Intelligent detection method, device and equipment based on AI dynamic probe, and medium
Patent Information
- Application Number
- CN202610919357.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-24
- Publication Date
- 2026-09-25
AI Technical Summary
[0005]本发明的主要目的在于提供一种基于AI动态探针的智能侦测方法、装置、设备及存储介质,旨在解决现有信创化检测方式静态、滞后、粗放,无法对系统运行时状态进行多维度、量化评估的技术问题
[0010]有益效果:本发明涉及人工智能技术领域,公开了一种基于AI动态探针的智能侦测方法、装置、设备及介质,包括:根据监测任务匹配采集模块和推理模块,将所述采集模块和推理模块组装成AI动态探针,并将所述AI动态探针植入目标组件;由所述AI动态探针根据监测任务实时捕获目标组件的多源运行数据,对所述多源运行数据进行预处理,生成多源异构监测数据;通过自适应特征提取框架根据所述多源异构监测数据的组件类型标签识别关键信创特征;基于所述关键信创特征构建标准化特征向量;采用长短期记忆网络,并结合图神经网络对所述多源异构监测数据、关键信创特征和标准化特征向量进行融合分析,输出四维信创指数。本发明可应用于金融科技和医疗健康等业务场景中,通过动态组装与植入AI探针实时采集多源数据,结合自适应特征提取与深度学习融合分析,实现信创化程度的智能量化评估。
Smart Images

Figure CN122817050A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of artificial intelligence technology, and in particular to an intelligent detection method, apparatus, device, and medium based on an AI dynamic probe. Background Technology
[0002] Domestic IT innovation testing platforms are key infrastructure for the national IT innovation strategy. They are responsible for conducting compatibility testing, quality assessment, and authoritative certification of software and hardware systems built on the full stack of domestically developed chips, operating systems, databases, middleware, and applications. This provides quality assurance and access criteria for domestic substitution in key industries such as finance and energy. However, the core shortcomings of existing domestic IT innovation testing platforms are mainly manifested in their static nature, lag, and extensiveness. On the one hand, these platforms generally rely on pre-built static rule bases and manually configured strategies, failing to dynamically adapt to the rapid iteration and complex combinations of the IT innovation ecosystem, including chips, operating systems, databases, middleware, and applications. This results in poor timeliness and incomplete coverage of test results. On the other hand, they lack deep perception capabilities regarding the dynamic behavior of the system during operation, the real interaction relationships between components, and key operational characteristics such as performance and stability, resulting in a single testing dimension. Furthermore, the testing process has a low degree of automation and intelligence, heavily relying on human experience, leading to low efficiency and a high risk of errors. The test results often only provide a binary judgment of "compliant / non-compliant" or a simple count, lacking multi-dimensional, quantitative, traceable, and in-depth analysis and visualization assessment of the degree of information technology innovation, such as the depth of component replacement, the degree of technology stack integration, the degree of performance matching, and potential risk points. Ultimately, its static, lagging, and extensive nature constitutes its core defects, ultimately leading to its inability to meet the needs of precise, intelligent, and dynamic information technology innovation construction and continuous governance.
[0003] In the fintech field, the update speed of static rule bases lags far behind the iteration speed of domestic IT innovation products. For example, a typical bank core system may require over 2,000 combinations of domestic CPUs, operating systems, and databases to be compatible. Static rule bases, which rely on manual maintenance, simply cannot exhaustively enumerate and update such complex heterogeneous environments in a timely manner, leading to a large number of potential compatibility issues going undetected in advance. Secondly, there is a lack of deep understanding of runtime dynamic behavior. Financial businesses have extremely high requirements for millisecond or even microsecond-level stability in high-concurrency transactions. Current detection methods rely on traditional APM instrumentation solutions, which have uncontrollable performance overhead and are often not enabled in production environments. This completely masks performance bottlenecks and compatibility risks during actual operation, only to expose them explosively after the system goes live. Thirdly, the automation level of detection is insufficient, and the results are crude and simplistic. Performance testing typically only selects a limited number of transactions for single-transaction or mixed-transaction stress testing, resulting in severely insufficient transaction coverage and concurrency scenario coverage. This leads to frequent exposure of the system's insufficient stress resistance after deployment. There is a fundamental contradiction between financial institutions' rigid demand for "uninterrupted business operations and zero tolerance for risk" and the extensive nature of existing testing methods, and there is an urgent need for a new testing paradigm with dynamic perception and accurate assessment capabilities.
[0004] In the healthcare field, medical information systems have long been developed based on the Windows + Intel architecture. Hospitals have numerous business systems with diverse architectures and different programming languages. The static rule bases relied upon by existing testing platforms are simply unable to cover such complex technology stack migration scenarios, leading to numerous compatibility issues. More importantly, the testing process severely lacks deep awareness of runtime dynamic behavior—the response time of the electronic medical record system surged from 1.2 seconds to 8.7 seconds after migration; the LIS system experienced a 45-minute delay in emergency reports due to lock waiting in a real high-concurrency write scenario with laboratory instruments. Such performance degradation only becomes apparent under real business loads, and existing static testing methods cannot detect or warn of it in advance. The flaw of crude and simplistic testing results is equally severe in the medical field. Standardized SQL scripts and simulated data tests often "pass all tests, but encounter performance fluctuations immediately after deployment." Traditional comparison and verification cannot identify subtle misalignments at the temporal semantic level. For example, after a hospital's HIS system migration, pharmacy and nursing records showed a 3-5 second timestamp discrepancy, leading to the failure of clinical pathway closed-loop auditing. The industry has even seen a situation where "people dare not, are unwilling, and do not know how to replace" the existing testing system. Ultimately, this is because the existing testing system is too crude to provide a reliable guarantee for the safety and continuity of medical services. There is an urgent need for an intelligent assessment solution that can deeply perceive operational behavior and accurately quantify the degree of information technology innovation. Summary of the Invention
[0005] The main objective of this invention is to provide an intelligent detection method, device, equipment, and storage medium based on AI dynamic probes, aiming to solve the technical problems of existing information technology innovation detection methods being static, lagging, and crude, and unable to perform multi-dimensional and quantitative evaluation of the system's runtime status.
[0006] To achieve the above objectives, the present invention provides an intelligent detection method based on an AI dynamic probe, comprising: According to the monitoring task, the acquisition module and the inference module are matched, the acquisition module and the inference module are assembled into an AI dynamic probe, and the AI dynamic probe is implanted into the target component; The AI dynamic probe captures multi-source operational data of the target component in real time according to the monitoring task, and preprocesses the multi-source operational data to generate multi-source heterogeneous monitoring data. Key information technology innovation features are identified based on the component type labels of the multi-source heterogeneous monitoring data using an adaptive feature extraction framework. Construct standardized feature vectors based on the aforementioned key information technology innovation features; A long short-term memory network is used, combined with a graph neural network, to perform fusion analysis on the multi-source heterogeneous monitoring data, key information technology innovation features, and standardized feature vectors, and output a four-dimensional information technology innovation index.
[0007] Furthermore, to achieve the above objectives, the present invention provides an intelligent detection device based on an AI dynamic probe, comprising: The probe implantation module is used to match the acquisition module and the inference module according to the monitoring task, assemble the acquisition module and the inference module into an AI dynamic probe, and implant the AI dynamic probe into the target component; The data processing module is used to capture multi-source operational data of the target component in real time according to the monitoring task by the AI dynamic probe, preprocess the multi-source operational data, and generate multi-source heterogeneous monitoring data. The feature recognition module is used to identify key information technology innovation features based on the component type labels of the multi-source heterogeneous monitoring data through an adaptive feature extraction framework; A vector construction module is used to construct standardized feature vectors based on the key information technology innovation features; The detection output module is used to perform fusion analysis on the multi-source heterogeneous monitoring data, key information technology innovation features and standardized feature vectors by using a long short-term memory network and combining it with a graph neural network, and output a four-dimensional information technology innovation index.
[0008] Furthermore, to achieve the above objectives, the present invention also provides a computer device, the computer device including a memory, a processor, and an AI dynamic probe-based intelligent detection program stored in the memory and executable on the processor, wherein the AI dynamic probe-based intelligent detection program, when executed by the processor, implements the steps of the AI dynamic probe-based intelligent detection method as described above.
[0009] Furthermore, to achieve the above objectives, the present invention also provides a computer-readable storage medium storing an AI-based dynamic probe-based intelligent detection program, which, when executed by a processor, implements the steps of the AI-based dynamic probe-based intelligent detection method as described above.
[0010] Beneficial Effects: This invention relates to the field of artificial intelligence technology and discloses an intelligent detection method, device, equipment, and medium based on AI dynamic probes. The method includes: matching a data acquisition module and an inference module according to a monitoring task; assembling the data acquisition module and the inference module into an AI dynamic probe; and embedding the AI dynamic probe into a target component. The AI dynamic probe captures multi-source operational data of the target component in real time according to the monitoring task, preprocesses the multi-source operational data to generate multi-source heterogeneous monitoring data, and identifies key information technology innovation features based on the component type labels of the multi-source heterogeneous monitoring data using an adaptive feature extraction framework. A standardized feature vector is constructed based on the key information technology innovation features. A long short-term memory network, combined with a graph neural network, is used to perform fusion analysis on the multi-source heterogeneous monitoring data, key information technology innovation features, and standardized feature vectors to output a four-dimensional information technology innovation index. This invention can be applied to business scenarios such as fintech and healthcare. By dynamically assembling and embedding AI probes to collect multi-source data in real time, and combining adaptive feature extraction with deep learning fusion analysis, an intelligent quantitative assessment of the degree of information technology innovation can be achieved. Attached Figure Description
[0011] The present invention will be further described below with reference to the accompanying drawings and embodiments. In the accompanying drawings: Figure 1 This is a schematic diagram of an application environment for an intelligent detection method based on an AI dynamic probe according to an embodiment of the present invention; Figure 2 This is a flowchart illustrating an embodiment of the intelligent detection method based on AI dynamic probes according to the present invention. Figure 3 This is a schematic diagram of the functional modules of a preferred embodiment of the intelligent detection device based on AI dynamic probe of the present invention; Figure 4 This is a schematic diagram of the structure of a computer device according to an embodiment of the present invention; Figure 5 This is another structural schematic diagram of a computer device according to one embodiment of the present invention. Detailed Implementation
[0012] It should be understood that the specific embodiments described herein are for illustrative purposes only and are not intended to limit the scope of the invention.
[0013] The intelligent detection method based on AI dynamic probes provided in this invention can be applied to, for example... Figure 1 In this application environment, the client communicates with the server via a network. The server can use the client to match the acquisition module and inference module according to the monitoring task, assemble the acquisition module and inference module into an AI dynamic probe, and implant the AI dynamic probe into the target component. The AI dynamic probe captures multi-source operational data of the target component in real time according to the monitoring task, preprocesses the multi-source operational data to generate multi-source heterogeneous monitoring data, and identifies key information technology innovation features based on the component type labels of the multi-source heterogeneous monitoring data using an adaptive feature extraction framework. A standardized feature vector is constructed based on the key information technology innovation features. A long short-term memory network, combined with a graph neural network, is used to perform fusion analysis on the multi-source heterogeneous monitoring data, key information technology innovation features, and standardized feature vectors, outputting a four-dimensional information technology innovation index. This invention can be applied to business scenarios such as fintech and healthcare, achieving intelligent quantitative assessment of the degree of information technology innovation through the dynamic assembly and implantation of AI probes to collect multi-source data in real time, combined with adaptive feature extraction and deep learning fusion analysis. The client can be, but is not limited to, various personal computers, laptops, smartphones, tablets, and portable wearable devices. The server can be implemented using a standalone server or a server cluster composed of multiple servers. The present invention will now be described in detail through specific embodiments.
[0014] Please see Figure 2 , Figure 2 This is a flowchart illustrating an embodiment of the AI-based dynamic probe-based intelligent detection method provided by the present invention. It should be noted that although the logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than that shown here.
[0015] like Figure 2 As shown, the intelligent detection method based on AI dynamic probe proposed in this invention includes the following steps: S100. Match the acquisition module and the inference module according to the monitoring task, assemble the acquisition module and the inference module into an AI dynamic probe, and implant the AI dynamic probe into the target component; S200: The AI dynamic probe captures multi-source operating data of the target component in real time according to the monitoring task, preprocesses the multi-source operating data, and generates multi-source heterogeneous monitoring data. S300. Identify key information technology innovation features based on the component type labels of the multi-source heterogeneous monitoring data using an adaptive feature extraction framework; S400. Construct a standardized feature vector based on the key information technology innovation features; S500 employs a long short-term memory network and combines it with a graph neural network to perform fusion analysis on the multi-source heterogeneous monitoring data, key information technology innovation features, and standardized feature vectors, and outputs a four-dimensional information technology innovation index.
[0016] In this embodiment, based on the specific requirements of the monitoring task, the system first matches the corresponding acquisition module and inference module. The acquisition module may include a log parser, an application programming interface hook (API hook), etc., while the inference module is a lightweight artificial intelligence model with a size of less than 5 megabytes. These modules are automatically assembled through a modular container generator to form an artificial intelligence dynamic probe, which is then implanted into the target component according to its type (such as a central processing unit, operating system, database, middleware, or application). After implantation, the probe captures multi-source runtime data of the target component in real time through core channels such as deep hooking system calls, application programming interfaces, log streams, and performance counters. This data includes instruction set compatibility, kernel scheduling behavior, cross-component communication protocols, latency, throughput, error rate, and security logs. Subsequently, the probe preprocesses the raw data, including cleaning, alignment, and formatting, to generate multi-source heterogeneous monitoring data, laying the foundation for subsequent analysis.
[0017] Next, the system activates an adaptive feature extraction framework. This framework automatically identifies key features related to information technology innovation (IT innovation) based on the component type labels attached to the data (e.g., domestically produced central processing units or distributed databases), such as instruction extension support rate, frequency of calls to national cryptographic algorithms, or dependence on domestic middleware, thus eliminating reliance on static rule bases. Based on these key IT innovation features, the system further constructs standardized feature vectors to ensure that data from different sources and structures can be represented uniformly.
[0018] Finally, the system employs an ensemble learning model combining Long Short-Term Memory (LSTM) networks and Graph Neural Networks (GNNs) to perform deep fusion analysis on multi-source heterogeneous monitoring data, key information technology innovation (ITI) features, and standardized feature vectors. LSTM networks excel at processing time-series data and capturing the dynamic evolution of component operating states; GNNs can model complex interactions between components, such as call chains and data flows. Through this model, the system outputs a four-dimensional ITI index, specifically including: component replacement depth (measuring the functional coverage and call weight of domestic components in the core link), technology stack integration compatibility (assessing the smoothness of collaboration between domestic and non-domestic components), performance degradation ratio (comparing the performance degradation before and after replacement), and risk exposure coefficient (identifying potential compatibility, stability, or security risks). This quantitative result can intuitively reflect the degree of ITI and guide subsequent optimization and governance.
[0019] This embodiment monitors task matching and assembles AI dynamic probes, which are then implanted into target components to capture multi-source operational data in real time. After preprocessing, adaptive feature extraction and standardization, combined with the fusion analysis of Long Short-Term Memory Network (LSTM) and Graph Neural Network (GNN), a four-dimensional information technology innovation index is output. This achieves a leap from static judgment to real-time quantification of information technology innovation level, and from human experience to AI intelligent diagnosis, significantly improving detection accuracy and efficiency.
[0020] In the fintech sector, this technology can be used to monitor the degree of domestic substitution of core banking transaction systems, payment gateways, and blockchain nodes. By dynamically capturing transaction processing latency, frequency of national cryptographic algorithm calls, and cross-service call chain data in real time, it can quantitatively assess the depth of component substitution and performance degradation, accurately pinpointing bottlenecks. This helps financial institutions meet compliance requirements, ensure system stability in high-concurrency scenarios, and drive the development of domestic IT infrastructure from passive compliance to proactive governance.
[0021] In the healthcare sector, it can be applied to the detection of domestically developed IT applications in hospital information systems, electronic medical record platforms, and medical image processing systems. Dynamic probes collect real-time data on patient access logs, treatment service response latency, and cross-system interface compatibility, outputting a substitution depth and integration compatibility index. This helps medical institutions assess the reliability of domestically produced software and hardware in key treatment processes, identify data consistency risks, and ensure the quality of medical services and patient information security under the domestically developed IT environment.
[0022] In one embodiment, S100 includes: S101. A module probe template library is pre-created, which stores acquisition modules and inference modules; S102. Analyze the monitoring task to obtain the target component and component type; S103. The AI probe generator retrieves the matching acquisition module and inference module from the module probe template library according to the component type. S104. Assemble the acquisition module and the inference module into an AI dynamic probe, and implant the AI dynamic probe into the target component.
[0023] In this embodiment, a module probe template library needs to be established before the system runs. This library stores two core types of modules: acquisition modules and inference modules. The acquisition module includes sub-modules for different data sources and acquisition methods, such as a log parser (for reading and analyzing system log files) and an application programming interface hook (API hook, used to intercept and record interface calls provided by the component). The inference module is a lightweight artificial intelligence model, typically less than 5 megabytes in size, capable of real-time data analysis and feature extraction within the target component. These modules are categorized and organized according to the type of the target component (such as a CPU, operating system, database, middleware, or application software) for rapid matching later.
[0024] When a task to detect the level of domestic IT innovation needs to be executed, the system first parses the monitoring task. The parsing process includes identifying the target component specified in the task (such as a domestic database instance or middleware service) and the specific type of the component. Through parsing, the system obtains the component type label, which is the key basis for subsequently selecting the appropriate module.
[0025] Next, the system's AI probe generator extracts matching collection and inference modules from the module probe template library based on the parsed component type. For example, if the target component is a database, it extracts a collection module for database logs (such as a database transaction log parser) and a lightweight inference model for database performance characteristics; if the target component is an operating system kernel, it extracts a system call hook module and a kernel behavior analysis model. During the extraction process, the AI probe generator also injects a real-time knowledge graph of domestic IT innovation—this knowledge graph contains the latest national standards, policy requirements, and compatibility information for various domestic components, ensuring that the probe can collect and analyze data according to the latest specifications.
[0026] After module matching is complete, the system dynamically assembles the selected acquisition module and inference module using a modular container generator. The assembly process is similar to building a lightweight execution unit: the acquisition module is responsible for obtaining raw runtime data from designated channels of the target component (such as system call interfaces, log streams, performance counters, etc.), while the inference module performs preliminary preprocessing and feature calculations on this data. The assembled whole is called an AI dynamic probe. This probe is encapsulated in a containerized form, featuring low resource consumption and high cohesion, and can be flexibly deployed.
[0027] Finally, the assembled AI dynamic probe is implanted into the target component. The implantation method varies depending on the component type: for components with clear process boundaries, such as operating systems or databases, the probe can be embedded through dynamic link library injection or kernel module loading; for application software, critical code paths can be implanted through bytecode enhancement or hook function mounting. Once implanted, the probe becomes part of the target component, capable of perceiving the component's operational behavior in real time from within, without relying on external scanning tools. This shift from "observational detection" to "endogenous perception" provides a high-quality, low-latency data foundation for subsequent multi-dimensional quantitative assessment of the degree of information technology innovation.
[0028] This embodiment pre-establishes a template library containing acquisition and inference modules, parses the component types obtained from the monitoring task, and uses an AI probe generator to extract matching modules and assemble them into dynamic probes, which are then implanted into the target components. This enables on-demand generation and dynamic implantation of probes, transforming external scanning into intrinsic perception and improving the adaptability and real-time performance of the detection.
[0029] In the fintech business, probes are dynamically assembled and implanted according to component type (such as domestic databases and encryption machines) to capture data in real time, including transaction flow processing latency, accuracy of domestic cryptographic algorithm calls, and cross-system interface compatibility. This helps financial institutions quantitatively assess the substitution depth and operational reliability of domestic software and hardware in critical business links, quickly locate performance bottlenecks, meet regulatory compliance requirements, and ensure system stability and data security in high-concurrency and high-consistency scenarios.
[0030] In the healthcare sector, AI-powered dynamic probes are automatically generated and embedded for different types of domestically produced components (such as operating systems, databases, and middleware). These probes collect real-time data on indicators such as patient information read / write latency, abnormal call chains in medical services, and image data loading success rates. This helps medical institutions assess business continuity and data integrity under the new information technology environment, identify compatibility risks caused by component replacement, and ensure smooth treatment processes and compliant management of patient privacy data.
[0031] In one embodiment, S200 includes: S201. The AI dynamic probe's acquisition module adopts multi-level hooking technology to collect multi-source operational data of the target component according to the monitoring task; S202. Classify the multi-source operational data to obtain performance and anomaly data, static configuration data, and dynamic behavior data; S203. Perform data preprocessing on the performance and anomaly data, static configuration data and dynamic behavior data to generate multi-source heterogeneous monitoring data; S204. The multi-source heterogeneous monitoring data is timestamped and labeled with component tags, and the labeled multi-source heterogeneous monitoring data is uploaded to a time-series database for storage.
[0032] In this embodiment, after the AI dynamic probe is successfully implanted into the target component, its internal acquisition module is responsible for collecting multi-source runtime data according to the monitoring task. To achieve comprehensive and low-intrusion data capture, the acquisition module adopts multi-level hooking technology. Multi-level hooking refers to setting interception points at multiple levels, such as the operating system kernel mode, runtime environment, and application layer. Specifically, the acquisition module dynamically captures various raw data generated by the target component during operation by deeply hooking a series of core channels, including system calls (such as kernel interfaces for file reading and writing, process scheduling, and network communication), application programming interfaces (APIs, i.e., function entry points exposed by the component), log streams (such as database transaction logs and middleware access logs), and performance counters (CPU hardware counters, memory bandwidth counters, etc.). This data includes: instruction set compatibility information (such as whether the central processing unit supports domestic instruction extensions), kernel scheduling behavior (such as thread switching frequency and interrupt response latency), cross-component communication protocols (such as remote procedure call format and message queue interaction mode), data stream format (such as serialization and deserialization types), end-to-end latency, throughput, error rate, and abnormal alarms in security logs.
[0033] After collecting raw data from multiple sources, the collection module first categorizes it into three main types: static configuration data, dynamic behavior data, and performance and anomaly data. Static configuration data covers the component's initial parameters, configuration file content, dependency library versions, and installed patch information; this data typically remains unchanged at component startup or within a fixed period. Dynamic behavior data records real-time interactions and state changes during component operation, such as function call chains, memory allocation patterns, thread collaboration relationships, and requests and responses to external services. Performance and anomaly data includes the percentile distribution of latency, throughput fluctuation curves, the frequency of various error codes, warnings and error entries in system logs, and hardware events such as cache misses or page faults.
[0034] After classification, the data acquisition module performs unified data preprocessing on the raw data. The preprocessing steps include: cleaning, which removes duplicate, incomplete, or incorrectly formatted data entries; alignment, which synchronizes data from different sampling frequencies or timestamps within a unified time window; and formatting, which converts unstructured log text into structured fields, for example, by extracting key information using regular expressions. The preprocessed data is referred to as multi-source heterogeneous monitoring data because it comes from diverse sources (system calls, logs, counters, etc.) and has different structures (time-series metrics, event records, configuration key-value pairs), but it already possesses basic analyzable quality.
[0035] Subsequently, the acquisition module tags each preprocessed data entry with a timestamp and component label. The timestamp is accurate to the millisecond or even microsecond level, used for subsequent time-series analysis and alignment; the component label indicates the specific target component (e.g., "database node A" or "middleware service B") from which the data originates and its type (e.g., operating system, database, or application). Finally, this multi-source heterogeneous monitoring data, containing complete metadata, is uploaded to a time-series database for persistent storage via an efficient batch write interface. Time-series databases (such as InfluxDB or Prometheus) are designed specifically for processing high-frequency data arriving in chronological order, supporting fast writing of large-scale data, efficient time-range queries, and data compression strategies, providing a reliable data foundation for subsequent quantitative analysis of information technology innovation capabilities.
[0036] This embodiment employs multi-level hooking technology to collect multi-source operational data of the target component, classifying it into static configuration, dynamic behavior, and performance anomaly data. After preprocessing, the data is tagged with timestamps and component labels and stored in a time-series database. This achieves real-time capture and persistence of multi-dimensional, high-precision data, providing a complete and traceable data foundation for subsequent quantitative evaluation.
[0037] In the fintech business, multi-level hooking is used to capture static configuration (such as encryption module version), dynamic behavior (such as cross-service call chains), and performance anomaly data (such as transaction timeout rate), and store them in a time-series database for real-time analysis. This helps financial institutions track transaction latency fluctuations in domestic databases during peak periods, pinpoint abnormal behavior patterns caused by component replacements, meet compliance audit requirements for data traceability, and support continuous performance optimization of domestic IT innovation systems.
[0038] In the healthcare sector, data is collected and uploaded to a time-series database by tracking static configurations (such as database connection pool settings), dynamic behaviors (such as patient data read / write sequences), and performance anomalies (such as image loading failure rates). This data is then tagged and uploaded to the database. The system assists medical institutions in monitoring the stability of domestically developed operating systems and middleware in actual clinical practice, identifying patterns in abnormal logs caused by interface compatibility issues, ensuring the continuity of clinical operations and the consistency of patient data, and providing objective evidence for domestic IT innovation transformation.
[0039] In one embodiment, S300 includes: S301. The multi-source heterogeneous monitoring data is grouped and iteratively processed according to component labels to locate the target component instance to be identified; S302. Extract the static configuration fields and dynamic system call frequency vector of the target component instance using a hybrid classifier; S303. Identify the primary component category and secondary component category of the target component instance based on the static configuration field and the dynamic system call frequency vector, and output the component type label; S304. Based on the component type label, retrieve the prior candidate feature template associated with the component type label from the meta-feature library; S305. Divide the multi-source heterogeneous monitoring data into fixed time windows, and aggregate the basic indicators in each time window into a basic feature matrix. S306. Based on the prior candidate feature template, select the corresponding feature subset from the basic feature matrix; S307. Input the feature subset into the variational autoencoder, calculate the reconstruction error of each basic feature dimension, and filter out the basic features whose reconstruction error is higher than a set threshold. S308. Calculate the attention weight between each basic feature and the evaluation index based on the basic features, and take the features with attention weights higher than the weight threshold as key information technology innovation features.
[0040] In this embodiment, after storing the multi-source heterogeneous monitoring data, the system begins dynamic feature extraction to automatically identify key features closely related to the level of information technology innovation. First, the system performs iterative grouping processing according to the component tags carried by each data entry. The component tags indicate the source component of the data (e.g., "database node A" or "middleware service B"). Through grouping, the system can locate the target component instance to be identified in each iteration—that is, a specific running component process or service instance.
[0041] Subsequently, the system invokes a lightweight policy-model hybrid classifier to read the static configuration fields and dynamic system call frequency vector of the target component instance. The static configuration fields include component version information, compilation options, configuration file parameters, etc.; the dynamic system call frequency vector records the number or frequency distribution of various system calls (such as opening files, sending network data, and allocating memory) made by the component during runtime. This hybrid classifier combines a rule-based policy (for quickly matching common patterns) with a lightweight machine learning model (for handling fuzzy or abnormal cases) to identify the primary and secondary component categories of the target component instance based on these two types of input data. For example, the primary category might be "database," and the secondary category might be "relational database" or "NoSQL database." After identification, the system outputs a clear component type label, such as "domestic distributed database" or "real-time operating system kernel."
[0042] After obtaining the component type label, the system accesses the Meta-Feature Library (a knowledge base that pre-stores known feature templates for various components). Based on the component type label, the system extracts the associated prior candidate feature template from the Meta-Feature Library. This template lists the feature dimensions that typically need attention for this type of component. For example, for database components, it might include "transaction commit latency," "index hit rate," and "connection pool utilization," while for CPUs, it might include "instruction set extension support" and "cache miss rate."
[0043] To extract these features from actual monitoring data, the system first divides the multi-source heterogeneous monitoring data into fixed time windows (e.g., every 5 seconds or every 10 seconds). Within each time window, basic indicators (such as CPU utilization, memory usage in bytes, requests per second, error count, etc.) are aggregated, and their mean, maximum, minimum, standard deviation, and other statistics are calculated to form a basic feature matrix. Each row of this matrix corresponds to a time window, and each column corresponds to a basic indicator.
[0044] Next, the system uses the previously extracted prior candidate feature templates to select corresponding feature subsets from the basic feature matrix. In other words, only the indicator columns listed in the template are retained, while noisy indicators irrelevant to the current component type are removed. This selection process significantly reduces the complexity of subsequent calculations.
[0045] To further improve the discriminative power and effectiveness of features, the system inputs a selected subset of features into a Variational Autoencoder (VAE, a generative neural network model capable of learning the latent distribution of data and detecting anomalies). The VAE attempts to encode and reconstruct the input features, calculating the reconstruction error for each fundamental feature dimension—the difference between the original input value and the reconstructed output value. For critical features sensitive to the degree of information technology innovation, due to their large fluctuations or complex patterns during operation, the VAE struggles to reconstruct them perfectly, resulting in higher reconstruction errors. The system sets a reconstruction error threshold and filters out those fundamental features with reconstruction errors exceeding this threshold; these features often carry important information related to the degree of information technology innovation.
[0046] Finally, the system calculates the attention weight between each of the selected basic features and the final evaluation metric (such as the comprehensive score for domestic IT innovation or the depth of substitution). Attention weight is a coefficient that measures the contribution of a feature to the output result, and can be obtained through an attention mechanism or correlation analysis. The system uses features with attention weights higher than a preset weight threshold as key domestic IT innovation features. These features are the core inputs to the subsequent quantitative evaluation model, such as instruction extension support rate, frequency of national cryptographic algorithm calls, and compatibility indicators of cross-component communication protocols. Through this adaptive, multi-stage feature extraction process, the system can dynamically identify the most representative domestic IT innovation features for different component types, completely eliminating reliance on static rule bases.
[0047] This embodiment processes multi-source heterogeneous monitoring data through grouped iterative processing, utilizes a lightweight policy-model hybrid classifier to identify component categories, extracts prior candidate feature templates from a meta-feature library, segments and aggregates them through a time window, employs a variational autoencoder (VAE) to calculate reconstruction error and filter high-error features, and then extracts key information technology innovation features through attention weight calculation. This achieves adaptive and dynamic key feature identification, completely eliminating reliance on static rule bases and accurately capturing features highly correlated with the degree of information technology innovation, providing high-quality input for subsequent quantitative evaluation.
[0048] In the fintech business, facing complex combinations of domestically produced components (such as domestic CPUs, operating systems, databases, and middleware), the system first iterates through grouping according to component tags (such as "transaction database instance" or "payment gateway service") to locate each target component instance. A lightweight strategy-model hybrid classifier reads static configurations (such as kernel version and encryption library information) and dynamic system call frequency vectors (such as network packet sending and receiving call frequency) to quickly identify the primary category (such as "database") and secondary category (such as "distributed relational database") of the component, outputting an accurate component type label. Based on this label, prior candidate feature templates for this type of component are extracted from the meta-feature library (e.g., for databases, these include "transaction commit latency," "index hit rate," and "connection pool utilization"). Subsequently, the system segments the monitoring data according to a fixed time window (such as 5 seconds), aggregates it to form a basic feature matrix, and selects feature subsets based on the templates. A subset of features is input into a variational autoencoder (VAE) to calculate the reconstruction error for each feature dimension. Basic features with reconstruction errors exceeding a threshold are selected—these features often correspond to indicators that fluctuate significantly after the replacement of traditional IT systems with modern IT technologies, such as lock contention patterns unique to domestic databases or abnormal branch predictions caused by instruction set compatibility. Finally, the attention weights of each feature and evaluation indicators (such as transaction throughput and response latency compliance rate) are calculated. Features with weights exceeding a threshold are designated as key IT innovation features, such as "frequency of national cryptographic algorithm calls" and "protocol conversion latency in cross-service call chains."
[0049] In the healthcare business, multi-source heterogeneous monitoring data is grouped and iterated by component labels to locate specific target component instances, such as "image storage service instance" or "patient master index database instance". A lightweight strategy-model hybrid classifier reads static configurations (such as DICOM communication protocol version, database character set) and dynamic system call frequency vectors (such as file read frequency, network connection count), identifies primary component categories (such as "middleware") and secondary categories (such as "message middleware"), and outputs component type labels. Based on these labels, prior candidate feature templates are extracted from the meta-feature library. For example, for imaging systems, templates include "image loading success rate", "JPEG2000 decompression time", and "HL7 message parsing error rate". The system segments the monitoring data by time windows (such as 10 seconds), aggregates them into a basic feature matrix, and filters feature subsets. These feature subsets are input into a variational autoencoder (VAE) to calculate the reconstruction error of each feature, filtering out features with errors exceeding a threshold—for example, the abnormal page splitting frequency of domestic databases when storing large patient fields, or the thread switching latency jitter of domestic operating systems when concurrently processing multiple image transmissions. Finally, the attention weights of each feature and evaluation index (such as the response latency of the clinic queuing system and the image retrieval completeness rate) are calculated, and features with attention weights higher than the threshold are used as key information technology innovation features, such as "the proportion of time spent encrypting patient privacy data using national cryptographic algorithms" and "the number of compatibility retries for cross-hospital data synchronization".
[0050] In one embodiment, S400 includes: S401. Use the key information technology innovation features as candidate features; S402. Perform mutual information calculation on the candidate features to determine the dynamic feature set of the current component; S403. For each key information technology innovation feature in the dynamic feature set, perform the corresponding acquisition and calculation operations to obtain the feature value of each key information technology innovation feature; S404. Construct a standardized feature vector from the feature values, component type labels, and time window start time of each key information technology innovation feature.
[0051] In this embodiment, after identifying key information technology innovation features, the system uses these features as candidate features for feature selection and standardization. To further remove redundancy and retain the features most relevant to the degree of information technology innovation, the system calculates mutual information for the candidate features. Mutual information (MI) is a statistic that measures the degree of interdependence between two random variables; a higher value indicates a stronger contribution of a feature to the evaluation target (such as the comprehensive index of information technology innovation). The system calculates the mutual information value between each candidate feature and the final evaluation target, and selects features with mutual information higher than the preset threshold, thereby determining the dynamic feature set of the current component. The features in this set can dynamically adapt to changes in different component types and operational stages, rather than being fixed static rules.
[0052] After determining the dynamic feature set, the system needs to perform corresponding data acquisition and calculation operations on each key domestic IT innovation feature in the set to obtain its feature value. Specifically, different features need to be obtained from different data sources or through different calculation methods. For example, the feature "instruction extension support rate" requires collecting the number of instructions that support a specific instruction set from the CPU's performance counter, and then dividing by the total number of instructions for calculation; "national cryptographic algorithm call frequency" requires intercepting calls to the national cryptographic algorithm library through an application programming interface hook (API Hook) and counting the number of calls per unit time; "domestic middleware dependency" may require analyzing the list of shared libraries loaded by components and the import function table to calculate the proportion of function calls provided by domestic middleware. Based on the definition and source of each feature, the system automatically calls the corresponding acquisition module or calculation operator to complete the conversion from raw monitoring data to specific feature values.
[0053] After obtaining the feature values of each key information technology innovation feature, the system combines these feature values, component type labels, and the start time of the current time window to form a standardized feature vector. The standardized feature vector is a fixed-length numerical sequence, where each position corresponds to a specific feature dimension. The feature values are normalized (e.g., scaled to the [0,1] interval) to eliminate the influence of dimensions. The component type label is appended to the feature vector in the form of one-hot encoding or embedding vector, informing the subsequent model which component (e.g., database, operating system, or middleware) the current feature originates from. The start time of the time window serves as the anchor point for the time dimension, allowing feature vectors from multiple time windows to be arranged chronologically for processing by time-series models such as Long Short-Term Memory (LSTM) networks. Finally, this standardized feature vector becomes the direct input to the subsequent quantitative evaluation model, providing a unified, structured, and computable data representation for calculating the four-dimensional information technology innovation index (component replacement depth, technology stack integration compatibility, performance loss ratio, and risk exposure coefficient).
[0054] This embodiment uses mutual information calculation to filter candidate features to obtain a dynamic feature set. For each feature in the set, corresponding acquisition and calculation operations are performed to obtain the feature value. This value, along with the component type label and the start time of the time window, forms a standardized feature vector. Redundant features are removed to ensure that the features are highly correlated with the evaluation target, outputting a structured, normalized vector that provides accurate input for subsequent quantization models.
[0055] In the fintech business, the system performs mutual information calculations on candidate features (such as the frequency of calls to domestic cryptographic algorithms and the latency of distributed transaction commits) to filter out a dynamic feature set most relevant to evaluation targets such as transaction throughput and compliance rate. Subsequently, data collection and calculation are performed on each feature within the set (e.g., counting the number of encrypted calls via API hooks) to obtain feature values. Finally, the feature values, component type labels (such as "domestic distributed database"), and the start time of the time window are combined to form a standardized feature vector. This vector is directly input into the subsequent neural network for quantitative scoring, helping financial institutions accurately quantify the substitution depth and performance loss of domestic components, avoiding the subjectivity and lag of manually configured rules.
[0056] In the healthcare business domain, the system performs mutual information calculations on candidate features (such as patient data read / write latency, DICOM image decompression time, and HL7 message parsing error rate) to filter out a dynamic feature set most relevant to objectives such as treatment response latency and data consistency. For each feature in the set, the corresponding acquisition operator is automatically triggered (e.g., by using a log hook to calculate the time consumption of an interface call) to obtain the feature value. Finally, the feature value, component type label (e.g., "image archiving middleware"), and time window start time are combined to form a standardized feature vector. This vector provides a unified input for subsequent evaluation of the domestic IT innovation index, helping medical institutions objectively evaluate the compatibility and reliability of domestically produced software and hardware in actual clinical environments and identify key bottlenecks affecting the smoothness of the treatment process.
[0057] In one embodiment, S500 includes: S501. Iteratively process the multi-source heterogeneous monitoring data and standardized feature vectors to locate the overall instance of the current information technology innovation system to be evaluated; S502. Input the time-series performance data in the standardized feature vector into the long short-term memory network through the fusion analysis module, and extract the time-dependent features of each component. S503. Input the cross-component call chain data and inter-component communication relationship in the standardized feature vector into the graph neural network to obtain the interaction dependency relationship between components and generate the embedding vector of each component in the interaction graph. S504. The time-dependent features output by the Long Short-Term Memory Network are concatenated and fused with the graph embedding vector output by the Graph Neural Network to obtain a fused feature tensor. S505. Input the fused feature tensor into a fully connected regression branch to evaluate the four-dimensional information technology innovation index. Each branch outputs a quantization score and the corresponding confidence interval width. S506. Integrate the quantization score and corresponding confidence interval width of each branch output into a four-dimensional information technology innovation index.
[0058] In this embodiment, after accumulating multi-source heterogeneous monitoring data and standardized feature vectors, the system begins iterative processing to locate the overall instance of the domestically developed information technology (IT) system to be evaluated. The overall instance of an IT system refers to a complete operating environment composed of multiple IT components (such as domestically produced central processing units, operating systems, databases, middleware, and applications). By aggregating data according to system identifiers or deployment units, the system can identify all components belonging to the same system instance and their corresponding standardized feature vectors, thus laying the foundation for overall evaluation.
[0059] After localization is complete, the system initiates the fusion analysis module. This module first inputs the time-series performance data from the standardized feature vector into a Long Short-Term Memory (LSTM) network (a variant of recurrent neural networks adept at processing time series data). The time-series performance data includes indicators that change continuously over time, such as CPU utilization, memory usage fluctuations, transaction response latency, and throughput variation curves. Through its unique gating mechanism (input gate, forget gate, output gate), the LSTM network can capture the long-term dependencies and short-term fluctuation patterns of these indicators across multiple time windows, thereby extracting the time-dependent features of each component. For example, a database component might experience periodic increases in latency at night; this pattern will be memorized by the LSTM network and encoded into a feature vector.
[0060] Meanwhile, the fusion analysis module inputs the cross-component call chain data and inter-component communication relationships from the standardized feature vectors into a Graph Neural Network (GNN, a type of neural network specifically designed for graph-structured data). The cross-component call chain data records the path of a request sequentially invoked across multiple components, such as "Application A → Middleware B → Database C"; the inter-component communication relationships describe the dependency topology of components, such as the call relationship between the operating system kernel and the database driver. The GNN treats these components as nodes in a graph, and the calls and communication relationships as directed edges. Through message passing and neighbor aggregation mechanisms, it learns the embedding representation of each node. After multiple layers of graph convolution, the system obtains the interaction dependencies between components and generates an embedding vector (a low-dimensional dense vector representing the role and influence of a node in the graph) for each component in the interaction graph. This embedding vector reflects the degree of coupling, critical path location, and potential fault propagation risk of the component within the overall information technology innovation system.
[0061] To comprehensively utilize information from both the temporal and structural dimensions, the system concatenates and fuses the temporal dependency features output by the Long Short-Term Memory (LSTM) network with the graph embedding vectors output by the Graph Neural Network (GNN). This concatenation and fusion involves linking the two vectors end-to-end along the feature dimension to form a new, more dimensional fusion feature tensor. This tensor simultaneously contains the component's own temporal behavior patterns and its interactive role within the entire system, enabling a more comprehensive characterization of multiple aspects of the degree of information technology innovation.
[0062] The fused feature tensor is then fed into the fully connected regression branch. The fully connected regression branch is a sub-network composed of multiple fully connected layers, each responsible for predicting one dimension of the four-dimensional information technology innovation index. Specifically, the system sets up four parallel fully connected regression branches, corresponding to component replacement depth, technology stack fusion compatibility, performance loss ratio, and risk exposure coefficient, respectively. Each branch, based on the same fused feature tensor, calculates a quantized score (e.g., a continuous value between 0 and 100) and its corresponding confidence interval width through forward propagation. The confidence interval width reflects the uncertainty of the branch's prediction and is generated by the variance output layer at the end of the branch; a larger width indicates a lower confidence level in the score.
[0063] Finally, the system integrates the quantitative scores and confidence intervals output from the four branches into a four-dimensional domestic IT innovation index. This index can be represented as a structured result in the form of "[Substitution Depth: 87.3±2.1, Fusion Compatibility: 72.8±3.5, Performance Loss Ratio: 15.2±1.8, Risk Exposure Coefficient: 23.5±4.0]", where the values of each dimension and the confidence intervals together provide a quantifiable assessment of the degree of domestic IT innovation. This output not only informs users of the specific scores of the current system in the four dimensions of domestic substitution depth, compatibility, performance, and risk, but also gives the model's confidence range for the assessment results, thus providing accurate and traceable decision-making basis for the continuous optimization and governance of the domestic IT innovation system.
[0064] This embodiment iteratively processes and locates the overall instance of the domestic IT innovation system. It utilizes a Long Short-Term Memory (LSTM) network to extract the temporal dependency features of components and a Graph Neural Network (GNN) to model cross-component call chains and interaction relationships. After fusing these two methods, a fully connected regression branch is used to output a four-dimensional domestic IT innovation index and confidence intervals for each dimension. This achieves a global, dynamic, and quantitative evaluation from components to the system, providing a multi-dimensional domestic IT innovation degree indicator with uncertainty, significantly improving the comprehensiveness and reliability of the evaluation.
[0065] In the fintech business, iterative processing of multi-source heterogeneous monitoring data and standardized feature vectors is used to locate overall system instances (e.g., a complete payment chain including domestic databases, middleware, and transaction gateways). Long Short-Term Memory (LSTM) networks are used to extract time-series performance data (e.g., the periodic fluctuation pattern of transaction response latency during peak business periods) to capture the time-dependent features of each component. Simultaneously, cross-component call chain data (e.g., the "gateway → accounting → risk control" call sequence) and inter-component communication relationships are input into a graph neural network (GNN) to generate embedding vectors for each component in the interaction graph, reflecting the degree of coupling between services and the risk of fault propagation. After concatenation and fusion, a fused feature tensor is obtained, which is then input into a fully connected regression branch. The four branches output quantitative scores and confidence interval widths for component substitution depth, technology stack fusion compatibility, performance loss ratio, and risk exposure coefficient, respectively. Finally, these are integrated into a four-dimensional fintech innovation index, for example, "[Substitution Depth: 91.2±1.5, Fusion Compatibility: 78.6±2.3, Performance Loss Ratio: 12.4±1.1, Risk Exposure: 18.9±2.0]". It helps financial institutions to monitor in real time the actual substitution level and performance degradation of the domestic IT innovation system in the core payment chain.
[0066] In the healthcare business domain, iterative processing of multi-source heterogeneous monitoring data and standardized feature vectors is used to locate overall system instances (e.g., hospital information integration platforms covering the entire process of registration, diagnosis and treatment, image retrieval, and billing). Long Short-Term Memory (LSTM) networks extract time-series performance data (such as the trend of electronic medical record writing latency and image loading success rate over time during peak periods) to capture the time-dependent features of each component. Graph Neural Networks (GNNs) model cross-component call chain data (such as the request flow path of "HIS→Integration Platform→PACS→Reporting System") and inter-component communication relationships, generating embedding vectors for each component in the interaction graph, reflecting the strength of data flow dependencies and potential single-point failure risks. After fusion, a fusion feature tensor is obtained, which, through a fully connected regression branch, outputs a four-dimensional information technology innovation index, including component replacement depth (the proportion of domestic databases writing to core diagnosis and treatment tables), fusion compatibility (HL7 message parsing success rate), performance loss ratio (average increase in image retrieval time), risk exposure coefficient (probability of abnormal synchronization of the patient's master index), and confidence intervals for each dimension.
[0067] In one embodiment, after matching the acquisition module and the inference module according to the monitoring task, assembling the acquisition module and the inference module into an AI dynamic probe, and implanting the AI dynamic probe into the target component, the method further includes: Monitor change events in the domestic IT innovation knowledge base; When a change event is detected, the changes made in the change event are compiled into a lightweight policy package; The lightweight policy package is pushed to the deployed AI dynamic probe via edge nodes; When the AI dynamic probe receives the lightweight policy package, it hot-loads and updates the inference module.
[0068] In this embodiment, the system continuously monitors change events in the domestic IT innovation knowledge base during operation. The domestic IT innovation knowledge base is a centrally stored and dynamically updated database containing the latest national and industry-released technical standards, policies and regulations, compatibility lists of domestically produced components, instruction set requirements, encryption algorithm specifications, and other information. Change events can originate from manual input, web scraping of policy websites, or data synchronization with official domestic IT innovation certification platforms. When any specification is added, modified, or deleted from the knowledge base (e.g., adding support requirements for a new domestic central processing unit instruction set, or updating the compatibility certification status of a database with an operating system), the system will detect the change event.
[0069] Once a change event is detected, the system immediately compiles the changes into a lightweight policy package. The compilation process includes: transforming policy terms or technical specifications described in natural language into structured rule expressions, such as converting "requiring the operating system kernel to support a specific system call" into an executable detection rule; and simultaneously generating corresponding configuration parameters and threshold settings based on the scope of the change's impact (e.g., targeting a specific type of CPU or database). The compiled lightweight policy package is very small, typically less than 10 kilobytes (KB), to ensure fast transmission and loading. This policy package uses a compact binary or text format (such as Protocol Buffers or JSON) and includes a version number, an effective timestamp, and the identifiers of the probe module interfaces it depends on.
[0070] After generating the lightweight policy package, the system pushes it to the deployed AI dynamic probes via edge nodes. Edge nodes are gateways or proxy services located at the network edge close to the target component, such as lightweight message middleware deployed in the same data center or virtual private cloud. Long-lived connections or efficient message queue channels (such as using MQTT or WebSocket) are maintained between the edge nodes and each AI dynamic probe. Once the lightweight policy package is ready, the edge nodes push it to all relevant probe instances within seconds using a publish-subscribe pattern or direct addressing. Verification and encryption are performed during the push process to ensure the integrity and security of the policy package.
[0071] After receiving a lightweight policy package, the AI dynamic probe performs a hot-loading update of the inference module. Hotloading refers to dynamically replacing or enhancing the inference module within the probe without stopping the probe or restarting the target component's process. Specifically, the probe maintains a policy package manager. Upon receiving a new package, it first verifies the package's signature and version, confirming its legitimacy and that it is newer than the current version. Then, the probe replaces the old rules or model parameters in the inference module with the new rules and parameters. If the new policy package introduces entirely new computational logic (e.g., adding a feature extraction operator), the probe dynamically loads the corresponding shared library or bytecode and registers it in the inference module's execution chain. The entire update process is seamless and uninterrupted to the target component's normal business operations. After the update, the AI dynamic probe collects data and performs inference according to the latest requirements of the domestic IT innovation knowledge base, thus achieving a minute-level closed loop from policy updates to detection capability synchronization, completely solving the lag problem of traditional static detection methods.
[0072] This embodiment continuously monitors changes to the domestic IT innovation knowledge base, compiles the changes into lightweight policy packages, and pushes them to deployed AI dynamic probes via edge nodes within seconds. The probes then hot-load and update the inference module. This achieves minute-level synchronization between detection capabilities and policy standards, without requiring component restarts, completely resolving the lag issue of traditional detection methods.
[0073] In the fintech business, when the domestic IT innovation knowledge base is updated with new national cryptographic algorithm regulations or new central processing unit instruction set requirements, the system automatically compiles the changes into a lightweight strategy package (<10KB) and pushes it to AI dynamic probes embedded in various components of the transaction chain via edge nodes. The probes hot-load and update the inference module, immediately collecting data and assessing compliance according to the new specifications without interrupting business operations. This helps financial institutions respond quickly to regulatory changes, ensuring that transaction signature algorithms and encrypted channel configurations under domestic environments meet standards in a timely manner, thus reducing compliance risks.
[0074] In the healthcare sector, when the domestic IT innovation knowledge base releases new standards regarding patient data encryption strength and diagnostic interface compatibility, the system automatically compiles the changes into lightweight policy packages and pushes them to various AI dynamic probes via edge nodes. Probes are hot-loaded to update the inference module without requiring a restart of the imaging service or medical record database. This ensures that medical institutions can synchronize with the latest data security specifications and compatibility requirements with zero downtime, guaranteeing the continuity of clinical operations and compliance with patient privacy protection in the domestic IT innovation environment.
[0075] In one embodiment, an AI-based dynamic probe-based intelligent detection device is provided, which corresponds one-to-one with the AI-based dynamic probe-based intelligent detection method described in the above embodiments. (Refer to...) Figure 3 , Figure 3This is a schematic diagram of the functional modules of a preferred embodiment of the intelligent detection device based on AI dynamic probes of the present invention. The modules include a probe implantation module 10, a data processing module 20, a vector construction module 40, and a detection output module 50. Detailed descriptions of each functional module are as follows: The probe implantation module 10 is used to match the acquisition module and the inference module according to the monitoring task, assemble the acquisition module and the inference module into an AI dynamic probe, and implant the AI dynamic probe into the target component. The data processing module 20 is used to capture multi-source operating data of the target component in real time according to the monitoring task by the AI dynamic probe, preprocess the multi-source operating data, and generate multi-source heterogeneous monitoring data. Feature recognition module 30 is used to identify key information technology innovation features based on the component type labels of the multi-source heterogeneous monitoring data through an adaptive feature extraction framework; A vector construction module 40 is used to construct a standardized feature vector based on the key information technology innovation features; The detection output module 50 is used to perform fusion analysis on the multi-source heterogeneous monitoring data, key information technology innovation features and standardized feature vectors by using a long short-term memory network and combining it with a graph neural network, and output a four-dimensional information technology innovation index.
[0076] In one embodiment, the probe implantation module 10 includes: A module probe template library is pre-created, which stores acquisition modules and inference modules; The monitoring task is parsed to obtain the target component and component type; The AI probe generator retrieves the matching acquisition module and inference module from the module probe template library according to the component type; The acquisition module and the inference module are assembled into an AI dynamic probe, and the AI dynamic probe is implanted into the target component.
[0077] In one embodiment, the data processing module 20 includes: The AI dynamic probe's acquisition module employs multi-level hooking technology to collect multi-source operational data of the target component according to the monitoring task; The multi-source operational data is classified to obtain performance and anomaly data, static configuration data, and dynamic behavior data; The performance and anomaly data, static configuration data, and dynamic behavior data are preprocessed to generate multi-source heterogeneous monitoring data; The multi-source heterogeneous monitoring data is timestamped and tagged with component labels, and the tagged multi-source heterogeneous monitoring data is uploaded to a time-series database for storage.
[0078] In one embodiment, the feature recognition module 30 includes: The multi-source heterogeneous monitoring data is grouped and iteratively processed according to component labels to locate the target component instance to be identified; The static configuration fields and dynamic system call frequency vectors of the target component instance are extracted using a hybrid classifier. Based on the static configuration fields and the dynamic system call frequency vector, identify the primary and secondary component categories of the target component instance, and output the component type label; Based on the component type label, retrieve the prior candidate feature template associated with the component type label from the meta-feature library; The multi-source heterogeneous monitoring data is divided into fixed time windows, and the basic indicators within each time window are aggregated into a basic feature matrix. Based on the prior candidate feature template, a corresponding feature subset is selected from the basic feature matrix; The feature subset is input into the variational autoencoder to calculate the reconstruction error of each basic feature dimension, and basic features with reconstruction errors higher than a set threshold are selected. Based on the aforementioned basic features, the attention weight between each basic feature and the evaluation index is calculated, and features with attention weights higher than the weight threshold are taken as key information technology innovation features.
[0079] In one embodiment, the vector module 40 is constructed, including: The key information technology innovation features are used as candidate features; Mutual information is calculated on the candidate features to determine the dynamic feature set of the current component; For each key information technology innovation feature in the dynamic feature set, perform the corresponding acquisition and calculation operations to obtain the feature value of each key information technology innovation feature; The feature values, component type labels, and time window start times of each key information technology innovation feature are used to construct a standardized feature vector.
[0080] In one embodiment, the detection output module 50 includes: Iterative processing of multi-source heterogeneous monitoring data and standardized feature vectors is performed to locate the overall instance of the domestic information technology innovation system to be evaluated. The time-series performance data in the standardized feature vector is input into the long short-term memory network through the fusion analysis module to extract the time-dependent features of each component. The cross-component call chain data and inter-component communication relationships in the standardized feature vector are input into the graph neural network to obtain the interaction dependencies between components and generate the embedding vector of each component in the interaction graph. The time-dependent features output by the Long Short-Term Memory Network are concatenated and fused with the graph embedding vector output by the Graph Neural Network to obtain a fused feature tensor. The fused feature tensor is input into a fully connected regression branch to evaluate the four-dimensional information technology innovation index. Each branch outputs a quantized score and the corresponding confidence interval width. The quantized score and corresponding confidence interval width of each branch output are integrated into a four-dimensional information technology innovation index.
[0081] In one embodiment, the hot update module further includes: Monitor change events in the domestic IT innovation knowledge base; When a change event is detected, the changes made in the change event are compiled into a lightweight policy package; The lightweight policy package is pushed to the deployed AI dynamic probe via edge nodes; When the AI dynamic probe receives the lightweight policy package, it hot-loads and updates the inference module.
[0082] Specific limitations regarding the AI-based dynamic probe-based intelligent detection device can be found in the aforementioned limitations of the AI-based dynamic probe-based intelligent detection method, and will not be repeated here. Each module in the aforementioned AI-based dynamic probe-based intelligent detection device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device in hardware form, or stored in the memory of a computer device in software form, so that the processor can call and execute the operations corresponding to each module.
[0083] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 4 As shown, the computer device includes a processor, memory, network interface, and database connected via a system bus. The processor provides determination and control capabilities. The memory includes non-volatile and / or volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. The network interface is used to communicate with external clients via a network connection. When the computer program is executed by the processor, it implements the functions or steps of a server-side intelligent detection method based on AI dynamic probes.
[0084] In one embodiment, a computer device is provided, which may be a client, and its internal structure diagram may be as follows: Figure 5As shown, the computer device includes a processor, memory, network interface, display screen, and input devices connected via a system bus. The processor provides determination and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. The network interface is used to communicate with an external server via a network connection. When the computer program is executed by the processor, it implements the functions or steps of a client-side intelligent detection method based on AI dynamic probes.
[0085] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to perform the following steps: According to the monitoring task, the acquisition module and the inference module are matched, the acquisition module and the inference module are assembled into an AI dynamic probe, and the AI dynamic probe is implanted into the target component; The AI dynamic probe captures multi-source operational data of the target component in real time according to the monitoring task, and preprocesses the multi-source operational data to generate multi-source heterogeneous monitoring data. Key information technology innovation features are identified based on the component type labels of the multi-source heterogeneous monitoring data using an adaptive feature extraction framework. Construct standardized feature vectors based on the aforementioned key information technology innovation features; A long short-term memory network is used, combined with a graph neural network, to perform fusion analysis on the multi-source heterogeneous monitoring data, key information technology innovation features, and standardized feature vectors, and output a four-dimensional information technology innovation index.
[0086] In one embodiment, a computer-readable storage medium is provided, which may be non-volatile or volatile, and a computer program is stored thereon, which, when executed by a processor, performs the following steps: According to the monitoring task, the acquisition module and the inference module are matched, the acquisition module and the inference module are assembled into an AI dynamic probe, and the AI dynamic probe is implanted into the target component; The AI dynamic probe captures multi-source operational data of the target component in real time according to the monitoring task, and preprocesses the multi-source operational data to generate multi-source heterogeneous monitoring data. Key information technology innovation features are identified based on the component type labels of the multi-source heterogeneous monitoring data using an adaptive feature extraction framework. Construct standardized feature vectors based on the aforementioned key information technology innovation features; A long short-term memory network is used, combined with a graph neural network, to perform fusion analysis on the multi-source heterogeneous monitoring data, key information technology innovation features, and standardized feature vectors, and output a four-dimensional information technology innovation index.
[0087] It should be noted that the functions or steps that can be implemented by the computer-readable storage medium or computer device described above can be referred to the relevant descriptions on the server side and client side in the foregoing method embodiments. To avoid repetition, they will not be described one by one here.
[0088] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0089] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is used as an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.
[0090] It should be noted that any software tools or components not belonging to this company appearing in the embodiments of this application are merely illustrative examples and do not represent actual use. All user personal information involved in the embodiments of this application has been authorized (with knowledge and consent) by the relevant parties or has been fully authorized by all parties, and the executing entity may obtain it through various legal and compliant means. The collection, storage, use, processing, transmission, provision, and disclosure of the information, data, and signals involved all comply with relevant laws and regulations and do not violate public order and good morals.
[0091] The above-described embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.
Claims
1. An intelligent detection method based on AI dynamic probes, characterized in that, Includes the following steps: According to the monitoring task, the acquisition module and the inference module are matched, the acquisition module and the inference module are assembled into an AI dynamic probe, and the AI dynamic probe is implanted into the target component; The AI dynamic probe captures multi-source operational data of the target component in real time according to the monitoring task, and preprocesses the multi-source operational data to generate multi-source heterogeneous monitoring data. Key information technology innovation features are identified based on the component type labels of the multi-source heterogeneous monitoring data using an adaptive feature extraction framework. Construct standardized feature vectors based on the aforementioned key information technology innovation features; A long short-term memory network is used, combined with a graph neural network, to perform fusion analysis on the multi-source heterogeneous monitoring data, key information technology innovation features, and standardized feature vectors, and output a four-dimensional information technology innovation index.
2. The intelligent detection method based on AI dynamic probe as described in claim 1, characterized in that, The step of matching the acquisition module and the inference module according to the monitoring task, assembling the acquisition module and the inference module into an AI dynamic probe, and embedding the AI dynamic probe into the target component includes: A module probe template library is pre-created, which stores acquisition modules and inference modules; The monitoring task is parsed to obtain the target component and component type; The AI probe generator retrieves the matching acquisition module and inference module from the module probe template library according to the component type; The acquisition module and the inference module are assembled into an AI dynamic probe, and the AI dynamic probe is implanted into the target component.
3. The intelligent detection method based on AI dynamic probe as described in claim 1, characterized in that, The AI dynamic probe captures multi-source operational data of the target component in real time according to the monitoring task, preprocesses the multi-source operational data, and generates multi-source heterogeneous monitoring data, including: The AI dynamic probe's acquisition module employs multi-level hooking technology to collect multi-source operational data of the target component according to the monitoring task; The multi-source operational data is classified to obtain performance and anomaly data, static configuration data, and dynamic behavior data; The performance and anomaly data, static configuration data, and dynamic behavior data are preprocessed to generate multi-source heterogeneous monitoring data; The multi-source heterogeneous monitoring data is timestamped and tagged with component labels, and the tagged multi-source heterogeneous monitoring data is uploaded to a time-series database for storage.
4. The intelligent detection method based on AI dynamic probe as described in claim 1, characterized in that, Key information technology innovation features are identified based on the component type labels of the multi-source heterogeneous monitoring data using an adaptive feature extraction framework, including: The multi-source heterogeneous monitoring data is grouped and iteratively processed according to component labels to locate the target component instance to be identified; The static configuration fields and dynamic system call frequency vectors of the target component instance are extracted using a hybrid classifier. Based on the static configuration fields and the dynamic system call frequency vector, identify the primary and secondary component categories of the target component instance, and output the component type label; Based on the component type label, retrieve the prior candidate feature template associated with the component type label from the meta-feature library; The multi-source heterogeneous monitoring data is divided into fixed time windows, and the basic indicators within each time window are aggregated into a basic feature matrix. Based on the prior candidate feature template, a corresponding feature subset is selected from the basic feature matrix; The feature subset is input into the variational autoencoder to calculate the reconstruction error of each basic feature dimension, and basic features with reconstruction errors higher than a set threshold are selected. Based on the aforementioned basic features, the attention weight between each basic feature and the evaluation index is calculated, and features with attention weights higher than the weight threshold are taken as key information technology innovation features.
5. The intelligent detection method based on AI dynamic probe as described in claim 1, characterized in that, Based on the aforementioned key information technology innovation features, a standardized feature vector is constructed, including: The key information technology innovation features are used as candidate features; Mutual information is calculated on the candidate features to determine the dynamic feature set of the current component; For each key information technology innovation feature in the dynamic feature set, perform the corresponding acquisition and calculation operations to obtain the feature value of each key information technology innovation feature; The feature values, component type labels, and time window start times of each key information technology innovation feature are used to construct a standardized feature vector.
6. The intelligent detection method based on AI dynamic probe as described in claim 1, characterized in that, A long short-term memory network is used in conjunction with a graph neural network to fuse and analyze the multi-source heterogeneous monitoring data, key information technology innovation features, and standardized feature vectors, outputting a four-dimensional information technology innovation index, including: Iterative processing of multi-source heterogeneous monitoring data and standardized feature vectors is performed to locate the overall instance of the domestic information technology innovation system to be evaluated. The time-series performance data in the standardized feature vector is input into the long short-term memory network through the fusion analysis module to extract the time-dependent features of each component. The cross-component call chain data and inter-component communication relationships in the standardized feature vector are input into the graph neural network to obtain the interaction dependencies between components and generate the embedding vector of each component in the interaction graph. The time-dependent features output by the Long Short-Term Memory Network are concatenated and fused with the graph embedding vector output by the Graph Neural Network to obtain a fused feature tensor. The fused feature tensor is input into a fully connected regression branch to evaluate the four-dimensional information technology innovation index. Each branch outputs a quantized score and the corresponding confidence interval width. The quantized score and corresponding confidence interval width of each branch output are integrated into a four-dimensional information technology innovation index.
7. The intelligent detection method based on AI dynamic probe as described in claim 1, characterized in that, The step of matching the acquisition module and the inference module according to the monitoring task, assembling the acquisition module and the inference module into an AI dynamic probe, and implanting the AI dynamic probe into the target component further includes: Monitor change events in the domestic IT innovation knowledge base; When a change event is detected, the changes made in the change event are compiled into a lightweight policy package; The lightweight policy package is pushed to the deployed AI dynamic probe via edge nodes; When the AI dynamic probe receives the lightweight policy package, it hot-loads and updates the inference module.
8. An intelligent detection device based on an AI dynamic probe, characterized in that, The AI-based dynamic probe-based intelligent detection device includes: The probe implantation module is used to match the acquisition module and the inference module according to the monitoring task, assemble the acquisition module and the inference module into an AI dynamic probe, and implant the AI dynamic probe into the target component; The data processing module is used to capture multi-source operational data of the target component in real time according to the monitoring task by the AI dynamic probe, preprocess the multi-source operational data, and generate multi-source heterogeneous monitoring data. The feature recognition module is used to identify key information technology innovation features based on the component type labels of the multi-source heterogeneous monitoring data through an adaptive feature extraction framework; A vector construction module is used to construct standardized feature vectors based on the key information technology innovation features; The detection output module is used to perform fusion analysis on the multi-source heterogeneous monitoring data, key information technology innovation features and standardized feature vectors by using a long short-term memory network and combining it with a graph neural network, and output a four-dimensional information technology innovation index.
9. A computer device, characterized in that, The computer device includes a memory, a processor, and an AI-based dynamic probe-based intelligent detection program stored in the memory and executable on the processor. When executed by the processor, the AI-based dynamic probe-based intelligent detection program implements the steps of the AI-based dynamic probe-based intelligent detection method as described in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The storage medium stores an AI-based dynamic probe-based intelligent detection program, which, when executed by a processor, implements the steps of the AI-based dynamic probe-based intelligent detection method as described in any one of claims 1-7.