An artificial intelligence-based network information security defense system
By constructing an AI-based network information security defense system, the fragmentation and siloed state of network defense systems have been resolved, achieving full-domain situational awareness and collaborative evolution, enhancing defense capabilities, and adapting to complex threats and dynamic attacks.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- DELUMENGYU (HEBEI XIONGAN) TECHNOLOGY CO LTD
- Filing Date
- 2026-05-09
- Publication Date
- 2026-07-21
AI Technical Summary
Existing network security defense systems are fragmented and functionally isolated, making it difficult to achieve real-time data purification, in-depth analysis, and collaborative decision-making. This results in low overall effectiveness of the defense system and an inability to effectively cope with complex APT attacks.
An AI-based network information security defense system is adopted, including a data immunity and purification engine, a distributed intelligent sensing agent, a cognitive analysis and decision-making center, a co-evolutionary network, and an active evolutionary layer. Through real-time data cleaning, deep analysis, and autonomous learning, it achieves full-domain situational awareness and co-evolution, forming an organic and holistic defense system.
It achieves a seamless transition from single-point detection to systematic defense, enhancing defense capabilities by a hundredfold. It can autonomously learn and adapt to new threats and respond to dynamic attacks from AI hackers, solving the fragmentation and passive response problems of traditional defense systems and improving protection capabilities.
Smart Images

Figure CN122437702A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network information security defense technology, and more specifically, to a network information security defense system based on artificial intelligence. Background Technology
[0002] Cybersecurity refers to the technologies, measures, and policies that protect network systems, network devices, network data, and network users from threats such as unauthorized access, damage, tampering, and disclosure. The openness, sharing, and convenience of computer information networks have brought great convenience to people's work, life, and study, but they have also brought significant information security threats to society.
[0003] Although the application of artificial intelligence in network defense has become a trend, existing solutions are mostly fragmented and functionally isolated. Improving a certain detection algorithm, optimizing a certain type of firewall rule, or building an independent threat intelligence platform are like powerful islands, lacking a top-level architectural design that connects data collection, real-time purification, in-depth analysis, collaborative decision-making, and autonomous evolution. This fragmentation leads to low overall effectiveness of the defense system and an inability to form a synergy. When facing complex, multi-stage APT attacks, it is difficult to conduct effective correlation analysis and global response. The traditional model of relying on manual analysis of massive fragmented alerts has an extremely low judgment rate, which has become the biggest vulnerability. Summary of the Invention
[0004] To address the problems existing in the prior art, the purpose of this invention is to provide a network information security defense system based on artificial intelligence. In addition to achieving network information security defense, this invention can also immunize and purify data, and automatically identify, clean and verify malicious samples or contaminated data in training data.
[0005] To solve the above problems, the present invention adopts the following technical solution: An artificial intelligence-based network information security defense system includes: a data immunity and purification engine, a distributed intelligent sensing agent, a cognitive analysis and decision-making center, a co-evolutionary network, and an active evolutionary layer; The data immunity and purification engine is used to clean, desensitize, and make trusted multi-source heterogeneous security data input into the system in real time, so as to eliminate data poisoning attacks and ensure data quality. The distributed intelligent sensing agent is deployed at the network edge and terminal, and is used to perform real-time monitoring and preliminary threat response to local behavior based on a lightweight artificial intelligence model. The cognitive analysis and decision-making center is based on a cloud-based artificial intelligence model to perform in-depth analysis of purified data, enabling the identification of unknown threats, tracing of attack chains, and generation of automated response decisions. The co-evolutionary network is used to achieve trusted sharing and co-evolution of threat intelligence, defense strategies, and model knowledge while protecting the data privacy of all participants. The active evolution layer is used to automatically generate variants using newly emerging threat samples for adversarial training, and to memorize successful defense cases, enabling the system as a whole to have the ability to learn autonomously and evolve iteratively.
[0006] Compared with the prior art, the advantages of this invention are: This invention uses a data immunity and purification engine as the first line of defense, similar to skin and the innate immune system, to ensure the cleanliness of internal data flow. Distributed intelligent sensing agents act as nerve endings throughout the body, enabling full-domain, real-time situational awareness and initial reflexes. The cognitive analysis and decision-making center acts as a highly developed brain, performing deep semantic understanding, causal reasoning, and multi-objective trade-offs. The co-evolutionary network and the active evolutionary layer together constitute an evolutionary system capable of continuous learning, adaptation, and growth. These five layers are tightly coupled through the DIKWP semantic model, federated learning, and collaborative control laws, achieving smooth flow and bidirectional feedback of data, information, knowledge, wisdom, and intent. This completely breaks down the isolated state of fragmented defense, enabling the system to seamlessly connect from single-point detection to systemic defense and intelligent source tracing and countermeasures, just like a living organism. This is the platform foundation for achieving a hundredfold or thousandfold leap in AI-driven security capabilities.
[0007] This invention, through an active evolution layer, can automatically generate variants using adversarial training and memorize successful cases, enabling the system to possess the ability to continuously engage in AI-versus-AI games. Secondly, its evolution is global, not only optimizing detection model parameters but also adjusting the collaborative processes of multi-agents and reconstructing the topology of the collaborative network, achieving comprehensive adaptation from software to hardware, and from individuals to groups. Finally, through blockchain-based trusted contribution pricing in the collaborative evolution network, it establishes an incentive-compatible defense knowledge market, solving the trust and incentive problems in sharing. This allows high-quality threat intelligence to be proactively and securely shared, accelerating the formation of herd immunity. This makes the system's defense capability no longer a fixed initial value but a function that continuously grows over time and with the accumulation of adversarial experience. In persistent cyber warfare, this mechanism of faster system evolution leading to victory is crucial. This solution helps users seize and maintain core intellectual control in future cyberspace confrontations by enabling the defense system to evolve faster and more intelligently than the attack system, fundamentally changing the asymmetric landscape of offense and defense. Attached Figure Description
[0008] Figure 1 This is a schematic diagram of a network information security defense system based on artificial intelligence according to the present invention; Figure 2This is a schematic diagram of a data immunity and purification engine module in an artificial intelligence-based network information security defense system according to the present invention. Detailed Implementation
[0009] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.
[0010] Example: Please see Figure 1-2 A network information security defense system based on artificial intelligence includes: a data immunity and purification engine, a distributed intelligent sensing agent, a cognitive analysis and decision-making center, a co-evolutionary network, and an active evolutionary layer; The data immunity and purification engine is used to clean, de-identify, and make trusted multi-source heterogeneous security data entering the system in real time to eliminate data poisoning attacks and ensure data quality. Distributed intelligent sensing agents are deployed at the network edge and terminals to monitor local behavior in real time and provide initial threat response based on lightweight artificial intelligence models; The cognitive analysis and decision-making center is based on a cloud-based artificial intelligence big data model to perform in-depth analysis of purified data, enabling the identification of unknown threats, tracing of attack chains, and generation of automated response decisions. Co-evolutionary networks are used to achieve trusted sharing and co-evolution of threat intelligence, defense strategies, and model knowledge while protecting the data privacy of all participants. The active evolution layer is used to automatically generate variants for adversarial training using newly emerging threat samples, and to memorize successful defense cases, enabling the system as a whole to have the ability to learn autonomously and evolve iteratively.
[0011] In a specific embodiment of this invention, the data immunization and purification engine serves as the first line of defense, performing real-time trusted processing on multi-source heterogeneous data to eliminate the risk of data poisoning and provide high-quality input for subsequent analysis. Distributed intelligent sensing agents perform lightweight real-time monitoring and initial response at the network edge, enabling early detection and local containment of threats. The cognitive analysis and decision-making center, based on a large cloud model, performs deep semantic analysis and attack chain reconstruction on the purified data, generating automated response decisions. The co-evolutionary network, while protecting privacy, achieves trusted cross-node sharing and collaborative optimization of defense strategies and model parameters. The active evolutionary layer utilizes adversarial training and case memory to drive the entire system to self-iterate and upgrade its capabilities. These five layers are not linearly stacked but form an organic whole of perception, purification, co-evolution, and co-evolution, realizing comprehensive defense capabilities. The spiral-like architecture fundamentally solves the core shortcomings of traditional network security systems, namely fragmented defense and passive response. Through five layers of collaboration, it integrates isolated defense devices and links into an organism with a central nervous system, realizing autonomous network monitoring, protection, and counterattack. It achieves a high degree of automation and intelligence in the defense process, freeing security personnel from analyzing massive amounts of alarms and resolving the contradiction between manpower shortage and low efficiency. Secondly, the system has a leap in full-chain capabilities from single-point detection to systematic defense and intelligent source tracing and countermeasures. According to Qi An Xin's practice, AI brings about an improvement in protection capabilities. Finally, the built-in collaboration and evolution mechanism enables the system to continuously learn and adapt to new threats, especially in dealing with dynamic and continuous attacks launched by AI hackers, achieving a qualitative change from a static rule base to a dynamic immune system.
[0012] Specifically, the data immunity and purification engine includes a heterogeneous data perception and fusion layer, an intelligent purification decision and execution layer, and an immune memory and evolution layer; The heterogeneous data perception and fusion layer is used to collect and fuse multi-source heterogeneous data from network traffic, terminal behavior logs, asset configuration information and external threat intelligence in real time to form a unified and trusted data view. The intelligent purification decision and execution layer is used to implement a three-level progressive purification process on the fused data, including primary filtering based on rules and strategies, adversarial deep purification based on a self-iterative multi-instance learning model, and anomaly detection and removal based on an artificial immune clonal selection algorithm. The adversarial deep purification based on a self-iterative multi-instance learning model in the intelligent purification decision and execution layer is used to process weakly labeled data with multiple alleles. When it is known that there are malicious samples in a batch of data but the specific attribution is unknown, the original fuzzy multi-allele data is peeled off layer by layer through a self-iterative learning method, and the accurate malicious data features are identified from the mixed samples. The immune memory and evolutionary layer are used to store the data threat features identified during the purification process as immune memory. Based on the federated learning framework, the purification model and strategy are co-evolved with other defense nodes in the network to form herd immunity while protecting data privacy.
[0013] In a specific embodiment of the present invention, the steps of anomaly detection and removal based on the artificial immune clonal selection algorithm in the intelligent purification decision and execution layer include: A. Input the dataset to be tested as the antigen. Random initialization A collection of antibodies Each antibody represents a potential normal data pattern; B. For each antigen data ,calculate All antibodies and their affinity Affinity is calculated using a metric based on the distance between feature vectors. C. Choose affinity The highest front Each antibody is cloned and amplified according to its affinity; the higher the affinity, the more clones are produced. The more; D. Mutate the cloned antibody to produce an antibody with higher affinity. The mutation formula is as follows: ,in These are mutated antibodies. Original antibody, As an antigen, Mutation rate is a function of randomness and affinity. Dimensionless coefficients that are jointly determined and take values in the range [0,1]; E. Recalculate the mutated antibody With antigen The affinity of the antibody is selected, and the antibody with the highest affinity is added to the memory cell set; F. Introduce newly generated random antibodies to replace Individuals with the lowest affinity achieve self-organization and renewal; G. Repeat steps B to F until the preset number of iterations is reached or the convergence condition is met. The data pattern in the final memory set is the normal pattern learned by the system. Data that deviates significantly from this pattern will be judged as abnormal and cleared.
[0014] The immune memory and evolutionary layer includes a conditional functional dependency CFD relation mining engine, a violation tuple detection engine, and a federated evolutionary network; The conditional function-dependent CFD relation mining engine is used to automatically mine potential rules that characterize data consistency in a dataset and store these rules as part of immune memory. The violation tuple detection engine uses stored CFD rules to scan data in a forward direction, automatically detects and marks inconsistent records that violate the rules, and achieves secondary cleanup based on the inherent logic of the data; The Federated Evolutionary Network adopts a federated learning architecture, enabling the local engine to update its local model using global threat feature knowledge while ensuring that the original data does not leave the local machine. It also contributes the newly learned purification strategies to the global network, giving the system a re-response capability similar to biological immunity. That is, when the same or similar threats reappear, the response speed is faster and the accuracy is higher. When the model is aggregated, the Federated Evolutionary Network introduces a contribution-based dynamic weight allocation algorithm, which assigns higher model update weights to nodes that provide high-quality and scarce threat features, incentivizing effective sharing and accelerating the establishment of herd immunity.
[0015] Specifically, the distributed intelligent sensing agent includes a heterogeneous sensing fusion module, a collaborative decision-making and planning module, a distributed collaborative control module, and an immune memory and evolution module; The heterogeneous sensing fusion module is used to receive physical, chemical, biological, and audio-visual symbol data through multiple sensor interfaces, and perform filtering and normalization preprocessing. It uses a convolutional neural network to extract feature maps of the preprocessed data and adds a unique object identifier and object relationship identifier to each sensing object to achieve information traceability and association. Then, the feature maps from different sensors are fused at the feature level to generate a unified environmental state representation. The collaborative decision-making and planning module is used to generate action plans based on state estimation, internal objectives, and received neighbor information; The distributed collaborative control module is used to calculate and output local control commands based on the action plan and the status of neighboring intelligent agents. The immune memory and evolution module is used to store historical threat characteristics and purification rules, and exchanges model updates with other nodes in the network through federated learning to achieve the co-evolution of local and global detection and purification capabilities.
[0016] In a specific embodiment of the present invention, distributed intelligent sensing agents constitute the nerve endings of the system. Their design is inspired by the collaborative perception and swarming behavior of biological groups. The heterogeneous perception fusion module collects environmental data through multi-sensor interfaces, extracts features using CNN and performs cross-modal fusion, adds a unique identifier to each sensing object, realizes accurate traceability and association of information, and forms a unified environmental state representation. The collaborative decision-making and planning module drives each intelligent agent to perform distributed multi-objective Monte Carlo tree search based on the updated scene map and dual-objective reward map, generating Pareto optimal action plans. The distributed collaborative control module is based on the swarming control principle. By exchanging compressed state information among neighbors, it calculates control commands containing repulsive force, speed consistency and navigation terms, enabling the intelligent agent group to autonomously maintain formation, avoid collisions and move collaboratively towards the target area. The immune memory and evolution module ensures that each sensing agent can learn threat patterns locally and absorb global experience through federated evolution, realizing the synchronous evolution of individual and group detection capabilities.
[0017] Specifically, the collaborative decision-making and planning module includes a scene cognition and reward map unit and a distributed multi-objective optimization planning unit; The scene cognition and reward map unit is used to maintain a scene map based on prior knowledge and update two reward maps according to the agent's real-time observations: one is a Gaussian reward map based on the discovery of associated objects, which drives the agent to search for target-related areas; the other is a decaying reward map based on the degree of area exploration, which drives the agent to cover unknown areas. The distributed multi-objective optimization planning unit is used to employ the distributed multi-objective Monte Carlo tree search algorithm, with two reward maps as dual objectives, to perform parallel search and sampling in the action space, generating Pareto optimal or near-optimal action sequence planning; The update formula for the Gaussian reward map based on associated object discovery is: ,in This represents the coordinates of the navigation point to be evaluated on the map, in meters. This represents the coordinates of the observed associated object $j$, in meters. For intelligent agents The perceived uncertainty parameter, expressed in meters, decreases dynamically during the exploration process. Indicates navigation point The reward value obtained is a dimensionless scalar. This formula means that the closer the location is to a discovered associated object, the higher the reward value at that location.
[0018] The distributed collaborative control module includes a neighbor state awareness and communication unit and a distributed consistency control unit; The neighbor state awareness and communication unit is used to determine the neighbor set based on distance or field of view rules. It also exchanges compressed state information with its neighbors, among which For intelligent agents , The position vector, in meters. Maximum communication distance, in meters. To perceive the field of view, the unit is degrees; The distributed consensus control unit is used to calculate the control input that keeps the group of agents in formation, avoids collisions, and achieves consistent speed, based on the principle of congestion control. Its calculation formula is ,in This is a repulsive force term based on the potential energy function, used for collision prevention. It is an adjustable potential energy function. These are the position and velocity vectors, respectively. For speed consistency, For distance-based communication weights, For navigation, it drives the intelligent agent to move toward the target, and the unit of all forces is Newton.
[0019] In a specific embodiment of the present invention, the immune memory and evolution module includes a dynamic anomaly detection unit, an immune memory storage unit, and a federated evolution unit. The dynamic anomaly detection unit is used to perform real-time analysis of the input data stream using an improved clone selection algorithm, and to use the identified abnormal patterns or threat features as antigens. The immune memory storage unit is used to structure and store antigens, corresponding effective purification rules, and optimized detection model parameters as antibodies to form an immune memory library. The federated evolutionary unit is used periodically as a federated learning client to perform secure collaboration with other defense nodes in the network. It exchanges only the parameter updates of the detection model rather than the original data, enabling the local model to absorb global knowledge and achieve rapid adaptation to new data threats.
[0020] Specifically, the cognitive analysis and decision-making center includes a multimodal data perception and standardization module, a DIKWP-based semantic understanding and cognitive state management module, a dynamic knowledge graph and reasoning module, a multi-agent collaborative decision-making engine module, and a global interpretability and ethical constraint module. The multimodal data perception and standardization module is used to receive raw data from physical sensors, text reports, audio and video streams and databases through heterogeneous interfaces, and to clean, align and standardize the format, and output a structured data stream with a unified spatiotemporal reference. The semantic understanding and cognitive state management module based on DIKWP is used to map structured data streams to five semantic spaces: data (D), information (I), knowledge (K), wisdom (W), and intent (P), and to manage the semantic states of each layer and the network interaction relationships between them. The dynamic knowledge graph and reasoning module is used to store and update entities, attributes, and relationships extracted from the information layer I, forming a domain knowledge graph, and to perform logical reasoning and causal discovery based on the graph, supporting the construction of the knowledge layer K. The multi-agent collaborative decision engine module is used to generate a Pareto optimal or near-optimal decision scheme sequence through negotiation and optimization by multiple professional agents based on the problem definition of the W layer and the goal constraints of the P layer. The global interpretability and ethical constraints module is used to trace and explain the transformation process and decision-making reasoning chain of each semantic layer within the system, and to ensure that all decision-making behaviors comply with preset ethical rules and security boundaries.
[0021] In a specific embodiment of the present invention, the multi-agent collaborative decision-making engine module adopts a multi-objective optimization decision-making method based on semantic consensus, and its decision-making process is defined by the following optimization formula: ,in It is A 3D decision variable vector represents a candidate decision scheme. It is A vector of dimensional objective functions, each objective function... This corresponds to the semantic dimensions that an intelligent agent focuses on. These semantic dimensions include efficiency, cost, and fairness, with units varying depending on the objective, such as yuan, seconds, or percentages. The inequality and equality constraint functions are jointly defined by the domain rules in the dynamic knowledge graph and reasoning module and the ethical boundaries in the global interpretability and ethical constraint module. As the feasible region of the decision variables, the module solves the Pareto front of the problem through a distributed algorithm, and submits the front solution set to the intelligent W layer of the semantic understanding and cognitive state management module based on DIKWP for final trade-off selection.
[0022] Specifically, the semantic understanding and cognitive state management module based on DIKWP includes a semantic mapping unit, a mesh interaction management unit, and a cognitive evolution driving unit; The semantic mapping unit is used to parse the input structured data and label its DIKWP level using a locally deployed multimodal large language model as the basic semantic engine; The mesh interaction management unit is used to maintain a DIKWP state transition diagram, record and drive the bidirectional transformation between the five semantic states of data (D), information (I), knowledge (K), wisdom (W), and intention (P) in real time. The transformation includes top-down intention control and bottom-up perception accumulation. The cognitive evolution driving unit is used to calculate the semantic tension between adjacent or cross-layer semantic states. When the tension value exceeds a threshold, it triggers the system's active learning or knowledge update mechanism. Its driving criterion formula is as follows: ,in and This represents the current semantic state of any two layers in the DIKWP model. This represents a function that maps states to high-dimensional vectors. This indicates that the Euclidean distance between two vectors is dimensionless. The predefined inter-layer interaction weight coefficients are dimensionless and are used to adjust the sensitivity of different paths. The semantic tension value is dimensionless and is used to quantify the degree of cognitive inconsistency.
[0023] In a specific embodiment of the present invention, the global explainability and ethical constraint module includes a causal tracing engine, a fairness embedding unit, an ethical rule review unit, and a cognitive architecture meta-management module; The causal tracing engine, based on a structural causal model, performs counterfactual intervention and reasoning on the decision schemes output by the multi-agent collaborative decision-making engine module, generating a form of multiple variables. If it does not occur, then the result is... The probability will change Causal explanation statements; The fairness embedding unit introduces a group fairness regularization term into the optimization objective or constraints of the multi-agent collaborative decision-making engine module. This term is used to reduce discriminatory bias in decision outcomes towards different protected groups. Its regularization term takes the form of: ,in It represents a protected group. Indicates the impact of the decision-making scheme on the group The average output value, This represents the average output value across all groups. The fairness weight coefficient is dimensionless and is used to control the strength of fairness constraints. The penalty term is dimensionless; the smaller its value, the smaller the difference between groups. The ethics review unit has a built-in, updatable knowledge base of ethics rules. Before a decision is implemented, it simulates and assesses the potential social impact and safety risks of the decision and has the power to veto decisions that clearly violate the rules. The cognitive architecture meta-management module is used to enable the system's self-reflection and continuous evolution. It operates by maintaining a DIKWP semantic completeness model, which defines the complete set of semantic content that the system should have in an ideal state and compares it with the system's current actual semantic state. The cognitive architecture meta-management module calculates the semantic gap between the actual state and the ideal complete set, and dynamically adjusts the interaction weights in the mesh interaction management unit accordingly. It can either send an active data collection request to the multimodal data perception and standardization module, or trigger the knowledge update process of the dynamic knowledge graph and reasoning module, thereby driving the system to autonomously evolve towards a more semantically complete and cognitively more coordinated direction.
[0024] The semantic gap is calculated using a similarity metric method based on a vector space model, with the specific formula as follows: ,in This represents the semantic gap value at a certain DIKWP level. It is dimensionless and ranges from [0,1]. A larger value indicates a larger gap. This is an aggregated vector representation of all semantic states at this level. This is the semantic complete set vector representation of this level under the ideal complete model. This represents the vector dot product operation.
[0025] Specifically, the co-evolutionary network includes a semantic coordinator, a distributed local evolver, a cross-layer knowledge distillation module, a trusted contribution evaluation and incentive module, and a dynamic subpopulation reconstructor; The semantic coordinator is used to semantically deconstruct global optimization problems or cooperative tasks based on formal concept analysis (FCA), forming a formal background and concept lattice, and adaptively grouping nodes or variables participating in the coordination according to the concept lattice, generating and dynamically adjusting the cooperative evolution strategy. The distributed local evolver is deployed on each cooperating node to run an improved evolutionary algorithm for independent optimization within the groups divided by the semantic coordinator, based on local data and tasks. Improvements include the introduction of a crossover strategy based on historical success cases and a mutation strategy targeting resource bottlenecks. The cross-layer knowledge distillation module is used to extract and merge heterogeneous knowledge generated from different nodes and different evolutionary stages, refine it into transferable and lightweight knowledge essence, and distribute it securely in the network. The Trusted Contribution Assessment and Incentive Module is used to quantitatively assess and record the quality of knowledge provided by each node in the co-evolution process, the consumption of computing resources, and the final improvement of group benefits, based on smart contracts and cryptographic technology, and to allocate incentive points according to the assessment results. The dynamic subpopulation reconstructor is used to dynamically adjust the grouping strategy according to environmental changes during co-evolution. When continuous subpopulations are detected... If the optimal solution has not been updated, or if there is a significant shift in the network task objective, the decision variables under the current environment should be re-collected. With attributes Relational data, update format background And generate new concept lattices Furthermore, based on the new conceptual lattice, subpopulations are merged, split, or recombined to achieve online adaptive evolution of cooperative topology.
[0026] In a specific embodiment of the present invention, the cross-layer knowledge distillation module employs a modality-aware dual-track proxy distillation method, which includes two parallel lightweight proxy models: Local performance proxy: used to quickly evaluate the potential performance of new solutions generated by a single node's local evolver; its evaluation function is... ,in For nodes The resulting solution vector For feature extraction function, For nodes Weight vectors for modal characteristic adaptive training; Global Fusion Agent: Used to evaluate the expected performance of the joint solution generated after knowledge fusion from different nodes; its evaluation function is as follows. ,in An attention mechanism fusion network is used to model the interaction effects between cross-node solutions; This method significantly reduces the number of expensive evaluations of the full model by using a dual-track proxy, and only performs real evaluations on high-potential solutions evaluated by the proxy, thereby accelerating the co-evolution process.
[0027] Specifically, the semantic coordinator employs an adaptive grouping algorithm based on formal concept analysis, the core steps and formulas of which include: Constructing the formal context: Defining the collaborative optimization problem as the formal context. ,in It is a set of all decision variables. It is a set of all attributes that describe the characteristics of a variable. yes and A binary relation between variables represents a variable. Has attributes ; Generate concept lattices: for any Define its exported property set For any Define its exported object set A formal concept is the binary tuple. ,satisfy All formal concepts and their sub-concept-superconcept relationships constitute a concept lattice. ; Grouping based on concept lattice: grouping concept lattices Each concept in Mapped to a co-evolutionary subpopulation, where the object set The variables responsible for optimization for this subpopulation are grouped together. The attribute set $B$ describes the inherent coupling characteristics and optimization constraints of the variables in this group. The grouping principle satisfies the condition that the variables within the group are strongly coupled and the variables between the groups are weakly interacting.
[0028] In a specific embodiment of the present invention, the operation of the trusted contribution assessment and incentive module relies on a blockchain-based contribution pricing model, which calculates the node's contribution pricing through the following steps. Single-round contribution value : Quality assessment: Computation nodes Shared knowledge model updates Improvement in global model performance ,in is the performance metric on the public validation set, and is a dimensionless ratio; Scarcity assessment: Calculate the scarcity of this knowledge relative to the global knowledge base. ,in The cosine similarity function is used. It is a dimensionless scalar; Contribution pricing: Node Contribution value Calculated by the following formula: ,in , The weights are dimensionless to adjust for mass, scarcity, and energy consumption, respectively. The unit of measurement is joule. The function is used to normalize quality gains and contribution values. Recorded on the blockchain as a token, it is used for subsequent priority allocation of resources or exchange of rights.
[0029] Specifically, the active evolution layer includes an evolutionary strategy generator, a multimodal performance monitor, a memory and knowledge base, a retraining and optimization engine, and a safety and ethical constraint mechanism. The evolutionary strategy generator generates evolutionary strategy schemes, including exploration direction, mutation intensity, and component selection, based on the current task objective and environmental state. It employs a hybrid exploration algorithm based on safe envelope and knowledge guidance. Its core lies in defining a dynamic safe exploration interval for each decision variable to be optimized, and using historical knowledge to guide sampling within this interval. The algorithm's exploration action generation formula is as follows: ,in In time step The generated exploration action vectors, the units of which depend on the specific variables, such as degrees, Newtons, or percentages. This is a knowledge-guided cross function, whose input is the current system state. and memory bank The elite strategy in the text outputs a recommended action based on historical success. This indicates that the mean is 0 and the variance is 0. Gaussian random noise, with units identical to the action, is used to ensure diversity in exploration. The weights for knowledge utilization are dimensionless and dynamically adjusted according to the evolutionary stage, starting small to encourage exploration and increasing later to accelerate convergence. For truncation functions, the final action is restricted to a range defined by a lower bound. and upper limit Within the defined safe motion envelope, which is provided by the safety and ethics constraint in real time; The multimodal performance monitor is used to collect task execution results in real time and generate quantitative performance scores and qualitative improvement feedback through multiple evaluation methods such as rule validator, reference model comparison and LLM judge; Memory and knowledge bases are used to persistently store historical evolution strategies, corresponding performance results, and structured knowledge rules extracted from success cases; The retraining and optimization engine connects the evolutionary strategy generator, the multimodal performance monitor, and the memory and knowledge base. When performance is not up to standard, it updates the internal components of the host system based on feedback information. The update objects include, but are not limited to, prompt word templates, model fine-tuning parameters, tool call logic, and workflow topology. Safety and ethical constraints, embedded in and applied to all the above modules, are used to define safety boundaries for the exploration space of evolutionary strategies and to conduct compliance reviews of optimized new strategies to prevent harmful or illegal behaviors from arising during the evolutionary process.
[0030] In a specific embodiment of the present invention, a knowledge-guided cross function The specific operations based on critical path knowledge transfer steps include: From memory bank Retrieve from the current state Most similar A historical elite's strategy solution; Analyze the critical paths to success of these elite solutions, and identify the decision sequences or parameter combinations that contribute the most to the final performance; With probability Copy the core decision units or parameter values from the critical path into the newly generated strategy draft, probabilistically. Dynamically adjusted by feedback mechanism ,in For the current generation, For the total algebra, For continuous unimproved algebra, For the preset threshold, The initial coefficients are dimensionless. This mechanism can enhance randomness in the early stages of evolution and when it stagnates, and enhance knowledge utilization during the convergence period. The retraining and optimization engine employs a hierarchical collaborative optimization framework, decomposing the optimization problem of the host system into three levels and using different optimizers to handle them collaboratively: Level 1 component-level optimization: For a single agent or model, use an evolutionary policy generator to optimize its prompt and internal parameters. The optimization process is represented as ,in For component optimizer, Evaluation feedback from the multimodal performance monitor; Level 2 Collaborative Optimization: Optimizing the topology of multi-agent workflows. Interaction protocols between nodes are implemented by adding, deleting, or reorganizing nodes in the workflow graph. With edge To improve the efficiency of task breakdown and collaboration; Level 3 memory-level optimization: Optimize the storage, retrieval, and forgetting strategies of memory and knowledge base to ensure that the evolutionary process can effectively utilize long-term experience while avoiding knowledge overload or conflict; Each optimizer runs in parallel and is coordinated through shared performance signals, ultimately outputting a consistent, globally improved new system configuration.
[0031] Specifically, the evolutionary strategy generator employs a hybrid exploration algorithm based on safe envelope and knowledge guidance. Its core lies in defining a dynamic safe exploration interval for each decision variable to be optimized, and using historical knowledge to guide sampling within this interval. The algorithm's exploration action generation formula is as follows: ,in In time step The generated exploration action vectors, the units of which depend on the specific variables, such as degrees, Newtons, or percentages. This is a knowledge-guided cross function, whose input is the current system state. and memory bank The elite strategy in the text outputs a recommended action based on historical success. This indicates that the mean is 0 and the variance is 0. Gaussian random noise, with units identical to the action, is used to ensure diversity in exploration. The weights for knowledge utilization are dimensionless and dynamically adjusted according to the evolutionary stage, starting small to encourage exploration and increasing later to accelerate convergence. For truncation functions, the final action is restricted to a range defined by a lower bound. and upper limit Within the defined safe motion envelope, which is provided by the safety and ethics constraint in real time.
[0032] In a specific embodiment of the present invention, the safety and ethics constraint defines the safety boundary by constructing a formal safety verification module. This module encodes safety rules as logical or dynamic constraints. For robots and autonomous vehicles, the safety envelope is generated by solving the optimization control problem (OCP) that includes a vehicle dynamics model. The constraints include... ,in The minimum lateral distance that must be maintained is measured in meters. The smallest unit of longitudinal time interval is the second. The system's current speed is expressed in meters per second. These are parameters related to the physical characteristics of the system, with units of seconds, meters, dimensionless units, and seconds, respectively. For information systems, constraints are manifested as data access permissions, operation whitelists, and outcome fairness indicators.
[0033] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and its improved concept, should be covered within the scope of protection of the present invention.
Claims
1. A network information security defense system based on artificial intelligence, characterized in that, include: Data immunity and purification engine, distributed intelligent sensing agent, cognitive analysis and decision-making center, co-evolutionary network and active evolution layer; The data immunity and purification engine is used to clean, desensitize, and make trusted multi-source heterogeneous security data input into the system in real time, so as to eliminate data poisoning attacks and ensure data quality. The distributed intelligent sensing agent is deployed at the network edge and terminal, and is used to perform real-time monitoring and preliminary threat response to local behavior based on a lightweight artificial intelligence model. The cognitive analysis and decision-making center is based on a cloud-based artificial intelligence model to perform in-depth analysis of purified data, enabling the identification of unknown threats, tracing of attack chains, and generation of automated response decisions. The co-evolutionary network is used to achieve trusted sharing and co-evolution of threat intelligence, defense strategies, and model knowledge while protecting the data privacy of all participants. The active evolution layer is used to automatically generate variants using newly emerging threat samples for adversarial training, and to memorize successful defense cases, enabling the system as a whole to have the ability to learn autonomously and evolve iteratively.
2. The network information security defense system based on artificial intelligence according to claim 1, characterized in that, The data immunity and purification engine includes a heterogeneous data perception and fusion layer, an intelligent purification decision and execution layer, and an immune memory and evolution layer. The heterogeneous data perception and fusion layer is used to collect and fuse multi-source heterogeneous data from network traffic, terminal behavior logs, asset configuration information and external threat intelligence in real time to form a unified and trusted data view. The intelligent purification decision and execution layer is used to implement a three-level progressive purification process on the fused data, including primary filtering based on rules and strategies, adversarial deep purification based on a self-iterative multi-instance learning model, and anomaly detection and removal based on an artificial immune clonal selection algorithm. The adversarial deep purification based on a self-iterative multi-instance learning model in the intelligent purification decision and execution layer is used to process weakly labeled data with multiple alleles. When it is known that there are malicious samples in a batch of data but the specific attribution is unknown, the original fuzzy multi-allele data is peeled off layer by layer through a self-iterative learning method, and the accurate malicious data features are identified from the mixed samples. The immune memory and evolution layer is used to store the data threat features identified during the purification process as immune memory. Based on the federated learning framework, it co-evolves the purification model and strategy with other defense nodes in the network to form herd immunity while protecting data privacy.
3. The network information security defense system based on artificial intelligence according to claim 1, characterized in that, The distributed intelligent sensing agent includes a heterogeneous sensing fusion module, a collaborative decision-making and planning module, a distributed collaborative control module, and an immune memory and evolution module; The heterogeneous sensing fusion module is used to receive physical quantity, chemical quantity, biological quantity and audio and video symbol data through multiple sensor interfaces, and perform filtering and normalization preprocessing. It uses a convolutional neural network to extract feature maps of the preprocessed data, and adds a unique object identifier and object relationship identifier to each sensing object to realize information traceability and association. Then, the feature maps from different sensors are fused at the feature level to generate a unified environmental state representation. The collaborative decision-making and planning module is used to generate action plans based on the state estimation, internal objectives, and received neighbor information; The distributed collaborative control module is used to calculate and output local control commands based on the action plan and the state of neighboring intelligent agents. The immune memory and evolution module is used to store historical threat characteristics and purification rules, and to exchange model updates with other nodes in the network through federated learning, thereby achieving the co-evolution of local and global detection and purification capabilities.
4. The network information security defense system based on artificial intelligence according to claim 3, characterized in that, The collaborative decision-making and planning module includes a scene cognition and reward map unit and a distributed multi-objective optimization planning unit; The scene cognition and reward map unit is used to maintain a scene map based on prior knowledge and update two reward maps according to the real-time observation of the agent: one is a Gaussian reward map based on the discovery of associated objects, which drives the agent to search for target-related areas; the other is a decaying reward map based on the degree of area exploration, which drives the agent to cover unknown areas. The distributed multi-objective optimization planning unit is used to employ the distributed multi-objective Monte Carlo tree search algorithm, with the two reward maps as dual objectives, to perform parallel search and sampling in the action space, generating Pareto optimal or near-optimal action sequence planning. The update formula for the Gaussian reward map based on associated object discovery is as follows: ,in This represents the coordinates of the navigation point to be evaluated on the map, in meters. This represents the coordinates of the observed associated object j, in meters. For intelligent agents The perceived uncertainty parameter, expressed in meters, decreases dynamically during the exploration process. Indicates navigation point The reward value obtained is a dimensionless scalar. This formula means that the closer the location is to a discovered associated object, the higher the reward value at that location. The distributed collaborative control module includes a neighbor state awareness and communication unit and a distributed consistency control unit; The neighbor state perception and communication unit is used to determine the neighbor set based on distance or field of view rules. It also exchanges compressed state information with its neighbors, among which For intelligent agents The position vector, in meters. Maximum communication distance, in meters; FOV, the field of view, in degrees. The distributed consensus control unit is used to calculate the control input that keeps the agent group in formation, avoids collisions, and achieves consistent speed, based on the principle of swarm control. Its calculation formula is ,in This is a repulsive force term based on the potential energy function, used for collision prevention. It is an adjustable potential energy function. These are the position and velocity vectors, respectively. For speed consistency, For distance-based communication weights, For navigation, it drives the intelligent agent to move toward the target, and the unit of all forces is Newton.
5. A network information security defense system based on artificial intelligence according to claim 1, characterized in that, The cognitive analysis and decision-making center includes a multimodal data perception and standardization module, a DIKWP-based semantic understanding and cognitive state management module, a dynamic knowledge graph and reasoning module, a multi-agent collaborative decision-making engine module, and a global interpretability and ethical constraint module. The multimodal data perception and standardization module is used to receive raw data from physical sensors, text reports, audio and video streams and databases through heterogeneous interfaces, and to clean, align and standardize the format, and output a structured data stream with a unified spatiotemporal reference. The DIKWP-based semantic understanding and cognitive state management module is used to map structured data streams to five semantic spaces: data (D), information (I), knowledge (K), wisdom (W), and intent (P), and to manage the semantic states of each layer and the network interaction relationships between them. The dynamic knowledge graph and reasoning module is used to store and update entities, attributes, and relationships extracted from the information layer I, forming a domain knowledge graph, and to perform logical reasoning and causal discovery based on the graph, supporting the construction of the knowledge layer K. The multi-agent collaborative decision engine module is used to generate a Pareto optimal or near-optimal decision scheme sequence based on the problem definition of the W layer and the target constraints of the P layer of intent through negotiation and optimization of multiple professional agents. The global interpretability and ethical constraints module is used to trace and explain the transformation process and decision-making reasoning chain of each semantic layer within the system, and to ensure that all decision-making behaviors comply with preset ethical rules and security boundaries.
6. The network information security defense system based on artificial intelligence according to claim 5, characterized in that, The DIKWP-based semantic understanding and cognitive state management module includes a semantic mapping unit, a mesh interaction management unit, and a cognitive evolution driving unit. The semantic mapping unit is used to parse the input structured data and label its DIKWP level using a locally deployed multimodal large language model as the basic semantic engine. The mesh interaction management unit is used to maintain a DIKWP state transition diagram, record and drive the bidirectional transformation between the five semantic states of data D, information I, knowledge K, wisdom W, and intention P in real time. The transformation includes top-down intention control and bottom-up perception accumulation. The cognitive evolution driving unit is used to calculate the semantic tension between adjacent or cross-layer semantic states. When the tension value exceeds a threshold, it triggers the system's active learning or knowledge update mechanism. Its driving criterion formula is as follows: ,in and This represents the current semantic state of any two layers in the DIKWP model. This represents a function that maps states to high-dimensional vectors. This indicates that the Euclidean distance between two vectors is dimensionless. The predefined inter-layer interaction weight coefficients are dimensionless and are used to adjust the sensitivity of different paths. The semantic tension value is dimensionless and is used to quantify the degree of cognitive inconsistency.
7. A network information security defense system based on artificial intelligence according to claim 1, characterized in that, The co-evolutionary network includes a semantic coordinator, a distributed local evolver, a cross-layer knowledge distillation module, a trustworthy contribution evaluation and incentive module, and a dynamic subpopulation reconstructor. The semantic coordinator is used to semantically deconstruct global optimization problems or cooperative tasks based on formal concept analysis (FCA), forming a formal background and concept lattice, and adaptively grouping nodes or variables participating in the coordination according to the concept lattice, generating and dynamically adjusting the cooperative evolution strategy. The distributed local evolver is deployed on each cooperating node and is used to run an improved evolutionary algorithm for independent optimization within the groups divided by the semantic coordinator, based on local data and tasks. The improvements include the introduction of a crossover strategy based on historical success cases and a mutation strategy targeting resource bottlenecks. The cross-layer knowledge distillation module is used to extract and merge heterogeneous knowledge generated by different nodes and different evolutionary stages, refine it into transferable and lightweight knowledge essence, and distribute it securely in the network. The trusted contribution evaluation and incentive module is used to quantitatively evaluate and record the knowledge quality, computing resource consumption and final group benefit improvement of each node in the co-evolution process based on smart contracts and cryptography, and to allocate incentive points according to the evaluation results. The dynamic subpopulation reconstructor is used to dynamically adjust the grouping strategy according to environmental changes during co-evolution. When continuous subpopulations are detected... If the optimal solution has not been updated, or if there is a significant shift in the network task objective, the decision variables under the current environment should be re-collected. With attributes Relational data, update format background And generate new concept lattices Furthermore, based on the new conceptual lattice, subpopulations are merged, split, or recombined to achieve online adaptive evolution of cooperative topology.
8. A network information security defense system based on artificial intelligence according to claim 7, characterized in that, The semantic coordinator employs an adaptive grouping algorithm based on formal concept analysis, the core steps and formulas of which include: Constructing the formal context: Defining the collaborative optimization problem as the formal context. ,in It is a set of all decision variables. It is a set of all attributes that describe the characteristics of a variable. yes and A binary relation between variables represents a variable. Has attributes ; Generate concept lattices: for any Define its exported property set For any Define its exported object set A formal concept is the binary tuple. ,satisfy and All formal concepts and their sub-concept-superconcept relationships constitute a concept lattice. ; Grouping based on concept lattice: grouping concept lattices Each concept in The mapping is represented as a co-evolutionary subpopulation, where the object set A is the variable grouping responsible for optimization in this subpopulation, and the attribute set B describes the inherent coupling characteristics and optimization constraints of the variables in this group. The grouping principle satisfies the strong coupling of variables within the group and the weak interaction between variables between groups.
9. A network information security defense system based on artificial intelligence according to claim 1, characterized in that, The active evolution layer includes an evolutionary strategy generator, a multimodal performance monitor, a memory and knowledge base, a retraining and optimization engine, and a safety and ethical constraint mechanism. The evolution strategy generator is used to generate an evolution strategy scheme that includes exploration direction, mutation intensity, and component selection based on the current task objective and environmental state. The multimodal performance monitor is used to collect task execution results in real time and generate quantitative performance scores and qualitative improvement feedback through multiple evaluation methods such as rule validator, reference model comparison and LLM judge. The memory and knowledge base are used to persistently store historical evolution strategies, corresponding performance results, and structured knowledge rules extracted from successful cases. The retraining and optimization engine connects the evolutionary strategy generator, the multimodal performance monitor, and the memory and knowledge base. When the performance is not up to standard, it updates the internal components of the host system based on the feedback information. The update objects include, but are not limited to, prompt word templates, model fine-tuning parameters, tool call logic, and workflow topology. The aforementioned safety and ethical constraints are embedded in and act on all the modules mentioned above. They are used to define safety boundaries for the exploration space of evolutionary strategies and to conduct compliance reviews of optimized new strategies to prevent harmful or illegal behaviors from occurring during the evolutionary process.
10. A network information security defense system based on artificial intelligence according to claim 9, characterized in that, The evolutionary strategy generator employs a hybrid exploration algorithm based on safe envelope and knowledge guidance. Its core lies in defining a dynamic safe exploration interval for each decision variable to be optimized, and using historical knowledge to guide sampling within this interval. The algorithm's exploration action generation formula is as follows: ,in In time step The generated exploration action vectors, the units of which depend on the specific variables, such as degrees, Newtons, or percentages. This is a knowledge-guided cross function, whose input is the current system state. and memory bank The elite strategy in the text outputs a recommended action based on historical success. This indicates that the mean is 0 and the variance is 0. Gaussian random noise, with units identical to the action, is used to ensure diversity in exploration. The weights for knowledge utilization are dimensionless and dynamically adjusted according to the evolutionary stage, starting small to encourage exploration and increasing later to accelerate convergence. For truncation functions, the final action is restricted to a range defined by a lower bound. and upper limit Within the defined safe motion envelope, which is provided by the safety and ethics constraint in real time; The safety and ethical constraint mechanism defines the safety boundary by constructing a formal safety verification module. This module encodes safety rules as logical or dynamic constraints. For robots and autonomous vehicles, the safety envelope is generated by solving the optimization control problem (OCP) that includes a vehicle dynamics model. The constraints include... ,in The minimum lateral distance that must be maintained is measured in meters. The smallest unit of longitudinal time interval is the second. The system's current speed is expressed in meters per second. These are parameters related to the physical characteristics of the system, with units of seconds, meters, dimensionless units, and seconds, respectively. For information systems, constraints are manifested as data access permissions, operation whitelists, and outcome fairness indicators.