An adaptive data security policy generation method based on artificial intelligence
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- HAITIANDI DIGITAL TECH (BEIJING) CO LTD
- Filing Date
- 2026-01-09
- Publication Date
- 2026-05-12
Smart Images

Figure CN121479814B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data security technology, and more specifically, to an adaptive data security policy generation method based on artificial intelligence. Background Technology
[0002] With the rapid development of information technology and the deepening of digital transformation, the amount of data accumulated by enterprises and organizations has exploded, making data a core asset. However, frequent security incidents such as data breaches, data misuse, and unauthorized access have brought huge economic losses and reputational risks to enterprises. Therefore, ensuring data security is of paramount importance.
[0003] Traditional data security measures, such as static access control lists, firewall rules, and data masking, typically rely on pre-defined, fixed rules. These rules are difficult to dynamically adjust after configuration and cannot effectively cope with complex and ever-changing internal and external threats. For example, an internal user with legitimate privileges may exhibit abnormal behavior at a certain point in time (such as downloading large amounts of sensitive data outside of working hours), and traditional static rules may not be able to identify and prevent such legitimate but high-risk behavior in a timely manner.
[0004] Traditional methods often focus only on single-dimensional behavioral characteristics, such as operation frequency or access time, making it difficult to fully capture the complexity of user behavior. User behavior is the result of the combined effects of environmental factors (such as IP address, device fingerprint, login time) and operational factors (such as querying, downloading, modifying, copying). Single-dimensional analysis is prone to false positives and false negatives. The performance of artificial intelligence models is highly dependent on the configuration of their hyperparameters. Traditional hyperparameter optimization methods, such as grid search and random search, are computationally expensive and inefficient. While some improved intelligent optimization algorithms (such as the standard Grey Wolf algorithm) are still prone to getting trapped in local optima when dealing with high-dimensional and complex hyperparameter spaces, resulting in insufficient model generalization ability and low recognition accuracy. Summary of the Invention
[0005] This application aims to provide an adaptive data security policy generation method based on artificial intelligence, which seeks to solve the problems of single feature dimension, low model optimization efficiency and lack of adaptability in traditional data security solutions.
[0006] This application provides an adaptive data security policy generation method based on artificial intelligence, including:
[0007] Obtain multi-dimensional user behavior samples and their corresponding behavioral risk tags input through human-computer interaction; wherein, the multi-dimensional user behavior samples include at least access behavior environment samples and data operation behavior samples;
[0008] Construct an artificial intelligence model; wherein the artificial intelligence model includes an environmental feature extraction sub-model, an operation feature extraction sub-model, and a feature recognition sub-model;
[0009] Based on the multi-dimensional user behavior samples and their corresponding behavioral risk tags, the GCGWO algorithm is used to optimize and deploy the artificial intelligence model to obtain the deployed artificial intelligence model.
[0010] During the process of user accessing data, target multi-dimensional user behavior samples are used, and the deployed artificial intelligence model is scheduled to identify the target multi-dimensional user behavior samples to obtain user access behavior identification results.
[0011] Based on the results of the user access behavior, an adaptive data security policy is generated, and the adaptive data security policy is used to control the user's data access process.
[0012] In one possible implementation, constructing an artificial intelligence model includes:
[0013] The environmental feature extraction sub-model is set as a convolutional neural network model, the operation feature extraction sub-model is set as a convolutional neural network model, a long short-term memory network or a Transformer model, and the feature recognition sub-model is set as a backpropagation neural network model.
[0014] The feature vector output by the environmental feature extraction sub-model is concatenated with the feature vector output by the operational feature extraction sub-model and used as the input to the feature recognition sub-model to obtain the artificial intelligence model.
[0015] In one possible implementation, based on the multi-dimensional user behavior samples and their corresponding behavioral risk tags, the GCGWO algorithm is used to optimize and deploy the artificial intelligence model to obtain the deployed artificial intelligence model, including:
[0016] The hyperparameters of the artificial intelligence model are initialized using a piecewise sinusoidal chaotic mapping strategy to obtain the gray wolf pack;
[0017] Based on the multi-dimensional user behavior samples and their corresponding behavioral risk labels, the fitness of each gray wolf in the gray wolf pack is obtained.
[0018] Based on the fitness of all gray wolves, the gray wolf pack was divided into: Wolf, Wolf, wolves and Wolf;
[0019] For any given target wolf, a chaotic spiral balance search strategy is used to update the target wolf, resulting in an updated target wolf; wherein, the target wolf is... Wolf, wolves and Wolf;
[0020] For any one Wolves, employing an individual memory weighted fusion strategy for the aforementioned The wolf updates itself and obtains the updated version. Wolf;
[0021] The updated target wolf and the updated The wolves are re-integrated into a gray wolf pack, and a focused chaotic search strategy is used to update each target gray wolf in the re-integrated gray wolf pack to obtain the updated target gray wolves.
[0022] If the number of training iterations reaches the preset maximum number of training iterations, then the global optimal solution is obtained based on the updated target gray wolf, and the artificial intelligence model is deployed based on the global optimal solution to obtain the deployed artificial intelligence model.
[0023] If the number of training sessions has not reached the preset maximum number of training sessions, the process returns to the fitness acquisition step, based on the updated target gray wolf pack.
[0024] In one possible implementation, a piecewise sinusoidal chaotic mapping strategy is used to initialize the hyperparameters of the artificial intelligence model to obtain a gray wolf pack, including:
[0025] The hyperparameters of the artificial intelligence model are randomly initialized between the upper and lower bounds and encoded into vectors to obtain the basic vectors.
[0026] Based on the aforementioned base vector, multiple gray wolves are obtained as follows:
[0027]
[0028] in, Indicates the first i The first gray wolf d dimensional hyperparameters, and i When =1, Represents the first fundamental vector d dimensional hyperparameters, d =1,2,…,D, where D represents the total dimension of the hyperparameters. Represents the sine function. This represents the amplitude control coefficient of the sine function. Represents pi (π). Represents the modulo function. This represents the segmented control value and is set to a constant between (0, 0.5).
[0029] All the gray wolves obtained from the initialization are grouped into a gray wolf pack.
[0030] In one possible implementation, the fitness of each gray wolf in the gray wolf pack is obtained based on the multi-dimensional user behavior samples and their corresponding behavioral risk labels, including:
[0031] Using the multi-dimensional user behavior samples as input and the behavior risk labels corresponding to the multi-dimensional user behavior samples as expected output, the root mean square loss function value corresponding to Gray Wolf is obtained.
[0032] The fitness of the gray wolf is obtained by adding the root mean square loss function value corresponding to the gray wolf to a preset constant.
[0033] Iterate through each gray wolf in the gray wolf pack to obtain the fitness of each gray wolf.
[0034] In one possible implementation, the gray wolf pack is divided into groups based on the fitness of all the gray wolves. Wolf, Wolf, wolves and Wolves, including:
[0035] Based on the fitness of all gray wolves, the gray wolf with the highest fitness is determined as... Wolves, the gray wolf being the second most adaptable. Wolves, the gray wolf with the third highest fitness level is wolves and the remaining gray wolves Wolf.
[0036] In one possible implementation, the target wolf is updated using a chaotic spiral balance search strategy to obtain the updated target wolf, including:
[0037] According to the above The wolf obtains the chaotic search boundary as follows:
[0038]
[0039]
[0040] in, This represents the lower boundary vector of the chaotic search. This represents the upper boundary vector of the chaotic search. This represents the upper boundary vector corresponding to the gray wolf. This represents the lower boundary vector corresponding to the gray wolf. Indicates the first tDuring this training process Wolf; Indicates boundary control parameters, and , This indicates the preset maximum number of training iterations; Indicates will and Compare parameters of the same dimension and take the maximum value to form a vector. Indicates will and Compare parameters of the same dimension and take the minimum value to form a vector;
[0041] Based on the chaotic search boundary, a chaotic spiral balance search is performed on the target wolf to obtain the updated target wolf as follows:
[0042]
[0043] in, Indicates the first t During the training process, the first j One target wolf, j =1,2,3; Indicates the first j The updated target wolf, Represents the natural constant. Indicates the adaptive spiral shape parameters. cos represents the cosine function. k This represents a constant coefficient, set to 5; T represents the preset maximum number of training iterations. This represents the spiral direction parameter between [-1, 1]. This represents the first spiral spacing constant, and is set to 2, 3, or 4; This represents the second spiral spacing constant, and is set to 1 or -1.
[0044] In one possible implementation, an individual memory weighted fusion strategy is used for the... The wolf updates itself and obtains the updated version. Wolves, including:
[0045] According to the above Wolf, wolves and The wolf obtains the first, second, and third learning positions as follows:
[0046]
[0047]
[0048]
[0049] in, Indicates the first t During the training process, the first m indivual Wolf, Indicates the first learning position. Indicates the second learning position. Indicates the third learning position. Denotes the convergence factor, and ; This represents the first random number between (0,1). This represents the second random number between (0,1). This represents the third random number between (0,1). This represents the fourth random number between (0,1). This represents the fifth random number between (0,1). This represents the sixth random number between (0,1). Indicates the first t During this training process Wolf, Indicates the first t During this training process Wolf;
[0050] Based on the first learning position, the second learning position, and the third learning position, the first weighted weight, the second weighted weight, and the third weighted weight are obtained as follows:
[0051]
[0052]
[0053]
[0054] in, Indicates the first weighted weight. Indicates the second weighting weight. This indicates the third weighting weight, and || represents the modulo operation;
[0055] Based on the first learning position, the second learning position, the third learning position, and taking the first weighted weight, the second weighted weight, and the third weighted weight, the... The wolf searches its individual memory mechanism to obtain the updated information. Wolves are:
[0056]
[0057] in, Indicates the first t During the training process, the first m indivual Wolf, Indicates the first m The updated version Wolf, m =1,2,…,M, where M represents... Total number of wolves This represents the population acceleration factor, and is set to 2. This represents the individual acceleration factor, and is set to 2. This represents the seventh random number between (0,1). This represents the eighth random number between (0,1). express The corresponding historical best value.
[0058] In one possible implementation, a focused chaotic search strategy is used to update each target gray wolf in the re-fused gray wolf pack, resulting in the updated target gray wolves, including:
[0059] The focus density factor is obtained as follows:
[0060]
[0061] in, Indicates the first t During this training process The wolf's first d dimensional hyperparameters, Indicates the first t During the training process, the first n The first target of the Grey Wolf d dimensional hyperparameters, n =1,2,…,M+3 express The corresponding focus density factor;
[0062] Based on the focus density factor, the focus position information is obtained as follows:
[0063]
[0064] in, The first one represents the focus position information. d dimensional hyperparameters, This represents the ninth random number between (0,1). Indicates As the mean, with A Gaussian distributed random number with variance;
[0065] The chaotic mapping factor is obtained as follows:
[0066]
[0067] in, express The corresponding chaotic mapping factor, Represents the arctangent function;
[0068] Based on the chaotic mapping factor and the focusing position information, each target gray wolf in the re-fused gray wolf pack is updated to obtain the updated target gray wolves as follows:
[0069]
[0070] in, Indicates the first n The updated target is the Grey Wolf. d dimensional hyperparameters, This represents the tenth random number between (0,1).
[0071] In one possible implementation, an adaptive data security policy is generated based on the user access behavior results, and the user's data access process is controlled using the adaptive data security policy, including:
[0072] Based on the results of the user access behavior, a preset policy mapping table is queried to obtain an adaptive data security policy;
[0073] The adaptive data security strategy described above is used to control the user's data access process.
[0074] Beneficial effects:
[0075] This application provides an artificial intelligence-based adaptive data security policy generation method. First, it acquires multi-dimensional user behavior samples and behavioral risk labels, including access behavior environment and data operation behavior. Next, it constructs an artificial intelligence model composed of an environment feature extraction sub-model, an operation feature extraction sub-model, and a feature recognition sub-model. Then, it proposes a GCGWO algorithm and efficiently optimizes the hyperparameters of the artificial intelligence model based on the multi-dimensional user behavior samples and behavioral risk labels to obtain a high-precision artificial intelligence model. Finally, in real-time data access, it utilizes this artificial intelligence model to identify user behavior risks and dynamically generate adaptive data security policies for access control, significantly improving the accuracy of risk identification and the adaptive capability of the policies, thus realizing intelligent and dynamic data security protection. Attached Figure Description
[0076] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the description of the embodiments of this application will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0077] Figure 1 This is a flowchart of an adaptive data security policy generation method based on artificial intelligence, proposed in an embodiment of this application.
[0078] Figure 2 This is a flowchart illustrating the acquisition and deployment of an artificial intelligence model according to an embodiment of this application. Detailed Implementation
[0079] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0080] like Figure 1 As shown in the figure, this application provides an adaptive data security policy generation method based on artificial intelligence, including:
[0081] S101. Obtain multi-dimensional user behavior samples and their corresponding behavioral risk tags input through human-computer interaction. The multi-dimensional user behavior samples include at least access behavior environment samples and data operation behavior samples.
[0082] In this embodiment, security administrators input historical user behavior data as samples through a human-computer interaction interface. Each sample contains multi-dimensional information, including at least:
[0083] Access behavior environment samples include, for example, the user's login IP address, device fingerprint (operating system, browser version), geographical location, and login time (weekday / weekend, working hours / weekend). Another example is that access behavior environment samples can be set as network traffic characteristics.
[0084] Data manipulation behavior samples: For example, the number of SQL queries executed by a user within a unit of time, data download volume, file copy / paste operations, and the sensitivity level of accessed data. These operations can be time-series data. Alternatively, user identity, parts of their profile, device IDs of the N most recent logged-in accounts, and the N most recent file access operations can be used as data manipulation behavior samples. However, it is worth noting that regardless of the data collection settings, data with fixed dimensions must be collected to ensure data identification accuracy. For the same type of data, if the number of digits differs, leading zeros can be added to ensure consistent data length.
[0085] Meanwhile, safety managers label each sample with a behavioral risk label, such as normal, low risk, medium risk, or high risk. These labels constitute the supervised learning objective of the model.
[0086] S102. Construct an artificial intelligence model. The artificial intelligence model includes an environmental feature extraction sub-model, an operational feature extraction sub-model, and a feature recognition sub-model.
[0087] Optionally, the artificial intelligence model constructed in this embodiment is a dual-channel fusion model, specifically including:
[0088] Environmental feature extraction sub-model: Employs a convolutional neural network. Environmental samples (such as IP, device, time, etc.) are vectorized or encoded to form a two-dimensional or one-dimensional pseudo-image or structured vector, which is then input into the CNN (Convolutional Neural Network). Through its convolutional and pooling layers, the CNN can effectively extract the local correlations and deep patterns between these environmental features.
[0089] Operation feature extraction sub-model: This can employ a Long Short-Term Memory (LSTM) network or a Transformer model. Operational behavior samples (such as chronologically ordered operation sequences) are input into an LSTM or Transformer. These models excel at capturing long- and short-term dependencies in sequence data, effectively understanding the context and dynamic changes of user operations.
[0090] Among them, the environmental feature extraction sub-model and the operation feature extraction sub-model need to remove the output layer in order to obtain the feature vector of fixed dimension before the output layer.
[0091] Feature recognition sub-model: Employs a BP neural network (multilayer perceptron). The feature vector F_env output from the environmental feature extraction sub-model and the feature vector F_op output from the operational feature extraction sub-model are concatenated to form a fused feature vector F_fusion = [F_env, F_op]. F_fusion is then input into the BP neural network for final classification or regression, outputting the risk level of the user's behavior.
[0092] S103. Based on the multi-dimensional user behavior samples and their corresponding behavioral risk tags, the GCGWO algorithm is used to optimize and deploy the artificial intelligence model to obtain the deployed artificial intelligence model.
[0093] This application proposes the GCGWO algorithm to optimize the hyperparameters of artificial intelligence models. This algorithm integrates a variety of advanced strategies and solves the pain points of traditional optimization algorithms. Compared with standard gray wolf algorithms, genetic algorithms, etc., it has a faster convergence speed, higher solution accuracy and stronger stability, thereby enabling the optimized artificial intelligence model to have excellent generalization ability and recognition performance.
[0094] S104. During the process of user accessing data, target multi-dimensional user behavior samples are used, and the deployed artificial intelligence model is scheduled to identify the target multi-dimensional user behavior samples to obtain user access behavior identification results.
[0095] In practical applications, when a user attempts to access data, the system captures the user's current multi-dimensional behavioral data in real time, forming a target multi-dimensional user behavior sample. This sample is then input into a deployed artificial intelligence model, which outputs a user access behavior recognition result, such as a risk score or a discrete risk level label (e.g., normal or low risk).
[0096] S105. Based on the results of the user access behavior, generate an adaptive data security policy and use the adaptive data security policy to control the user's data access process.
[0097] For example, the system pre-defines a policy mapping table, which establishes the correspondence between behavior recognition results and security policies. For instance:
[0098]
[0099] Based on the identification results obtained in step S104, the system queries this table to obtain the corresponding adaptive data security policy and immediately executes the policy to control the user's data access process in real time and dynamically.
[0100] Through the above steps, this application embodiment realizes a closed-loop adaptive data security protection system from data acquisition, model training and optimization to real-time decision-making and strategy execution.
[0101] This invention constructs an artificial intelligence model comprising an environmental feature extraction sub-model and an operational feature extraction sub-model, enabling parallel processing of access behavior environmental samples (such as IP address, device, and time) and data operation behavior samples (such as querying, downloading, and copying). Environmental features (such as those excelling at handling spatial or structured data like CNNs) and operational features (such as those excelling at handling sequence data like LSTM / Transformers) are extracted in depth separately and then concatenated and fused into the feature recognition sub-model. This dual-channel, multimodal feature fusion mechanism, compared to single-feature analysis, can more comprehensively and profoundly characterize user behavior profiles, effectively capturing potential risk patterns that are difficult to detect using traditional methods. This significantly improves the accuracy of identifying malicious and abnormal behavior while reducing false positive and false negative rates.
[0102] In one possible implementation, constructing an artificial intelligence model includes:
[0103] The environmental feature extraction sub-model is set as a convolutional neural network model, the operation feature extraction sub-model is set as a convolutional neural network model, a long short-term memory network or a Transformer model, and the feature recognition sub-model is set as a backpropagation neural network model.
[0104] The feature vector output by the environmental feature extraction sub-model is concatenated with the feature vector output by the operational feature extraction sub-model and used as the input to the feature recognition sub-model to obtain the artificial intelligence model.
[0105] like Figure 2 As shown, based on the multi-dimensional user behavior samples and their corresponding behavioral risk labels, the GCGWO (Global Chaotic Grey Wolf Optimizer) algorithm is used to optimize and deploy the artificial intelligence model, obtaining the deployed artificial intelligence model, including:
[0106] S201. The hyperparameters of the artificial intelligence model are initialized using a piecewise sinusoidal chaotic mapping strategy to obtain the gray wolf pack.
[0107] S202. Based on the multi-dimensional user behavior samples and their corresponding behavior risk labels, obtain the fitness of each gray wolf in the gray wolf pack.
[0108] S203. Based on the fitness of all gray wolves, the gray wolf pack is divided into... Wolf, Wolf, wolves and Wolf;
[0109] S204. For any target wolf, update the target wolf using a chaotic spiral balance search strategy to obtain the updated target wolf; wherein, the target wolf is... Wolf, wolves and Wolf;
[0110] S205, for any one Wolves, employing an individual memory weighted fusion strategy for the aforementioned The wolf updates itself and obtains the updated version. Wolf;
[0111] S206, The updated target wolf and the updated... The wolves are re-integrated into a gray wolf pack, and a focused chaotic search strategy is used to update each target gray wolf in the re-integrated gray wolf pack to obtain the updated target gray wolves.
[0112] S207. When the number of training sessions reaches the preset maximum number of training sessions, the global optimal solution is obtained based on the updated target gray wolf, and the artificial intelligence model is deployed based on the global optimal solution to obtain the deployed artificial intelligence model.
[0113] For example, the hyperparameters contained in the global optimal solution can be used as the final hyperparameters of the artificial intelligence model and deployed (e.g., deployed to a server) to obtain the deployed artificial intelligence model.
[0114] S208. If the number of training sessions has not reached the preset maximum number of training sessions, then return to the step of obtaining fitness based on the updated target gray wolf pack.
[0115] Optionally, after each update of any individual, out-of-bounds handling can be performed on the individual to ensure the validity of the individual.
[0116] This application proposes the GCGWO algorithm to optimize the hyperparameters of artificial intelligence models. This algorithm integrates a variety of advanced strategies and solves the pain points of traditional optimization algorithms. Compared with standard gray wolf algorithms, genetic algorithms, etc., it has a faster convergence speed, higher solution accuracy and stronger stability, thereby enabling the optimized artificial intelligence model to have excellent generalization ability and recognition performance.
[0117] In one possible implementation, a piecewise sinusoidal chaotic mapping strategy is used to initialize the hyperparameters of the artificial intelligence model to obtain a gray wolf pack, including:
[0118] The hyperparameters of the artificial intelligence model are randomly initialized between the upper and lower bounds and encoded into vectors to obtain the basic vectors.
[0119] Based on the aforementioned base vector, multiple gray wolves are obtained as follows:
[0120]
[0121] in, Indicates the first i The first gray wolf d dimensional hyperparameters, and i When =1, Represents the first fundamental vector d dimensional hyperparameters, d =1,2,…,D, where D represents the total dimension of the hyperparameters. Represents the sine function. The amplitude control coefficient for the sine function can be set to 5; Represents pi (π). Represents the modulo function. This represents the segmented control value and is set to a constant between (0, 0.5).
[0122] All the gray wolves obtained from the initialization are grouped into a gray wolf pack.
[0123] In terms of enhanced complexity and exploration capability, by introducing piecewise intervals and the nonlinear characteristics of the sine function, the piecewise sinusoidal chaotic mapping strategy can generate sequences with specific chaotic characteristics in different intervals, significantly enhancing the algorithm's exploration capability in the search space. Regarding flexibility, the transformation formula of the piecewise sinusoidal chaotic mapping strategy depends on parameters such as the interval partitioning threshold q and the sine function coefficients A, allowing for flexible adjustment to generate different chaotic behaviors. In terms of smoothness and stability, the piecewise sinusoidal chaotic mapping strategy uses sine transformations in different intervals and generates continuous chaotic sequences through smooth function transitions, avoiding drastic jumps and improving the stability of the search process. Regarding diversity, due to the periodicity and randomness of the sine function, the chaotic sequences generated by the piecewise sinusoidal chaotic mapping strategy exhibit higher diversity, further improving the coverage of population initialization.
[0124] In one possible implementation, the fitness of each gray wolf in the gray wolf pack is obtained based on the multi-dimensional user behavior samples and their corresponding behavioral risk labels, including:
[0125] Using the multi-dimensional user behavior samples as input and the behavior risk labels corresponding to the multi-dimensional user behavior samples as expected output, the root mean square loss function value corresponding to Gray Wolf is obtained.
[0126] The fitness of the gray wolf is obtained by adding the root mean square loss function value corresponding to the gray wolf to a preset constant (such as 0.0001 or 1).
[0127] Iterate through each gray wolf in the gray wolf pack to obtain the fitness of each gray wolf.
[0128] In one possible implementation, the gray wolf pack is divided into groups based on the fitness of all the gray wolves. Wolf, Wolf, wolves and Wolves, including:
[0129] Based on the fitness of all gray wolves, the gray wolf with the highest fitness is determined as... Wolves, the gray wolf being the second most adaptable. Wolves, the gray wolf with the third highest fitness level is wolves and the remaining gray wolves Wolf.
[0130] In one possible implementation, the target wolf is updated using a chaotic spiral balance search strategy to obtain the updated target wolf, including:
[0131] According to the above The wolf obtains the chaotic search boundary as follows:
[0132]
[0133]
[0134] in, This represents the lower boundary vector of the chaotic search. This represents the upper boundary vector of the chaotic search. This represents the upper bound vector corresponding to the gray wolf, which is the vector composed of the upper bound of the hyperparameters in each dimension; This represents the lower bound vector corresponding to the gray wolf, which is the vector composed of the lower bounds of the hyperparameters in each dimension; Indicates the first t During this training process Wolf; Indicates boundary control parameters, and , This indicates the preset maximum number of training iterations; Indicates will and Parameters of the same dimension are compared and the maximum value is taken to form a vector. For example, for the parameter of the y-th dimension, if... The y-th dimension parameter is greater than If the parameter in the y-th dimension is given, then it should be... The y-th dimension parameter is used as The y-th dimension parameter; Indicates will and Compare parameters of the same dimension and take the minimum value to form a vector;
[0135] Based on the chaotic search boundary, a chaotic spiral balance search is performed on the target wolf to obtain the updated target wolf as follows:
[0136]
[0137] in, Indicates the first t During the training process, the first j One target wolf, j =1,2,3; Indicates the first j The updated target wolf, Represents the natural constant. Indicates the adaptive spiral shape parameters. cos represents the cosine function. k This represents a constant coefficient, set to 5; T represents the preset maximum number of training iterations. This represents the spiral direction parameter between [-1, 1]. This represents the first spiral spacing constant, and is set to 2, 3, or 4; This represents the second spiral spacing constant, and is set to 1 or -1.
[0138] For the optimal α, β, and δ wolves, this strategy combines the characteristics of spiral search and chaotic search boundaries. While ensuring the algorithm's convergence speed, it prevents elite individuals from prematurely falling into local optima through chaotic perturbation. Furthermore, in the later stages of the algorithm, the search can be limited to the vicinity of the optimal position, achieving a dynamic balance between exploration and exploitation.
[0139] In one possible implementation, an individual memory weighted fusion strategy is used for the... The wolf updates itself and obtains the updated version. Wolves, including:
[0140] According to the above Wolf, wolves and The wolf obtains the first, second, and third learning positions as follows:
[0141]
[0142]
[0143]
[0144] in, Indicates the first t During the training process, the first m indivual Wolf, Indicates the first learning position. Indicates the second learning position. Indicates the third learning position. Denotes the convergence factor, and ; This represents the first random number between (0,1). This represents the second random number between (0,1). This represents the third random number between (0,1). This represents the fourth random number between (0,1). This represents the fifth random number between (0,1). This represents the sixth random number between (0,1). Indicates the first t During this training process Wolf, Indicates the first t During this training process Wolf;
[0145] Based on the first learning position, the second learning position, and the third learning position, the first weighted weight, the second weighted weight, and the third weighted weight are obtained as follows:
[0146]
[0147]
[0148]
[0149] in, Indicates the first weighted weight. Indicates the second weighting weight. This indicates the third weighting weight, and || represents the modulo operation;
[0150] Based on the first learning position, the second learning position, the third learning position, and taking the first weighted weight, the second weighted weight, and the third weighted weight, the... The wolf searches its individual memory mechanism to obtain the updated information. Wolves are:
[0151]
[0152] in, Indicates the first t During the training process, the first m indivual Wolf, Indicates the first m The updated version Wolf, m =1,2,…,M, where M represents... Total number of wolves This represents the population acceleration factor, and is set to 2. This represents the individual acceleration factor, and is set to 2. This represents the seventh random number between (0,1). This represents the eighth random number between (0,1). express The corresponding historical best value.
[0153] For the ω wolf, this strategy borrows from particle swarm optimization, incorporating the individual's historical optimal memory and performing weighted learning based on its distance from α, β, and δ wolves. This makes the update direction of the ω wolf more instructive, accelerating the convergence of the population towards the optimal region.
[0154] In one possible implementation, a focused chaotic search strategy is used to update each target gray wolf in the re-fused gray wolf pack, resulting in the updated target gray wolves, including:
[0155] The focus density factor is obtained as follows:
[0156]
[0157] in, Indicates the first t During this training process The wolf's first d dimensional hyperparameters, Indicates the first t During the training process, the first n The first target of the Grey Wolf d dimensional hyperparameters, n =1,2,…,M+3 express The corresponding focus density factor;
[0158] Based on the focus density factor, the focus position information is obtained as follows:
[0159]
[0160] in, The first one represents the focus position information. d dimensional hyperparameters, This represents the ninth random number between (0,1). Indicates As the mean, with A Gaussian distributed random number with variance;
[0161] The chaotic mapping factor is obtained as follows:
[0162]
[0163] in, express The corresponding chaotic mapping factor, Represents the arctangent function;
[0164] Based on the chaotic mapping factor and the focusing position information, each target gray wolf in the re-fused gray wolf pack is updated to obtain the updated target gray wolves as follows:
[0165]
[0166] in, Indicates the first n The updated target is the Grey Wolf. d dimensional hyperparameters, This represents the tenth random number between (0,1).
[0167] After population updates, this strategy performs refined chaotic perturbations based on the focusing density of individuals and the current optimal solution, which can... The area near wolves has a higher sampling density, which will generate a series of surrounding... The wolf sequence, this mechanism makes candidate solutions in The generation of statistically regular perturbations within the wolf's neighborhood maintains population diversity and enables refined searching through decay characteristics, greatly enhancing the algorithm's ability to escape local optima and ensuring that the final solution found is globally optimal or close to globally optimal.
[0168] Artificial intelligence models trained using the aforementioned strategies can more accurately identify user behavior, thereby providing more precise data security strategies and effectively improving the security of data management.
[0169] In one possible implementation, an adaptive data security policy is generated based on the user access behavior results, and the user's data access process is controlled using the adaptive data security policy, including:
[0170] Based on the results of the user access behavior, a preset policy mapping table is queried to obtain an adaptive data security policy;
[0171] The adaptive data security strategy described above is used to control the user's data access process.
[0172] This application's embodiments do not simply issue alerts or block access. Instead, they take user access behavior results (such as risk level: low, medium, high) identified by an artificial intelligence model as input and dynamically generate an adaptive data security policy that matches the risk level by querying a preset policy mapping table. For example, for low-risk behavior, access can be allowed but logged; for medium-risk behavior, multi-factor authentication or temporary restriction of download permissions can be triggered; for high-risk behavior, access is immediately blocked, the session is isolated, and a security audit process is initiated. This differentiated and refined response mechanism based on risk level effectively prevents security threats while maximizing the normal business experience of legitimate users, achieving an organic unity of security and convenience.
[0173] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.
[0174] This application describes embodiments with reference to flowchart illustrations and / or block diagrams of methods, apparatuses, electronic devices, and computer program products according to embodiments of this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing terminal device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing terminal device, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0175] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing terminal device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0176] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal equipment, causing a series of operational steps to be performed on the computer or other programmable terminal equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable terminal equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0177] Although preferred embodiments of the present application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of the embodiments of the present application.
[0178] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or terminal device. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or terminal device that includes said element.
[0179] This document uses specific examples to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the methods and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.
Claims
1. A method for generating adaptive data security policies based on artificial intelligence, characterized in that, include: Obtain multi-dimensional user behavior samples and their corresponding behavioral risk tags input through human-computer interaction; wherein, the multi-dimensional user behavior samples include at least access behavior environment samples and data operation behavior samples; Construct an artificial intelligence model; wherein the artificial intelligence model includes an environmental feature extraction sub-model, an operation feature extraction sub-model, and a feature recognition sub-model; Based on the multi-dimensional user behavior samples and their corresponding behavioral risk tags, the GCGWO algorithm is used to optimize and deploy the artificial intelligence model to obtain the deployed artificial intelligence model. During the process of user accessing data, target multi-dimensional user behavior samples are used, and the deployed artificial intelligence model is scheduled to identify the target multi-dimensional user behavior samples to obtain user access behavior identification results. Based on the results of the user access behavior, an adaptive data security policy is generated, and the adaptive data security policy is used to control the user's data access process. Based on the multi-dimensional user behavior samples and their corresponding behavioral risk tags, the GCGWO algorithm is used to optimize and deploy the artificial intelligence model, resulting in the deployed artificial intelligence model, including: The hyperparameters of the artificial intelligence model are initialized using a piecewise sinusoidal chaotic mapping strategy to obtain the gray wolf pack; Based on the multi-dimensional user behavior samples and their corresponding behavioral risk labels, the fitness of each gray wolf in the gray wolf pack is obtained. Based on the fitness of all gray wolves, the gray wolf pack was divided into: Wolf, Wolf, wolves and Wolf; For any given target wolf, a chaotic spiral balance search strategy is used to update the target wolf, resulting in an updated target wolf; wherein, the target wolf is... Wolf, wolves and Wolf; For any one Wolves, employing an individual memory weighted fusion strategy for the aforementioned The wolf updates itself and obtains the updated version. Wolf; The updated target wolf and the updated The wolves are re-integrated into a gray wolf pack, and a focused chaotic search strategy is used to update each target gray wolf in the re-integrated gray wolf pack to obtain the updated target gray wolves. If the number of training iterations reaches the preset maximum number of training iterations, then the global optimal solution is obtained based on the updated target gray wolf, and the artificial intelligence model is deployed based on the global optimal solution to obtain the deployed artificial intelligence model. If the number of training sessions has not reached the preset maximum number of training sessions, the process returns to the fitness acquisition step, based on the updated target gray wolf pack.
2. The adaptive data security policy generation method based on artificial intelligence according to claim 1, characterized in that, Building artificial intelligence models, including: The environmental feature extraction sub-model is set as a convolutional neural network model, the operation feature extraction sub-model is set as a convolutional neural network model, a long short-term memory network or a Transformer model, and the feature recognition sub-model is set as a backpropagation neural network model. The feature vector output by the environmental feature extraction sub-model is concatenated with the feature vector output by the operational feature extraction sub-model and used as the input to the feature recognition sub-model to obtain the artificial intelligence model.
3. The adaptive data security policy generation method based on artificial intelligence according to claim 1, characterized in that, The hyperparameters of the artificial intelligence model are initialized using a piecewise sinusoidal chaotic mapping strategy to obtain the gray wolf pack, including: The hyperparameters of the artificial intelligence model are randomly initialized between the upper and lower bounds and encoded into vectors to obtain the basic vectors. Based on the aforementioned base vector, multiple gray wolves are obtained as follows: in, Indicates the first i The first gray wolf d dimensional hyperparameters, and i When =1, Represents the first fundamental vector d dimensional hyperparameters, d =1,2,…,D, where D represents the total dimension of the hyperparameters. Represents the sine function. This represents the amplitude control coefficient of the sine function. Represents pi (π). Represents the modulo function. This represents the segmented control value and is set to a constant between (0, 0.5). All the gray wolves obtained from the initialization are grouped into a gray wolf pack.
4. The adaptive data security policy generation method based on artificial intelligence according to claim 1, characterized in that, Based on the multi-dimensional user behavior samples and their corresponding behavioral risk labels, the fitness of each gray wolf in the gray wolf pack is obtained, including: Using the multi-dimensional user behavior samples as input and the behavior risk labels corresponding to the multi-dimensional user behavior samples as expected output, the root mean square loss function value corresponding to Gray Wolf is obtained. The fitness of the gray wolf is obtained by adding the root mean square loss function value corresponding to the gray wolf to a preset constant. Iterate through each gray wolf in the gray wolf pack to obtain the fitness of each gray wolf.
5. The adaptive data security policy generation method based on artificial intelligence according to claim 1, characterized in that, Based on the fitness of all gray wolves, the gray wolf pack was divided into: Wolf, Wolf, wolves and Wolves, including: Based on the fitness of all gray wolves, the gray wolf with the highest fitness is determined as... Wolves, the gray wolf being the second most adaptable. Wolves, the gray wolf with the third highest fitness level is wolves and the remaining gray wolves Wolf.
6. The adaptive data security policy generation method based on artificial intelligence according to claim 1, characterized in that, The target wolf is updated using a chaotic spiral balance search strategy to obtain the updated target wolf, including: According to the above The wolf obtains the chaotic search boundary as follows: in, This represents the lower boundary vector of the chaotic search. This represents the upper boundary vector of the chaotic search. This represents the upper boundary vector corresponding to the gray wolf. This represents the lower boundary vector corresponding to the gray wolf. Indicates the first t During this training process Wolf; Indicates boundary control parameters, and , This indicates the preset maximum number of training iterations; Indicates will and Compare parameters of the same dimension and take the maximum value to form a vector. Indicates will and Compare parameters of the same dimension and take the minimum value to form a vector; Based on the chaotic search boundary, a chaotic spiral balance search is performed on the target wolf to obtain the updated target wolf as follows: in, Indicates the first t During the training process, the first j One target wolf, j =1,2,3; Indicates the first j The updated target wolf, Represents the natural constant. Indicates the adaptive spiral shape parameters. cos represents the cosine function. k This represents a constant coefficient, set to 5; T represents the preset maximum number of training iterations. This represents the spiral direction parameter between [-1, 1]. This represents the first spiral spacing constant, and is set to 2, 3, or 4; This represents the second spiral spacing constant, and is set to 1 or -1.
7. The adaptive data security policy generation method based on artificial intelligence according to claim 6, characterized in that, The individual memory weighted fusion strategy is used to analyze the above. The wolf updates itself and obtains the updated version. Wolves, including: According to the above Wolf, wolves and The wolf obtains the first, second, and third learning positions as follows: in, Indicates the first t During the training process, the first m indivual Wolf, Indicates the first learning position. Indicates the second learning position. Indicates the third learning position. Denotes the convergence factor, and ; This represents the first random number between (0,1). This represents the second random number between (0,1). This represents the third random number between (0,1). This represents the fourth random number between (0,1). This represents the fifth random number between (0,1). This represents the sixth random number between (0,1). Indicates the first t During this training process Wolf, Indicates the first t During this training process Wolf; Based on the first learning position, the second learning position, and the third learning position, the first weighted weight, the second weighted weight, and the third weighted weight are obtained as follows: in, Indicates the first weighted weight. Indicates the second weighting weight. This indicates the third weighting weight, and || represents the modulo operation; Based on the first learning position, the second learning position, the third learning position, and taking the first weighted weight, the second weighted weight, and the third weighted weight, the... The wolf searches its individual memory mechanism to obtain the updated information. Wolves are: in, Indicates the first t During the training process, the first m indivual Wolf, Indicates the first m The updated version Wolf, m =1,2,…,M, where M represents... Total number of wolves This represents the population acceleration factor, and is set to 2. This represents the individual acceleration factor, and is set to 2. This represents the seventh random number between (0,1). This represents the eighth random number between (0,1). express The corresponding historical best value.
8. The adaptive data security policy generation method based on artificial intelligence according to claim 7, characterized in that, A focused chaotic search strategy is used to update each target gray wolf in the re-merged gray wolf pack, resulting in the updated target gray wolves, including: The focus density factor is obtained as follows: in, Indicates the first t During this training process The wolf's first d dimensional hyperparameters, Indicates the first t During the training process, the first n The first target of the Grey Wolf d dimensional hyperparameters, n =1,2,…,M+3 express The corresponding focus density factor; Based on the focus density factor, the focus position information is obtained as follows: in, The first one represents the focus position information. d dimensional hyperparameters, This represents the ninth random number between (0,1). Indicates As the mean, with A Gaussian distributed random number with variance; The chaotic mapping factor is obtained as follows: in, express The corresponding chaotic mapping factor, Represents the arctangent function; Based on the chaotic mapping factor and the focusing position information, each target gray wolf in the re-fused gray wolf pack is updated to obtain the updated target gray wolves as follows: in, Indicates the first n The updated target is the Grey Wolf. d dimensional hyperparameters, This represents the tenth random number between (0,1).
9. The adaptive data security policy generation method based on artificial intelligence according to claim 7, characterized in that, Based on the user access behavior results, an adaptive data security policy is generated, and the adaptive data security policy is used to control the user's data access process, including: Based on the results of the user access behavior, a preset policy mapping table is queried to obtain an adaptive data security policy; The adaptive data security strategy described above is used to control the user's data access process.