Methods and apparatus for artificial intelligence model security protection using mobile target defense

By fine-tuning the pre-trained endpoint detection model on endpoint devices and utilizing low-rank adaptation techniques and user behavior data, the problem of existing endpoint protection systems being vulnerable to adversarial attacks is solved, achieving more efficient malware detection and personalized protection.

CN122133142APending Publication Date: 2026-06-02INTEL CORP

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
INTEL CORP
Filing Date
2025-11-07
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

Existing AI-based endpoint protection systems are vulnerable to adversarial attacks, cannot effectively identify slightly modified or obfuscated malware, and their global models cannot adapt to the unique behavior of individual users and devices, resulting in insufficient security.

Method used

The mobile target defense technology is adopted. By locally fine-tuning the pre-trained endpoint detection model on each endpoint device, and using low-rank adaptation (LoRA) technology, combined with user and platform behavior data, the adaptability and security of the model are enhanced.

Benefits of technology

It improves the ability to detect malicious attacks, enhances the robustness and personalized protection of the model, reduces the success rate of adversarial attacks, and adapts to the unique patterns of various users and devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122133142A_ABST
    Figure CN122133142A_ABST
Patent Text Reader

Abstract

An example apparatus includes: an interface circuit system for obtaining a pre-trained detection model; machine-readable instructions; and at least one processor circuitry for being programmed by the machine-readable instructions to perform the following operations: adjusting the pre-trained detection model based on first local behavioral data; and executing the adjusted detection model to detect anomalies in second local behavioral data associated with the apparatus.
Need to check novelty before this filing date? Find Prior Art

Description

Background Technology

[0001] Malware endpoint protection provides defense against malware. Malware can include ransomware that encrypts valuable data or Trojans that create backdoors for adversarial attacks. Attached Figure Description

[0002] Figure 1 This is a block diagram of an example implementation of a malware detector circuitry system for AI-based security protection using mobile target defense, constructed in accordance with the teachings of this disclosure.

[0003] Figure 2 This indicates that it can be implemented, instantiated, and / or executed by the example programmable circuit system. Figure 1 The flowchart shows example machine-readable instructions and / or example operations of an example malware detector circuit system.

[0004] Figure 3 This indicates that it can be implemented, instantiated, and / or executed by the example programmable circuit system. Figure 1 The computing system enables the computing system to train a neural network to generate flowcharts of example machine-readable instructions and / or example operations for an endpoint detection model.

[0005] Figure 4 This indicates that it can be implemented, instantiated, and / or executed by the example programmable circuit system. Figure 1 The flowchart shows an example malware detector circuit system that uses fine-tuning to update the endpoint detection model, including example machine-readable instructions and / or example operations.

[0006] Figure 5 This is an example process execution sequence diagram based on the teachings of this disclosure for deploying a finely tuned endpoint detection model to monitor data anomalies.

[0007] Figure 6 The diagram shows the relationship between Figure 1 Examples of training and inference phases associated with the malware detector circuitry system, including example responses to adversary attacks.

[0008] Figure 7 This includes items constructed for execution, instantiation, and / or implementation. Figure 2 and Figure 4 Example machine-readable instructions and / or execution Figure 2 and Figure 4 Example operations to implement Figure 1 A block diagram of an example processing platform for a programmable circuit system of a malware detector circuit system.

[0009] Figure 8 This includes items constructed for execution, instantiation, and / or implementation. Figure 3 Example machine-readable instructions and / or execution Figure 3 Example operations to implement Figure 1 A block diagram of an example processing platform for a programmable circuit system of a computing system.

[0010] Figure 9 yes Figures 7-8 A block diagram illustrating an example implementation of a programmable circuit system.

[0011] Figure 10 yes Figures 7-8 A block diagram of another example implementation of a programmable circuit system.

[0012] Figure 11 This is a block diagram of an example software / firmware / instruction distribution platform (e.g., one or more servers) used to distribute software, instructions, and / or firmware (e.g., with...) Figures 2-4 The software / firmware / instructions corresponding to the example machine-readable instructions are distributed to client devices associated with end users and / or consumers (e.g., for licensing, selling and / or using), retailers (e.g., for selling, reselling, licensing and / or sublicensing), and / or original equipment manufacturers (OEMs) (e.g., for inclusion in products to be distributed to, for example, retailers and / or other end users such as direct purchase customers).

[0013] Generally, the same reference numerals will be used to refer to the same or similar parts throughout the accompanying drawings and written description. The drawings are not necessarily drawn to scale. Detailed Implementation

[0014] Artificial intelligence (AI) and machine learning (ML) systems using classifiers can be incorporated into endpoint detection and response systems and / or antivirus solutions. However, such integration of AI / ML systems can introduce additional vulnerabilities, increasing susceptibility to malware attacks. For example, malware attacks could intentionally manipulate AI models to misclassify malware as benign, allowing it to evade detection. In some examples, adversarial attacks can be used to create slightly modified versions of malware samples to deceive the classifier. Thus, given that AI / ML systems using classifiers can be downloaded, attackers have unlimited time and / or resources to disable the model in test environments to prepare for evading the target classifier, making these systems vulnerable to attack. While the target classifier (e.g., used to identify and flag potential malicious activity) interacts with defenders (e.g., systems or tools that proactively protect against cyber threats) (e.g., can be performed by the defenders), the defenders are limited to known attacks (e.g., those not previously exposed to new adversarial training and / or obfuscation attacks).

[0015] For example, with the increasing use of AI-based endpoint protection to identify anomalous execution behavior associated with malicious code, there is a corresponding increase in techniques such as injecting external binaries into process memory and others, which can be observed using various methods (e.g., filter drivers, extended Berkeley Packet Filter (eBPF), etc.). The current reliance on fixed, trained classifiers for malware detection does not account for adversaries who test different modifications and / or obfuscations of their code to identify code that will not be flagged as malicious by the classifier. For example, an adversary could repeatedly test modified and / or obfuscated code against known endpoint protections until the code is no longer flagged, and then deploy a malicious payload to interact with (or one or more) endpoint protection systems. With the increasing use of adversarial AI, attackers can easily try a large number (e.g., an unlimited number) of options for code and / or binary modifications until the code is no longer classified as malware, allowing malicious actors to intentionally disrupt the functionality of AI systems. Therefore, when an adversary introduces attacks into the input data, thereby altering the original data or the AI ​​model itself through changes in architecture or parameters, the AI ​​system may make incorrect or unexpected predictions or decisions. For example, adversarial AI can be used to manipulate autonomous vehicles, medical diagnostic systems, facial recognition systems, and / or any other AI-driven applications.

[0016] Using known endpoint protection systems, static AI models can be manipulated to accept malicious binaries and will fail to identify threats even if the AI ​​model has been trained to detect such attacks before adversarial training and / or malware adaptation based on the attacker. The use of adversarial training allows attackers to bypass existing static defenses much faster and easier. Thus, while current models can be tested before deployment, such models are unverifiable in the field, and new adversarial attacks are reactively addressed only after significant impacts on end users have already occurred.

[0017] The improved endpoint protection system disclosed herein can reduce and / or eliminate the risks of: prompt injection attacks (e.g., manipulation of generative AI systems via malicious input masquerading as legitimate user prompts), data leakage, and / or harmful large language model (LLM) responses from generative AI-based applications. Additionally, the improved endpoint protection system disclosed herein can assist in ensuring data privacy, detecting data leaks (e.g., unauthorized removal of data from computers or servers), and / or verifying Web Application Firewall (WAF) security, Application Programming Interface (API) security, and / or AI-based security (e.g., data poisoning, model theft, etc.). While globally pre-trained models are effective in generalized environments, such models are vulnerable to adversarial training, failing to account for the unique behaviors and / or usage patterns of individual users and / or devices, and allowing adversaries to exploit these global vulnerabilities to compromise devices.

[0018] The methods and apparatus disclosed herein introduce AI-based model security protection using mobile target defense. In the examples disclosed herein, a pre-trained endpoint protection model is independently fine-tuned on one or more endpoint devices and / or one or more systems using system-specific derivations. In the examples disclosed herein, Low Rank Adaptation (LoRA) is used to perform fine-tuning, but any other fine-tuning techniques can also be implemented to locally adjust model training (e.g., using endpoint devices to perform fine-tuning based on user and / or platform behavior). As a result of local model adaptation via fine-tuning, each model is customized for locally observed normal behavior on the target system, and thus, each local model is not only different from other local models but also more accurate than known static models. Therefore, an attacker trained against the fine-tuned local models does not train against all models, which introduces a generalization loss that no longer guarantees successful evasion in the real world using adversarial AI.

[0019] In the examples disclosed herein, the specific model is personalized (e.g., localized) for each device based on observed executable behaviors and / or user behaviors associated with the model. Thus, the methods and apparatuses disclosed herein provide an additional layer of protection relative to pre-trained endpoint detection models through mobile target defense, resulting in significantly higher detection rates against malicious attackers, even when adversarial learning is used against anti-malware tools deployed on endpoints. The methods and apparatuses disclosed herein enhance the security of endpoint-based AI models by incorporating user-specific and / or platform-specific observed behaviors, making the AI ​​model resilient against attacks exploiting global model vulnerabilities. By dynamically adapting to the unique patterns of individual users and devices, the methods and apparatuses disclosed herein ensure a high level of security and personalization. Thus, the methods and apparatuses disclosed herein achieve robust and personalized device protection through locally fine-tuning of pre-trained AI models.

[0020] Figure 1 This is a block diagram 100 illustrating an example implementation of a malware detector circuit system 105 for security protection using an AI-based model with mobile target defense, constructed in accordance with the teachings of this disclosure. Figure 1 The malware detector circuitry 105 can be instantiated by executing first instructions through a programmable circuitry system (such as a central processing unit (CPU)). This includes actions such as creating an instance of malware detector circuitry 105, making it malware detector circuitry 105 for any duration, materializing malware detector circuitry 105, implementing malware detector circuitry 105, etc. Additionally or alternatively, Figure 1 The malware detector circuitry 105 can be instantiated (e.g., creating an instance of the malware detector circuitry 105, making it the malware detector circuitry 105 for any duration, materializing the malware detector circuitry 105, implementing the malware detector circuitry 105, etc.) by (i) an application-specific integrated circuit (ASIC) and / or (ii) a field-programmable gate array (FPGA) constructed and / or configured to perform operations corresponding to the first instruction in response to the execution of the second instruction. It should be understood that... Figure 1 Some or all of the circuit system can thus be instantiated at the same or different times. For example, Figure 1 Some or all of the circuitry can be instantiated in one or more threads that execute concurrently and / or serially on the hardware. Furthermore, in some examples, Figure 1 Some or all of the circuitry in the system can be implemented by microprocessor circuitry executing instructions and / or FPGA circuitry executing operations to realize one or more virtual machines and / or containers.

[0021] exist Figure 1 In the example, the malware detector circuitry system 105 includes an example model identifier circuitry system 110, an example behavior data identifier circuitry system 115, an example tuner circuitry system 120, an example anomaly detector circuitry system 125, an example response initiator circuitry system 130, and an example data storage device 140. Figure 1 In the example, the model identifier circuitry 110, the behavior data identifier circuitry 115, the tuner circuitry 120, the anomaly detector circuitry 125, the response initiator circuitry 130, and the data storage device 140 communicate with the example bus 145.

[0022] Model identifier circuitry 110 identifies a pre-trained endpoint detection model. In the examples disclosed herein, the endpoint detection model is a robust, globally (e.g., centrally) pre-trained AI model designed for endpoint detection. As described in more detail in conjunction with tuner circuitry 120, the endpoint detection model can be used as a base model to be distributed to multiple endpoints. The base model is a pre-trained model, but is adapted to integrate low-rank adaptation (LoRA) layers into this pre-trained model for efficient local fine-tuning. For example, the endpoint detection model can be part of Endpoint Detection and Response (EDR) cybersecurity for monitoring and responding to threats on endpoints (e.g., physical devices connected to a network system, including mobile devices, desktop computers, virtual machines, embedded devices, servers, etc.). In some examples, the endpoint detection model can be used for data collection, data analysis (e.g., for identifying malicious activity), and / or response to cybersecurity threats (e.g., blocking malicious activity, disconnecting endpoints, etc.) associated with endpoint activity (e.g., file changes, network connections, user activity, etc.). For example, endpoint detection models can use behavioral analysis based on local behavioral data to detect anomalies and / or potential threats in real time. In some examples, endpoint detection models can be used to distinguish between benign anomalies and genuine threats. In some examples, endpoint detection models can be used to automatically isolate affected endpoints when a potential threat is detected.

[0023] like Figure 1 As illustrated, model identifier circuitry 110 communicates with computing system 150, which trains a neural network to generate example endpoint detection model 168. For example, as described above, model identifier circuitry 110 identifies the pre-trained endpoint detection model for further fine-tuning. In some examples, training data used for training during model generation includes local behavior data, endpoint activity data, and malware detection data. In some examples, the training data is labeled. In some examples, the training data is subdivided such that a portion of the data is used for validation purposes. In some examples, malware detector circuitry 105 is implemented by / within computing system 150.

[0024] Once training is complete, the endpoint detection model 168 is stored in one or more databases (e.g., Figure 1 The database (166) is used. Once trained, the deployed model can be manipulated during the inference phase to process the data, such as combining... Figure 6This is illustrated in more detail. During the inference phase, the data to be analyzed (e.g., live data) is input into the model, and the model executes to create output. Furthermore, in some examples, the output data may undergo post-processing after it is generated by the AI ​​model to transform the output into a useful result (e.g., a display of data, instructions to be executed by a machine, etc.). In some examples, the output of (one or more) deployed models can be captured and provided as feedback. By analyzing this feedback, the accuracy of (one or more) deployed models can be determined. If the feedback indicates that the accuracy of (one or more) deployed models is below a threshold or other criterion, the feedback, along with an updated training dataset, hyperparameters, etc., can be used to trigger the training of an updated (one or more) deployed model to generate an updated version of the deployed model.

[0025] like Figure 1 As shown, computing system 150 trains a neural network to generate endpoint detection model 168. Example computing system 150 includes neural network processor 164. In the example disclosed herein, neural network processor 164 implements a neural network. Figure 1 The computing system 150 also includes a neural network trainer 162. Figure 1 The neural network trainer 162 performs training of the neural network implemented by the neural network processor 164.

[0026] Figure 1 The computing system 150 includes a training controller 160. The training controller 160 instructs a neural network trainer 162 to perform training of the neural network based on training data 158. Figure 1 In the example, the training data 158 used by the neural network trainer 162 to train the neural network is stored in the database 156. Figure 1The example database 156 illustrated herein is implemented using any memory, storage device, and / or disk (such as, for example, flash memory, magnetic media, optical media, etc.) for storing data. Furthermore, the data stored in example database 156 can be in any data format, such as, for example, binary data, comma-separated data, tab-separated data, structured query language (SQL) structures, image data, etc. Although the example database 156 is illustrated as a single element, database 156 and / or any other data storage element described herein can be implemented using any number and / or (one or more) types of memory. Neural network trainer 162 uses training data 158 to train a neural network implemented by neural network processor 164 to generate endpoint detection model 168 as the result of neural network training. Endpoint detection model 168 is stored in database 166. Databases 156 and 166 can be implemented on the same storage device or on different storage devices.

[0027] The illustrated behavioral data identifier circuitry system 115 identifies behavioral data associated with a device (e.g., file access patterns, network activity, system interactions, etc.). In some examples, behavioral data is associated with user behavior or platform behavior on the device (e.g., usage patterns, interaction styles, other relevant metrics, etc.). However, behavioral data is not limited to endpoint security and control data. Behavioral data can also be associated with activity within a browser or application. For example, behavioral data identifier circuitry system 115 can identify user activity on (one or more) applications and / or (one or more) browsers used on a local device (e.g., website visits, login locations, application usage frequency, etc.). In the examples disclosed herein, behavioral data identifier circuitry system 115 identifies first behavioral data provided to tuner circuitry system 120 for performing local fine-tuning on a pre-trained endpoint detection model. In the examples disclosed herein, behavioral data identifier circuitry system 115 provides second behavioral data to anomaly detector circuitry system 125 for use as part of malware detection to monitor for anomalies in the second behavioral data. In some examples, the behavior data identifier circuitry 115 adapts to the endpoint detection model to modify the collection frequency, quantity, and / or data type of the first and / or second behavior data.

[0028] The tuner circuit system 120 illustrated in this document performs fine-tuning of a pre-trained endpoint detection model. In the example disclosed herein, the tuner circuit system 120 uses Low-Rank Adaptation (LoRA) to perform fine-tuning. However, one or more other types of fine-tuning techniques can be implemented. Fine-tuning involves training a pre-trained model on a smaller dataset to refine the model's capabilities and improve performance for a specific task or domain. For example, the application of LoRA techniques enables faster fine-tuning and less memory consumption, making the model more suitable for a specific task without requiring expensive full-scale fine-tuning. Thus, the pre-trained LLM (e.g., the pre-trained endpoint detection model 168) can be adapted to more specialized tasks. While obtaining large amounts of labeled data for a specific task or domain can be challenging, fine-tuning allows for more efficient use of pre-existing labeled data by adapting the pre-trained LLM to the available labeled dataset. In the example disclosed herein, the tuner circuit system 120 integrates LoRA layers into the pre-trained endpoint detection model 168 to achieve efficient local fine-tuning. In the examples disclosed herein, tuner circuitry 120 fine-tunes the model using collected user-based and / or platform-based behavioral data (e.g., first behavioral data, second behavioral data obtained using behavioral data identifier circuitry 115). Low-rank layers are tuned to better fit the behavioral data, thereby adapting the model to the specific context of the device and the user. In some examples, tuner circuitry 120 prepares the model for further deployment on a local machine by updating the pre-trained endpoint model by integrating the fine-tuned parameters into the model.

[0029] In the examples disclosed herein, adaptation efficiency is improved by using an integrated LoRA layer, which allows for efficient fine-tuning with little (e.g., minimal) additional computational overhead, making such fine-tuning feasible for resource-constrained local devices. For example, tuner circuitry system 120 integrates a LoRA layer into a pre-trained endpoint detection model 168, receives the pre-trained model with the integrated LoRA layer, and prepares the model for fine-tuning with local data. Tuner circuitry system 120 then fine-tunes the pre-trained model using behavioral data collected from the local device and adapts the model to the local context based on the behavioral data. In some examples, tuner circuitry system 120 stores a fine-tuned version of the endpoint detection model in a local data storage device 140. In some examples, tuner circuitry system 120 deploys the fine-tuned model as part of real-time malware detection analysis.

[0030] Anomaly detector circuitry system 125 monitors user and / or platform behavior to determine whether the behavior is consistent with expected usage patterns. In the examples disclosed herein, anomaly detector circuitry system 125 uses a fine-tuned pre-trained endpoint detection model 168 to detect anomalies to detect any deviations from normal behavior (such as those reflected in local data) that may indicate a potential malware attack. In the examples disclosed herein, anomaly detector circuitry system 125 reports anomalies to response initiator circuitry system 130. For example, anomaly detector circuitry system 125 identifies system data related to network traffic, file access patterns, and / or user activity to determine if any deviations are present. In some examples, anomaly detector circuitry system 125 identifies data deviations associated with browser activity or application activity. In the examples disclosed herein, anomaly detector circuitry system 125 uses a fine-tuned endpoint detection model to distinguish anomalies from noise and / or other deviations from the canonical. In some examples, both local and global behavioral data are used in training.

[0031] The response initiator circuitry system 130 triggers detection and protection mechanisms based on received anomalous data. For example, if an anomaly is detected, the response initiator circuitry system 130 initiates and / or activates one or more protection mechanisms to mitigate the risk of malware attacks. In some examples, the response initiator circuitry system 130 initiates mitigation actions such as isolating suspicious files, blocking malicious network connections, and / or issuing threat alerts to the user. In some examples, the response initiator circuitry system 130 initiates mitigation actions specific to the identified anomaly (e.g., anomalies in behavioral data associated with browser activity, application activity, etc.). For example, the response initiator circuitry system 130 can implement measures to protect applications (e.g., third-party commercial software applications, operating system package applications, etc.) from malware (e.g., through the use of access control, authentication protocols, encryption, etc.). In the examples disclosed herein, the malware detection system is highly sensitive to the specific behavior and usage patterns of individual user devices, making it more effective in identifying and mitigating malware that may not be detected by a general, globally trained model.

[0032] Data storage device 140 can be used to store any information associated with model identifier circuit system 110, behavior data identifier circuit system 115, tuner circuit system 120, anomaly detector circuit system 125, and / or response initiator circuit system 130. Figure 1The data storage device 140 illustrated in the figure can be implemented by any memory, storage device, and / or storage disk (such as flash memory, magnetic media, optical media, etc.) used for storing data. Furthermore, the data stored in the data storage device 140 can be in any data format, such as binary data, comma-separated data, tab-separated data, Structured Query Language (SQL) structures, image data, etc.

[0033] In some examples, the device includes means for identifying the model. For example, the means for identifying the model may be implemented by a model identifier circuit system 110. In some examples, the model identifier circuit system 110 may be implemented by, for example, Figure 7 Example programmable circuit systems such as the programmable circuit system 712 can be instantiated. For example, the model identifier circuit system 110 can be instantiated using... Figure 9 Example microprocessor 900 performs tasks such as those performed by Figure 2 The model identifier circuit system 110 may be instantiated by machine-executable instructions, such as those implemented in at least box 205. In some examples, the model identifier circuit system 110 may be instantiated by a hardware logic circuit system, which may be an ASIC, XPU, or other system configured to perform operations corresponding to machine-readable instructions. Figure 10 The FPGA circuit system 1000 is implemented. Additionally or alternatively, the model identifier circuit system 110 can be instantiated by any other combination of hardware, software, and / or firmware. For example, the model identifier circuit system 110 can be implemented by at least one or more hardware circuits (e.g., processor circuit systems, discrete and / or integrated analog and / or digital circuit systems, FPGAs, ASICs, XPUs, comparators, operational amplifiers (op-amps), logic circuits, etc.) configured to execute some or all of machine-readable instructions without executing software or firmware, but other configurations are equally applicable.

[0034] In some examples, the device includes means for collecting data. For example, the means for collecting data may be implemented by a behavioral data identifier circuit system 115. In some examples, the behavioral data identifier circuit system 115 may be implemented by, for example, a... Figure 7 The example programmable circuit system 712 can be instantiated using a programmable circuit system such as the example programmable circuit system 712. For example, the behavior data identifier circuit system 115 can be instantiated using a programmable circuit system such as the example programmable circuit system 712. Figure 9 Example microprocessor 900 performs tasks such as those performed by Figure 4The behavior data identifier circuitry system 115 may be instantiated by machine-executable instructions, such as those implemented in at least box 410. In some examples, the behavior data identifier circuitry system 115 may be instantiated by a hardware logic circuitry system, which may be an ASIC, XPU, or other system configured to perform operations corresponding to machine-readable instructions. Figure 10 The behavior data identifier circuit system 1000 is implemented. Additionally or alternatively, the behavior data identifier circuit system 115 can be instantiated by any other combination of hardware, software, and / or firmware. For example, the behavior data identifier circuit system 115 can be implemented by at least one or more hardware circuits (e.g., processor circuit systems, discrete and / or integrated analog and / or digital circuit systems, FPGAs, ASICs, XPUs, comparators, operational amplifiers (op-amps), logic circuits, etc.) configured to execute some or all of machine-readable instructions without executing software or firmware, but other configurations are equally applicable.

[0035] In some examples, the device includes means for making adjustments. For example, the means for making adjustments may be implemented by tuner circuitry system 120. In some examples, tuner circuitry system 120 may be implemented by, for example... Figure 7 The example programmable circuit system 712 can be instantiated using a programmable circuit system such as the example programmable circuit system 712. For example, tuner circuit system 120 can be instantiated using... Figure 9 Example microprocessor 900 performs tasks such as those performed by Figure 4 The tuner circuitry 120 may be instantiated by machine-executable instructions, such as those implemented in at least box 415. In some examples, the tuner circuitry 120 may be instantiated by a hardware logic circuitry system, which may be an ASIC, XPU, or other system configured to perform operations corresponding to machine-readable instructions. Figure 10 The FPGA circuit system 1000 is implemented. Additionally or alternatively, the tuner circuit system 120 can be instantiated by any other combination of hardware, software, and / or firmware. For example, the tuner circuit system 120 can be implemented by at least one or more hardware circuits (e.g., processor circuit systems, discrete and / or integrated analog and / or digital circuit systems, FPGAs, ASICs, XPUs, comparators, operational amplifiers (op-amps), logic circuits, etc.) configured to execute some or all of the machine-readable instructions and / or perform some or all of the operations corresponding to the machine-readable instructions without executing software or firmware, but other configurations are equally applicable.

[0036] In some examples, the device includes means for executing a modified detection model. For example, the means for executing the modified detection model may be implemented by an anomaly detector circuitry system 125. In some examples, the anomaly detector circuitry system 125 may be implemented by, for example, Figure 7 The example programmable circuit system 712 can be instantiated using a programmable circuit system such as the example programmable circuit system 712. For example, the anomaly detector circuit system 125 can be instantiated using... Figure 9 Example microprocessor 900 performs tasks such as those performed by Figure 2 The exception detector circuitry 125 may be instantiated by machine-executable instructions, such as those implemented in at least block 235. In some examples, the exception detector circuitry 125 may be instantiated by a hardware logic circuitry system, which may be an ASIC, XPU, or other system configured to perform operations corresponding to machine-readable instructions. Figure 10 The FPGA circuit system 1000 is implemented. Additionally or alternatively, the anomaly detector circuit system 125 can be instantiated by any other combination of hardware, software, and / or firmware. For example, the anomaly detector circuit system 125 can be implemented by at least one or more hardware circuits (e.g., processor circuit systems, discrete and / or integrated analog and / or digital circuit systems, FPGAs, ASICs, XPUs, comparators, operational amplifiers (op-amps), logic circuits, etc.) configured to execute some or all of machine-readable instructions without executing software or firmware, but other configurations are equally applicable.

[0037] In some examples, the device includes means for triggering a protection response. For example, the means for triggering a protection response may be implemented by a response initiator circuit system 130. In some examples, the response initiator circuit system 130 may be implemented by, for example, Figure 7 The example programmable circuit system 712 can be instantiated using a programmable circuit system such as the example programmable circuit system 712. For example, the response initiator circuit system 130 can be instantiated using... Figure 9 Example microprocessor 900 performs tasks such as those performed by Figure 2 The system is instantiated by machine-executable instructions, such as those implemented in at least box 250. In some examples, the response initiator circuitry 130 may be instantiated by a hardware logic circuitry system, which may be an ASIC, XPU, or other system configured to perform operations corresponding to machine-readable instructions. Figure 10The FPGA circuit system 1000 is implemented. Additionally or alternatively, the response initiator circuit system 130 may be instantiated by any other combination of hardware, software, and / or firmware. For example, the response initiator circuit system 130 may be implemented by at least one or more hardware circuits (e.g., processor circuit systems, discrete and / or integrated analog and / or digital circuit systems, FPGAs, ASICs, XPUs, comparators, operational amplifiers (op-amps), logic circuits, etc.) configured to execute some or all of the machine-readable instructions and / or perform some or all of the operations corresponding to the machine-readable instructions without executing software or firmware, but other configurations are equally applicable.

[0038] although Figure 1 The diagram illustrates an example of implementing a malware detector circuit system 105, but... Figure 1 One or more of the elements, processes, and / or devices illustrated herein may be combined, split, rearranged, omitted, eliminated, and / or implemented in any other way. Furthermore, Figure 1 Example model identifier circuit system 110, example behavior data identifier circuit system 115, example tuner circuit system 120, example anomaly detector circuit system 125, example response initiator circuit system 130, and / or (more generally) example malware detector circuit system 105 can be implemented by hardware, software, firmware, and / or any combination of hardware, software, and / or firmware. Thus, for example, any of the following can be implemented by combining a programmable circuit system with machine-readable instructions (e.g., firmware or software), a processor circuit system, one or more analog circuits, one or more digital circuits, one or more logic circuits, one or more programmable processors, one or more programmable microcontrollers, one or more graphics processing units (one or more GPUs), one or more digital signal processors (one or more DSPs, one or more ASICs), one or more programmable logic devices (one or more PLDs), and / or one or more field-programmable logic devices (one or more FPLDs) such as FPGAs: example model identifier circuit system 110, example behavioral data identifier circuit system 115, example tuner circuit system 120, example anomaly detector circuit system 125, example response initiator circuit system 130, and / or (more generally) example malware detector circuit system 105. Furthermore, Figure 1 Example malware detector circuitry system 105 may include additional or replacement Figure 1One or more of the elements, processes and / or devices illustrated herein, and / or may include more than one of any or all of the elements, processes and devices illustrated herein.

[0039] This indicates that it can be implemented and / or instantiated by a programmable circuit system. Figure 1 A flowchart and / or representation of example machine-readable instructions for the malware detector circuit system 105 that can be executed by a programmable circuit system to implement and / or instantiate it. Figure 1 A flowchart of an example operation of the computing system 150 is shown in Figures 2-4 As shown below. Machine-readable instructions can be one or more executable programs or portions thereof for execution by a programmable circuit system, such as those described below. Figures 7-8 The programmable circuit systems 712, 812 shown in the example processor platforms(s) discussed 700, 800, and / or machine-readable instructions may be as follows: Figure 9 and / or Figure 10 The example programmable circuit system discussed (e.g., FPGA) implements one or more functions or portions of functions. In some examples, machine-readable instructions cause operations, tasks, etc., to be performed and / or executed in a real-world manner. As used herein, “automation” means without human intervention.

[0040] The program may be embodied in instructions (e.g., software and / or firmware) stored on one or more non-transitory computer-readable and / or machine-readable storage media, such as cache memory, magnetic storage devices or disks (e.g., floppy disks, hard disk drives (HDDs) etc.), optical storage devices or disks (e.g., Blu-ray discs, compact disks (CDs), digital versatile disks (DVDs) etc.), redundant arrays of independent disks (RAID), registers, ROM, solid-state drives (SSDs), SSD memory, non-volatile memory (e.g., electrically erasable programmable read-only memory (EEPROM), flash memory, etc.), volatile memory (e.g., any type of random access memory (RAM) etc.), and / or any other storage device or disk. Instructions on a non-transitory computer-readable and / or machine-readable medium may be programmed and / or executed by a programmable circuit system located in one or more hardware devices, but the entire program and / or portions thereof may be executed and / or instantiated, and / or embodied in dedicated hardware by one or more hardware devices other than the programmable circuit system. Machine-readable instructions may be distributed across multiple hardware devices and / or executed by two or more hardware devices (e.g., server and client hardware devices). For example, a client hardware device may be implemented by an endpoint client hardware device (e.g., a hardware device associated with a human and / or machine user) or an intermediate client hardware device gateway (e.g., a radioaccess network (RAN)) that facilitates communication between a server and an endpoint client hardware device. Similarly, a non-transitory computer-readable storage medium may include one or more media. Further, although references... Figures 2-4 The flowchart shown in the figure illustrates the example program, but an implementation can be used instead. Figure 1The example malware detector circuit system 105 employs many other methods. For example, the execution order of boxes in (one or more) the flowchart can be changed, and / or some boxes in the described boxes can be changed, eliminated, or combined. Additionally or alternatively, any or all boxes in the flowchart can be implemented by one or more hardware circuits (e.g., processor circuit systems, discrete and / or integrated analog and / or digital circuit systems, FPGAs, ASICs, comparators, operational amplifiers (op-amps), logic circuits, etc.) configured to perform the corresponding operations without executing software or firmware. The programmable circuit system can be distributed across different network locations and / or located locally on one or more hardware devices (e.g., single-core processors (e.g., single-core CPUs), multi-core processors (e.g., multi-core CPUs, XPUs, etc.)). For example, the programmable circuit system can be a CPU and / or FPGA located in the same package (e.g., the same integrated circuit (IC) package, or in two or more separate housings), one or more processors in a single machine, multiple processors distributed across multiple servers in a server rack, multiple processors distributed across one or more server racks, etc., and / or any (one or more) combinations thereof.

[0041] The machine-readable instructions described herein may be stored in one or more formats, such as compressed formats, encrypted formats, segmented formats, compiled formats, executable formats, and encapsulated formats. The machine-readable instructions described herein may be stored as data (e.g., computer-readable data, machine-readable data, one or more bits (e.g., one or more computer-readable bits, one or more machine-readable bits, etc.), bit streams (e.g., computer-readable bit streams, machine-readable bit streams, etc.) etc.) or data structures (e.g., as part of instructions, code, code representations, etc.) that can be used to create, manufacture, and / or produce machine-executable instructions. For example, machine-readable instructions may be segmented and stored on one or more storage devices, disks, and / or computing devices (e.g., servers) located at the same or different locations within a network or set of networks (e.g., in the cloud, at an edge device, etc.). Machine-readable instructions may require one or more of the following to be installed, modified, adapted, updated, combined, supplemented, configured, decrypted, decompressed, unpacked, distributed, redistributed, compiled, etc., so that they are directly readable, interpretable, and / or executable by computing devices and / or other machines. For example, machine-readable instructions may be stored in multiple parts that are individually compressed, encrypted, and / or stored on separate computing devices, wherein these parts, when decrypted, decompressed, and / or combined, form a set of computer-executable instructions and / or machine-executable instructions that, together, can form one or more functions and / or operations of a program such as the program described herein.

[0042] In another example, machine-readable instructions may be stored in a state where they can be read by a programmable circuit system, but require the addition of libraries (e.g., dynamic link libraries (DLLs)), software development kits (SDKs), application programming interfaces (APIs), etc., to execute the machine-readable instructions on a specific computing device or other device. In another example, the machine-readable instructions may need to be configured (e.g., stored settings, input data, recorded network addresses, etc.) before they can be executed, either wholly or partially. Thus, as used herein, machine-readable, computer-readable, and / or machine-readable media may include instructions and / or (one or more) programs, regardless of their specific format or state.

[0043] The machine-readable instructions described in this article can be represented by any past, present, or future instruction language, scripting language, programming language, etc. For example, machine-readable instructions can be represented using any of the following languages: C, C++, Java, C#, Perl, Python, JavaScript, HyperText Markup Language (HTML), Structured Query Language (SQL), Swift, etc.

[0044] As mentioned above, Figures 2-4Example operations can be implemented using executable instructions (e.g., computer-readable and / or machine-readable instructions) stored on one or more non-transitory computer-readable and / or machine-readable media. As used herein, the terms non-transitory computer-readable medium, non-transitory computer-readable storage medium, non-transitory machine-readable medium, and / or non-transitory machine-readable storage medium are explicitly defined to include any type of computer-readable storage device and / or disk, and are defined to exclude propagation signals and transmission media. Examples of such non-transitory computer-readable media, non-transitory computer-readable storage media, non-transitory machine-readable media, and / or non-transitory machine-readable storage media include optical storage devices, magnetic storage devices, HDDs, flash memory, read-only memory (ROM), CDs, DVDs, caches, any type of RAM, registers, and / or any other storage device or disk in which information is stored for any duration (e.g., up to an extended time period, permanently, during a short instance, during temporary buffering and / or information caching). As used herein, the terms "non-transitory computer-readable storage device" and "non-transitory machine-readable storage device" are defined as any physical (mechanical, magnetic, and / or electrical) hardware used to retain information for a period of time, excluding propagation signals and transmission media. Examples of non-transitory computer-readable storage devices and / or non-transitory machine-readable storage devices include any type of random access memory, any type of read-only memory, solid-state memory, flash memory, optical disc, hard disk, disk drive, and / or redundant array (RAID) systems of individual disks. As used herein, the term "device" refers to a physical structure such as mechanical and / or electrical equipment, hardware, and / or circuitry that may or may not be configured with, and / or manufactured for executing, computer-readable instructions, machine-readable instructions, etc.

[0045] Figure 2 This indicates that it can be implemented, instantiated, and / or executed by the example programmable circuit system. Figure 1 The flowcharts for example machine-readable instructions and / or example operations of example malware detector circuit system 105 are shown in the example. Figure 2 Machine-readable instructions and / or operations 200 begin at box 205, where the model identifier circuitry 110 identifies the endpoint detection model (e.g., Figure 1Endpoint detection model 168). For example, the endpoint detection model can be used to monitor and respond to potential malware-based threats on endpoints, and to collect data associated with endpoint activity. In some examples, at box 210, model identifier circuitry 110 determines whether the endpoint detection model has been trained. If model identifier circuitry 110 determines that the endpoint detection model has not been trained or requires further training to obtain a pre-trained endpoint detection model, control proceeds to box 215 to train the endpoint detection model, as in conjunction with... Figure 3 A more detailed description.

[0046] Once the endpoint detection model is trained, at box 220, the tuner circuitry system 120 determines whether to perform additional training on the pre-trained model (e.g., fine-tuning the model using a smaller, more specific dataset). If the tuner circuitry system 120 determines to perform additional training, at box 225, the tuner circuitry system 120 uses fine-tuning to update the pre-trained endpoint detection model. For example, as in combination Figure 4 In more detail, tuner circuitry 120 uses LoRA to perform local fine-tuning. At box 230, anomaly detector circuitry 125 loads the fine-tuned endpoint detection model and, at box 235, monitors behavioral data associated with a given device. For example, anomaly detector circuitry 125 monitors second behavioral data associated with the device (e.g., file access patterns, network activity, system interactions, etc.) and determines the presence of any anomalies based on the fine-tuned, pre-trained endpoint detection model. If anomaly detector circuitry 125 identifies an anomaly in the second behavioral data at box 240, then at box 245, response initiator circuitry 130 determines whether the anomaly corresponds to malware activity (e.g., activity associated with potential data breaches, data corruption, etc.). If malware activity is detected, then at box 250, response initiator circuitry 130 triggers a protective response (e.g., isolating suspicious files, blocking malicious network connections, etc.) to mitigate the risk of malware-based attacks.

[0047] Figure 3 This means that it can be executed, instantiated, and / or implemented by a programmable circuit system. Figure 1 The flowcharts for example machine-readable instructions and / or example operations of example malware detector circuit system 105 are shown in the example malware detector circuit system 105. Figure 3Machine-readable instructions and / or operations 215 begin at box 305, where the model identifier circuitry accesses training data 158. Training data 158 may include results from training the endpoint detection model. In some examples, the training data is labeled. In some examples, the training data is subdivided such that a portion of the data is used for validation purposes. At box 310, trainer 162 identifies the data features represented by training data 158. In some examples, at box 315, training controller 160 instructs trainer 162 to perform training of the neural network using training data 158 to generate endpoint detection model 168. In some examples, at box 320, additional training is performed to refine endpoint detection model 168.

[0048] Figure 4 This indicates that it can be implemented, instantiated, and / or executed by the example programmable circuit system. Figure 1 The flowchart of example machine-readable instructions and / or example operations 225 for example malware detector circuitry system 105, which uses fine-tuning to update endpoint detection model 168. Figure 4 Machine-readable instructions and / or operations 225 begin at box 405, where tuner circuitry 120 integrates a fine-tuning layer into the endpoint detection model. For example, tuner circuitry 120 integrates a LoRA layer into a pre-trained endpoint detection model 168 to achieve efficient local fine-tuning, thereby allowing more effective use of pre-existing labeled data by adapting the pre-trained LLM to an available labeled dataset. Once the LoRA layer is integrated into the pre-trained endpoint detection model, at box 410, behavioral data identifier circuitry 115 collects first behavioral data (e.g., file access patterns, network activity, system interactions, etc.) associated with a given device. At box 415, tuner circuitry 120 performs local fine-tuning of the endpoint detection model based on the collected first behavioral data. Subsequently, at box 420, tuner circuitry 120 integrates the fine-tuned parameters into the endpoint detection model (e.g., parameters within the pre-trained model are tuned through training on a dedicated dataset).

[0049] Figure 5 Figure 500 illustrates an example process execution sequence diagram 500 for deploying a finely tuned endpoint detection model to monitor data anomalies, according to the teachings of this disclosure. Figure 5 In the example, user 502 initiates the deployment (e.g., initial deployment 516) of a pre-trained model (e.g., pre-trained endpoint detection model 168), which is then installed on local device 504 (e.g., installing pre-trained model 518). In some examples, such as combining... Figure 2 As described, Figure 1The model identifier circuitry 110 initiates the deployment of the pre-trained endpoint detection model 168 on the local device 504. The tuner circuitry 120 performs the following: initialization of the fine-tuning layer 506 (e.g., initialization of the fine-tuning layer 520). For example, fine-tuning layer initialization can be performed using LoRA, but is not limited to this fine-tuning technique. The behavior data identifier circuitry 115 collects first behavior data associated with behavior data 508 (e.g., collects user and / or platform behavior data 522) and provides the behavior data to the local device 504 (e.g., provides the collected data 524). The tuner circuitry 120 fine-tunes the pre-trained endpoint detection model 168 using fine-tuning techniques (e.g., fine-tuning using LoRA 526) to update the fine-tuning layer 506, and updates the endpoint detection model 168 on the local device 504 with the fine-tuned parameters (e.g., updates model 528 with the fine-tuned parameters). Anomaly detector circuitry 125 deploys a fine-tuned model 510 to initiate monitoring for data anomalies using that fine-tuned model (e.g., deploying a fine-tuned model 530). The fine-tuned model, as part of monitoring system 512, monitors, detects, and reports anomalies (e.g., initiating monitoring behavior 532, detecting anomalies 534, reporting anomalies 536). In some examples, response initiator circuitry 130 triggers a protection mechanism on local device 504 (e.g., triggering protection mechanism 538). In some examples, as part of an adversary-based attack, adversary 514 performs analysis of a global model to identify malicious code that can be used to deceive a classifier of a pre-trained model (e.g., analyzing the global model 540). Based on the global model analysis, adversary 514 exposes any global vulnerabilities and attempts to exploit those identified vulnerabilities on local device 504 (e.g., exposing global vulnerability 542, attempting to exploit vulnerability 544). Due to the use of... Figure 1 The malware detector circuitry system 105 performs local pre-trained model adaptation based on layer fine-tuning (e.g., using LoRA) (e.g., local adaptation in place 546), which provides a security mechanism to prevent potential malware attacks from adversaries 514 (e.g., attack failure due to local adaptation 548).

[0050] Figure 6 The diagram shows the relationship between Figure 1 Example setups 600 for the training and inference phases associated with the malware detector circuitry system 105, including example responses to adversary attacks. Figure 6In the example, training phase 605 and inference phase 601 are integrated into endpoint detection model training and deployment performed using malware detector circuitry system 105. In training phase 605, model identifier circuitry system 110 identifies the pre-trained AI endpoint detection model (e.g., pre-trained AI endpoint detection 620), and tuner circuitry system performs initialization of fine-tuning layers (e.g., LoRA layer initialization 625), then initiates behavioral data collection using behavioral data identifier circuitry system 115 (e.g., user and platform behavioral data collection 630). Tuner circuitry system 120 performs fine-tuning of the integrated fine-tuning layers based on the behavioral data collection (e.g., fine-tuning with LoRA 635). Subsequently, tuner circuitry system 120 updates the model by integrating the fine-tuned parameters into the endpoint detection model (e.g., model update 640). Anomaly detector circuitry system 125 and response initiator circuitry system 130 perform inference phase 610 associated with the deployment of the fine-tuned pre-trained endpoint detection model (e.g., fine-tuned model loading 645). For example, the anomaly detector circuitry 125 initiates monitoring of data (e.g., behavior monitoring 650) to detect changes in user-based and / or platform-based usage patterns.

[0051] In the examples disclosed herein, personalized device protection is achieved through local fine-tuning of the endpoint detection model (e.g., using LoRA) to significantly enhance malware detection. Starting with a globally pre-trained malware detection model, the malware detector circuitry system 105 integrates a LoRA layer into that model for efficient local fine-tuning. As previously described, collected local behavioral data is used to fine-tune the model, adapting it to the unique characteristics of the local environment. The fine-tuned model continuously monitors activity in real time, allowing the detection of any anomalies deviating from the normal behavioral patterns learned during fine-tuning.

[0052] For example, changes in user-based and / or platform-based usage patterns can be initiated by an adversary attack 615. An adversary attack 615 includes performing analysis of a global endpoint detection model (e.g., global model analysis 665), identifying vulnerabilities in the global model (e.g., global vulnerability identification 670), and attempting to exploit the identified vulnerabilities (e.g., attempting to exploit a vulnerability on a local device 675). However, the adversary attack fails when a local adaptation of the endpoint detection model is implemented based on the use of local fine-tuning techniques (e.g., attack failure due to local adaptation 680). For example, an anomaly detector circuitry 125 identifies anomalies associated with collected data caused by the adversary attack 615 (e.g., anomaly detection 655). Based on the presence of data anomalies, a response initiator circuitry 130 triggers detection and protection mechanisms (e.g., protection mechanism 660) to mitigate the risk of malware attacks (e.g., blocking malicious network connections, etc.).

[0053] Figure 7 It is constructed for execution and / or instantiation. Figure 2 and Figure 4 Example machine-readable instructions and / or example operations to implement Figure 1 The example malware detector circuit system 105 is a block diagram of an example programmable circuit system platform 700. The programmable circuit system platform 700 can be, for example, a server, personal computer, workstation, self-learning machine (e.g., neural network), mobile device (e.g., cellular phone, smartphone, tablet such as iPad™), personal digital assistant (PDA), internet device, DVD player, CD player, digital video recorder, Blu-ray player, game console, personal video recorder, set-top box, head-mounted device (e.g., augmented reality (AR) head-mounted device, virtual reality (VR) head-mounted device, etc.) or other wearable device, or any other type of computing and / or electronic device.

[0054] The illustrated example programmable circuit system platform 700 includes a programmable circuit system 712. The illustrated example programmable circuit system 712 is hardware. For example, the programmable circuit system 712 can be implemented by one or more integrated circuits, logic circuits, FPGAs, microprocessors, CPUs, GPUs, DSPs, and / or microcontrollers from any desired family or manufacturer. The programmable circuit system 712 can be implemented by one or more semiconductor-based (e.g., silicon-based) devices. In this example, the processor circuit system 712 implements a model identifier circuit system 110, a behavior data identifier circuit system 115, a tuner circuit system 120, an anomaly detector circuit system 125, and a response initiator circuit system 130.

[0055] The illustrated programmable circuit system 712 includes local memory 713 (e.g., cache, registers, etc.). The illustrated programmable circuit system 712 communicates with main memory, including volatile memory 714 and non-volatile memory 716, via bus 718. Volatile memory 714 may be implemented using Synchronous Dynamic Random Access Memory (SDRAM), Dynamic Random Access Memory (DRAM), RAMBUS® Dynamic Random Access Memory (RDRAM®), and / or any other type of RAM device. Non-volatile memory 716 may be implemented using flash memory and / or any other desired type of memory device. Access to the illustrated main memory 714, 716 is controlled by a memory controller 717. In some examples, the memory controller 717 may be implemented using one or more integrated circuits, logic circuits, microcontrollers, or any other type of circuit system from any desired family or manufacturer, thereby managing the flow of data to and from the main memory 714, 716.

[0056] The illustrated programmable circuit system platform 700 also includes an interface circuit system 720. The interface circuit system 720 can be implemented in hardware according to any type of interface standard, such as an Ethernet interface, a universal serial bus (USB) interface, a Bluetooth® interface, a near field communication (NFC) interface, a peripheral component interconnect (PCI) interface, and / or a peripheral component interconnect express (PCIe) interface.

[0057] In the illustrated example, one or more input devices 722 are connected to the interface circuit system 720. The input devices 722 allow users (e.g., human users, machine users, etc.) to input data and / or commands into the programmable circuit system 712. The input devices 722 may be implemented using, for example, audio sensors, microphones, cameras (still or video), keyboards, buttons, mice, touchscreens, trackpads, trackballs, point-and-click mouse devices, and / or voice recognition systems.

[0058] One or more output devices 724 are also connected to the interface circuitry system 720 illustrated in the example. The output devices 724 may be implemented, for example, by display devices (e.g., light-emitting diodes (LEDs), organic light-emitting diodes (OLEDs), liquid crystal displays (LCDs), cathode ray tube (CRT) displays, in-place switching (IPS) displays, touchscreens, etc.), haptic output devices, printers, and / or speakers. Thus, the interface circuitry system 720 illustrated in the example typically includes a graphics driver card, a graphics driver chip, and / or a graphics processor circuitry system such as a GPU.

[0059] The illustrated interface circuit system 720 also includes communication devices, such as transmitters, receivers, transceivers, modems, residential gateways, wireless access points, and / or network interfaces, for facilitating data exchange with external machines (e.g., any kind of computing device) via network 726. Communication can be carried out via, for example, Ethernet connections, digital subscriber line (DSL) connections, telephone line connections, coaxial cable systems, satellite systems, line-to-line wireless systems, cellular telephone systems, optical connections, etc.

[0060] The illustrated programmable circuit system platform 700 also includes one or more mass storage devices 728 for storing software and / or data. Examples of such mass storage devices 728 include magnetic storage devices (e.g., floppy disks, drives, HDDs, etc.), optical storage devices (e.g., Blu-ray discs, CDs, DVDs, etc.), RAID systems, and / or solid-state storage disks or devices (such as flash memory devices and / or SSDs).

[0061] It can be by Figure 2 and Figure 4 The machine-executable instructions 732, implemented by machine-readable instructions, may be stored in mass storage device 728, in volatile memory 714, in non-volatile memory 716, and / or in at least one non-transitory computer-readable storage medium, such as a CD or DVD, which may be removable.

[0062] Figure 8 It is constructed for execution and / or instantiation. Figure 3 Example machine-readable instructions and / or example operations to implement Figure 1The example computing system 150 is a block diagram of an example programmable circuit system platform 800. The programmable circuit system platform 800 can be, for example, a server, personal computer, workstation, self-learning machine (e.g., neural network), mobile device (e.g., cellular phone, smartphone, tablet such as iPad™), personal digital assistant (PDA), internet device, DVD player, CD player, digital video recorder, Blu-ray player, game console, personal video recorder, set-top box, head-mounted device (e.g., augmented reality (AR) head-mounted device, virtual reality (VR) head-mounted device, etc.) or other wearable device, or any other type of computing and / or electronic device.

[0063] The illustrated example programmable circuit system platform 800 includes a programmable circuit system 812. The illustrated example programmable circuit system 812 is hardware. For example, the programmable circuit system 812 can be implemented by one or more integrated circuits, logic circuits, FPGAs, microprocessors, CPUs, GPUs, DSPs, and / or microcontrollers from any desired family or manufacturer. The programmable circuit system 812 can be implemented by one or more semiconductor-based (e.g., silicon-based) devices. In this example, the programmable circuit system 812 implements an example neural network processor 164, an example trainer 162, and an example training controller 160.

[0064] The illustrated programmable circuit system 812 includes local memory 813 (e.g., cache, registers, etc.). The illustrated programmable circuit system 812 communicates with main memory, including volatile memory 814 and non-volatile memory 816, via bus 818. Volatile memory 814 may be implemented using synchronous dynamic random access memory (SDRAM), dynamic random access memory (DRAM), RAMBUS® dynamic random access memory (RDRAM®), and / or any other type of RAM device. Non-volatile memory 816 may be implemented using flash memory and / or any other desired type of memory device. Access to the illustrated main memory 814, 816 is controlled by a memory controller 817. In some examples, the memory controller 817 may be implemented using one or more integrated circuits, logic circuits, microcontrollers, or any other type of circuit system from any desired family or manufacturer, thereby managing the flow of data to and from the main memory 814, 816.

[0065] The illustrated programmable circuit system platform 800 also includes an interface circuit system 820. The interface circuit system 820 can be implemented in hardware according to any type of interface standard, such as Ethernet interface, Universal Serial Bus (USB) interface, Bluetooth® interface, Near Field Communication (NFC) interface, Peripheral Component Interconnect (PCI) interface and / or Peripheral Component Interconnect Fast (PCIe) interface.

[0066] In the illustrated example, one or more input devices 822 are connected to the interface circuit system 820. The input devices 822 allow users (e.g., human users, machine users, etc.) to input data and / or commands into the programmable circuit system 812. The input devices 822 may be implemented using, for example, audio sensors, microphones, cameras (still or video), keyboards, buttons, mice, touchscreens, trackpads, trackballs, point-and-click mouse devices, and / or voice recognition systems.

[0067] One or more output devices 824 are also connected to the interface circuitry system 820 illustrated in the example. The output devices 824 may be implemented, for example, by display devices (e.g., light-emitting diode (LED), organic light-emitting diode (OLED), liquid crystal display (LCD), cathode ray tube (CRT) display, in-plane switching (IPS) display, touchscreen, etc.), haptic output devices, printers, and / or speakers. Thus, the interface circuitry system 820 illustrated in the example typically includes a graphics driver card, a graphics driver chip, and / or a graphics processor circuitry system such as a GPU.

[0068] The illustrated interface circuit system 820 also includes communication devices, such as transmitters, receivers, transceivers, modems, residential gateways, wireless access points, and / or network interfaces, for facilitating data exchange with external machines (e.g., any kind of computing device) via network 826. Communication can be carried out via, for example, Ethernet connections, digital subscriber line (DSL) connections, telephone line connections, coaxial cable systems, satellite systems, line-to-line wireless systems, cellular telephone systems, optical connections, etc.

[0069] The illustrated programmable circuit system platform 800 also includes one or more mass storage devices 828 for storing software and / or data. Examples of such mass storage devices 828 include magnetic storage devices (e.g., floppy disks, drives, HDDs, etc.), optical storage devices (e.g., Blu-ray discs, CDs, DVDs, etc.), RAID systems, and / or solid-state storage disks or devices (such as flash memory devices and / or SSDs).

[0070] It can be by Figure 3The machine-executable instructions 832 implemented by the machine-readable instructions can be stored in a mass storage device 828, in volatile memory 814, in non-volatile memory 816, and / or on at least one non-transitory computer-readable storage medium, such as a CD or DVD, which may be removable.

[0071] Figure 9 yes Figures 7-8 Block diagrams illustrating example implementations of the programmable circuit systems 712 and 812. In this example, Figures 7-8 The programmable circuit systems 712 and 812 are implemented by microprocessor 900. For example, microprocessor 900 can be a general-purpose microprocessor (e.g., a general-purpose microprocessor circuit system). Microprocessor 900 executes... Figures 2-4 The flowchart contains some or all of the machine-readable instructions to effectively translate... Figure 1 The circuit system is instantiated as logic circuitry for performing operations corresponding to those machine-readable instructions. In some such examples, Figure 1 The circuit system is instantiated by the hardware circuitry of the microprocessor 900 in conjunction with instructions. For example, the microprocessor 900 can implement a multi-core hardware circuit system, such as a CPU, DSP, GPU, XPU, etc. While the microprocessor may include any number of example cores 902 (e.g., one core), this example microprocessor 900 is a multi-core semiconductor device including N cores. The cores 902 of the microprocessor 900 can operate independently or can cooperate to execute machine-readable instructions. For example, machine code corresponding to firmware, embedded software programs, or software programs can be executed by one of the cores 902, or can be executed by multiple cores 902 at the same or different times. In some examples, the machine code corresponding to firmware, embedded software programs, or software programs is divided into threads and executed in parallel by two or more cores 902. The software program can be coupled with... Figures 2-4 The flowchart represents part or all of the machine-readable instructions and / or operations.

[0072] Core 902 can communicate via a first example bus 904. In some examples, the first bus 904 can implement a communication bus for implementing communication associated with one or more cores 902. For example, the first bus 904 can implement at least one of an Inter-Integrated Circuit (I2C) bus, a Serial Peripheral Interface (SPI) bus, a PCI bus, or a PCIe bus. Additionally or alternatively, the first bus 904 can implement any other type of computing or electrical bus. Core 902 can obtain data, instructions, and / or signals from one or more external devices through example interface circuitry 906. Core 902 can output data, instructions, and / or signals to one or more external devices through interface circuitry 906. While the core 902 of this example includes example local memory 920 (e.g., a Level 1 (L1) cache, which may be split into an L1 data cache and an L1 instruction cache), the microprocessor 900 also includes example shared memory 910 (e.g., a Level 2 (L2) cache) that can be shared by the cores for high-speed access to data and / or instructions. Data and / or instructions can be transferred (e.g., shared) by writing to and / or reading from shared memory 910. The local memory 920 of each core 902 in the core 902, as well as the shared memory 910, may be a cache memory and main memory comprising multiple levels (e.g., ...). Figure 8 The cache hierarchy is part of the main memory (814, 816). Typically, higher-level memories in the hierarchy exhibit lower access times and have smaller storage capacities compared to lower-level memories. Changes to the levels of the cache hierarchy are managed by cache coherency strategies (e.g., reconciliation).

[0073] Each core 902 may be referred to as a CPU, DSP, GPU, or any other type of hardware circuitry. Each core 902 includes a control unit circuitry 914, an arithmetic and logic (AL) circuitry (sometimes called an ALU) 916, multiple registers 918, an L1 cache 920, and a second example bus 922. Other structures may exist. For example, each core 902 may include a vector unit circuitry, a single instruction multiple data (SIMD) unit circuitry, a load / store unit (LSU) circuitry, a branch / jump unit circuitry, a floating-point unit (FPU) circuitry, etc. The control unit circuitry 914 includes semiconductor-based circuitry configured to control (e.g., coordinate) data movement within the corresponding core 902. The AL circuitry 916 includes semiconductor-based circuitry configured to perform one or more mathematical and / or logical operations on data within the corresponding core 902. Some example AL circuitry 916 performs integer-based operations. In other examples, the AL circuit system 916 also performs floating-point operations. In still other examples, the AL circuit system 916 may include a first AL circuit system that performs integer-based operations and a second AL circuit system that performs floating-point operations. In some examples, the AL circuit system 916 may be referred to as an Arithmetic Logic Unit (ALU).

[0074] Register 918 is a semiconductor-based structure used to store data and / or instructions (such as the result of one or more operations performed by the AL circuit system 916 of the corresponding core 902). For example, register 918 may include one or more vector registers, one or more SIMD registers, one or more general-purpose registers, one or more flag registers, one or more segment registers, one or more machine-specific registers, one or more instruction pointer registers, one or more control registers, one or more debug registers, one or more memory management registers, one or more machine check registers, etc. Register 918 can be configured as follows: Figure 9 The blocks shown are arranged as illustrated. Alternatively, register 918 can be organized in any other arrangement, format, or structure (including distribution throughout core 902) to reduce access time. The second bus 922 can be implemented by at least one of an I2C bus, an SPI bus, a PCI bus, or a PCIe bus.

[0075] Each core 902 and / or (more generally) microprocessor 900 may include additional and / or alternative structures to those shown and described above. For example, one or more clock circuits, one or more power supplies, one or more power gates, one or more cache home agents (CHAs), one or more converged / common mesh stops (CMSs), one or more shifters (e.g., one or more barrel shifters), and / or other circuitry may be present. The microprocessor 900 is a semiconductor device manufactured to include a number of transistors interconnected to implement the structures described above in one or more integrated circuits (ICs) contained in one or more packages.

[0076] Microprocessor 900 may include one or more accelerators (e.g., acceleration circuitry, hardware accelerators, etc.) and / or cooperate with one or more accelerators (e.g., acceleration circuitry, hardware accelerators, etc.). In some examples, the accelerators are implemented by logic circuitry systems, thereby enabling certain tasks to be performed faster and / or more efficiently than could be done by a general-purpose processor. Examples of accelerators include ASICs and FPGAs, such as those discussed herein. GPUs, DSPs, and / or other programmable devices may also be accelerators. Accelerators may be onboard with microprocessor 900, in the same chip package as microprocessor 900, and / or in one or more separate packages from microprocessor 900.

[0077] Figure 10 yes Figures 7-8 A block diagram illustrating another example implementation of a programmable circuit system. In this example, programmable circuit systems 712 and 812 are implemented by FPGA circuit system 1000. For example, FPGA circuit system 1000 can be implemented by an FPGA. For example, FPGA circuit system 1000 can be used to perform operations that would otherwise be implemented via... Figure 9 The example microprocessor 900 executes operations by corresponding machine-readable instructions. However, once configured, the FPGA circuit system 1000 instantiates the operations and / or functions corresponding to the machine-readable instructions in hardware, and thus can generally execute these operations / functions faster than if they could be executed by a general-purpose microprocessor executing the corresponding software.

[0078] More specifically, as described above Figure 9 The microprocessor 900 (a general-purpose device that can be programmed to perform operations by...) Figures 2-4 The flowchart represents some or all of the machine-readable instructions, but its interconnections and logic circuitry are fixed once manufactured. Figure 10The example FPGA circuit system 1000 includes interconnect and logic circuit systems that can be configured, constructed, programmed, and / or interconnected in different ways after manufacturing to instantiate, for example, with... Figures 2-4 The flowchart represents some or all of the machine-readable instructions corresponding to the operations / functions. Specifically, the FPGA 1000 can be considered as an array of logic gates, interconnects, and switches. Switches can be programmed to change how logic gates are interconnected via interconnects, effectively forming one or more dedicated logic circuits (unless and until the FPGA circuit system 1000 is reprogrammed). The configured logic circuits enable logic gates to cooperate in different ways, thereby performing different operations on data received from the input circuit system. Those operations can be associated with... Figures 2-4 The flowchart represents some or all of the instructions (e.g., software and / or firmware) that correspond to the instructions. Thus, the FPGA circuit system 1000 can be configured and / or constructed to efficiently connect with... Figures 2-4 Some or all of the machine-readable instructions in the flowchart are instantiated as dedicated logic circuits to execute the operations / functions corresponding to those software instructions in a dedicated manner similar to that of an ASIC. Therefore, the FPGA circuit system 1000 can perform operations / functions corresponding to those software instructions in a dedicated manner similar to that of an ASIC. Figures 2-4 Some or all of the corresponding operations / functions in the machine-readable instructions are faster than the same operations / functions that a general-purpose microprocessor can perform.

[0079] exist Figure 10 In some examples, the FPGA circuit system 1000 is configured and / or constructed in response to being programmed (and / or reprogrammed once or multiple times) based on a binary file. In some examples, the binary file can be compiled and / or generated based on instructions using a hardware description language (HDL) such as Lucid, VHSIC Hardware Description Language (VHDL), or Verilog. For example, a user (e.g., a human user, a machine user, etc.) can write code or programs corresponding to one or more operations / functions using HDL; the code / program can be translated into a low-level language as needed; and the code / program (e.g., low-level language code / program) can be converted into a binary file (e.g., through a compiler, software application, etc.). In some examples, Figure 10 The FPGA circuit system 1000 can access and / or load binary files to enable Figure 10The FPGA circuit system 1000 is configured and / or constructed to perform one or more operations / functions. For example, a binary file can be generated by... Figure 10 The FPGA circuit system 1000 accesses bitstreams (e.g., one or more computer-readable bits, one or more machine-readable bits, etc.), data (e.g., computer-readable data, machine-readable data, etc.), and / or machine-readable instructions to enable... Figure 10 Configure and / or construct the FPGA circuit system 1000 or one or more of its components.

[0080] In some examples, binary files are compiled, generated, transformed, and / or otherwise output from a unified software platform used to program the FPGA. For example, the unified software platform can translate first instructions (e.g., code or program) corresponding to one or more operations / functions in a high-level language (e.g., C, C++, Python, etc.) into second instructions corresponding to one or more operations / functions in HDL form. In some such examples, binary files are compiled, generated, and / or otherwise output from the unified software platform based on the second instructions. In some examples, Figure 10 The FPGA circuit system 1000 can access and / or load binary files to enable Figure 10 The FPGA circuit system 1000 is configured and / or constructed to perform one or more operations / functions. For example, a binary file can be generated by... Figure 10 The FPGA circuit system 1000 accesses bitstreams (e.g., one or more computer-readable bits, one or more machine-readable bits, etc.), data (e.g., computer-readable data, machine-readable data, etc.), and / or machine-readable instructions to enable... Figure 10 Configure and / or construct the FPGA circuit system 1000 or one or more of its components.

[0081] Figure 10The FPGA circuit system 1000 includes an example input / output (I / O) circuit system 1002 for obtaining data from and / or outputting data to the example configuration circuit system 1004 and / or external hardware 1006. For example, the configuration circuit system 1004 may be implemented by an interface circuit system that provides binary files for configuring the FPGA circuit system 1000 or portions thereof, the binary files being implemented as bitstreams, data, and / or machine-readable instructions. In some such examples, the configuration circuit system 1004 may obtain binary files from a user, a machine (e.g., a hardware circuit system (e.g., a programmable or dedicated circuit system) that can implement artificial intelligence / machine learning (AI / ML) models to generate binary files), and / or any combination thereof. In some examples, the external hardware 1006 may be implemented by an external hardware circuit system. For example, the external hardware 1006 may be implemented by... Figure 9 It is implemented using the 900 microprocessor.

[0082] The FPGA circuit system 1000 also includes an array of example logic gate circuit systems 1008, multiple example configurable interconnects 1010, and an array of example memory circuit systems 1012. The logic gate circuit system 1008 and the configurable interconnects 1010 are configurable for instantiating interoperable... Figures 2-4 One or more operations / functions corresponding to at least some of the machine-readable instructions and / or other expected operations. Figure 10 The logic gate system 1008 shown is manufactured in blocks or groups. Each block includes semiconductor-based electrical structures that can be configured into logic circuits. In some examples, the electrical structures include logic gates (e.g., AND gates, OR gates, NOR gates, etc.) that provide basic building blocks for logic circuits. Electrically controllable switches (e.g., transistors) are present within each logic gate system 1008 such that the configuration of the electrical structures and / or logic gates can form a circuit to perform a desired operation / function. The logic gate system 1008 may include other electrical structures (such as look-up tables (LUTs), registers (e.g., flip-flops or latches), multiplexers, etc.).

[0083] The configurable interconnect 1010 illustrated is a conductive path, trace, via, etc., which may include electrically controllable switches (e.g., transistors) whose states can be changed by programming (e.g., using an HDL instruction language) to activate or deactivate one or more connections between one or more logic gate systems 1008 in order to program a desired logic circuit.

[0084] The illustrated storage circuit system 1012 is configured to store the results of one or more operations performed by corresponding logic gates. The storage circuit system 1012 can be implemented using registers, etc. In the illustrated example, the storage circuit system 1012 is distributed among the logic gate circuit systems 1008 to facilitate access and improve execution speed.

[0085] Figure 10 The example FPGA circuit system 1000 also includes an example dedicated operating circuit system 1014. In this example, the dedicated operating circuit system 1014 includes a dedicated circuit system 1016 that can be invoked to implement common functions, thereby avoiding the need for on-site programming of those functions. Examples of such dedicated circuit systems 1016 include memory (e.g., DRAM) controller circuit systems, PCIe controller circuit systems, clock circuit systems, transceiver circuit systems, memory, and multiplier-accumulator circuit systems. Other types of dedicated circuit systems may be present. In some examples, the FPGA circuit system 1000 may also include example general-purpose programmable circuit systems 1018, such as example CPU 1020 and / or example DSP 1022. Other general-purpose programmable circuit systems 1018, such as GPUs, XPUs, etc., that can be programmed to perform other operations may additionally or alternatively be present.

[0086] although Figure 9 and Figure 10 The diagram shows Figures 7-8 The two example implementations of the 712 and 812 programmable circuit systems are presented, but many other approaches are envisioned. For example, an FPGA circuit system may include an onboard CPU (such as...) Figure 10 (One or more of the example CPUs 1020). Therefore... Figures 7-8 The programmable circuit systems 712 and 812 can be additionally combined by at least Figure 9 Example microprocessor 900 and Figure 10 The example FPGA circuit system 1000 is implemented. In some such hybrid examples, Figure 10 One or more cores 1002 can execute by Figures 2-4The flowchart(s) represent the first part of machine-readable instructions to perform one or more first operations / functions. Figure 10 The FPGA circuit system 1000 can be configured and / or constructed to implement and control the FPGA circuit system 1000. Figures 2-4 The flowchart represents the second part of a machine-readable instruction corresponding to one or more second operations / functions, and / or the ASIC can be configured and / or constructed to perform the operations / functions described above. Figures 2-4 The flowchart represents the third part of a machine-readable instruction, corresponding to one or more third operations / functions.

[0087] It should be understood that, Figure 1 Some or all of the circuit system can thus be instantiated at the same or different times. For example, Figure 9 The same and / or different (one or more) parts of the microprocessor 900 can be programmed to execute (one or more) machine-readable instructions at the same and / or different times. In some examples, Figure 10 The same and / or different (one or more) parts of the FPGA circuit system 1000 can be configured and / or constructed to perform operations / functions corresponding to (one or more) parts of machine-readable instructions at the same and / or different times.

[0088] In some examples, Figure 1 Some or all of the circuitry system can be instantiated in one or more threads, for example, executing concurrently and / or sequentially. Figure 9 The microprocessor 900 can execute machine-readable instructions in one or more threads that execute concurrently and / or sequentially. In some examples, Figure 10 The FPGA circuit system 1000 can be configured and / or constructed to implement operations / functions concurrently and / or serially. Furthermore, in some examples, Figure 1 Some or all of the circuit systems can be in Figure 9 One or more virtual machines and / or containers are implemented and executed on the microprocessor 900.

[0089] In some examples, Figures 7-8 The programmable circuit systems 712 and 812 can be housed in one or more packages. For example, Figure 9 microprocessor 900 and / or Figure 10 The FPGA circuitry system 1000 can be housed in one or more packages. In some examples, the XPU can be... Figures 7-8 The programmable circuit systems 712 and 812 are used to implement this, and these programmable circuit systems 712 and 812 can be housed in one or more packages. For example, the XPU may include a CPU in a package (e.g., Figure 9 microprocessor 900, Figure 10 CPU 1020, etc.), and DSP in another package (e.g., Figure 10 DSP 1022), GPU in another package, and FPGA in yet another package (e.g., Figure 10 FPGA circuit system 1000).

[0090] The diagram illustrates the use of, for example, Figures 7-8 A block diagram of an example software distribution platform 1105, which distributes software such as example machine-readable instructions 732, 832, to other hardware devices (e.g., hardware devices owned and / or operated by third parties from the software distribution platform's owner and / or operator), is shown in [the diagram]. Figure 11 The example software distribution platform 1105 is illustrated in the diagram. It can be implemented by any computer server, data facility, cloud service, etc., capable of storing software and delivering it to other computing devices. A third party can be a customer of the entity that owns and / or operates the software distribution platform 1105. For example, the entity owning and / or operating the software distribution platform 1105 can be the software (such as...). Figures 7-8 The developer, distributor, and / or licensor of the example machine-readable instructions 732, 832. Third parties may be consumers, users, retailers, OEMs, etc., who purchase and / or license the software for use and / or resell and / or sublicense. In the illustrated example, the software distribution platform 1105 includes one or more servers and one or more storage devices. The storage devices store the machine-readable instructions 732, 832, which can be used in conjunction with the machine-readable instructions as described above. Figures 2-4 This corresponds to the example machine-readable instructions. One or more servers of the example software distribution platform 1105 communicate with the example network 1110, which may correspond to the Internet and / or any one or more of the example networks described above. In some examples, as part of a business transaction, one or more servers deliver software to a requesting party in response to a request. Payments for the delivery, sale, and / or licensing of the software may be handled by one or more servers of the software distribution platform and / or by a third-party payment entity. The servers enable purchasers and / or licensors to download machine-readable instructions 732, 832 from the software distribution platform 1105. For example, software (which may be compatible with...) Figures 2-4 The example machine-readable instructions (corresponding to the example machine-readable instructions 732 and 832) can be downloaded to the example programmable circuit system platform 700, 800, which is used to execute the machine-readable instructions 732, 832 to implement... Figure 1 The malware detector circuitry system 105. In some examples, one or more servers of the software distribution platform 1105 periodically provide, deliver, and / or force software (e.g., Figures 7-8 Example machine-readable instructions 732, 832) are used to update software to ensure that improvements, patches, updates, etc., are distributed and applied to end-user devices. Although referred to as software above, the distributed "software" may alternatively be firmware.

[0091] "Including" and "comprising" (and all their forms and tenses) are used herein as open-ended terms. Thus, whenever a claim uses any form of "including" or "comprising" (e.g., including, containing, including, having, etc.) as a preamble or in the content of any kind of claim, it should be understood that additional elements, terms, etc., may be present and not fall outside the scope of the corresponding claim or statement. As used herein, when the phrase "at least" is used as a transitional term, for example, in the preamble of a claim, it is open-ended in the same way that the terms "comprising" and "containing" are open-ended. The term "and / or" when used, for example, in forms such as A, B, and / or C, refers to any combination or subset of A, B, and C, such as (1) only A, (2) only B, (3) only C, (4) A and B, (5) A and C, (6) B and C, or (7) A and B and C. As used herein in the context of describing structures, components, items, objects, and / or things, the phrase “at least one of A and B” is intended to refer to an implementation that includes any one of the following: (1) at least one A, (2) at least one B, or (3) at least one A and at least one B. Similarly, as used herein in the context of describing structures, components, items, objects, and / or things, the phrase “at least one of A and B” is intended to refer to an implementation that includes any one of the following: (1) at least one A, (2) at least one B, or (3) at least one A and at least one B. As used herein in the context of describing the conduct or execution of processes, instructions, actions, activities, etc., the phrase “at least one of A and B” is intended to refer to an implementation that includes any one of the following: (1) at least one A, (2) at least one B, or (3) at least one A and at least one B. Similarly, as used in this text in the context of describing the conduct or execution of processes, instructions, actions, activities, etc., the phrase “at least one of A or B” is intended to refer to an implementation that includes any of the following: (1) at least one A, (2) at least one B, or (3) at least one A and at least one B.

[0092] As used herein, singular references (e.g., "a ("a", "an")", "first", "second", etc.) do not exclude plurals. The term "a ("a" or "an")" as used herein refers to one or more of those objects. The terms "a ("a" or "an")", "one or more", and "at least one" are used interchangeably herein. Furthermore, although listed separately, multiple means, elements, or actions may be implemented by, for example, the same entity or object. Additionally, although individual features may be included in different examples or claims, these features may be combined, and inclusion in different examples or claims does not imply that the combination of features is not feasible and / or not advantageous.

[0093] As used herein, the phrase “to communicate” (including variations thereof) includes direct communication and / or indirect communication through one or more intermediate components, and does not require direct physical (e.g., wired) communication and / or continuous communication, but additionally includes selective communication performed at periodic intervals, predetermined intervals, non-periodic intervals, and / or one-off events.

[0094] As used herein, a “programmable circuit system” is defined as including (i) one or more dedicated electrical circuits (e.g., dedicated application circuits (ASICs)) configured to perform one or more specific operations and including one or more semiconductor-based logic devices (e.g., electrical hardware implemented by one or more transistors), and / or (ii) one or more semiconductor-based general-purpose electrical circuits that can be programmed with instructions to perform one or more specific functions and / or one or more operations and including one or more semiconductor-based logic devices (e.g., electrical hardware implemented by one or more transistors). Examples of programmable circuit systems include: programmable microprocessors (such as central processing unit (CPU)) that can execute first instructions to perform one or more operations and / or functions; field-programmable gate arrays (FPGAs) that can be programmed with second instructions to cause the configuration and / or construction of the FPGA to instantiate one or more operations and / or functions corresponding to the first instructions; graphics processing units (GPUs) that can execute first instructions to perform one or more operations and / or functions; digital signal processors (DSPs) that can execute first instructions to perform one or more operations and / or functions; XPUs; network processing units (NPUs); one or more microcontrollers that can execute first instructions to perform one or more operations and / or functions; and / or integrated circuits (such as application-specific integrated circuits (ASICs)). For example, an XPU can be implemented by a heterogeneous computing system that includes various types of programmable circuit systems (e.g., one or more FPGAs, one or more CPUs, one or more GPUs, one or more NPUs, one or more DSPs, etc., and / or any combination thereof) and orchestration techniques (e.g., one or more application programming interfaces (APIs)) that can assign one or more computing tasks to any of the various types of programmable circuit systems that are suitable for and can be used to perform one or more computing tasks.

[0095] As used herein, an integrated circuit / circuit system is defined as one or more semiconductor packages containing one or more circuit elements, such as transistors, capacitors, inductors, resistors, current paths, diodes, etc. For example, an integrated circuit can be implemented as one or more of an ASIC, FPGA, chip, microchip, programmable circuit system, semiconductor substrate coupling multiple circuit elements, system on chip (SoC), etc.

[0096] In summary, the example systems, methods, apparatuses, and artifacts disclosed herein present robust and personalized device protection mechanisms that utilize low-rank adaptation (LoRA) to locally fine-tune pre-trained AI models. In the examples disclosed herein, the security of endpoint-based AI models is enhanced by incorporating user-specific and / or platform-specific observed behaviors, making the models resilient to attacks exploiting global model vulnerabilities. The methods and apparatuses disclosed herein allow for dynamic local adaptation at the endpoint device of the AI ​​model to the unique patterns exhibited by each user and / or device on that local device, thereby ensuring a high level of security and personalization. Thus, the methods and apparatuses disclosed herein address the vulnerability of globally pre-trained endpoint detection models to adversarial training by taking into account the unique behaviors and / or usage patterns of each user and / or device, enabling different local models to function across the ecosystem at different endpoints. Consequently, the examples disclosed herein lead to improvements in the operation of machines and / or networks.

[0097] This document discloses example methods, apparatuses, systems, and articles for security protection using artificial intelligence models for defense against moving targets. Further examples and combinations thereof include the following:

[0098] Example 1 includes an apparatus comprising: an interface circuit system for obtaining a pre-trained detection model; machine-readable instructions; and at least one processor circuit for being programmed by the machine-readable instructions to perform: adjusting the pre-trained detection model based on first local behavioral data; and executing the adjusted detection model to detect anomalies in second local behavioral data associated with the apparatus.

[0099] Example 2 includes an apparatus as in Example 1, wherein anomalies in the second behavioral data are associated with potential malware activity.

[0100] Example 3 includes an apparatus as described in any of the preceding examples, wherein the first local behavioral data is associated with at least one of the following: network activity, browser activity, file access patterns, system interactions, or application activity.

[0101] Example 4 includes an apparatus as in any of the preceding examples, wherein the anomaly is malware activity, and one or more of at least one processor circuitry are used to trigger at least one of the following: quarantining a file, blocking a network connection, or generating a malware alert.

[0102] Example 5 includes an apparatus as described in any of the preceding examples, wherein one or more of at least one processor circuitry are used to adjust a pre-trained detection model based on low-rank adaptation (LoRA).

[0103] Example 6 includes an apparatus as in any of the preceding examples, wherein the pre-trained detection model is an endpoint detection model.

[0104] Example 7 includes a device as in any of the preceding examples, wherein at least one of a first local behavior data or a second local behavior data is associated with user behavior or platform behavior on the device.

[0105] Example 8 includes at least one non-transitory machine-readable medium, including machine-readable instructions for causing at least one processor circuit to perform at least the following operations: adjusting a pre-trained detection model based on first local behavioral data; and executing the adjusted detection model to detect anomalies in second local behavioral data associated with the device.

[0106] Example 9 includes at least one non-transitory machine-readable medium as in Example 8, wherein anomalies in the second behavioral data are associated with potential malware activity.

[0107] Example 10 includes at least one non-transitory machine-readable medium as in any of the preceding examples, wherein the first local behavioral data is associated with at least one of the following: network activity, browser activity, file access patterns, system interactions, or application activity.

[0108] Example 11 includes at least one non-transitory machine-readable medium as in any of the preceding examples, wherein the anomaly is malware activity and the machine-readable instructions are used to cause one or more of at least one processor circuitry to trigger at least one of the following: quarantining a file, blocking a network connection, generating a malware alert, or protecting an application.

[0109] Example 12 includes at least one non-transitory machine-readable medium as in any of the preceding examples, wherein machine-readable instructions are used to cause one or more pre-trained detection models in at least one processor circuit to adjust based on low-rank adaptation (LoRA).

[0110] Example 13 includes at least one non-transient machine-readable medium as in any of the preceding examples, wherein the pre-trained detection model is an endpoint detection model.

[0111] Example 14 includes at least one non-transitory machine-readable medium as in any of the preceding examples, wherein at least one of the first local behavioral data or the second local behavioral data is associated with user behavior or platform behavior on the device.

[0112] Example 15 includes an apparatus comprising: an adjustment means for adjusting a pre-trained detection model based on first local behavioral data; and an execution means for executing the adjusted detection model to detect anomalies in second local behavioral data associated with the apparatus.

[0113] Example 16 includes a device like that in Example 15, where anomalies in the second behavioral data are associated with potential malware activity.

[0114] Example 17 includes a device as in any of the preceding examples, wherein the first local behavioral data is associated with at least one of the following: network activity, browser activity, file access patterns, system interactions, or application activity.

[0115] Example 18 includes a device as in any of the preceding examples, wherein the anomaly is malware activity, and the device further includes a triggering device for triggering at least one of the following: isolating a file, blocking a network connection, generating a malware alert, or protecting an application.

[0116] Example 19 includes a device as in any of the preceding examples, wherein the adjustment means includes adjusting a pre-trained detection model based on low-rank adaptation (LoRA).

[0117] Example 20 includes a device as in any of the preceding examples, wherein the pre-trained detection model is an endpoint detection model.

[0118] Example 21 includes a method comprising: adjusting a pre-trained detection model based on first local behavioral data; and executing the adjusted detection model to detect anomalies in second local behavioral data associated with the device.

[0119] Example 22 includes a method as in Example 21, wherein anomalies in the second behavior data are associated with potential malware activity.

[0120] Example 23 includes a method as in any of the preceding examples, wherein the first local behavioral data is associated with at least one of the following: network activity, browser activity, file access patterns, system interactions, or application activity.

[0121] Example 24 includes a method as in any of the preceding examples, wherein the exception is malware activity that triggers at least one of the following: quarantining a file, blocking a network connection, generating a malware alert, or protecting an application.

[0122] Example 25 includes methods such as any of the preceding examples, including adjusting a pre-trained detection model based on low-rank adaptation (LoRA).

[0123] Example 26 includes a method as in any of the preceding examples, wherein the pre-trained detection model is an endpoint detection model.

[0124] Example 27 includes a method as described in any of the preceding examples, wherein at least one of the first local behavior data or the second local behavior data is associated with user behavior or platform behavior on the device.

[0125] The appended claims are hereby incorporated herein by reference. While certain example systems, methods, apparatuses, and articles of manufacture have been disclosed herein, the scope of this patent is not limited thereto. Rather, this patent covers all systems, methods, apparatuses, and articles of manufacture that fall entirely within the scope of the claims of this patent.

Claims

1. An apparatus comprising: Interface circuit system for obtaining pre-trained detection models; Machine-readable instructions; as well as At least one processor circuit, the at least one processor circuit being programmed by machine-readable instructions to perform the following operations: The pre-trained detection model is adjusted based on the first local behavioral data; and An adjusted detection model is executed to detect anomalies in second local behavioral data associated with the device.

2. The apparatus according to claim 1, wherein, The anomalies in the second behavioral data are associated with potential malware activity.

3. The apparatus according to claim 1 or 2, wherein, The first local behavioral data is associated with at least one of the following: network activity, browser activity, file access patterns, system interactions, or application activity.

4. The apparatus according to claim 1, 2 or 3, wherein, The anomaly is malware activity, and one or more of the at least one processor circuitry are used to trigger at least one of the following: quarantining a file, blocking a network connection, generating a malware alert, or protecting an application.

5. The apparatus according to claim 1, 2, 3 or 4, wherein, One or more of the at least one processor circuitry are used to adjust the pre-trained detection model based on low-rank adaptation (LoRA).

6. The apparatus according to claim 1, 2, 3, 4 or 5, wherein, The pre-trained detection model is an endpoint detection model.

7. The apparatus according to claim 1, 2, 3, 4, 5 or 6, wherein, At least one of the first local behavior data or the second local behavior data is associated with user behavior or platform behavior on the device.

8. At least one machine-readable medium, including machine-readable instructions, said machine-readable instructions being used to cause at least one processor circuitry to perform at least the following operations: Adjust the pre-trained detection model based on the first local behavioral data; and The adjusted detection model is executed to detect anomalies in the second local behavioral data associated with the device.

9. The at least one machine-readable medium according to claim 8, wherein, The anomalies in the second behavioral data are associated with potential malware activity.

10. The at least one machine-readable medium according to claim 8 or 9, wherein, The first local behavioral data is associated with at least one of the following: network activity, browser activity, file access patterns, system interactions, or application activity.

11. The at least one machine-readable medium according to claim 8, 9 or 10, wherein, The anomaly is malware activity, and the machine-readable instructions are used to cause one or more of the at least one processor circuitry to trigger at least one of the following: isolate a file, block a network connection, generate a malware alert, or protect an application.

12. The at least one machine-readable medium according to claim 8, 9, 10 or 11, wherein, The machine-readable instructions are used to cause one or more of the at least one processor circuitry to adjust the pre-trained detection model based on low-rank adaptation (LoRA).

13. The at least one machine-readable medium according to claim 8, 9, 10, 11 or 12, wherein, The pre-trained detection model is an endpoint detection model.

14. The at least one machine-readable medium according to claim 8, 9, 10, 11, 12 or 13, wherein, At least one of the first local behavior data or the second local behavior data is associated with user behavior or platform behavior on the device.

15. An apparatus comprising: An adjustment device for adjusting a pre-trained detection model based on first local behavioral data; as well as An execution device is used to execute a modified detection model to detect anomalies in second local behavioral data associated with the device.

16. The device according to claim 15, wherein, The anomalies in the second behavioral data are associated with potential malware activity.

17. The device according to claim 15 or 16, wherein, The first local behavioral data is associated with at least one of the following: network activity, browser activity, file access patterns, system interactions, or application activity.

18. The device according to claim 15, 16 or 17, wherein, The anomaly is malware activity, and the device further includes a triggering device for triggering at least one of the following: isolating a file, blocking a network connection, generating a malware alert, or protecting an application.

19. The device according to claim 15, 16, 17 or 18, wherein, The adjustment device includes adjusting the pre-trained detection model based on low-rank adaptation (LoRA).

20. The device according to claim 15, 16, 17, 18 or 19, wherein, The pre-trained detection model is an endpoint detection model.

21. A method comprising: The pre-trained detection model is adjusted based on the first local behavioral data; as well as The adjusted detection model is executed to detect anomalies in the second local behavioral data.

22. The method according to claim 21, wherein, The anomalies in the second behavioral data are associated with potential malware activity.

23. The method according to claim 21 or 22, wherein, The anomaly is malware activity. The method further includes: blocking network connections, generating malware alerts, or protecting applications.

24. The method according to claim 21, 22 or 23, further comprising: The pre-trained detection model is adjusted based on low-rank adaptation (LoRA).

25. The method according to claim 21, 22, 23 or 24, wherein, The pre-trained detection model is an endpoint detection model.