Deep learning-based method for tracking and detecting abnormality of secret carrier trajectory
By employing a deep learning-based trajectory tracking method for classified carriers, combined with multi-source data acquisition and blockchain evidence storage, the problems of high false negative rates and delayed response to unknown attacks in classified information systems have been solved. This approach enables dynamic detection and real-time response, thereby improving the system's security and adaptability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA POWER CONSTR ENG CONSULTING CORP
- Filing Date
- 2025-10-17
- Publication Date
- 2026-04-28
AI Technical Summary
Existing technologies in classified information systems suffer from problems such as high false negative rates for unknown attacks, limited risk assessment dimensions, delayed and isolated early warning responses, and a lack of adaptive learning capabilities, failing to meet the needs for dynamic detection, correlated assessment, and real-time response.
A deep learning-based method for tracking the trajectory of classified carriers is adopted. Through multi-source data collection, deep learning models, and blockchain evidence storage, multi-dimensional risk assessment and dynamic response are achieved. This includes multi-source data collection, anomaly detection by deep learning models, multi-dimensional risk assessment, and blockchain evidence storage.
It enables automatic identification and dynamic rule updates for new types of attacks, reduces the false negative rate, improves detection sensitivity and response speed, and meets the high security requirements of classified scenarios.
Smart Images

Figure CN121389084B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of information security technology, specifically, it relates to a method for tracking and detecting anomalies in classified carriers based on deep learning. Background Technology
[0002] In the security protection of classified information systems (such as those in the military, aerospace, and core government departments), abnormal operation detection and risk warning are core aspects of preventing data leakage. Currently, the widely adopted technical solution in this field is the traditional system of "static rule base + manual auditing + single-dimensional behavior analysis". Its typical architecture includes: a rule engine module that stores hundreds of fixed detection rules, a log collection module that only collects user operation logs, and a manual auditing terminal that relies on security administrators to manually review and handle anomalies.
[0003] However, after in-depth analysis, the existing technical solutions have the following four core flaws:
[0004] Anomaly detection relies on static rule bases, resulting in extremely high false negative rates for unknown attacks and gradual anomalies. Rule bases can only identify known attack patterns and cannot handle zero-day exploits, AI-generated spoofing commands, or gradual anomalies that steal data through multiple minor compliance operations. Statistics show that traditional systems have a false negative rate of up to 43.2% for unknown attacks.
[0005] Risk assessment is limited to a single dimension, making it prone to misjudgments and omissions. Traditional systems rely solely on user behavior for judgment, neglecting crucial dimensions such as device status (e.g., whether malicious firmware has been implanted), physical environment (e.g., unauthorized personnel approaching), and data flow. This leads to complete failure in complex risk scenarios such as "device hijacked but user behavior is normal."
[0006] The early warning response is delayed and isolated, requiring manual closure from detection to completion, which takes an average of several hours. Due to the lack of an automated linkage mechanism, the detection module and the terminal control module are physically isolated, making real-time blocking impossible, which leads to data theft during manual review.
[0007] Lacking adaptive learning capabilities and with long rule base update cycles (typically ≥3 months), the system is unable to cope with rapidly evolving new attack methods. The coverage of static rule bases has fallen below 37%, making it difficult to defend against AI-driven dynamic threats. In summary, the existing technology, based on an architecture of "deterministic rules + single-dimensional data + manual closed-loop," can no longer meet the core requirements of classified scenarios for "dynamic detection, correlated assessment, and real-time response." Summary of the Invention
[0008] The purpose of this invention is to provide a deep learning-based method for tracking the trajectory and detecting anomalies of classified carriers, which solves the problem that the existing architecture based on "deterministic rules + single-dimensional data + manual closed loop" can no longer meet the core requirements of classified scenarios for "dynamic detection, correlation evaluation and real-time response".
[0009] The objective of this invention can be achieved through the following technical solutions:
[0010] A deep learning-based method for tracking the trajectory and detecting anomalies of classified carriers includes the following steps:
[0011] S1: Periodically obtain the operation logs of each classified carrier, obtain the trajectory corresponding to each classified carrier, and compare the trajectory with the confidentiality rules in the rule base. When the trajectory does not conform to the confidentiality rules, the corresponding operation is considered to be an abnormal operation.
[0012] S2: Calculate and obtain the comprehensive risk level corresponding to each trajectory, determine whether the operation corresponding to the trajectory is an abnormal operation, and mark the abnormal operation samples and normal operation samples.
[0013] S3: Based on the type of classified carrier, statistically group each abnormal operation sample and normal operation sample, and update the confidentiality rules in the rule base based on the comparison results;
[0014] The method for updating the confidentiality rules in the rule base is as follows:
[0015] A set of abnormal operation samples corresponding to a type of classified carrier is compared with each confidentiality rule in the rule base, and the similarity is calculated.
[0016] When the similarity between an abnormal operation sample and any confidentiality rule is greater than a preset threshold, it is marked as an analyzable sample, and the corresponding reference confidentiality rule is obtained. If the similarity with all confidentiality rules is not greater than the threshold, the sample is marked as an unanalyzable sample.
[0017] The parts in the analyzable sample that differ from the control confidentiality rules are selected as distinguishing segments, and the types and number of distinguishing segments are counted.
[0018] The output targets of various categories are analyzed. If there is a part that is the same as the output target of the reference confidentiality rule, the corresponding part in the reference confidentiality rule is expanded. If there is no part, the analyzable sample is used as a new confidentiality rule. The unanalyzable sample is statistically analyzed and deduplicated, and then used as a new confidentiality rule in the rule base.
[0019] As a further aspect of the present invention, the expansion of the corresponding portion in the confidentiality rules includes at least one of the following methods:
[0020] In the corresponding trajectory section that corresponds to the confidentiality rules, add one or more alternative trajectory paths with the same output target but different specific operation procedures;
[0021] Use a generalized output target description to directly replace the specific operational process trajectory section in the confidentiality rules.
[0022] As a further aspect of the present invention, step S3 also includes: performing semantic recognition analysis on unanalyzable samples to identify key stages in their operation process and their output targets;
[0023] Using the identified output target, a generalized replacement is performed on a portion of the trajectory in the sample operation process;
[0024] The unanalyzable samples after replacement are deduplicated, and the deduplicated results are added to the rule base as new confidentiality rules.
[0025] As a further aspect of the present invention, the method for calculating and obtaining the comprehensive risk level corresponding to each trajectory is as follows:
[0026] The system synchronously collects four types of heterogeneous data: user behavior, device status, physical environment, and data flow direction through multi-source data acquisition terminals.
[0027] The four types of heterogeneous data are spatiotemporally aligned using timestamps, and a fused feature vector is extracted and generated.
[0028] The fused feature vector is input into a deep learning model for anomaly detection, and the anomaly probability is output.
[0029] Based on the DS evidence theory, risk indicators from four dimensions—user behavior, device status, physical environment, and data flow—are integrated to calculate and output a comprehensive risk level of 0-10.
[0030] As a further aspect of the present invention, the method further includes: triggering a graded response strategy based on the comprehensive risk level; automatically executing hardware-level physical blocking when the risk level is ≥6 points; and storing the anomaly detection log, risk assessment report, and handling record in an immutable manner through a consortium blockchain.
[0031] As a further aspect of the present invention, the hardware-level physical blocking includes: performing a power-off operation through a USB port controller;
[0032] The laser shutdown operation is performed via the network optical module to cut off the physical network link;
[0033] The keyboard, mouse, and screen are frozen by sending a command to the terminal motherboard BIOS.
[0034] As a further aspect of the present invention, the method is implemented through a deep learning-based system for tracking and detecting the trajectory of classified carriers, the system comprising:
[0035] Multi-source data acquisition terminals, deployed in classified terminals, are used to collect raw data;
[0036] The multi-source data preprocessing module is used to clean, extract features, and perform spatiotemporal alignment on the collected raw data.
[0037] The AI anomaly detection module employs an improved hybrid model of Transformer and graph neural network to detect anomalies in user operation sequences.
[0038] The multi-dimensional risk assessment module integrates multi-dimensional indicators based on the DS evidence theory to quantitatively output the comprehensive risk level.
[0039] The dynamic early warning and response module executes a tiered response strategy based on the overall risk level.
[0040] The blockchain evidence storage module is used to store all abnormal logs, assessment reports, and handling records.
[0041] As a further embodiment of the present invention, the blockchain evidence storage module consists of a consortium blockchain composed of multiple regulatory nodes and execution nodes, and adopts the PBFT consensus algorithm.
[0042] The beneficial effects of this invention are:
[0043] This invention automatically identifies novel attack trajectories by analyzing the similarity between abnormal operation samples and confidentiality rules. Based on the output target, it expands or adds rules, enabling the rule base to evolve dynamically and continuously improve the system's protection coverage and adaptability. Furthermore, the system is applicable to various types of classified media and achieves end-to-end security monitoring from data acquisition to response evidence storage through closed-loop management, meeting the needs of high-security classified environments.
[0044] This invention integrates behavioral, environmental, and device status sensors through a multi-source data acquisition terminal, and combines a daisy-chain topology and fiber optic transmission to ensure the comprehensiveness, real-time performance, and reliability of data acquisition. The preprocessing module employs advanced technologies such as LSTM autoencoders and Fourier transforms to achieve efficient feature extraction and nanosecond-level spatiotemporal alignment, providing a high-quality data foundation for subsequent analysis. It also utilizes a self-attention mechanism to capture long-term temporal dependencies and models entity associations through graph neural networks to effectively identify complex attack patterns. By combining contrastive learning and dynamic threshold adjustment, it significantly improves the detection sensitivity for gradual anomalies while reducing the false alarm rate.
[0045] This invention is based on DS evidence theory and AHP weight allocation to quantitatively output the comprehensive risk level, making the assessment results more objective and comprehensive; the dynamic early warning response module executes a hierarchical response strategy, from log recording to physical blocking, with short response time to ensure rapid handling of security incidents; the blockchain evidence storage module adopts a consortium blockchain and improved PBFT consensus to ensure that all logs, reports and records are tamper-proof, enhancing the system's auditing and traceability capabilities. Attached Figure Description
[0046] The invention will now be further described with reference to the accompanying drawings.
[0047] Figure 1 This is a flowchart illustrating the deep learning-based method for tracking the trajectory and detecting anomalies of classified carriers according to the present invention.
[0048] Figure 2 This is a schematic diagram of the framework structure of the deep learning-based system for tracking and detecting anomalies in classified carriers according to the present invention. Detailed Implementation
[0049] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0050] Example 1
[0051] A deep learning-based system for tracking the trajectory and detecting anomalies of classified carriers, such as... Figure 2 As shown, it includes:
[0052] Multi-source data acquisition terminals, deployed in classified terminals, are used to collect raw data;
[0053] The multi-source data acquisition terminal includes behavioral acquisition sensors such as a keyboard logger, a mouse trajectory capture device, and a screen operation recording unit.
[0054] Infrared intrusion detectors, temperature and humidity sensors, electromagnetic radiation monitors, and other environmental sensing sensors; and
[0055] Device status monitoring sensors such as BIOS log acquisition chips, hard drive SMART readers, and memory abnormal access detectors;
[0056] After each sensor is connected to the local data aggregation unit via a daisy-chain topology, the data is transmitted to the AI anomaly detection module via optical fiber.
[0057] The multi-source data preprocessing module is used to clean, extract features, and spatiotemporally align the collected raw data. It utilizes an LSTM autoencoder to convert the keyboard input sequence into a 128-dimensional behavioral feature vector, employs Fourier transform to extract mouse trajectory features, and precisely aligns the user operation, environmental parameters, and device status data based on BeiDou timestamps with an accuracy ≤10ns.
[0058] AI anomaly detection module: Employs an improved hybrid model combining Transformer and Graph Neural Network (GNN);
[0059] This improved Transformer+GNN hybrid deep learning model adopts the architecture described in the software copyright registration number 2025SR0376482. It captures long-range dependencies in user operation sequences through a self-attention masking mechanism and constructs a device-user-environment relationship graph using a graph neural network. The model input layer receives preprocessed behavioral feature vectors, environmental feature vectors, and device state vectors. After multi-head attention layers calculate feature correlations, cross-dimensional feature fusion is achieved through graph convolutional layers. During the training phase, a contrastive learning strategy is adopted to forcibly separate normal behavior samples from abnormal samples in the latent space, thereby improving the model's sensitivity to detecting gradual anomalies. During the inference phase, a dynamic threshold adjustment mechanism is used to automatically adapt the detection strictness according to the confidentiality level, thereby improving the anomaly detection rate and reducing the false alarm rate.
[0060] Specifically:
[0061] Among them, the Transformer layer uses a self-attention masking mechanism to capture long-term temporal dependencies of user operations (supporting sequences of more than 100 steps).
[0062] GNN layer: Models users, devices, and documents as graph nodes, dynamically represents the interaction frequency between entities through edge weights, and identifies abnormal associations such as "low-privilege users frequently accessing high-security documents".
[0063] Dynamic threshold adjuster: Based on reinforcement learning (DQN algorithm), the classification threshold is dynamically optimized every 24 hours according to the real-time false alarm rate.
[0064] Multi-dimensional risk assessment module: Based on the DS evidence theory, it integrates four major categories and eight indicators: user dimension (behavioral deviation, qualification matching), device dimension (firmware integrity, process abnormality), environmental dimension (space intrusion, electromagnetic anomaly), and data dimension (flow compliance, encryption status). It quantitatively outputs a comprehensive risk level of 0-10. The weight of each indicator is determined by the AHP analytic hierarchy process.
[0065] Specifically: The specific steps for calculating the comprehensive risk level include: calculating the behavioral deviation degree of the user dimension, which is the cosine distance between the current behavioral feature vector and the historical behavioral baseline;
[0066] Calculate firmware integrity at the device level, which is the result of comparing the current hash value of the terminal BIOS with the benchmark hash library;
[0067] Calculate the spatial intrusion risk in the environmental dimension, which is the number of times the infrared intrusion detector is triggered within a set time period;
[0068] The compliance of data flow is calculated, which involves whether the target address for data outgoing is within a preset whitelist.
[0069] Then, the risk values of the above indicators are fused using the DS evidence theory through a trust function to output a comprehensive risk value.
[0070] Dynamic early warning and response module: Executes tiered response strategies based on the overall risk level.
[0071] Low risk (0-3 points): Only normal operation logs are generated and stored on the blockchain.
[0072] Medium risk (3-6 points): Push an alarm work order to the administrator and activate the audible and visual alarm.
[0073] High risk (6-10 points): Automatically execute physical blocking and record the handling process on the blockchain in real time;
[0074] The physical blocking, such as the power-off operation performed by the USB port controller, has a response time of <0.5 seconds;
[0075] The laser shutdown operation is performed via the network optical module to cut off the physical network link;
[0076] The keyboard, mouse, and screen are frozen by sending a command to the terminal motherboard BIOS.
[0077] The trajectory tracking and anomaly detection algorithm also includes a blockchain evidence storage module. This module consists of a consortium blockchain composed of multiple regulatory nodes and execution nodes, and uses the PBFT consensus algorithm to store all anomaly logs, assessment reports, and handling records.
[0078] Example 2
[0079] A deep learning-based method for trajectory tracking and anomaly detection of classified carriers, such as... Figure 1 As shown, it includes the following steps:
[0080] S1. Periodically acquire the operation logs of each classified carrier to obtain the trajectory corresponding to each classified carrier;
[0081] The trajectory mentioned here refers to a complete set of operation data performed by an account on a classified medium, such as logging in, copying, and sending out, which constitutes a complete trajectory.
[0082] Each trajectory is compared with each confidentiality rule in the rule base. If a trajectory does not meet the requirements of each confidentiality rule in the rule base, the operation corresponding to that trajectory is considered to be an abnormal operation.
[0083] S2. Obtain the comprehensive risk level corresponding to each classified carrier through the above-mentioned trajectory tracking and anomaly detection system;
[0084] The specific method for obtaining it is as follows:
[0085] The system synchronously collects four types of heterogeneous data: user behavior, device status, physical environment, and data flow direction through multi-source data acquisition terminals.
[0086] The four types of heterogeneous data are spatiotemporally aligned using BeiDou timestamps, and a 128-dimensional fusion feature vector is extracted and generated.
[0087] The fused feature vector is input into a hybrid deep learning model of improved Transformer and GNN to perform anomaly detection and output the anomaly probability.
[0088] Based on the DS evidence theory, risk indicators from four dimensions—user, device, environment, and data—are integrated to calculate and output a comprehensive risk level of 0-10.
[0089] The tiered response strategy is triggered based on the comprehensive risk level. When the risk level is ≥6, hardware-level physical blocking is automatically executed.
[0090] Anomaly detection logs, risk assessment reports, and handling records will be stored immutably via a consortium blockchain.
[0091] Then, the dynamic early warning response module executes the above-mentioned graded response strategy according to the comprehensive risk level corresponding to each trajectory, and finally determines whether the operation corresponding to each trajectory is an abnormal operation; and marks the trajectories whose corresponding operations are determined to be abnormal operations as abnormal operation samples, and marks the trajectories whose corresponding operations are determined to be normal operations as normal operation samples.
[0092] S3. Based on the type of classified carrier, statistically group each abnormal operation sample and normal operation sample.
[0093] That is, each type of classified carrier corresponds to a set of abnormal operation samples and a set of normal operation samples.
[0094] The type of classified carrier refers to the file format type of the classified carrier, including images, documents, videos, audio, etc.
[0095] Taking a type of classified carrier as an example, a set of abnormal operation samples corresponding to it is compared with various confidentiality rules in the rule base. The comparison method is as follows:
[0096] An abnormal operation sample is compared with each confidentiality rule in the rule base in turn, and the similarity between the two is calculated. When the similarity between the abnormal operation sample and any confidentiality rule is greater than a preset threshold, the abnormal operation sample is marked as an analyzable sample.
[0097] When the similarity between the abnormal operation sample and any confidentiality rule is not greater than a preset threshold, the abnormal operation sample is marked as an unanalyzable sample.
[0098] It also obtains all confidentiality rules with similarity greater than a preset threshold corresponding to the analyzable sample, and marks these confidentiality rules as the control confidentiality rules corresponding to the analyzable sample;
[0099] Compare the analyzable sample with its corresponding confidentiality rules, and pick out the differences between the analyzable sample and its corresponding confidentiality rules. For ease of description, the differences are recorded as the differences segment. Then, obtain all the differences segments corresponding to a type of classified carrier in this way, and count the types of differences segments corresponding to a type of classified carrier and the number of differences segments of each type.
[0100] The output targets of various class distinction segments are analyzed; then, the parts of the reference confidentiality rule that have the same output target are obtained; if a class distinction segment and the reference confidentiality rule have the same output target, the corresponding part in the reference confidentiality rule is expanded; for example, in a confidentiality rule, a trajectory part can be replaced by multiple trajectory parts with the same output target but different specific operation procedures; examples are as follows:
[0101] The confidentiality rule is: Login → Copy → Send = Abnormal;
[0102] A new attack flow has been discovered: login → view → screenshot → OCR recognition → fragmented external transmission;
[0103] Therefore, the confidentiality rule can be modified to: Login → (Copy / View → Screenshot → OCR Recognition) → Outgoing = Abnormal;
[0104] For example, replacing a trajectory part of a confidentiality rule with an output target can be done as follows:
[0105] The confidentiality rule is: Login → Copy → Send = Abnormal;
[0106] A new attack flow has been discovered: login → view → screenshot → OCR recognition → fragmented external transmission;
[0107] Therefore, the confidentiality rule can be modified to: Login → Text message acquisition → Outbound = Abnormal;
[0108] This means replacing the specific operational process with the output target of "text information acquisition," thereby expanding the coverage of a confidentiality rule.
[0109] If a class distinction segment and the corresponding confidentiality rule do not have the same output target, then the confidentiality rules in the rule base are expanded, and the analyzable sample corresponding to the class distinction segment is used as a new confidentiality rule in the rule base.
[0110] Example 3
[0111] Based on Examples 1 and 2, the unanalyzable samples corresponding to a type of classified carrier are statistically analyzed, deduplicated, and then used as new confidentiality rules in the rule base. Alternatively, following the analysis method for analyzable samples, semantic recognition is used, and then the output target is used to replace part of the trajectory in each analyzable sample before deduplication is performed. The processed indivisible samples are then used as new confidentiality rules in the rule base.
[0112] The above description is merely an example and illustration of the present invention. Those skilled in the art can make various modifications or additions to the specific embodiments described or use similar methods to replace them, as long as they do not deviate from the invention or exceed the scope defined in the claims, they should all fall within the protection scope of the present invention.
Claims
1. A method for tracking the trajectory and detecting anomalies of classified carriers based on deep learning, characterized in that, Includes the following steps: S1: Periodically obtain the operation logs of each classified carrier, obtain the trajectory corresponding to each classified carrier, and compare the trajectory with the confidentiality rules in the rule base. When the trajectory does not conform to the confidentiality rules, the corresponding operation is considered to be an abnormal operation. S2: Calculate and obtain the comprehensive risk level corresponding to each trajectory, determine whether the operation corresponding to the trajectory is an abnormal operation, and mark the abnormal operation samples and normal operation samples. S3: Based on the type of classified carrier, statistically group each abnormal operation sample and normal operation sample, and update the confidentiality rules in the rule base based on the comparison results; The method for updating the confidentiality rules in the rule base is as follows: A set of abnormal operation samples corresponding to a type of classified carrier is compared with each confidentiality rule in the rule base, and the similarity is calculated. When the similarity between an abnormal operation sample and any confidentiality rule is greater than a preset threshold, it is marked as an analyzable sample, and the corresponding control confidentiality rule is obtained. If the similarity with all confidentiality rules is not greater than the threshold, the sample is marked as an unanalyzable sample. The parts in the analyzable sample that differ from the control confidentiality rules are selected as distinguishing segments, and the types and number of distinguishing segments are counted. The output targets of each category are analyzed. If there is a part that is the same as the output target of the reference confidentiality rule, the corresponding part in the reference confidentiality rule is expanded. If there is no part, the analyzable sample is used as a new confidentiality rule. The unanalyzable sample is statistically analyzed and deduplicated, and then used as a new confidentiality rule in the rule base. The method for calculating the comprehensive risk level corresponding to each trajectory is as follows: The system synchronously collects four types of heterogeneous data: user behavior, device status, physical environment, and data flow direction through multi-source data acquisition terminals. The four types of heterogeneous data are spatiotemporally aligned using timestamps, and a fused feature vector is extracted and generated. The fused feature vector is input into a deep learning model for anomaly detection, and the anomaly probability is output. Based on the DS evidence theory, risk indicators from four dimensions—user behavior, device status, physical environment, and data flow—are integrated to calculate and output a comprehensive risk level of 0-10.
2. The method for tracking and detecting anomalies in classified carriers based on deep learning according to claim 1, characterized in that, The expansion of the corresponding part of the confidentiality rules includes at least one of the following methods: In the corresponding trajectory section that corresponds to the confidentiality rules, add one or more alternative trajectory paths with the same output target but different specific operation procedures; Use a generalized output target description to directly replace the specific operational process trajectory section in the confidentiality rules.
3. The method for tracking and detecting anomalies in classified carriers based on deep learning according to claim 2, characterized in that, Step S3 also includes: performing semantic recognition analysis on unanalyzable samples to identify key stages in their operation process and their output targets; Using the identified output target, a generalized replacement is performed on a portion of the trajectory in the sample operation process; The unanalyzable samples after replacement are deduplicated, and the deduplicated results are added to the rule base as new confidentiality rules.
4. The method for tracking and detecting anomalies in classified carriers based on deep learning according to claim 1, characterized in that, Also includes: The tiered response strategy is triggered based on the comprehensive risk level. When the risk level is ≥6, hardware-level physical blocking is automatically executed. Anomaly detection logs, risk assessment reports, and handling records will be stored immutably via a consortium blockchain.
5. The method for tracking and detecting anomalies in classified carriers based on deep learning according to claim 4, characterized in that, The hardware-level physical blocking includes: performing a power-off operation through the USB port controller; The laser shutdown operation is performed via the network optical module to cut off the physical network link; The keyboard, mouse, and screen are frozen by sending a command to the terminal motherboard BIOS.
6. The method for tracking and detecting anomalies of classified carriers based on deep learning according to any one of claims 3-5, characterized in that, This method is implemented through a deep learning-based system for tracking and detecting anomalies in classified carriers. This system includes: Multi-source data acquisition terminals are deployed in classified terminals to collect raw data; The multi-source data preprocessing module is used to clean, extract features, and perform spatiotemporal alignment on the collected raw data. The AI anomaly detection module employs an improved hybrid model of Transformer and graph neural network to detect anomalies in user operation sequences. The multi-dimensional risk assessment module integrates multi-dimensional indicators based on the DS evidence theory to quantitatively output the comprehensive risk level. The dynamic early warning and response module executes a tiered response strategy based on the overall risk level. The blockchain evidence storage module is used to store all abnormal logs, assessment reports, and handling records.
7. The method for tracking and detecting anomalies of classified carriers based on deep learning according to claim 6, wherein the blockchain evidence storage module consists of a consortium blockchain composed of multiple regulatory nodes and execution nodes, and adopts the PBFT consensus algorithm.
Citation Information
Patent Citations
Deep learning-based classified carrier trajectory tracking and anomaly detection method and system
CN119128832A
System for detecting malicious nodes in a wireless sensor network and a method thereof
US20250234201A1