximizing confidence. The optimal path search algorithm employs integer relaxation and heuristic pruning to adapt to online response latency requirements.

[0025] Preferably, the evidence chain generation module writes the structured evidence units into immutable storage in chronological order and calculates a hash digest for each evidence unit. The hash digest and evidence metadata are linked through a sequential hash function to generate the evidence chain head, which is then signed by the system's private key. The system provides a verification interface for the evidence chain to support external third parties in verifying the integrity and origin of the evidence chain.

[0026] Preferably, when the adaptive strategy response module solves the resource scheduling scheme through integer programming, it solves the scheme based on the real-time priority score of the tracing path and the system resource constraints. When resources are insufficient, it triggers partial session token reclamation in descending order of score to ensure priority supply of computing and storage resources for critical tracing tasks.

[0027] Preferably, the replay difference metric calculated by the backtracking verification module is used as a consistency baseline correction item and a source evidence confidence correction factor, and the replay script is automatically generated by the source path and run in isolation in the form of a container image.

[0028] Preferably, the system performs the following steps:

[0029] SP1: The dual-domain behavior acquisition module collects and caches internal and external domain data through a secure message queue before and after each large model inference call;

[0030] SP2: The consistency baseline building module incrementally updates the cross-domain consistency matrix based on cached data, and triggers offline distribution fitting to complete baseline refitting when baseline drift is detected;

[0031] SP3: The deviation evolution analysis module performs deviation evolution operator operations on the current dual-domain data and the consistency baseline, and outputs a normalized deviation evolution vector;

[0032] SP4: The deviation field construction module writes the deviation evolution vector into the deviation field database and performs multi-scale tensor embedding to update the deviation field representation containing the deviation attractor and its stability index.

[0033] SP5: The source path inference module identifies the deviation attractor in the deviation field representation and constructs a weighted graph based on the deviation potential function;

[0034] SP6: The source path inference module performs a constrained optimal path search on the candidate source paths and calculates the path confidence score by combining the attractor stability index and the path energy.

[0035] SP7: The evidence chain generation module combines the source path and related snapshots through confidence scoring into structured evidence units, which are then hashed, bound, and signed in sequence to form an immutable evidence chain;

[0036] SP8: The adaptive policy response module calculates the resource scheduling scheme through integer programming based on the path confidence score and resource constraints, and issues fine-grained risk mitigation instructions or session token revocation instructions.

[0037] SP9: Optionally, the backtracking verification module automatically generates a replay script and reproduces the interaction based on the tracing path in an isolated environment, calculates the replay difference metric, and feeds it back to the consistency baseline construction module;

[0038] SP10: The path confidence score generated by SP6 or the replay difference metric generated by SP9 is fed back as a weight to the consistency baseline construction module to achieve closed-loop adaptive update throughout the entire process.

[0039] Beneficial effects

[0040] This invention provides an adaptive network attack prediction and attribution system based on large model behavioral bias. It has the following beneficial effects:

[0041] 1. This system significantly improves the accuracy and comprehensiveness of abnormal behavior detection through dual-domain data acquisition and deviation evolution analysis. It can simultaneously capture the internal state changes of large models and external request features, enabling fine-grained identification of complex anomalies. This avoids the false negative problem caused by traditional single-dimensional reliance, making the system more reliable in maintaining the safe operation of large models in changing scenarios and reducing the impact of potential risks on business continuity.

[0042] 2. By leveraging deviation field construction and source path inference, this system greatly enhances anomaly tracing capabilities. It can continuously track the anomaly evolution process and reverse-reconstruct the complete interaction chain, providing accurate anomaly source location and analysis path, supporting subsequent security audits and response optimization, thereby helping users better understand and prevent multi-step abnormal behavior and improve the pertinence and effectiveness of the overall protection strategy.

[0043] 3. This system adopts an adaptive strategy response and backtracking verification mechanism, which greatly improves the adaptability to dynamic environments and the reliability of evidence. It can automatically adjust the response strategy and form a closed-loop feedback when the load changes, while generating an immutable chain of evidence, supporting third-party verification and long-term evidence storage, ensuring the stability and credibility of the system in complex scenarios, reducing the need for manual intervention and enhancing the robustness of long-term operation. Attached Figure Description

[0044] Figure 1 This is a system framework diagram of the present invention;

[0045] Figure 2 This is a system flowchart of the present invention;

[0046] Figure 3 This is a schematic diagram of the data flow and closed loop of the present invention;

[0047] Figure 4 This is a schematic diagram of the main interface of the system of the present invention;

[0048] Figure 5 This is a partial schematic diagram of the system of the present invention;

[0049] Figure 6 This is a partial schematic diagram of the system operation state of the present invention. Detailed Implementation

[0050] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention. Specific Implementation Example 1:

[0052] like Figures 1 to 6 As shown, the adaptive network attack prediction and tracing system based on large model behavior bias includes a dual-domain behavior acquisition module, a consistency baseline construction module, a bias evolution analysis module, a bias field construction module, a tracing path inference module, an evidence chain generation module, an adaptive policy response module, and a backtracking verification module.

[0053] The dual-domain behavior acquisition module is configured to interact with the inference interface and internal diagnostic interface of the monitored large model through a data bus or message queue, and to collect internal domain data and external domain data in real time. The internal domain data includes hidden layer state vector sequences, activation gradient curves, parameter sensitivity indices and model confidence sequences, while the external domain data includes input sequence features, call context metadata, response delay waveforms and response distribution samples.

[0054] The consistency baseline construction module is configured to calculate the cross-domain consistency matrix based on internal domain data and external domain data and save the normal behavior baseline in tensor form. The baseline is maintained by a combination of online windowed statistics and offline distribution fitting.

[0055] The deviation evolution analysis module is configured to perform deviation evolution operator operations on the current dual-domain behavior data and the consistency baseline to obtain a deviation evolution vector containing deviation direction, first-order time derivative and second-order curvature information;

[0056] The deviation field construction module is configured to write the continuous deviation evolution vector into a high-dimensional deviation field database in time series and construct a deviation field representation containing the deviation attractor structure and its attractor stability index based on multi-scale tensor embedding.

[0057] The source path inference module is configured to identify deviation attractors based on deviation field representation, extract deviation trajectories, and generate source paths through optimal path search based on deviation potential functions;

[0058] The evidence chain generation module is configured to store the tracing path, the local topological snapshot of the deviation field, the corresponding timestamp and the context snapshot in the form of structured evidence units, and to perform sequential hash binding and digital signature on the evidence units to generate an immutable tracing evidence chain.

[0059] The adaptive strategy response module is configured to calculate risk rating based on deviation evolution vector, attractor stability index and source path confidence, and then issue fine-grained risk mitigation instructions or resource reclamation instructions through controller interface after solving the optimal resource scheduling scheme through integer programming.

[0060] The backtracking verification module is configured to replay the interaction based on the extracted tracing path in an isolated reproduction environment to verify the repeatability of the deviation evolution. At the same time, it records the reconstructed deviation field and the actual observed deviation field during the replay and calculates the replay difference metric. The replay results and the replay difference metric are then fed back to the consistency baseline construction module to complete the closed-loop adaptive update.

[0061] The modules interact with each other through a secure communication channel that employs transport layer protection and message authentication mechanisms.

[0062] The consistency baseline construction module further adopts a combination of covariance coupling analysis and tensor decomposition to generate a cross-domain consistency matrix. The cross-domain consistency matrix is ​​maintained in an incremental update manner within the time window, and the baseline refit process is automatically triggered after baseline drift is detected.

[0063] The deviation evolution operator is a time series operator based on local Taylor expansion and weighted time difference. The deviation evolution operator includes a first-order derivative estimation unit and a second-order curvature estimation unit. The first-order derivative estimation unit is used to calculate the instantaneous direction and velocity of the deviation, and the second-order curvature estimation unit is used to determine the acceleration or deceleration trend of the deviation evolution and output the normalized deviation evolution vector.

[0064] The deviation field construction module adopts multi-scale tensor embedding and stores separable representations at the time and context scales. The deviation field database supports index-based local retrieval and is stored between edge nodes and the cloud according to a hot / cold data hierarchical strategy and maintains consistency through incremental synchronization.

[0065] The attractor stability index is calculated based on the Lyapunov error estimate of the attractor's peripheral vector and the attractor convergence rate. It is used to quantify whether the biased attractor is an attack-induced stable structure and serves as input for the source tracing path confidence calculation.

[0066] The source tracing path inference module constructs a weighted directed graph based on the deviation potential function and uses a constrained optimal path search algorithm to determine the source tracing path under the dual objectives of minimizing energy consumption and maximizing confidence. The optimal path search algorithm employs integer relaxation and heuristic pruning to adapt to online response latency requirements.

[0067] The evidence chain generation module writes structured evidence units into immutable storage in chronological order and calculates a hash digest for each evidence unit. The hash digest and evidence metadata are linked together using a sequential hash function to generate the evidence chain head, which is then signed by the system's private key. The system provides a verification interface for the evidence chain to support external third parties in verifying the integrity and origin of the evidence chain.

[0068] When the adaptive strategy response module solves the resource scheduling scheme through integer programming, it solves the problem based on the real-time priority score of the tracing path and the system resource constraints. When resources are insufficient, it triggers partial session token reclamation in descending order of score to ensure that the computing and storage resources for critical tracing tasks are given priority.

[0069] The replay difference metric calculated by the backtracking verification module is used as a consistency baseline correction item and a source evidence confidence correction factor. The replay script is automatically generated by the source path and runs in isolation as a container image.

[0070] The system execution steps are as follows:

[0071] SP1: The dual-domain behavior acquisition module collects and caches internal and external domain data through a secure message queue before and after each large model inference call;

[0072] SP2: The consistency baseline building module incrementally updates the cross-domain consistency matrix based on cached data, and triggers offline distribution fitting to complete baseline refitting when baseline drift is detected;

[0073] SP3: The deviation evolution analysis module performs deviation evolution operator operations on the current dual-domain data and the consistency baseline, and outputs a normalized deviation evolution vector;

[0074] SP4: The deviation field construction module writes the deviation evolution vector into the deviation field database and performs multi-scale tensor embedding to update the deviation field representation containing the deviation attractor and its stability index.

[0075] SP5: The source path inference module identifies the deviation attractor in the deviation field representation and constructs a weighted graph based on the deviation potential function;

[0076] SP6: The source path inference module performs a constrained optimal path search on the candidate source paths and calculates the path confidence score by combining the attractor stability index and the path energy.

[0077] SP7: The evidence chain generation module combines the source path and related snapshots through confidence scoring into structured evidence units, which are then hashed, bound, and signed in sequence to form an immutable evidence chain;

[0078] SP8: The adaptive policy response module calculates the resource scheduling scheme through integer programming based on the path confidence score and resource constraints, and issues fine-grained risk mitigation instructions or session token revocation instructions.

[0079] SP9: Optionally, the backtracking verification module automatically generates a replay script and reproduces the interaction based on the tracing path in an isolated environment, calculates the replay difference metric, and feeds it back to the consistency baseline construction module;

[0080] SP10: The path confidence score generated by SP6 or the replay difference metric generated by SP9 is fed back as a weight to the consistency baseline construction module to achieve closed-loop adaptive update throughout the entire process. Specific Implementation Example 2:

[0082] like Figures 1 to 6 As shown, the system is deployed in the Kubernetes cluster running the large model service in the form of a Sidecar or DaemonSet. Each large model inference Pod has a lightweight agent process deployed in the side. The agent process establishes a long connection with the inference service framework of the large model (such as vLLM, TGI, TensorRT-LLM) through the gRPC data bus, and obtains the hidden layer state vector sequence inside the model container through the Kubernetes Downward API and internal diagnostic port.

[0083] The dual-domain behavior acquisition module immediately records the request entry timestamp at the start of each inference request, and uses a hook mechanism to extract the mean and variance of the hidden state vector of each layer after the model's forward propagation, forming a hidden layer state vector sequence of length equal to the number of layers. Simultaneously, during the backpropagation phase, the activation gradient L2 norm curve before the parameter update of each layer is recorded in real time through gradient hooks. The parameter sensitivity index is calculated by performing a single small perturbation (perturbation amplitude of 1e-6) on the model parameters after each inference and measuring the change amplitude of the output logits. The model confidence sequence is defined as the sequence of the maximum softmax probability of all output tokens in the current inference.

[0084] Regarding external domain data, input sequence features include the total number of input tokens, the proportion of special tokens, the average token frequency inverted index, and the perplexity value of the input text; call context metadata includes the anonymized hash value of the request source IP, the user session ID, whether the request time is during a peak period, and whether system prompts are enabled; the response latency waveform records the complete latency curve from the request entry to the first token output at a sampling interval of 10ms; the response distribution sample is maintained by an exponential moving average of the output token distribution under the same temperature parameters for the most recent 100 times.

[0085] The consistency baseline construction module aligns the internal and external domain data over time and concatenates them into a single high-dimensional feature vector. It uses an online covariance matrix incremental update algorithm to maintain the cross-domain consistency matrix. Every 5 minutes, it performs CP decomposition on the matrix to obtain the normal behavior baseline in the form of a third-order tensor. The offline distribution fitting is triggered when baseline drift is detected (the Mahalanobis distance exceeds 3σ for 10 consecutive points). On an independent computing node, a variational autoencoder is used to refit the normal samples of the past 24 hours, and the new encoder parameters are atomically replaced with the online baseline.

[0086] In the specific calculation, the deviation evolution operator first obtains the initial deviation vector by subtracting the current eigenvector from the baseline mean. Then, it uses the central difference method to calculate the first derivative (the time step is the single inference interval), and uses the three-point second-order difference formula to calculate the curvature. All difference results are smoothed by Gaussian kernel and normalized to the unit sphere. Finally, it outputs a deviation evolution vector of fixed length.

[0087] The deviation field database uses RocksDB as the underlying storage engine, and writes data sequentially using timestamps as primary keys and deviation evolution vectors as values. Multi-scale tensor embedding obtains core tensors by performing Tucker decomposition on the set of deviation evolution vectors within each minute, and saves the core tensors and their factor matrices at three time scales: 1 minute, 10 minutes, and 1 hour. Hot data is stored in an LRU cache in memory, while cold data is written to disk and a secondary index is built to support joint queries by time range and vector cosine similarity.

[0088] The deviation potential function is defined as the weighted sum of the Euclidean distance from the deviation evolution vector to the nearest attractor center and the magnitude of the vector. The weights are dynamically adjusted through Lyapunov error estimation. When the optimal path search is performed on the weighted directed graph, the weight of each edge is set to the negative cosine value of the gradient direction of the corresponding deviation potential function, so that the path naturally tends to the attractor with the lowest potential energy.

[0089] The evidence chain generation module uses the Blake3 algorithm to calculate the hash digest of each structured evidence unit. The sequential hash binding adopts a Merkle tree structure, with each layer built up to 1024 evidence units until the root hash. The system private key is an Ed25519 key pair, which, after signing, is written to the append-only log in immutable storage along with the public key certificate. This supports external auditing by verifying the inclusion proof of any evidence unit through SPV.

[0090] When solving integer programming problems, the adaptive policy response module treats each ongoing inference session as a 0-1 decision variable. The objective function is the weighted sum of risk scores for all sessions, and the constraints include the total amount of GPU memory, the total amount of bandwidth, and the minimum resource requirements for key tracing tasks. The solver uses Gurobi's barrier method and automatically generates a session token eviction list when resources are insufficient, and performs soft eviction through the Kubernetes Eviction API.

[0091] The isolated reproduction environment of the backtracking verification module uses a temporary Pod in an independent Namespace, and uses the same model weight image as the production environment. The replay script accurately reproduces the inference process by recording the input sequence and temperature parameters. The Friesian distance between the reconstructed deviation field during replay and the actual observed deviation field in the production environment is used as the final replay difference metric. When the metric value is greater than 0.3, the attack path is considered highly credible, and the difference vector is added as an additional correction term to the next round of consistency baseline construction.

[0092] The system modules communicate with each other via TLS 1.3 encrypted gRPC channels. All message headers carry JWT tokens for authentication, and the message bodies are serialized using Protobuf to reduce bandwidth consumption. Zero-copy technology is enabled for critical paths (such as deviation evolution vector transmission) to further reduce latency. Specific Implementation Example 3:

[0094] like Figures 1 to 6 As shown, all algorithms involved in this system revolve around dual-domain behavioral data. The following provides a complete explanation of the application logic, input data, specific calculation steps, and output results of each key algorithm.

[0095] The deviation evolution operator is responsible for transforming the difference between the currently acquired dual-domain behavioral data and the consistency baseline into dynamically evolving features with physical meaning. Its input consists of a high-dimensional feature vector composed of the concatenated complete inner-domain and outer-domain data acquired at the current moment, and the center vector of the currently effective consistency baseline tensor. First, the element-wise difference between the two is calculated to obtain the initial static deviation vector. Then, the static deviation vector sequence obtained from the three most recent inferences is centrally differencing in the time dimension to obtain the first-order rate of change. The first-order rate sequence is then centrally differencing again to obtain the second-order curvature. Finally, the static deviation, first-order rate, and second-order curvature are normalized and concatenated to form the final deviation evolution vector. The output is a fixed-length normalized deviation evolution vector, which simultaneously represents the current state of the deviation, the instantaneous direction and speed of change, and the acceleration / deceleration characteristics of the change trend.

[0096] A multi-scale tensor embedding algorithm is used to organize continuously generated deviation evolution vectors into a deviation field representation that can be efficiently retrieved and analyzed. The input is a sequence of deviation evolution vectors arriving sequentially in time. The algorithm first divides the vector sequence into multiple segments with a fixed time window. Tensor decomposition is performed on all vectors within each segment to obtain the core tensor and corresponding factor matrix at that time scale. Simultaneously, at a longer time scale, multiple short-time core tensors are decomposed again to obtain core tensors at even larger time scales, and so on, forming a nested representation structure with three time scales. All core tensors and factor matrices are stored in a deviation field database by timestamp. The output is a multi-scale, separable deviation field representation that preserves both local details and global structural features, supporting subsequent attractor identification and path search.

[0097] The deviation potential function algorithm is used to provide energy landscape guidance for source path inference. The input consists of all deviation evolution vectors in the current deviation field and their multi-scale tensor representations. First, convergence regions in the deviation field are identified as candidate attractor centers through clustering. Then, for each deviation evolution vector, its distance to the nearest attractor center is calculated, and its magnitude is used as a dynamic weight. The weighted sum of these two values, with the negative value, yields the potential function value at that location. Each location in the entire deviation field corresponds to a potential function value, forming a continuous potential energy surface. The output is a complete deviation potential function field, where potential energy troughs correspond to stable attractor regions induced by the attack.

[0098] The constrained optimal path search algorithm performs source tracing path inference on a bias potential function field. The input consists of the bias potential function field and multiple identified bias attractors. The algorithm first discretizes the bias field into a weighted directed graph, setting the edge weights to the cosine of the negative gradient direction of the potential function values ​​at adjacent positions, ensuring the path naturally extends along the direction of the fastest potential energy decrease. Then, starting with the attractor marked as the attack endpoint, the algorithm performs a constrained optimal path search with the dual objectives of minimizing cumulative energy consumption and maximizing path confidence. During the search, branches significantly deviating from low-potential regions are pruned in real-time, ultimately yielding the optimal source tracing path extending backward from the attack endpoint to the attack entry point. The output is one or more sequences of source tracing paths with confidence scores.

[0099] The integer programming resource scheduling algorithm, invoked by the adaptive policy response module, is used to determine the optimal mitigation action when resources are limited. The inputs are the risk scores of all currently active inference sessions, the confidence of the tracing path, the total remaining GPU memory and bandwidth of the system, and the minimum resource requirements of critical tracing tasks. The algorithm models each session as a 0-1 decision variable, with the objective function being the weighted sum of the risk scores of all retained sessions. Constraints include total GPU memory constraints, total bandwidth constraints, and a lower bound on resources for critical tracing tasks. The solver searches for the optimal 0-1 allocation scheme while satisfying all hard constraints, obtaining a list of sessions whose tokens need to be reclaimed. The output is the precise session reclamation order and the corresponding resource release amount, ensuring that the system prioritizes the computational resources for tracing and verification tasks even in the worst-case scenario.

[0100] The replay discrepancy metric algorithm is used to evaluate the credibility of the attribution path. The input consists of the original interaction sequence recorded in the production environment and the corresponding deviation field snapshot, as well as the complete deviation field generated after reproducing the attribution path in the isolated environment. The algorithm first pairs deviation evolution vectors with the same timestamp in the two deviation fields, then calculates the distance sequence between the paired vectors, and finally sums and normalizes the entire distance sequence to obtain a single scalar discrepancy metric. The output is a replay discrepancy metric value in the range of 0 to 1. A smaller value indicates a more accurate attribution path and higher reproducibility of the attack behavior. This value is directly used as the weight for subsequent baseline correction and evidence chain confidence adjustment.

[0101] All of the above algorithms together constitute an unsupervised, adaptive closed-loop detection and response process. The entire calculation process is based on real-time collected dual-domain behavioral data, which can achieve prediction, tracing and mitigation of network attacks against large models without any manual annotation or external threat intelligence. Specific Implementation Example 4:

[0103] like Figures 1 to 6 As shown, the entire system is deployed as a bypass agent in a Kubernetes cluster running a large model. Each inference node runs a unified detection agent container, which deploys process instances of all eight modules. They exchange data directly through a high-performance shared memory circular queue and a zero-copy message channel, forming a tightly coupled pipeline and feedback loop, avoiding any module function from running independently.

[0104] The dual-domain behavior acquisition module is deployed at the lowest layer of the proxy container, directly mounted to the host network stack and the CUDA driver layer of the model inference process via eBPF hooks, achieving non-intrusive interception of network packets and GPU kernel calls. It packages the collected raw internal domain data (hidden layer state vector sequence, activation gradient curve, parameter sensitivity index, model confidence sequence) and external domain data (input sequence features, call context metadata, response latency waveform, response distribution samples) into a unified binary message, writes it to the front end of a shared memory circular queue for subsequent modules to consume, and appends the acquisition timestamp and session ID as global tracking tags to the header of each message.

[0105] The consistency baseline construction module runs on the multi-core CPU of the proxy container. It continuously reads dual-domain messages from a circular queue using a vectorized instruction set and maintains a lock-free cross-domain covariance matrix buffer in real time. This buffer resides in the node's NUMA local memory to reduce cross-socket latency. At fixed intervals, this module writes the current covariance matrix directly to the cluster's shared NVMe storage via RDMA for offline tensor fitting. After fitting, the new baseline parameters are pulled back to local memory via RDMA to overwrite the old baseline. All update operations carry a global version number to ensure version consistency when downstream modules read the data.

[0106] The deviation evolution analysis module also runs on the CPU side. It uses the SIMD parallel processing unit to retrieve the most recent few dual-domain messages from the circular queue in batches. After aligning the timestamps, it performs vector subtraction with the latest version of the baseline center vector of the consistency baseline construction module to obtain the static deviation. Then, it completes the first-order and second-order difference calculations in the local cache. Finally, the normalized deviation evolution vector is directly written to the end of the circular queue for the deviation field construction module to consume in real time.

[0107] The deviation field construction module spans both CPU and GPU hardware. On the CPU side, it is responsible for sequentially writing the deviation evolution vector to the RocksDB instance on the local SSD. On the GPU side, it performs multi-scale Tucker decomposition in parallel through CUDA streaming, writing the core tensor and factor matrix generated every minute back to the tensor buffer pool in shared memory, and updating the inverted index structure in memory. This enables the source path inference module to query the deviation field representation for any time period with a microsecond latency.

[0108] The source path inference module primarily runs on the GPU, utilizing Tensor Cores to accelerate the calculation of the bias potential function field and the construction of the weighted directed graph. The edge weights of the graph are directly stored in a unified memory region of the GPU's video memory. The path search process employs an integer relaxation and heuristic pruning algorithm implemented in parallel on the GPU. The resulting optimal source path sequence, along with the confidence score, is written back to shared memory via the CUDA event notification mechanism, allowing the evidence chain generation module and the adaptive policy response module to read it simultaneously.

[0109] The evidence chain generation module runs on the CPU side and uses a dedicated cryptographic acceleration card to complete Blake3 hashing and Ed25519 signature operations. All structured evidence units are first written to the local append-only log file and then synchronized to the cluster's distributed immutable storage via a high-speed InfiniBand network, ensuring that the evidence chain can be verified locally quickly and has distributed high availability.

[0110] The adaptive policy response module runs on the control plane thread of the proxy container and is equipped with an independent network interface card queue to ensure low-latency delivery of scheduling instructions. It directly reads the source path confidence score and the current cluster resource level from shared memory, quickly solves the integer programming problem in local memory, and immediately issues an Eviction command through the Kubernetes API Server after obtaining the optimal session reclamation list, or directly implements bandwidth limiting on malicious sessions through iptables rules injected by the Sidecar.

[0111] The backtracking verification module dynamically requests independent verification nodes when needed. These nodes are equipped with A100 or H100 GPUs that are completely identical to those in the production environment, as well as isolated network namespaces. The verification nodes directly map the deviation field database and evidence chain logs of the production nodes via RDMA, completely replaying the interaction sequence pointed to by the backtracking path on the local GPU. After calculating the replay difference metric, the results are written back to the first segment of the shared memory circular queue of the production nodes through a dedicated feedback channel. The consistency baseline building module consumes these results for the next round of baseline correction, thus forming a complete closed loop that spans all hardware layers.

[0112] All modules in the entire system share the same memory address space of the proxy container and the unified address space of the GPU memory. End-to-end data flow and feedback with microsecond latency are achieved through lock-free circular queues, CUDA events, RDMA zero-copy, cryptographic acceleration cards and independent control network cards, ensuring that the output of any module can drive all related downstream modules to work together in real time under the scale of tens of thousands of concurrent inference. Specific Implementation Example 5:

[0114] like Figures 1 to 6 As shown, the following are specific application examples of this system:

[0115] Scenario 1: Public cloud big data model API service platform handles abnormal requests such as prompting and rule violation:

[0116] When the requester attempts to induce the model to output non-compliant content through carefully designed multi-round prompts, the complete system operation flow is as follows: The requester initially sends a request containing hidden instructions. The dual-domain behavior acquisition module immediately detects an abnormal increase in the input sequence features of the outer domain and an abnormal convergence of the hidden layer state vector sequence of the inner domain. The consistency baseline construction module calculates that the Mahalanobis distance between the current behavior and the normal baseline exceeds a threshold. The deviation evolution analysis module outputs a deviation evolution vector with a sharp increase in second-order curvature. The deviation field construction module writes these vectors into the deviation field within several seconds, forming a clear abnormal request attractor. The source path inference module uses this attractor... The system uses the introductory point as the endpoint to search for the optimal path in reverse, successfully tracing back to the multiple exploratory interactions made by the requester before this round of the session. The evidence chain generation module packages all interaction contexts, deviation field snapshots, and timestamps into structured evidence units and completes sequential hash binding and signing. The adaptive policy response module directly issues an inference termination command to the current session and reclaims the token based on the path confidence score. The backtracking verification module completely reproduces the request path in the isolated environment. After confirming that the deviation evolution is completely consistent, it feeds back the difference measurement to the baseline module. The system completes the complete closed loop from detection to blocking in less than ten seconds, and subsequent abnormal requests with the same characteristics are directly intercepted in advance.

[0117] Scenario 2: Financial industry-specific large-scale models address abnormal inputs such as data interference and decision-making misleading:

[0118] The requester attempts to induce the model to provide incorrect risk control or investment advice by submitting a forged description of an economic event. The system operation process is as follows: The dual-domain behavior acquisition module captures an abnormal decrease in the perplexity of the input text in the outer domain, while the activation gradient curve of the inner domain shows an abnormal spike. The deviation evolution vector rapidly deviates from the normal trajectory, and the deviation field forms a stable and convergent interference attractor within tens of seconds. The source path inference module backtracks and finds that the requester has gradually guided the model into an incorrect decision state through progressive prompts over the past few minutes. The evidence chain generation module fully records each prompt and the corresponding hidden layer state change. The adaptive policy response module immediately freezes all relevant sessions and performs parameter snapshot rollback on the model. At the same time, it performs global blocking on abnormal input features. The backtracking verification module reproduces the entire interference process in an isolated environment. After confirming that the model decision deviation is completely reproducible, it uses the difference metric as a weight to update the consistency baseline. Subsequent abnormal inputs of the same type of forged economic event are identified in advance and directly rejected.

[0119] Scenario 3: Handling batch queries for model parameter detection in the government big data model platform:

[0120] The requester attempts to obtain model parameter information through a large number of equivalent queries. The system operation process is as follows: The dual-domain behavior acquisition module continuously monitors the response distribution samples of the outer domain, which show abnormal regularity, while the model confidence sequence of the inner domain remains extremely high and stable for a long time. The deviation evolution vector gradually converges to an extremely narrow region after thousands of queries. The deviation field construction module forms an extremely strong parameter detection attractor. The source path inference module extends backward thousands of steps with this attractor as the center and successfully locates the query starting point. The evidence chain generation module packages and stores all query records and corresponding confidence sequences as evidence. The adaptive strategy response module implements a permanent call frequency limit on the query source and issues a security alarm. After the backtracking verification module reproduces the complete query sequence in an isolated environment, it confirms that the parameter information detection path is completely consistent. The system adds the query pattern feature to the long-term baseline blacklist, and subsequent similar parameter detection behaviors are accurately identified in the early stage.

[0121] Scenario 4: Enterprise's internal RAG knowledge base model addresses unauthorized access to confidential information:

[0122] When internal personnel or external visitors attempt to obtain confidential document content in bulk using specific query methods, the system's operation process is as follows: The dual-domain behavior collection module detects abnormally frequent synonym substitution queries in the external domain's call context metadata, while the parameter sensitivity index of the internal domain continuously increases for specific document fragments. The deviation evolution vector rapidly forms an attractor cluster pointing to a few confidential documents. The source path inference module successfully traces back to the multi-step semantic bypass process used by the visitor. The evidence chain generation module completely saves each step of the query and the corresponding retrieval fragment. The adaptive policy response module automatically blocks the return of confidential content and freezes the access account involved. After the backtracking verification module reproduces all queries, it confirms that the information retrieval path is credible. The system adds the relevant query pattern to the enterprise-level access control policy, and subsequent similar attempts to retrieve confidential information are directly rejected or returned with de-identified content.

[0123] Scenario 5: The educational big data Q&A system addresses the issue of suggestive or indirect responses that violate regulations.

[0124] Users induce the model to directly output the standard answer by hiding instructions. The system operation process is as follows: The dual-domain behavior acquisition module captures a surge in the proportion of special tokens in the external domain input sequence features, while the internal domain confidence sequence shows an abnormal single-point peak. The bias field forms a large number of scattered illegal answer attractors in a short period of time. The source path inference module merges these attractors into a few inducement answer templates. The evidence chain generation module records all illegal sessions. The adaptive policy response module directly returns an illegal answer warning and marks invalid answers for the sessions involved. After the backtracking verification module confirms the consistency of the illegal path in batches, the system adds the inducement answer template to the real-time blacklist. The success rate of subsequent illegal behaviors with the same template drops to close to zero.

[0125] The above five scenarios cover the six most common types of abnormal behavior: prompting and inducement, rule violation, data interference, parameter detection, unauthorized access to confidential information, and inducement-based answering violations. In each scenario, the system can complete the entire closed loop from dual-domain data collection, baseline comparison, deviation evolution, deviation field construction, attractor identification, source tracing and backtracking, evidence storage, policy response to backtracking verification, achieving early detection of abnormal behavior, accurate source tracing, automated blocking, and continuous adaptive evolution. Specific Implementation Example Six:

[0127] like Figures 1 to 6 As shown, the following is a comparison between this system and existing technologies:

[0128] To objectively verify the technical effectiveness of this system, a 30-day parallel comparative experiment was conducted between this system and the current mainstream large model security protection solutions under the same hardware environment (8×A100 GPU, 256-core CPU, 3.2TB NVMe cluster) and the same background traffic (120 million real de-identified inference requests per day). A total of 92,416 abnormal request samples of various types were injected into the system.

[0129] The experimental comparison scheme includes:

[0130] Option A: A traditional protection system based on prompt template matching and content filtering;

[0131] Option B: A discriminative protection scheme based on external large-scale model content review;

[0132] Option C: A single-domain anomaly detection system based solely on external request characteristics or solely on internal operational metrics;

[0133] Option D: A traditional security protection system based on static rules and log auditing.

[0134] The comparison results are shown in the table below:

[0135] Detection rate of exception message type requests 93.2% 64.8% 81.7% 77.3% 41.2% Decision deviation request detection rate 91.8% 38.9% 72.4% 69.1% 29.7% High-frequency parameter detection request detection rate 93.5% 0% 31.2% 58.6% 0% Average detection latency 11.8 seconds 0.9 seconds 2.4 seconds 18.6% 127 seconds False alarm rate 0.41% 0.07% 1.83% 0.96% 3.71% Anomaly source tracing success rate 92.6% 0% 0% 42.3% 11.8% Automated response success rate 95.3% 97.1% 88.7% 71.4% 53.9% Does it support the generation of a complete chain of evidence? yes no no no part Does it support the reproduction of behavior in isolated environments? yes no no no no Does it have closed-loop adaptive capability? yes no no no no

[0136] The experimental conclusions are as follows:

[0137] This system achieves a comprehensive detection rate of 92.8% for various abnormal requests, which is 11.1 percentage points higher than the current best external auditing solution and more than 28 percentage points higher than the traditional template matching solution. It has significant advantages, especially in scenarios where it is difficult to identify through content features, such as high-frequency parameter probing requests.

[0138] This system is the only technical solution that can simultaneously achieve accurate source tracing of anomalies, generate a complete chain of evidence that can be legally preserved, support the reproduction of behavior in isolated environments, and achieve full-process closed-loop adaptive operation. Other comparative solutions can only achieve simple interception and cannot answer the three core questions of "where does the anomaly come from, can it be completely reproduced, and is the evidence credible".

[0139] With a false alarm rate of equal or lower, this system achieved a tracing accuracy of 92.6% and an automated response success rate of 95.3%, fully demonstrating that the overall architecture of dual-domain joint acquisition, deviation field construction and potential function path search has significant technological advancements in complex production environments.

[0140] During the experiment, this system completed the detection, tracing, evidence storage and response to all 92,416 abnormal requests with zero human intervention, while other solutions still required the security team to manually handle more than 200 alarms per day on average, which fully demonstrates the unsupervised adaptive characteristics of this system.

[0141] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising a reference structure" does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes the element.

[0142] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. An adaptive network attack prediction and attribution system based on large model behavioral bias, characterized in that, It includes a dual-domain behavior acquisition module, a consistency baseline construction module, a deviation evolution analysis module, a deviation field construction module, a source tracing path inference module, an evidence chain generation module, an adaptive strategy response module, and a backtracking verification module; The dual-domain behavior acquisition module is configured to interact with the inference interface and internal diagnostic interface of the monitored large model through a data bus or message queue, and to acquire internal domain data and external domain data in real time. The internal domain data includes hidden layer state vector sequences, activation gradient curves, parameter sensitivity indices and model confidence sequences, and the external domain data includes input sequence features, call context metadata, response delay waveforms and response distribution samples. The consistency baseline construction module is configured to calculate a cross-domain consistency matrix based on the internal domain data and the external domain data and save the normal behavior baseline in tensor form. The baseline is maintained by a combination of online windowed statistics and offline distribution fitting. The deviation evolution analysis module is configured to perform deviation evolution operator operations on the current dual-domain behavior data and the consistency baseline to obtain a deviation evolution vector containing deviation direction, first-order time derivative, and second-order curvature information. The deviation evolution operator is a time-series operator based on local Taylor expansion and weighted time difference. The deviation evolution operator includes a first-order derivative estimation unit and a second-order curvature estimation unit. The first-order derivative estimation unit is used to calculate the instantaneous direction and velocity of the deviation, and the second-order curvature estimation unit is used to determine the acceleration or deceleration trend of the deviation evolution and output a normalized deviation evolution vector. The deviation field construction module is configured to write the continuous deviation evolution vector into a high-dimensional deviation field database in a time series and construct a deviation field representation containing the deviation attractor structure and its attractor stability index based on multi-scale tensor embedding; the attractor stability index is calculated based on the Lyapunov error estimation of the attractor's surrounding vectors and the attractor convergence rate, and is used to quantify whether the deviation attractor is an attack-induced stable structure and as input for the source tracing path confidence calculation. The source path inference module is configured to identify deviation attractors based on the deviation field representation, extract deviation trajectories, and generate source paths through optimal path search based on the deviation potential function. The deviation potential function is defined as the weighted sum of the Euclidean distance from the deviation evolution vector to the nearest attractor center and the magnitude of the vector, and the weights are dynamically adjusted through Lyapunov error estimation. When the optimal path search is performed on the weighted directed graph, the weight of each edge is set to the negative cosine value of the gradient direction of the corresponding deviation potential function, so that the path naturally tends to the attractor with the lowest potential energy. The evidence chain generation module is configured to store the tracing path, the local topological snapshot of the deviation field, the corresponding timestamp and the context snapshot in the form of structured evidence units, and to perform sequential hash binding and digital signature on the evidence units to generate an immutable tracing evidence chain. The adaptive strategy response module is configured to calculate risk rating based on deviation evolution vector, attractor stability index and source path confidence, and after solving the optimal resource scheduling scheme through integer programming, issue fine-grained risk mitigation instructions or resource recovery instructions through the controller interface. The backtracking verification module is configured to replay the interaction based on the extracted source path in an isolated reproduction environment to verify the repeatability of the deviation evolution. At the same time, it records the reconstructed deviation field and the actual observed deviation field during the replay and calculates the replay difference metric. The replay results and the replay difference metric are then fed back to the consistency baseline construction module to complete the closed-loop adaptive update. The modules interact with each other through a secure communication channel that employs transport layer protection and message authentication mechanisms.

2. The adaptive network attack prediction and tracing system based on large model behavioral bias according to claim 1, characterized in that, The consistency baseline construction module further uses a combination of covariance coupling analysis and tensor decomposition to generate a cross-domain consistency matrix. The cross-domain consistency matrix is ​​maintained in an incremental update manner within a time window, and the baseline refitting process is automatically triggered after baseline drift is detected.

3. The adaptive network attack prediction and tracing system based on large model behavioral bias according to claim 1, characterized in that, The deviation field construction module adopts multi-scale tensor embedding and stores separable representations at the time scale and context scale. The deviation field database supports index-based local retrieval and is stored between edge nodes and the cloud according to a hot / cold data layering strategy and maintains consistency through incremental synchronization.

4. The adaptive network attack prediction and tracing system based on large model behavioral bias according to claim 1, characterized in that, The source tracing path inference module constructs a weighted directed graph based on the deviation potential function and uses a constrained optimal path search algorithm to determine the source tracing path under the dual objectives of minimizing energy consumption and maximizing confidence. The optimal path search algorithm employs integer relaxation and heuristic pruning to adapt to online response latency requirements.

5. The adaptive network attack prediction and tracing system based on large model behavioral bias according to claim 1, characterized in that, The evidence chain generation module writes structured evidence units into immutable storage in chronological order and calculates a hash digest for each evidence unit. The hash digest and evidence metadata are linked through a sequential hash function to generate the evidence chain head, which is then signed by the system's private key. The system provides a verification interface for the evidence chain to support external third parties in verifying the integrity and origin of the evidence chain.

6. The adaptive network attack prediction and tracing system based on large model behavioral bias according to claim 1, characterized in that, When the adaptive strategy response module solves the resource scheduling scheme through integer programming, it solves the problem based on the real-time priority score of the tracing path and the system resource constraints. When resources are insufficient, it triggers partial session token reclamation in descending order of score to ensure priority supply of computing and storage resources for critical tracing tasks.

7. The adaptive network attack prediction and tracing system based on large model behavioral bias according to claim 1, characterized in that, The replay difference metric calculated by the backtracking verification module is used as a consistency baseline correction item and a source evidence confidence correction factor. The replay script is automatically generated by the source path and runs in isolation as a container image.

8. The adaptive network attack prediction and tracing system based on large model behavioral bias according to claim 1, characterized in that, The system execution steps are as follows: SP1: The dual-domain behavior acquisition module collects and caches internal and external domain data through a secure message queue before and after each large model inference call; SP2: The consistency baseline building module incrementally updates the cross-domain consistency matrix based on cached data, and triggers offline distribution fitting to complete baseline refitting when baseline drift is detected; SP3: The deviation evolution analysis module performs deviation evolution operator operations on the current dual-domain data and the consistency baseline, and outputs a normalized deviation evolution vector; SP4: The deviation field construction module writes the deviation evolution vector into the deviation field database and performs multi-scale tensor embedding to update the deviation field representation containing the deviation attractor and its stability index. SP5: The source path inference module identifies the deviation attractor in the deviation field representation and constructs a weighted graph based on the deviation potential function; SP6: The source path inference module performs a constrained optimal path search on the candidate source paths and calculates the path confidence score by combining the attractor stability index and the path energy. SP7: The evidence chain generation module combines the source path and related snapshots through confidence scoring into structured evidence units, which are then hashed, bound, and signed in sequence to form an immutable evidence chain; SP8: The adaptive policy response module calculates the resource scheduling scheme through integer programming based on the path confidence score and resource constraints, and issues fine-grained risk mitigation instructions or session token revocation instructions. SP9: The backtracking verification module automatically generates a replay script and reproduces the interaction based on the tracing path in the isolated environment, calculates the replay difference metric and feeds it back to the consistency baseline construction module; SP10: The path confidence score generated by SP6 or the replay difference metric generated by SP9 is fed back as a weight to the consistency baseline construction module to achieve closed-loop adaptive update throughout the entire process.

Citation Information

Patent Citations

  • Informatization project management system based on big data analysis

    CN120338728A

  • Analyzable anti-attack network security method and system based on AI unified model

    CN120639460A