Semantic adaptation interface and behavior fingerprint authentication method for heterogeneous agents
Patent Information
- Application Number
- CN202611024912.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-10
- Publication Date
- 2026-09-25
AI Technical Summary
[0004]本发明针对现有技术中异构智能体接口适配效率低、身份认证依赖静态凭证无法防范智能体被劫持或仿冒、以及缺乏语义层面安全验证的技术问题,提供一种面向异构智能体的语义适配接口与行为指纹认证方法
相较于现有技术,本发明首先通过多模态解析引擎将目标智能体的原始输出自动转换为标准化操作指令,并评估操作风险等级,无需人工编写适配器,解决了异构输出格式的接入障碍。其次,构建基于行为指纹库的动态认证体系,通过提取时序特征、语义特征与交互模式特征评估行为相似度,能够及时发现智能体行为异常,防范合法智能体被劫持后的恶意操作。再次,融合操作风险等级、行为相似度与信任等级,通过动态阈值规则进行智能体验证,对高风险或行为偏离的操作予以拒绝并触发告警。本发明通过语义适配与行为指纹的协同机制,实现了异构智能体的高效接入与持续可信认证,保障了物理世界控制系统的运行安全。
Smart Images

Figure CN122818339A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of fingerprint recognition technology, specifically to a semantic adaptation interface and behavioral fingerprint authentication method for heterogeneous intelligent agents. Background Technology
[0002] Heterogeneous intelligent agents include large language models, industrial robots, automation scripts, and human operators, with output formats encompassing natural language, JSON structured data, binary protocols, and more. Existing control systems typically only recognize instructions in specific formats, requiring manual adapter writing for each agent, leading to inefficient integration and a high risk of errors. Current authentication methods largely rely on static keys or digital signatures, failing to prevent the hijacking of legitimate agents or the impersonation of malicious ones. Once keys are leaked, attackers can arbitrarily manipulate physical devices. Existing systems lack semantic-level security verification capabilities; even if the instruction format is correct, the intent may still violate physical laws or security policies, causing equipment damage or security incidents.
[0003] Therefore, there is an urgent need for a universal semantic adaptation interface and behavioral fingerprint authentication mechanism to ensure that heterogeneous intelligent agents can securely and reliably access the physical world control system. Summary of the Invention
[0004] This invention addresses the technical problems in existing technologies, such as low efficiency of heterogeneous intelligent agent interface adaptation, reliance on static credentials for identity authentication which cannot prevent intelligent agents from being hijacked or impersonated, and lack of semantic-level security verification. It provides a semantic adaptation interface and behavior fingerprint authentication method for heterogeneous intelligent agents.
[0005] The technical solution of the present invention to solve the above-mentioned technical problems is as follows: This invention provides a semantic adaptation interface and behavioral fingerprint authentication method for heterogeneous intelligent agents, including: Receive the raw output from the target intelligent agent, convert the raw output into standardized operation instructions through multimodal parsing, and perform an operation risk assessment; Establish and maintain a behavioral fingerprint database for heterogeneous intelligent agents, and evaluate the behavioral similarity of the original output based on the behavioral fingerprint database; Combining the operational risk assessment results with the behavioral similarity, agent verification is performed based on dynamic threshold rules, and the standardized operation instructions are triggered according to the agent verification results.
[0006] The beneficial effects of this invention are: Compared to existing technologies, this invention firstly automatically converts the raw output of the target intelligent agent into standardized operation instructions through a multimodal parsing engine and assesses the operation risk level, eliminating the need for manually written adapters and overcoming the access barrier of heterogeneous output formats. Secondly, it constructs a dynamic authentication system based on a behavioral fingerprint database, evaluating behavioral similarity by extracting temporal features, semantic features, and interaction pattern features, enabling timely detection of abnormal agent behavior and preventing malicious operations after legitimate agents are hijacked. Thirdly, it integrates operation risk level, behavioral similarity, and trust level, using dynamic threshold rules to verify the intelligent agent, rejecting high-risk or behaviorally deviant operations and triggering alarms. This invention, through the collaborative mechanism of semantic adaptation and behavioral fingerprinting, achieves efficient access and continuous trusted authentication of heterogeneous intelligent agents, ensuring the operational security of physical world control systems. Attached Figure Description
[0007] Figure 1 This is a flowchart illustrating the semantic adaptation interface and behavioral fingerprint authentication method for heterogeneous intelligent agents provided by the present invention. Figure 2 This is a schematic diagram illustrating the process of establishing a behavioral fingerprint database for heterogeneous intelligent agents, as provided by the present invention. Detailed Implementation
[0008] Examples, such as Figure 1 As shown, embodiments of the present invention provide a semantic adaptation interface and behavioral fingerprint authentication method for heterogeneous intelligent agents, including: S10: Receive the raw output sent by the target intelligent agent, convert the raw output into standardized operation instructions through multimodal parsing, and perform operation risk assessment; In physical world control systems, various types of intelligent agents need to be integrated, including large language models, industrial robots, automation scripts, and human operators. The raw output formats issued by these agents differ; for example, some use natural language text, while others use JSON structured data or binary protocols. The control system cannot directly understand these heterogeneous output formats, therefore this step is necessary to unify the raw output processing.
[0009] Specifically, this step receives the raw output from the target agent and converts it into standardized operation instructions that the control system can recognize using multimodal parsing technology. Multimodal parsing refers to the process of calling the corresponding parsing sub-engine for processing based on the data format type of the raw output. After parsing, standardized operation instructions are generated. Simultaneously, to prevent high-risk operations from being mistakenly executed, this step also performs an operational risk assessment on the converted standardized operation instructions, determining the risk level based on the operation category involved in the instruction. This addresses the access barrier caused by the inconsistent output formats of heterogeneous agents and provides a quantitative basis for operational risk for subsequent agent verification.
[0010] Specifically, the system receives the raw output from the target agent, converts the raw output into standardized operation instructions through multimodal parsing, and performs an operation risk assessment, including: Obtain the data format type of the original output, wherein the data format type includes at least natural language text format, structured data format, and binary protocol format; According to the data format type, the corresponding parsing sub-engine is called to sequentially perform semantic disambiguation and intent recognition on the original output to obtain the operation intent vector and operation parameters. The operation intent vector and the operation parameters are mapped to a preset standardized instruction template to generate the standardized operation instruction; The operational risk level is determined based on the operational categories involved in the standardized operational instructions. The operational categories include at least read-only query operations, parameter configuration operations, and physical execution operations.
[0011] First, determine the data format type of the raw output. The raw output issued by the target agent may use different data formats, including at least natural language text format, structured data format, and binary protocol format. Natural language text format is common in human operators or large language models, such as "set the temperature of area A to 25 degrees"; structured data format is common in API calls or automation scripts, such as JSON key-value pairs; binary protocol format is common in industrial robots or IoT devices, such as custom byte stream protocols.
[0012] Secondly, based on the data format type, the corresponding parsing sub-engine is called to sequentially perform semantic disambiguation and intent recognition on the original output to obtain the operation intent vector and operation parameters.
[0013] Specifically, for natural language text formats, the large language model parsing sub-engine is invoked to dissolve ambiguity and identify user intent through semantic understanding; for example, parsing "raise the temperature a little" in "raise the temperature a little" into a specific temperature increment value. For structured data formats, the JSON Schema validator parsing sub-engine is invoked to validate the data structure and extract field values. For binary protocol formats, the code parser parsing sub-engine is invoked to deserialize and decode according to the protocol specification. After parsing, a structured operation intent vector and operation parameters are obtained. The operation intent vector represents the type of operation the agent wishes to perform, and the operation parameters represent the specific numerical value or target object of the operation.
[0014] The corresponding parsing sub-engines are pre-configured and specifically trained or customized for different data format types, selected based on the format type identifier or content characteristics of the original output. Optionally, the large language model parsing sub-engine uses a pre-trained general-purpose large language model, fine-tuned with domain-specific prompt word templates, enabling the model to convert ambiguous expressions in natural language into precise operational parameters, such as mapping "turn it up a little" to a specific temperature increment value. The JSON Schema validator parsing sub-engine, based on a predefined JSON Schema specification file, performs field type validation, required field checks, and numerical range validation on the input structured data, extracting field values that conform to the specification. The code parser parsing sub-engine is written for a specific binary protocol specification, using steps such as protocol header recognition, byte order conversion, and data unpacking to restore binary data into readable operational fields. The above parsing sub-engines can be implemented using existing mature parsing technologies, but require customized configuration for the operational semantics of the physical world control system to ensure the accuracy and security of the parsing results.
[0015] Then, the operation intent vector and operation parameters are mapped to a preset standardized instruction template to generate standardized operation instructions. The standardized instruction template is comprehensively set according to the instruction specification requirements of the physical world control system and the set of operation types that the system needs to perform. It is used to unify the heterogeneous outputs of different intelligent agents into a standard format that the system can recognize, eliminating access barriers caused by differences in data formats.
[0016] Optionally, the standardized instruction template is set up as follows: First, analyze all operation types that the physical world control system can recognize, including equipment control, parameter adjustment, status query, etc.; second, define a unified field structure for each operation type, such as an agent identifier field to indicate the source of the instruction, an operation intent field to indicate the type of operation to be performed, a target object field to specify the device or area to be operated on, an operation parameter field to carry specific values or status, and a timestamp field to record the time the instruction was issued; finally, combine the above fields into a fixed template format.
[0017] For example, in an agricultural greenhouse scenario, the standardized instruction template can be set as follows: the agent identifier field is 16 bytes long; the operation intent field uses enumerated values (01 for adjusting temperature, 02 for adjusting humidity, and 03 for querying status); the target object field uses a region number plus a device type code; the operation parameter field uses floating-point numbers to represent the target value; and the timestamp field uses a Unix timestamp format. Through this standardized instruction template, the raw outputs from different agents can be parsed and filled into a unified format to generate standardized operation instructions that the control system can directly understand and execute.
[0018] Finally, the operational risk level is determined based on the operational categories involved in the standardized operating instructions. These operational categories include at least read-only query operations, parameter configuration operations, and physical execution operations. Read-only query operations are used to read system status or data without changing the system's operating state; they have the lowest risk level, such as querying the current temperature value. Parameter configuration operations are used to modify system parameters, changing the system's operating strategy but not directly driving physical devices; they have a medium risk level, such as modifying the temperature setpoint. Physical execution operations are used to directly control physical devices to perform actions, changing the state of the physical world; they have the highest risk level, such as starting a heater or opening a valve.
[0019] By determining the operational risk level, we can provide a quantitative basis for adjusting the dynamic threshold in subsequent agent verification, ensuring that high-risk operations require more stringent behavioral similarity verification.
[0020] S20: Establish and maintain a behavioral fingerprint database for heterogeneous intelligent agents, and evaluate the behavioral similarity of the original output based on the behavioral fingerprint database; Secondly, after multimodal parsing converts the raw output into standardized operation instructions, the agent's identity and credibility need to be verified. Traditional static keys or digital signatures cannot prevent malicious behavior after the agent is hijacked; therefore, this step introduces a dynamic authentication mechanism based on behavioral characteristics.
[0021] Specifically, this step first establishes and maintains a behavioral fingerprint database for heterogeneous intelligent agents. The behavioral fingerprint database is a database storing behavioral feature templates for each intelligent agent. During registration or observation, each agent's multi-dimensional behavioral characteristics in a controlled environment are collected, including the time distribution of command issuance, decision-making time, output format preferences, and consistency of responses to standard test scenarios. This constructs a unique behavioral fingerprint template for that agent, which is then bound and stored with the agent's unique identifier. The behavioral fingerprint template represents the agent's behavioral pattern under normal conditions.
[0022] Based on the established behavioral fingerprint database, this step further evaluates the behavioral similarity of the currently received raw output. Specifically, behavioral feature vectors are extracted from the current interaction and compared with the historical behavioral fingerprint templates corresponding to the agent in the behavioral fingerprint database to calculate a similarity score. A higher similarity score indicates that the current behavior is closer to the agent's normal behavior pattern; a lower similarity score indicates that the behavior is abnormal, and there may be a risk of the agent being hijacked or impersonated. Through continuous behavioral feature comparison, dynamic and reliable verification of the agent's identity can be achieved, thus compensating for the inherent defects of static credential authentication.
[0023] First, such as Figure 2 As shown, establishing and maintaining a behavioral fingerprint database for heterogeneous intelligent agents includes: In a controlled environment, behavioral data of multiple heterogeneous target intelligent agents are collected, and multi-dimensional behavioral features are extracted to construct an initial behavioral fingerprint template. The multi-dimensional behavioral features include at least temporal features, semantic features, and interaction pattern features. The initial behavioral fingerprint template is stored in a distributed ledger to generate a fingerprint identifier that uniquely corresponds to the target intelligent agent, thereby obtaining the behavioral fingerprint database; The behavioral fingerprint database is configured with progressive trust level management, including sandbox period, observation period, standard period, trust period and privilege period.
[0024] First, in a controlled environment, behavioral data from multiple heterogeneous target agents are collected, and multi-dimensional behavioral features are extracted to construct an initial behavioral fingerprint template. The controlled environment refers to the secure testing environment in which the agent first accesses the system, where the agent's operations will not affect the actual physical devices. Behavioral data refers to the interaction records generated by the agent during the execution of various tasks, including the time of instruction issuance, decision-making time, output format, and instruction content.
[0025] Specifically, multidimensional behavioral features include at least temporal features, semantic features, and interaction pattern features. Temporal features reflect the agent's behavioral patterns over time, such as the distribution of command issuance frequency, active periods, and statistical values of decision-making time. Semantic features reflect the language style and vocabulary habits of the agent's output, such as commonly used command types, parameter value preferences, and sentence structure. Interaction pattern features reflect the interaction methods between the agent and the system, such as the stability of response latency, whether multiple interactions are required to complete a single task, and the handling of abnormal situations. These features, after feature engineering, are used to construct a unique initial behavioral fingerprint template for the agent.
[0026] Optionally, for the instruction issuance time in the time-series features, the frequency distribution of instruction issuance in each time period of the day is statistically analyzed to construct a 24-dimensional frequency vector; for decision-making time consumption, the mean, standard deviation, and quantile values of decision-making time consumption for all interaction records are calculated; for output format preference, the frequency of occurrence of natural language format, JSON format, and binary protocol format are statistically analyzed; for the operation type distribution in the semantic features, the proportion of occurrence of query, configuration, and control operations are statistically analyzed; for the response latency in the interaction pattern features, the mean and variance of the response latency time series for each interaction are calculated. The statistical values of the above features are combined into a multi-dimensional feature vector, which serves as the initial behavioral fingerprint template for the agent.
[0027] Secondly, the initial behavioral fingerprint template is stored in a distributed ledger to generate a fingerprint identifier uniquely corresponding to the target agent, thus obtaining the behavioral fingerprint database. A distributed ledger is a data recording system that shares, replicates, and synchronizes data among multiple nodes in a network. This distributed ledger is implemented using blockchain technology, specifically storing the behavioral fingerprint template in encrypted form across multiple consensus nodes to prevent tampering. Blockchain technology is a decentralized distributed database technology where data is linked in chronological order in blocks. Each block contains a timestamp and the hash value of the previous block, making it difficult to tamper with once data is written. Consensus nodes refer to multiple computer devices participating in the blockchain network to verify and store data. Each device independently maintains a complete copy of the ledger, and the consistency of data across nodes is ensured through a consensus algorithm.
[0028] Specifically, each agent corresponds to a unique fingerprint identifier, which is bound to the agent's digital identity. The digital identity is a globally unique string generated using distributed identity technology, used to identify the agent within the network. The final behavioral fingerprint database is the collection of behavioral fingerprint templates and their fingerprint identifiers for all agents, serving as a comparison benchmark for subsequent behavioral similarity assessments. By storing the behavioral fingerprint templates in a distributed ledger, the integrity and immutability of the template data are ensured, preventing attackers from maliciously modifying the behavioral fingerprints of registered agents.
[0029] Finally, the behavioral fingerprint database is configured with progressive trust level management, including a sandbox period, observation period, standard period, trust period, and privileged period. The sandbox period is the initial stage when an agent first joins the system. During this stage, the agent can only perform operations in an isolated environment, and all instructions must be manually reviewed before release. Behavioral data is collected to construct the initial fingerprint. The observation period is the stage where the agent's behavior is initially stable. During this stage, the agent can perform operations within a limited scope. The system continuously collects behavioral data and verifies its consistency with the behavioral fingerprint template. The standard period is the stage where the agent's behavior fully conforms to the behavioral fingerprint template. During this stage, the agent can perform operations with normal permissions, and the system periodically performs behavioral sampling verification. The trust period is the stage where the agent has been running for a long time and its behavior is highly stable. During this stage, the agent enjoys higher operating permissions, and updates to the behavioral fingerprint template require multi-party approval. The privileged period is the stage where the agent is recognized as completely trustworthy. During this stage, the agent can perform operations with the highest permissions, and updates to the behavioral fingerprint template require a more stringent consensus process.
[0030] The settings for each stage are based on factors such as the agent's cumulative runtime, behavioral consistency, number of completed tasks, and whether the behavior fingerprint template update has been approved. Optionally, the sandbox period duration is set according to the agent type; for example, for a newly added unknown agent, the sandbox period can be set to 24 hours or 10 operations. The observation period duration is set based on the accumulation of behavioral data; for example, it automatically enters the standard period after accumulating 100 valid behavioral records. The standard period duration is set according to the system's security policy; for example, it enters the trust period after 30 days of stable operation without any abnormal alarms. The trust period duration is set according to the agent's importance; for example, it enters the privileged period after 90 days of continuous operation and a successful behavior fingerprint template update. The privileged period has no fixed duration and continues until behavioral anomalies are detected or the behavior fingerprint template update fails. Through this progressive trust level management, the system can dynamically adjust the agent's permission scope and verification strength based on the agent's runtime and behavioral stability, ensuring security while avoiding excessive verification that could affect normal operational efficiency.
[0031] In addition, establishing and maintaining a behavioral fingerprint database for heterogeneous intelligent agents also includes: When the behavioral data of the target agent accumulates to a preset amount, the update evaluation of the behavioral fingerprint template is triggered, a new behavioral fingerprint template is calculated, and the difference between the new behavioral fingerprint template and the current behavioral fingerprint template is evaluated. If the difference exceeds a preset security range, the update is rejected and an alarm is triggered; otherwise, adaptive routing is performed based on the trust level of the current behavior fingerprint template, including: If the trust level is a trust period, then submit an update proposal for the behavior fingerprint template; otherwise, update directly based on the new behavior fingerprint template. The updated proposal is sent to multiple preset approval nodes for independent approval, and the approval results of each approval node are obtained. If the approval result is passed, then enter shadow mode and update management is performed based on the new behavior fingerprint template and the current behavior fingerprint template.
[0032] When the behavioral data of the target agent accumulates to a preset amount, an update evaluation of the behavioral fingerprint template is triggered. As the agent operates over a long period, its behavioral patterns may gradually change. For example, the operating habits of a human operator may slowly change over time, and the decision-making patterns of a machine learning model may drift due to version updates. Therefore, it is necessary to trigger the update evaluation of the behavioral fingerprint template periodically or based on a data volume threshold. The preset amount can be set according to the type of agent; for example, an update evaluation may be triggered every 500 valid behavioral records accumulated.
[0033] At this point, a new behavioral fingerprint template is calculated, and the difference between the new behavioral fingerprint template and the current behavioral fingerprint template is evaluated. The new behavioral fingerprint template is recalculated based on a preset number of recently accumulated behavioral data. Similarly, the method for constructing the initial behavioral fingerprint template described above is used. Taking a preset number of 500 data points as an example, multidimensional behavioral features, including temporal features, semantic features, and interaction pattern features, are extracted from these 500 behavioral data points. These features are statistically calculated separately and combined into a feature vector, which serves as the new behavioral fingerprint template.
[0034] The dissimilarity measure quantifies the degree of deviation between the new behavioral fingerprint template and the current behavioral fingerprint template. Optionally, a vector distance metric, such as Euclidean distance, can be used. The greater the calculated dissimilarity measure, the more significant the change in the agent's behavioral pattern.
[0035] If the difference exceeds a preset safety range, the update is rejected and an alarm is triggered. The preset safety range is set based on the normal fluctuation range of the agent's behavior pattern; for example, the upper limit of the difference threshold can be set to 0.3. When the difference exceeds this threshold, it indicates an abnormal change in the agent's behavior, potentially indicating a risk of the agent being hijacked or impersonated. Therefore, the behavior fingerprint template update is rejected, an alarm is triggered, and the system administrator is notified to conduct a manual verification.
[0036] If the difference is within a preset security range, adaptive routing is performed based on the trust level of the current behavioral fingerprint template. The trust levels include sandbox period, observation period, standard period, trust period, and privileged period. Adaptive routing refers to selecting different update paths based on the trust level.
[0037] Specifically, if the current trust level is in the Trust Period, it indicates that the agent has been deemed highly trustworthy, and changes in its behavior pattern require confirmation from multiple parties. Therefore, a proposal to update the behavior fingerprint template is submitted and awaits approval. If the trust level is in the Sandbox Period, Observation Period, or Standard Period, it indicates that the agent is still in the monitoring phase and can be directly updated based on the new behavior fingerprint template without approval. Furthermore, if the current trust level is in the Privilege Period, no behavior fingerprint template update assessment is triggered because the agent's behavior during the Privilege Period has been deemed completely trustworthy and does not require updating.
[0038] When submitting a behavioral fingerprint template update proposal, the proposal is sent to multiple pre-defined approval nodes for independent review, and the approval results from each node are obtained. Approval nodes refer to multiple entities with approval authority within the system, such as other trusted intelligent agents, system administrators, or consensus nodes. Each approval node independently reviews the behavioral fingerprint template update proposal and provides a pass or fail approval result. This multi-party independent approval process prevents improper updates caused by single points of failure or attacks on a single approver.
[0039] In addition, sending the updated proposal to multiple preset approval nodes for independent approval and obtaining the approval results from each node also includes: Initiate a time lock, and record the lock start time and lock duration, wherein the lock duration is determined based on the target agent's current trust level; Based on the time lock, the behavior of the target agent is continuously drift detected. If the drift detection result triggers a severe drift threshold during the locking period of the time lock, the behavior fingerprint template update is canceled and an alarm is triggered. If the lockout period expires and the approval result of each approval node is "pass", the update proposal will be marked as "activatable" and the approval result will be "pass". If the approval results of each approval node do not reach the preset approval ratio when the lock period expires, the update proposal will be marked as rejected, the approval result will be unsuccessful, and the submission record and approval record will be stored in the distributed ledger.
[0040] Initiate a time lock, recording the lock start time and lock duration. A time lock is a time-based control mechanism used to set a waiting period after a behavioral fingerprint template update proposal is submitted. During this period, the update is not executed immediately, but rather waits for multi-party approval and observation of agent behavior stability. The lock duration is determined based on the target agent's current trust level. Trust levels, from low to high, are sandbox period, observation period, standard period, and trust period, each corresponding to a different lock duration.
[0041] Optionally, the sandbox period is the initial stage when the agent first connects to the system, before behavioral patterns are established. The behavioral fingerprint template update requires the longest observation time, and the lockout duration can be set to 168 hours (7 days). The observation period is the stage where the agent's behavior is initially stable, and the lockout duration can be set to 72 hours (3 days). The standard period is the stage where the agent's behavior fully conforms to the behavioral fingerprint template, and the lockout duration can be set to 48 hours (2 days). The trust period is the stage where the agent operates long-term and its behavior is highly stable, and the lockout duration can be set to 24 hours (1 day). The principle for setting the above lockout durations is: the lower the trust level, the greater the uncertainty of the agent's behavior, requiring a longer observation time to confirm the security of the behavioral fingerprint template update; the higher the trust level, the more fully verified the agent's behavior has been, and the lockout duration can be shortened accordingly to improve update efficiency.
[0042] For example, if an agent is currently in an observation period and submits a proposal to update its behavior fingerprint template, a time lock is activated. The lock start time is recorded as 8:00:00 AM on January 1, 2025, and the lock duration is set to 72 hours. The lock period expires at 8:00:00 AM on January 4, 2025. During these 72 hours, the system waits for multi-party approvals and continuously monitors the agent's behavior for any abnormal drift. Through this hierarchical setting, the time lock can adaptively adjust the waiting time according to the agent's trust level, optimizing update efficiency while ensuring security.
[0043] Secondly, based on time locks, drift detection is continuously performed on the target agent's behavior. Drift detection refers to continuously monitoring the deviation between the agent's real-time behavioral features and the current behavioral fingerprint template. Optionally, the deviation degree is quantified as follows: within each detection cycle, the target agent's behavioral data for that cycle is extracted, and multi-dimensional behavioral features are extracted using the same method as constructing the behavioral fingerprint template to form a real-time feature vector; the Euclidean distance or cosine distance between the real-time feature vector and the feature vector of the current behavioral fingerprint template is calculated, and the calculated distance value is used as the deviation degree value. The deviation degree value ranges from 0 to positive infinity, where 0 represents complete consistency, and a larger value indicates a more severe deviation.
[0044] If the drift detection result triggers a severe drift threshold during the time lock period, the behavior fingerprint template update is canceled and an alarm is triggered. The severe drift threshold is a pre-set upper limit for the degree of difference, for example, it can be set to 0.5. After calculating the deviation value in each detection cycle, this value is compared with the severe drift threshold. When the deviation value is greater than 0.5, the severe drift threshold is determined to be triggered. If the agent's behavior deviates severely during the lock period, it indicates that the agent may have been hijacked or its behavior pattern has changed abnormally. In this case, the behavior fingerprint template update proposal is canceled, and an alarm is sent to the system administrator. The alarm content includes the agent's identifier, trigger time, deviation value, and current trust level. Through the above quantitative detection mechanism, the system can continuously evaluate the agent's behavioral stability during the behavior fingerprint template update waiting period, ensuring that behavior fingerprint template updates are only allowed when the agent's behavior is normal.
[0045] If the lockout period expires and all approval nodes pass, the behavior fingerprint template update proposal will be marked as activatable. The lockout period expires when the cumulative duration from the start of the time lock to the current moment has reached the required lock duration. The activatable status indicates that the behavior fingerprint template update proposal has passed multi-party approval and lockout period observation, meeting the activation conditions, but has not yet officially replaced the current behavior fingerprint template.
[0046] Furthermore, if the approval results of each approval node do not reach the preset approval ratio by the end of the lock period, the behavioral fingerprint template update proposal will be marked as rejected. The preset approval ratio can be set according to the system's security policy, such as requiring more than half or two-thirds of the approval nodes to agree. If the number of approval votes does not reach this ratio, it indicates that the behavioral fingerprint template update has not gained sufficient trust, and the update proposal is rejected. Submission and approval records are stored in a distributed ledger, including the submission time of the behavioral fingerprint template update proposal, the proposal content, the approval opinions of each approval node, the approval time, and the final rejection status, ensuring that the entire approval process is traceable and tamper-proof. Specifically, this step aims to prevent malicious or improper updates to the behavioral fingerprint template through a time-locked, multi-party approval collaborative mechanism, ensuring the reliability and security of the behavioral fingerprint database.
[0047] Specifically, if the approval result is passed, the system enters shadow mode, where updates are managed based on the new behavioral fingerprint template and the current behavioral fingerprint template. Shadow mode is a secure update verification mechanism. In this mode, the new behavioral fingerprint template and the current behavioral fingerprint template run simultaneously. The system uses both templates to calculate behavioral similarity and compares their performance differences, but does not immediately switch to the new template. The validity and security of the new template are continuously verified through shadow mode, and formal activation is only performed after confirmation that everything is correct. Shadow mode ensures the security of behavioral fingerprint template updates, preventing malicious agents from masking abnormal behavior by frequently updating fingerprints, while allowing the gradual changes in the behavioral patterns of normal agents to be reasonably incorporated into the behavioral fingerprint template.
[0048] Specifically, entering shadow mode involves updating and managing the new behavior fingerprint template based on the new behavior fingerprint template and the current behavior fingerprint template, including: Simultaneously using the new behavior fingerprint template and the current behavior fingerprint template, the behavior similarity of the target agent is calculated respectively, and the new fingerprint similarity sequence and the current fingerprint similarity sequence are obtained; Calculate the difference index between the new fingerprint similarity sequence and the current fingerprint similarity sequence, wherein the difference index includes at least the mean difference and the variance difference; Based on the difference index, the drift rate of the new fingerprint similarity sequence is continuously calculated and monitored. If the drift rate exceeds the preset shadow mode drift threshold, the shadow mode is terminated and the system is rolled back to the current behavior fingerprint template. If the drift rate under the difference index is within the preset shadow mode drift threshold when the shadow mode runs to the preset verification period, the new behavior fingerprint template is marked as verified, the template activation operation is performed, and the behavior fingerprint template update event is stored in the distributed ledger.
[0049] First, the new behavioral fingerprint template and the current behavioral fingerprint template are used simultaneously to calculate the behavioral similarity of the target agent, obtaining the new fingerprint similarity sequence and the current fingerprint similarity sequence. In shadow mode, the system runs the new behavioral fingerprint template and the current behavioral fingerprint template simultaneously. For each interaction, the behavioral similarity is calculated using both templates. The new fingerprint similarity sequence is a sequence of similarity values calculated using the new behavioral fingerprint template, arranged in chronological order. The current fingerprint similarity sequence is a sequence of similarity values calculated using the current behavioral fingerprint template, arranged in chronological order. The length of each sequence is equal to the number of interactions collected during the shadow mode operation.
[0050] Secondly, the difference indices between the new fingerprint similarity sequence and the current fingerprint similarity sequence are calculated. These indices include at least the mean difference and the variance difference. The mean difference equals the average of the new fingerprint similarity sequence minus the average of the current fingerprint similarity sequence, reflecting the deviation between the two templates in terms of overall similarity level. The variance difference equals the variance of the new fingerprint similarity sequence minus the variance of the current fingerprint similarity sequence, reflecting the deviation between the two templates in terms of similarity stability. When the new behavioral fingerprint template correctly reflects the agent's behavior, the new fingerprint similarity sequence should be close to the current fingerprint similarity sequence, with both the mean difference and the variance difference approaching zero.
[0051] Furthermore, based on the difference index, the drift rate of the new fingerprint similarity sequence is continuously calculated and monitored. The drift rate refers to the rate of change of the new fingerprint similarity sequence over time, and is used to measure whether the similarity output of the new behavioral fingerprint template undergoes a systematic shift over time.
[0052] Optionally, the drift rate can be calculated as follows: Assume the new fingerprint similarity sequence consists of similarity values arranged chronologically, with each similarity value corresponding to an interaction time. Take the N most recent similarity values to form a sliding window. N can be set according to the system sampling frequency, for example, taking the similarity values corresponding to the 20 most recent interaction records. Within this sliding window, perform linear regression fitting with the interaction number or time as the x-axis and the similarity value as the y-axis to obtain the slope of the fitted line. The absolute value of this slope is the drift rate. A positive slope indicates that the similarity increases over time, while a negative slope indicates that the similarity decreases over time. The unit of the drift rate depends on the unit of the x-axis. When the x-axis is the interaction number, the unit of the drift rate is per interaction; when the x-axis is time, the unit of the drift rate is per hour. For example, in the last 20 interactions, the similarity value gradually decreased from 0.85 to 0.75. The slope of the fitted line is -0.005 per interaction. Multiplying this by the interaction frequency converts it to -0.05 per hour, so the absolute value of the drift rate is 0.05 per hour.
[0053] If the drift rate exceeds the preset shadow mode drift threshold, the shadow mode is terminated, and the system rolls back to the current behavior fingerprint template. The shadow mode drift threshold is set according to the system's requirements for behavior stability; for example, the drift rate threshold can be set to 0.05 per hour. When the drift rate exceeds this threshold, it indicates that the similarity of the new behavior fingerprint template output is unstable and may have problems. In this case, the shadow mode is terminated, the system rolls back to the current behavior fingerprint template, and the update is abandoned.
[0054] Furthermore, if the drift rate of the difference indicators remains within the preset shadow mode drift threshold during the preset verification period, the new behavioral fingerprint template is marked as verified and the template activation operation is performed. The verification period is the shortest duration for continuous operation of the shadow mode, which can be set to 72 hours or 100 interactions. Within the verification period, if the mean difference and variance difference remain within acceptable ranges and the drift rate remains below the threshold, it indicates that the new behavioral fingerprint template performs stably under long-term, multi-interaction conditions. At this point, the new behavioral fingerprint template is marked as verified and officially activated to replace the current behavioral fingerprint template.
[0055] Simultaneously, the behavior fingerprint template update event is stored in the distributed ledger. The stored information includes the hash value of the new behavior fingerprint template, the hash value of the old behavior fingerprint template, statistical values of the difference indicators during the shadow mode operation, drift rate records, verification cycle duration, and activation time. This storage ensures that the behavior fingerprint template update process is traceable and tamper-proof, and provides a basis for post-event auditing. The introduction of shadow mode allows the system to fully verify the stability and reliability of a new behavior fingerprint template before its official activation, avoiding behavior authentication failure due to erroneous behavior fingerprint templates.
[0056] Furthermore, after the behavioral fingerprint database is constructed, the behavioral similarity of the original output is evaluated. The behavioral fingerprint database represents the behavioral pattern benchmark established by the target agent during its historical operation, used to quantitatively describe the temporal patterns, semantic habits, and interaction characteristics of the agent under normal conditions; the original output is the real-time instructions and related behavioral data issued by the target agent in the current interaction. By comparing the real-time behavioral feature vector extracted from the original output with the behavioral fingerprint templates stored in the behavioral fingerprint database in multiple dimensions, temporal similarity, semantic similarity, and pattern similarity can be calculated, and then weighted and fused to obtain the behavioral similarity, thereby assessing the degree of consistency between the current behavior and historical behavioral patterns, and determining whether the agent has the risk of behavioral abnormalities or being hijacked.
[0057] Specifically, based on the behavioral fingerprint database, the behavioral similarity of the original output is evaluated, including: Extract behavioral feature vectors from the original output, wherein the behavioral feature vectors include at least temporal behavioral feature vectors, semantic behavioral feature vectors, and interaction pattern feature vectors; Calculate the temporal similarity, semantic similarity, and pattern similarity between the behavioral feature vector and the corresponding dimensions of the behavioral fingerprint template, respectively. The temporal similarity, semantic similarity, and pattern similarity are weighted and fused according to preset weight coefficients to obtain the behavioral similarity.
[0058] First, behavioral feature vectors are extracted from the raw output. Specifically, each time the agent issues raw output, the system synchronously records the behavioral data of that interaction, including the time of instruction issuance, decision-making time, output format type, instruction content, operation parameters, and response latency. Based on the behavioral data, behavioral feature vectors are extracted in three dimensions. The temporal behavioral feature vector reflects the agent's behavioral patterns over time, including the time period encoding of the current instruction issuance within a 24-hour period, the time interval since the last instruction issuance, and the ratio of the current decision-making time to the agent's historical average decision-making time. The semantic behavioral feature vector reflects the style and habits of the agent's output content, including the operation type encoding of the current instruction, the deviation of operation parameter values from historical parameter distributions, and the matching degree between the output format type and historical format preferences. The interaction mode feature vector reflects the interaction method between the agent and the system, including the response latency of the current interaction, whether a retry is needed, and whether there are any abnormal interruptions.
[0059] Secondly, the temporal similarity, semantic similarity, and pattern similarity are calculated between the behavioral feature vector and the corresponding dimensions in the behavioral fingerprint template. The behavioral fingerprint template stores the multi-dimensional feature statistics constructed by the agent under controlled conditions. For the temporal behavioral feature vector, the time period encoding, time interval ratio, and decision time ratio are compared with the corresponding statistical values in the behavioral fingerprint template, and the temporal similarity is calculated using the Gaussian probability density function or the inverse distance method, with values ranging from 0 to 1. For the semantic behavioral feature vector, the operation type encoding, parameter deviation, and format matching degree are compared with the corresponding distributions in the behavioral fingerprint template, and the semantic similarity is calculated using cosine similarity or Jaccard similarity coefficient. For the interaction pattern feature vector, the response latency, retry identifier, etc., are compared with the statistical values in the behavioral fingerprint template, and the pattern similarity is obtained using a matching degree calculation method.
[0060] Then, based on preset weight coefficients, temporal similarity, semantic similarity, and pattern similarity are weighted and fused to obtain behavioral similarity. The values for temporal similarity, semantic similarity, and pattern similarity all range from 0 to 1. When temporal similarity is calculated using the Gaussian probability density function, the output value naturally falls within the 0-1 range, where 1 indicates complete conformity to historical temporal patterns, and 0 indicates complete deviation. When semantic similarity is calculated using cosine similarity, the output value ranges from -1 to 1. Negative values need to be mapped to 0, i.e., values less than 0 are set to 0, thus converting the value range to 0-1. When pattern similarity is calculated using matching degree, the output value ranges from 0 to 1, where 1 indicates a perfect match, and 0 indicates a complete mismatch.
[0061] Specifically, the contributions of temporal similarity, semantic similarity, and pattern similarity to behavioral similarity may differ, therefore different weighting coefficients are set. The sum of the three weighting coefficients is 1. For example, the temporal similarity weight can be set to 0.4, the semantic similarity weight to 0.35, and the pattern similarity weight to 0.25. Behavioral similarity equals temporal similarity multiplied by its temporal weight, plus semantic similarity multiplied by its semantic weight, plus pattern similarity multiplied by its pattern weight.
[0062] Through weighted fusion, behavioral similarity comprehensively reflects the degree of consistency between the agent and its historical behavioral patterns across three dimensions: time, semantics, and interaction patterns. Higher similarity indicates that the current behavior is closer to a normal behavioral pattern, while lower similarity suggests potential abnormalities. This behavioral similarity will serve as the core input for subsequent agent verification, compared with a dynamic threshold to determine whether to grant the instruction.
[0063] In addition, the system dynamically evaluates and adjusts the trust level of the agent based on the historical behavior similarity sequence.
[0064] Specifically, based on the behavioral fingerprint database, the behavioral similarity of the original output is evaluated, and then the process further includes: Obtain the behavior similarity sequence within a preset period window, and calculate a multidimensional evaluation factor based on the behavior similarity sequence. The multidimensional evaluation factor includes at least the window mean similarity, variance, drift rate, and number of consecutive compliances. Based on the aforementioned multidimensional evaluation factors, the trust score of the target intelligent agent is calculated using a weighted average. If the trust score is greater than or equal to the first threshold, the corresponding behavioral fingerprint template enters the upgrade process, and performs pre-check based on the number of jobs, drift rate check and adaptive multi-party approval in sequence, and stores the upgrade event evidence according to the upgrade process result. If the trust score is less than or equal to the second threshold, the corresponding behavioral fingerprint template enters the downgrade process and performs adaptive downgrade based on the relative relationship between the trust score and the second threshold. If the trust score is greater than the second threshold and less than the first threshold, then the current trust level of the corresponding behavioral fingerprint template is maintained.
[0065] First, the behavior similarity sequence within a preset period window is obtained. This preset period window can be set according to the system's evaluation granularity, for example, 7 days or 30 days. Within this preset period window, after each time the agent issues a command and completes the behavior similarity calculation, the similarity value is recorded, forming a behavior similarity sequence arranged in chronological order.
[0066] Secondly, multidimensional evaluation factors are calculated based on the behavioral similarity sequence. These factors include at least the window mean similarity, variance, drift rate, and consecutive compliance count. The window mean similarity is the arithmetic mean of all similarity values within the window, reflecting the average consistency between the agent's behavior and the behavioral fingerprint template within that period. Variance is the average of the squared deviations of each similarity value from the mean within the window, reflecting the stability of similarity value fluctuations; a smaller variance indicates more stable behavior. The drift rate refers to the rate of change of the behavioral similarity sequence over time, which can be obtained through linear regression fitting; positive drift indicates an increasing trend in similarity, while negative drift indicates a decreasing trend. The consecutive compliance count refers to the maximum number of times the behavioral similarity is continuously greater than or equal to the dynamic threshold within the window, reflecting the stability of the agent's continued verification.
[0067] Furthermore, based on multi-dimensional evaluation factors, a weighted trust score is calculated for the target agent. The trust score is a comprehensive quantitative indicator used to characterize the agent's credibility at the current stage. For example, the trust score equals the window mean similarity multiplied by the first weight, plus the variance normalization value multiplied by the second weight, plus the drift rate correction value multiplied by the third weight, plus the normalized value of consecutive compliance count multiplied by the fourth weight. The sum of all weight coefficients is 1. Specific values can be set according to the system's emphasis on different evaluation factors; for example, the window mean similarity weight is set to 0.4, the variance weight to 0.2, the drift rate weight to 0.2, and the consecutive compliance count weight to 0.2.
[0068] Normalization refers to the process of mapping evaluation factors with different dimensions or value ranges to a uniform interval of 0 to 1. The original value ranges of variance and consecutive compliance counts differ from the mean similarity, requiring normalization before weighted fusion. The normalized variance value is calculated as follows: using the maximum possible variance value within the historical monitoring period as the upper limit (e.g., setting the upper limit to 0.25), the original variance is divided by the upper limit to obtain a normalized variance value between 0 and 1; values exceeding the upper limit are assigned a value of 1. The normalized consecutive compliance count value is calculated as follows: using the maximum possible number of interactions within a preset period window as the upper limit, the original consecutive compliance count is divided by the upper limit to obtain a normalized value between 0 and 1. The drift rate correction value is calculated as follows: the drift rate itself can be positive or negative; a positive value indicates an increase in similarity, and a negative value indicates a decrease in similarity. The absolute value of the negative value is taken, normalized to the upper limit, and then multiplied by a negative sign so that the larger the negative value, the greater the negative impact on the trust score. Through the above normalization process, each evaluation factor can be weighted and integrated under a unified scale to obtain a comprehensive trust score.
[0069] Specifically, if the trust score is greater than or equal to the first threshold, it indicates that the agent's behavior is excellent, and the corresponding behavior fingerprint template enters the upgrade process. The first threshold can be set according to the system security policy, for example, 0.85. The upgrade process includes, in sequence, a pre-check based on the number of jobs, a drift rate check, and adaptive multi-party approval. The pre-check based on the number of jobs is used to confirm that the agent has completed a sufficient number of valid operations, for example, requiring at least 1000 valid interactions. The drift rate check is used to confirm that the similarity of the agent's behavior has not shown a significant downward trend. Adaptive multi-party approval refers to sending the upgrade proposal to multiple approval nodes for independent approval, and deciding whether to allow the upgrade based on the approval results. After the upgrade process is completed, the upgrade event is stored in the distributed ledger.
[0070] Furthermore, if the trust score is less than or equal to the second threshold, it indicates that the agent's behavior is poor, and the corresponding behavior fingerprint template enters the degradation process. The second threshold can be set according to the system security policy, for example, set to 0.6, and the second threshold is less than the first threshold. The degradation process adaptively degrades based on the relative relationship between the trust score and the second threshold, and the degradation methods include at least three types: soft degradation, hard degradation, and emergency degradation.
[0071] Soft downgrading refers to maintaining the trust level while increasing the dynamic threshold correction amount for the agent. Soft downgrading is suitable for scenarios where the trust score is slightly below the second threshold and the behavioral deviation is minor. For example, when the trust score is between 0.55 and 0.6, only the base correction amount of the dynamic threshold is increased by 0.05, the trust level remains unchanged, and the agent's subsequent behavior is observed.
[0072] Hard downgrading refers to lowering the trust level by one level. Hard downgrading is suitable for scenarios where the trust score is significantly below the second threshold and the behavioral deviation is moderate. For example, when the trust score is between 0.4 and 0.55, the trust level is lowered by one level from the current level, while the base adjustment amount of the dynamic threshold is restored to the default value. If the agent is already at the lowest trust level, hard downgrading will not continue.
[0073] Emergency downgrade refers to directly lowering the trust level to the lowest available level. Emergency downgrade is suitable for scenarios with extremely low trust scores and severely abnormal behavior. For example, when the trust score is below 0.4, the trust level is directly lowered to the sandbox period, triggering an alarm to notify the system administrator for manual verification. After an emergency downgrade, the agent's operational permissions are significantly reduced, allowing only read-only query operations or completely prohibiting any operations.
[0074] Through the aforementioned three-level adaptive degradation mechanism, differentiated degradation strategies can be adopted based on the degree of decline in the agent's trust score, avoiding overreaction that could affect the operational efficiency of normal agents while ensuring security. After degradation is completed, the degradation event is recorded in a distributed ledger, including the trust level before degradation, the trust level after degradation, the reason for degradation, and the trust score that triggered the degradation.
[0075] If the trust score is greater than the second threshold and less than the first threshold, the current trust level of the corresponding behavioral fingerprint template will be maintained, and no upgrade or downgrade operation will be performed.
[0076] Through the aforementioned trust score assessment and upgrade / downgrade mechanism, the system can dynamically adjust the trust level of the agent based on its actual behavior, achieving progressive trust management from the sandbox period to the privileged period, ensuring security while avoiding human intervention.
[0077] S30: Combining the operational risk assessment results with the behavioral similarity, perform agent verification based on dynamic threshold rules, and trigger the standardized operation instructions according to the agent verification results.
[0078] Furthermore, after obtaining the operational risk assessment results and behavioral similarity, both need to be considered together to make an agent verification decision. The operational risk assessment results reflect the level of security risk that the current instruction may bring, while behavioral similarity reflects the degree of consistency between the current agent's behavior and its historical behavior patterns. High-risk operations require higher behavioral similarity to pass verification, while low-risk operations allow for relatively lower behavioral similarity. Therefore, this step adopts a dynamic threshold rule, dynamically adjusting the verification threshold based on the operational risk level, agent trust level, and drift detection status. The behavioral similarity is compared with the dynamic threshold to determine whether to allow the instruction to be executed or reject it.
[0079] If the behavioral similarity is greater than or equal to the dynamic threshold, the agent verification is deemed successful, triggering the execution of standardized operation instructions. During execution, the system stores key information such as the original output, adaptation results, behavioral similarity, dynamic threshold, and execution results on the blockchain for post-audit purposes. If the behavioral similarity is less than the dynamic threshold, the agent verification is deemed unsuccessful, the standardized operation instructions are refused execution, and an alarm is triggered. The alarm information includes the agent identifier, instruction content, behavioral similarity, dynamic threshold, and rejection time.
[0080] Simultaneously, rejection events and alarm information are stored on the blockchain for evidence. Through this dynamic threshold verification mechanism, the system can adopt differentiated verification standards for operations with different risk levels while ensuring security. This avoids low-risk operations from being inefficient due to overly strict verification, and also avoids high-risk operations from causing security incidents due to overly lenient verification.
[0081] Specifically, combining the operational risk assessment results with the behavioral similarity, agent verification is performed based on dynamic threshold rules, and the standardized operation instructions are triggered according to the agent verification results, including: Obtain the target agent's current trust level and drift detection status; Based on the current trust level, the operational risk level, and the drift detection status, a dynamic threshold is obtained through a preset multi-factor threshold lookup table. The behavior similarity is compared with the dynamic threshold. If the behavior similarity is greater than or equal to the dynamic threshold, the standardized operation instruction is executed, and the original output, the behavior similarity, and the execution result are stored in the distributed ledger. If the similarity of the behavior is less than the dynamic threshold, the standardized operation instruction will be refused to be executed, an alarm will be triggered, and the refusal event and alarm information will be stored in the distributed ledger.
[0082] First, the current trust level and drift detection status of the target agent are obtained. The current trust level is maintained by the progressive trust level management module, including sandbox period, observation period, standard period, trust period, and privilege period. Different trust levels correspond to different baseline credibility. The drift detection status refers to the monitoring result of the deviation between the agent's real-time behavior and the current behavior fingerprint template, including two states: attention state and alarm state. The attention state indicates that the behavior similarity is lower than the preset attention threshold but higher than the preset alarm threshold, indicating that the agent's behavior has deviated slightly and the verification threshold needs to be appropriately increased. The alarm state indicates that the behavior similarity is lower than the preset alarm threshold, indicating that the agent's behavior has deviated significantly and the verification threshold needs to be significantly increased. The attention threshold and alarm threshold are set comprehensively based on the system's sensitivity requirements to behavior deviation and the need to balance the false positive rate and the false negative rate. For example, the attention threshold can be set to 0.7 and the alarm threshold to 0.5. When the behavioral similarity is between 0.5 and 0.7, it is considered a state of concern; when the behavioral similarity is below 0.5, it is considered an alarm state; when the behavioral similarity is greater than or equal to 0.7, it is considered a normal state.
[0083] Secondly, based on the current trust level, operational risk level, and drift detection status, dynamic thresholds are obtained through a pre-defined multi-factor threshold lookup table. The basic threshold lookup table is a two-dimensional table, with the trust level as the row index and the operational risk level as the column index. Each cell in the table stores a corresponding basic threshold value. The lower the trust level and the higher the operational risk level, the higher the corresponding basic threshold. The drift detection status is used to adjust the basic thresholds.
[0084] Specifically, dynamic threshold rules include: Based on the target agent's current trust level and the operational risk level, a basic threshold is obtained from a preset basic threshold lookup table, wherein the basic threshold lookup table uses the trust level as the row index and the operational risk level as the column index. The base threshold is corrected based on the drift detection state, including: When the drift detection state is a state of interest, a first correction amount is added to the base threshold. When the drift detection state is an alarm state, a second correction amount is added to the base threshold, and the second correction amount is greater than the first correction amount.
[0085] First, based on the target agent's current trust level and operational risk level, a basic threshold is retrieved from a pre-defined basic threshold lookup table. This table is a two-dimensional lookup table, with trust level as the row index and operational risk level as the column index. Each cell stores a corresponding basic threshold value. Trust levels include sandbox period, observation period, standard period, and trust period, arranged in ascending order as the row index. Operational risk levels include read-only query operations, parameter configuration operations, and physical execution operations, arranged in ascending order as the column index. The value at the intersection of the row and column indices is the basic threshold. The lower the trust level and the higher the operational risk level, the higher the corresponding basic threshold.
[0086] The basic threshold is set based on the system's security policy requirements and the maximum permissible behavioral deviation tolerance of the agent under different trust levels. It represents the minimum threshold that the agent's behavioral similarity must reach to pass verification under a given trust level and operational risk level. The rules for setting the basic threshold are as follows: the lower the trust level, the lower the agent's credibility, and the higher the behavioral similarity required to pass verification, therefore the higher the basic threshold; the higher the operational risk level, the more serious the consequences of instruction execution, and the higher the behavioral similarity required to pass verification, therefore the higher the basic threshold.
[0087] For example, when the trust level is in the sandbox period, the base threshold for read-only query operations is set to 0.85, the base threshold for parameter configuration operations is set to 0.90, and the base threshold for physical execution operations is set to 0.95. When the trust level is in the observation period, the base threshold for read-only query operations is set to 0.80, the base threshold for parameter configuration operations is set to 0.85, and the base threshold for physical execution operations is set to 0.90. When the trust level is in the standard period, the base threshold for read-only query operations is set to 0.75, the base threshold for parameter configuration operations is set to 0.80, and the base threshold for physical execution operations is set to 0.85. When the trust level is in the trust period, the base threshold for read-only query operations is set to 0.70, the base threshold for parameter configuration operations is set to 0.75, and the base threshold for physical execution operations is set to 0.80. Through this base threshold lookup table, the system can quickly obtain the corresponding verification threshold, i.e., the base threshold, based on the trust level of the agent and the risk level of the instruction.
[0088] Secondly, the base threshold is adjusted based on the drift detection status. The drift detection status refers to the monitoring result of the deviation between the agent's real-time behavior and the current behavior fingerprint template, including two states: attention status and alarm status. The attention status indicates that the deviation exceeds the preset attention threshold but does not reach the alarm threshold, indicating that the agent's behavior is slightly abnormal; the alarm status indicates that the deviation exceeds the preset alarm threshold, indicating that the agent's behavior is seriously abnormal.
[0089] When the drift detection status is in the "concern" state, a first correction amount is added to the base threshold. The first correction amount is a small increment, such as 0.05, used to appropriately raise the verification threshold for minor abnormal behavior. When the drift detection status is in the "alarm" state, a second correction amount is added to the base threshold. The second correction amount is greater than the first correction amount, such as 0.1, used to significantly raise the verification threshold for severe abnormal behavior.
[0090] Through the above corrections, the sum of the base threshold and the correction amount constitutes the dynamic threshold. This dynamic threshold rule determines the base value based on the trust level and operational risk level, and then adaptively increases the correction amount according to the severity of the drift detection state, achieving dynamic verification through multi-factor fusion.
[0091] Furthermore, the behavioral similarity is compared with a dynamic threshold. Behavioral similarity, calculated in the preceding steps, is a value between 0 and 1, reflecting the consistency between the current agent's behavior and its historical behavioral patterns. If the behavioral similarity is greater than or equal to the dynamic threshold, the agent is deemed to have passed verification, and standardized operation instructions are executed. The original output, behavioral similarity, and execution result are then stored in a distributed ledger. The stored information includes the agent's identifier, the original output content, the converted standardized operation instructions, the behavioral similarity value, the dynamic threshold used, the execution time, and the execution status, ensuring the entire interaction process is traceable and tamper-proof.
[0092] Furthermore, if the behavioral similarity is less than the dynamic threshold, the agent verification is deemed failed, standardized operation instructions are refused to be executed, an alarm is triggered, and the refusal event and alarm information are stored in the distributed ledger. The alarm information includes the agent identifier, original output content, behavioral similarity value, dynamic threshold, reason for refusal, and alarm time. After storage, the system can push the alarm to the system administrator or security monitoring center for manual verification. Through this dynamic threshold verification mechanism, the system can adaptively adjust the verification strictness based on the agent's trust level, operational risk, and drift state, achieving a balance between security and efficiency.
[0093] In summary, the embodiments of this application have at least the following technical effects: This invention first converts the raw output issued by the target intelligent agent into standardized operation instructions through multimodal parsing, and simultaneously performs operation risk assessment. This solves the problems of inconsistent output formats of heterogeneous intelligent agents and the inability of the control system to directly understand them, eliminating the need for manually written adapters and improving the efficiency of intelligent agent access. Second, it establishes and maintains a behavioral fingerprint database for heterogeneous intelligent agents. Based on the behavioral fingerprint database, it assesses the behavioral similarity of the raw output, realizing dynamic identity authentication based on behavioral features. This effectively identifies the risk of legitimate intelligent agents being hijacked or malicious intelligent agents impersonating them, overcoming the inherent defects of static key authentication. Third, it combines the operation risk assessment results with behavioral similarity and performs intelligent agent verification based on dynamic threshold rules. Based on the verification results, it triggers the execution or rejection of standardized operation instructions, realizing a multi-dimensional integrated security decision-making mechanism.
[0094] This invention ensures that heterogeneous intelligent agents can securely and reliably access the physical world control system through the collaborative work of semantic adaptation interface and behavioral fingerprint authentication, and prevents security risks caused by heterogeneous instruction formats, identity impersonation and semantic violations.
Claims
1. A semantic adaptation interface and behavioral fingerprint authentication method for heterogeneous intelligent agents, characterized in that, include: Receive the raw output from the target intelligent agent, convert the raw output into standardized operation instructions through multimodal parsing, and perform an operation risk assessment; Establish and maintain a behavioral fingerprint database for heterogeneous intelligent agents, and evaluate the behavioral similarity of the original output based on the behavioral fingerprint database; Combining the operational risk assessment results with the behavioral similarity, agent verification is performed based on dynamic threshold rules, and the standardized operation instructions are triggered according to the agent verification results.
2. The semantic adaptation interface and behavioral fingerprint authentication method for heterogeneous intelligent agents as described in claim 1, characterized in that, Receive the raw output from the target agent, convert the raw output into standardized operation instructions through multimodal parsing, and perform an operation risk assessment, including: Obtain the data format type of the original output, wherein the data format type includes at least natural language text format, structured data format, and binary protocol format; According to the data format type, the corresponding parsing sub-engine is called to sequentially perform semantic disambiguation and intent recognition on the original output to obtain the operation intent vector and operation parameters. The operation intent vector and the operation parameters are mapped to a preset standardized instruction template to generate the standardized operation instruction; The operational risk level is determined based on the operational categories involved in the standardized operational instructions. The operational categories include at least read-only query operations, parameter configuration operations, and physical execution operations.
3. The semantic adaptation interface and behavioral fingerprint authentication method for heterogeneous intelligent agents as described in claim 1, characterized in that, Establish and maintain a behavioral fingerprint database for heterogeneous intelligent agents, including: In a controlled environment, behavioral data of multiple heterogeneous target intelligent agents are collected, and multi-dimensional behavioral features are extracted to construct an initial behavioral fingerprint template. The multi-dimensional behavioral features include at least temporal features, semantic features, and interaction pattern features. The initial behavioral fingerprint template is stored in a distributed ledger to generate a fingerprint identifier that uniquely corresponds to the target intelligent agent, thereby obtaining the behavioral fingerprint database; The behavioral fingerprint database is configured with progressive trust level management, including sandbox period, observation period, standard period, trust period and privilege period.
4. The semantic adaptation interface and behavioral fingerprint authentication method for heterogeneous intelligent agents as described in claim 3, characterized in that, Establishing and maintaining a behavioral fingerprint database for heterogeneous intelligent agents also includes: When the behavioral data of the target agent accumulates to a preset amount, the update evaluation of the behavioral fingerprint template is triggered, a new behavioral fingerprint template is calculated, and the difference between the new behavioral fingerprint template and the current behavioral fingerprint template is evaluated. If the difference exceeds a preset security range, the update is rejected and an alarm is triggered; otherwise, adaptive routing is performed based on the trust level of the current behavior fingerprint template, including: If the trust level is a trust period, then submit an update proposal for the behavior fingerprint template; otherwise, update directly based on the new behavior fingerprint template. The updated proposal is sent to multiple preset approval nodes for independent approval, and the approval results of each approval node are obtained. If the approval result is passed, then enter shadow mode and update management is performed based on the new behavior fingerprint template and the current behavior fingerprint template.
5. The semantic adaptation interface and behavioral fingerprint authentication method for heterogeneous intelligent agents as described in claim 4, characterized in that, Entering shadow mode, update management is performed based on the new behavior fingerprint template and the current behavior fingerprint template, including: Simultaneously using the new behavior fingerprint template and the current behavior fingerprint template, the behavior similarity of the target agent is calculated respectively, and the new fingerprint similarity sequence and the current fingerprint similarity sequence are obtained; Calculate the difference index between the new fingerprint similarity sequence and the current fingerprint similarity sequence, wherein the difference index includes at least the mean difference and the variance difference; Based on the difference index, the drift rate of the new fingerprint similarity sequence is continuously calculated and monitored. If the drift rate exceeds the preset shadow mode drift threshold, the shadow mode is terminated and the system is rolled back to the current behavior fingerprint template. If the drift rate under the difference index is within the preset shadow mode drift threshold when the shadow mode runs to the preset verification period, the new behavior fingerprint template is marked as verified, the template activation operation is performed, and the behavior fingerprint template update event is stored in the distributed ledger.
6. The semantic adaptation interface and behavioral fingerprint authentication method for heterogeneous intelligent agents as described in claim 5, characterized in that, The update proposal is sent to multiple preset approval nodes for independent approval, and the approval results of each node are obtained. The process also includes: Initiate a time lock, and record the lock start time and lock duration, wherein the lock duration is determined based on the target agent's current trust level; Based on the time lock, the behavior of the target agent is continuously drift detected. If the drift detection result triggers a severe drift threshold during the locking period of the time lock, the behavior fingerprint template update is canceled and an alarm is triggered. If the lockout period expires and the approval result of each approval node is "pass", the update proposal will be marked as "activatable" and the approval result will be "pass". If the approval results of each approval node do not reach the preset approval ratio when the lock period expires, the update proposal will be marked as rejected, the approval result will be unsuccessful, and the submission record and approval record will be stored in the distributed ledger.
7. The semantic adaptation interface and behavioral fingerprint authentication method for heterogeneous intelligent agents as described in claim 1, characterized in that, Based on the behavioral fingerprint database, the behavioral similarity of the original output is evaluated, including: Extract behavioral feature vectors from the original output, wherein the behavioral feature vectors include at least temporal behavioral feature vectors, semantic behavioral feature vectors, and interaction pattern feature vectors; Calculate the temporal similarity, semantic similarity, and pattern similarity between the behavioral feature vector and the corresponding dimensions of the behavioral fingerprint template, respectively. The temporal similarity, semantic similarity, and pattern similarity are weighted and fused according to preset weight coefficients to obtain the behavioral similarity.
8. The semantic adaptation interface and behavioral fingerprint authentication method for heterogeneous intelligent agents as described in claim 2, characterized in that, Combining the operational risk assessment results with the behavioral similarity, agent verification is performed based on dynamic threshold rules, and the standardized operation instructions are triggered according to the agent verification results, including: Obtain the target agent's current trust level and drift detection status; Based on the current trust level, the operational risk level, and the drift detection status, a dynamic threshold is obtained through a preset multi-factor threshold lookup table. The behavior similarity is compared with the dynamic threshold. If the behavior similarity is greater than or equal to the dynamic threshold, the standardized operation instruction is executed, and the original output, the behavior similarity, and the execution result are stored in the distributed ledger. If the similarity of the behavior is less than the dynamic threshold, the standardized operation instruction will be refused to be executed, an alarm will be triggered, and the refusal event and alarm information will be stored in the distributed ledger.
9. The semantic adaptation interface and behavioral fingerprint authentication method for heterogeneous intelligent agents as described in claim 1, characterized in that, Based on the behavioral fingerprint database, the behavioral similarity of the original output is evaluated, and then the process further includes: Obtain the behavior similarity sequence within a preset period window, and calculate a multidimensional evaluation factor based on the behavior similarity sequence. The multidimensional evaluation factor includes at least the window mean similarity, variance, drift rate, and number of consecutive compliances. Based on the aforementioned multidimensional evaluation factors, the trust score of the target intelligent agent is calculated using a weighted average. If the trust score is greater than or equal to the first threshold, the corresponding behavioral fingerprint template enters the upgrade process, and performs pre-check based on the number of jobs, drift rate check and adaptive multi-party approval in sequence, and stores the upgrade event evidence according to the upgrade process result. If the trust score is less than or equal to the second threshold, the corresponding behavioral fingerprint template enters the downgrade process and performs adaptive downgrade based on the relative relationship between the trust score and the second threshold. If the trust score is greater than the second threshold and less than the first threshold, then the current trust level of the corresponding behavioral fingerprint template is maintained.
10. The semantic adaptation interface and behavioral fingerprint authentication method for heterogeneous intelligent agents as described in claim 8, characterized in that, Dynamic threshold rules include: Based on the target agent's current trust level and the operational risk level, a basic threshold is obtained from a preset basic threshold lookup table, wherein the basic threshold lookup table uses the trust level as the row index and the operational risk level as the column index. The base threshold is corrected based on the drift detection state, including: When the drift detection state is a state of interest, a first correction amount is added to the base threshold. When the drift detection state is an alarm state, a second correction amount is added to the base threshold, and the second correction amount is greater than the first correction amount.