METHOD, DEVICE AND NON-VOID MACHINE-READY STORAGE MEDIUM FOR DETECTING AND MANAGING ARTIFICIAL INTELLIGENCE (AI) AGENTS
The method and system address the challenge of detecting and managing unknown AI agents by employing computational pattern analysis and security key management, ensuring controlled access and continuous monitoring to mitigate risks in enterprise IT environments.
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-08-19
- Publication Date
- 2026-03-19
AI Technical Summary
Existing solutions fail to effectively detect and manage unknown and high-risk AI agents within enterprise IT environments, which can introduce unpredictable risks by autonomously switching datasets, inheriting behaviors, and persisting unnoticed, leading to unforeseen problems.
A method and system for detecting AI agents using computational pattern analysis, logic comparison, and reference profile-based procedures, combined with security key management to control access, and adaptive behavioral monitoring to identify and manage high-risk agents.
Effectively identifies and manages AI agents, reducing the risks associated with unknown and high-risk AI agents by ensuring controlled access and continuous monitoring, thereby enhancing network security and stability.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
background
[0001] In today's digital age, some software running on a network, such as an enterprise information technology (IT) environment, may include an artificial intelligence (AI) agent that is unknown to the network. This unknown AI agent can introduce certain risks into the network. Brief description of the characters
[0002] Some examples of facilities and / or procedures are described below by way of example and with reference to the accompanying figures, in which Fig. Figure 1 shows a schematic figure of an example of a System 100 for detecting and managing AI agents; Fig. Figure 2 shows a flowchart of an example of a procedure 200 for detecting an AI agent of an application in a network; Fig. Figure 3 shows a flowchart of an example of data processing by a function; Fig.4 shows a flowchart of an example of a function that uses information sources; Fig. Figure 5 shows a flowchart of an example of Procedure 500 for performing access control for an application on a network; Fig. Figure 6 shows a flowchart of an example of a procedure 600 for performing access control on an access request that includes an encrypted security key; Fig. Figure 7 shows a flowchart of an example of a Procedure 700 for the procedure of KL agents based on APL keys; and Fig. Figure 8 shows a block diagram of an example of the 800 facility. Detailed description
[0003] Some examples are now described in more detail with reference to the accompanying figures. However, other possible examples are not limited to the features of these extensively described embodiments. Other examples may include modifications of the features as well as equivalents and alternatives to the features. Furthermore, the terminology used here to describe certain examples should not exclude other possible examples.
[0004] Throughout the description of the figures, identical or similar reference symbols refer to identical or similar elements and / or features, which may be identical or implemented in a modified form, thereby providing the same or a similar function. The thickness of lines, layers, and / or areas in the figures may also be exaggerated for clarity.
[0005] When two elements A and B are combined using "or," this is to be understood as revealing all possible combinations, i.e., only A, only B, and A and B, unless explicitly defined otherwise in a specific case. As an alternative formulation for identical combinations, "at least one of A and B" or "A and / or B" can be used. This applies equally to combinations of more than two elements.
[0006] When a singular form, such as "a", "an", and "the", is used, and the use of only a single element is neither explicitly nor implicitly defined as mandatory, subsequent examples may also use multiple elements to implement identical functionality. If a function is subsequently described as being implemented using multiple elements, further examples may implement the identical functionality using a single element or a single processing entity.It is further understood that the terms “include”, “containing”, “encompass” and / or “comprehensive”, when used, describe the presence of the specified features, integers, steps, operations, processes, elements, components and / or a group thereof, but do not exclude the presence or addition of one or more other features, integers, steps, operations, processes, elements, components and / or a group thereof.
[0007] The following description presents specific details; however, examples of the technologies described herein can be implemented without these specific details. Well-known circuits, structures, and techniques are not shown in detail so as not to obscure the understanding of this description. "An example," "several examples," "some examples," and the like may include features, structures, or characteristics, but not every example necessarily includes the specific features, structures, or characteristics.
[0008] Some examples may exhibit some, all, or none of the features described for other examples. “First,” “second,” “third,” and the like describe a common element and indicate different instances of similar elements being referred to. Such adjectives do not imply that the individual elements so described must occur in any given sequence, whether temporally or spatially, in any order of precedence or otherwise. “Connected” may indicate that elements are in direct physical or electrical contact with one another, and “coupled” may indicate that elements cooperate or interact, though they may or may not be in direct physical or electrical contact with one another.
[0009] As used herein, the terms “working”, “executing” or “running” relating to software or firmware in respect of a system, device, platform or resource are used interchangeably and can refer to software or firmware stored on one or more computer-readable storage media which the system, device, platform or resource can access, even if software or firmware instructions are not actively executed by the system, device, platform or resource.
[0010] The description may use the expressions “in one example,” “in examples,” “in some examples,” and / or “in several examples,” each of which may refer to one or more of the same or to different examples. Furthermore, the terms “comprehensive,” “including,” “with,” and the like, as used in relation to examples in this disclosure, are synonymous.
[0011] In some examples, software behavior is constrained by clear rules, even in complex systems like machine learning. However, in other examples of emerging technologies, such as AI-driven dynamic API generation, there is growing concern that software may evolve or repair itself without conventional safeguards, leading to unpredictable outcomes. In the AI-related examples above, the risks associated with AI-driven software may include: AI agents autonomously switching to use different datasets than originally intended; AI agents inheriting and modifying the behavior of other AI agents, similar to how software modules or primitives are used; and AI agents continuing to operate within complex workflows long after they have been forgotten, potentially causing unforeseen problems.
[0012] Some examples provide solutions such as Sonatype Nexus, Black Duck, and WhiteSource. Sonatype Nexus can provide component intelligence for open-source governance, ensuring the security of the software supply chain with automatic policy enforcement and vulnerability scanning. Black Duck offers comprehensive open-source license compliance and security management with automatic scanning and policy enforcement throughout the software development lifecycle. WhiteSource provides open-source license compliance and security solutions that include automatic vulnerability detection, policy management, and integration with common development tools. However, these solutions failed to address at least some of the risks mentioned above.
[0013] In some examples, AI agents can appear in various forms, such as encapsulated AI agents, multi-layered multi-model AI agents, and embedded AI agents. Encapsulated AI agents can be self-contained within a larger system, operating internally using a large language model (LLM) to process and generate output. Multi-layered multi-model AI agents can operate at multiple levels or process multiple models, with one AI agent containing or interacting with other AI agents to perform tasks, creating a layered or hierarchical system. Encapsulated AI agents can be integrated into different systems or software, functioning as part of core functionality rather than as standalone entities.
[0014] Fig.Figure 1 shows a schematic diagram of an example of a system 100 for detecting and managing AI agents. In this example, the system 100 can comprise a network 100A, which includes a variety of devices 110 and an AI model 160, and can further comprise an AI 170 outside the network 100A. Each of the devices 110, such as device 110a, can contain an operating system 120 and a variety of applications 130 running on the operating system 120. Some of the applications 130, such as application 130a, can include an AI agent 140, which further comprises an AI model 150, such as a large language model. In some examples, the devices 110 can be coupled to an AI model 160 within network 100A and also to an AI model 170 outside network 100A. In some other examples, either the AI model 160 or the AI model 170 can be removed.In some examples, an application 130 may refer to a software module in the OS 120, a software module encapsulated or embedded in a hardware component in the device 110, or a software module used in an intermediary component between hardware and software in the device 110. In some examples, a controller 180 may be coupled to the plurality of devices 130. In some examples, the AI model 150 may be a single-purpose model or a multi-purpose model. In some examples, the AI model 150 may run in parallel with other similar AI models in other AI agents to improve the overall performance and response time of a virtualized AI that includes the AI model 150 and the other similar AI models.
[0015] In some examples, the existence of certain AI agents 140 within the applications 130 is unknown to the controller 180, preventing the implementation of management specific to these AI agents. Consequently, risks can be introduced by the unmanaged AI agents 140. In some examples, a method for detecting AI agents 140 can be implemented. This method identifies variants of a multitude of application outputs corresponding to a multitude of identical inputs provided to the application 130. Furthermore, an AI agent of the application can be detected based on these identified variants of the multitude of outputs. The AI agent comprises an AI model that provides the application with AI-based resource information to generate the multitude of outputs. Thus, the controller 180 can detect the AI agents 140 within the network 100A.In some examples, Controller 180 can implement management on all detected AI agents, while in other examples, Controller 180 can further identify some high-risk or target AI agents from among all detected AI agents in order to implement proper management on those high-risk or target AI agents. In some examples, a logic comparison-based procedure and / or a reference profile-based procedure can be used to identify the high-risk or target AI agents. In other examples, management of AI agents, such as the high-risk or target AI agents identified above, can be performed to eliminate or reduce risks caused by AI agents.For example, security keys can be assigned to applications (130), including AI agents, so that application access to an AI model (160) or (170) can be controlled, for example, by denying or allowing access. The examples above relate to the detection of unknown AI agents, the detection of high-risk AI agents from among some AI agents, and the management of AI agents based on security keys. Each of these three sections can be independent of the others.
[0016] Fig. Figure 2 shows a flowchart of an example of a procedure 200 for detecting an AI agent of an application in a network.
[0017] In some examples, the procedure may include operations 210 and 230. Operation 210 may involve identifying variants of a multitude of application outputs corresponding to a multitude of identical inputs provided to the application. Operation 230 may involve identifying, based on the variants of the multitude of outputs, an AI agent of the application, where the AI agent may comprise an AI model that provides the application with AI-based resource information to generate the multitude of outputs.
[0018] In some examples, the application receives a multitude of identical inputs over an initial period. In some examples, the range of output variants may comprise an initial group of variants determined based on the initial set of respective analysis procedures performed on the multitude of outputs. In some examples, the initial set of respective analysis procedures may be performed in parallel on the multitude of outputs. In some other examples, the initial set of respective analysis procedures may be performed sequentially on the multitude of outputs.
[0019] In some examples, computational patterns in application output can be used to identify whether an AI agent is using an application to generate output. In some examples, the application can refer to an operating system. In some examples, these computational patterns exist along the operational stack of the application, OS, hardware, and intermediate connections, since AI agents can be present along the operational stack. Consequently, in some examples, detection operations can be performed along the operational stack. In some examples, the computational patterns can relate to specific features or signatures in the output data, and these specific features or signatures can be used to identify whether an AI agent is present. These patterns can manifest in various ways depending on the type of AI agent and the tasks it performs.Some computational patterns that could be used to detect AI agents may include text consistency and repetition, statistical regularity, predictable response patterns, absence of human-like errors, temporal interaction patterns, and / or semantic analysis.
[0020] In some examples, detecting the presence of Kl agents can exploit the fact that Kl agents are non-deterministic and produce slightly different outputs for some identical static inputs. In some examples, a hash algorithm can be used to efficiently detect these slight differences.
[0021] In some examples, an application may include one or more functions, some or all of which have their own inputs, outputs, and information sources. The information sources may be AI models that provide AI-based resource information. In some examples, the AI-based resource information provided to the functions can be used by the functions. Furthermore, because the functions belong to an application, the AI-based resource information can be used by the application to generate the application's outputs.
[0022] In some examples, a table (not illustrated) may be provided for a function, containing the function definition, input, input hash, output, and output hash. In a situation where the function is given several identical inputs, it can be determined that a Kl agent may exist if the outputs corresponding to the identical inputs change slightly. Although these slight changes in output may be difficult to detect, the output hash, which is the hashed output, can easily indicate the changes in some examples.
[0023] In some examples, in order to detect the existence of an AI agent with higher accuracy or confidence, the possibility of the existence of an AI agent can further be combined with a pattern comparison of semantic proximity.
[0024] With regard to AI agents based on the stochastic nature of LLMs, the probability of obtaining two identical outputs for two identical inputs in applications that include or utilize AI agents is low. In contrast, applications or functions without LLMs have higher probability of returning identical outputs corresponding to some identical inputs. In some examples, an application may include one or more functions, each or some of which may use one or more AI agents to generate outputs from the functions, where the outputs of the functions may be intermediate or final outputs of the application.
[0025] In some examples, the features of a KL model, such as an LLM, allow observation of any function that returns variable output values in response to some identical input values. Such output values can serve as an indication of an LLM function. In some examples, a software or hardware KL detection agent, which may be the controller 180 or a component of the controller 180, may be configured as a software requirement, such as for enterprise software, to detect KL agents 140. If it is determined that no KL detection agent is installed for or associated with an application, a process may encapsulate the application and / or report on the activity. Otherwise, the KL detection agent may implement its observation function at runtime on the application, which may have the extension .exe, .dll, or .api, indicating that the application also references some files or documents.In some examples, the AI detection agent can observe the assignment of values in a program flow, where the program flow, also known as control flow, can refer to the order in which individual statements, instructions, or function calls are executed or evaluated in a computer program. It can determine the sequence of operations the program follows, thereby controlling how the program processes inputs, makes decisions, and produces outputs. Furthermore, the AI detection agent can observe the program flow, which involves tracking how data moves and is processed within the program.For example, the AI detection agent can monitor internally returned values and externally returned values, where internally returned values are values or results generated by the program's own functions or processes, and externally returned values are results received from external systems after the program makes a request to an external API or service. Furthermore, the AI detection agent can build a dataset of features, also known as functional features. The AI detection agent can then use simple statistical comparison functions to identify stochastic behavior. In some examples, the identified stochastic behavior can be used as a flag to trigger further actions.
[0026] In some examples, applications may include random functions that represent a gray area between deterministic functions and AI models. To determine whether a random function operates as an AI function or an AI entity, such as an AI model, the AI detection agent may need to observe software processes and workflows in some examples. Therefore, the AI detection agent may include observational capabilities for programmatic function identification. A flag, warning, or similar notification may be triggered if a control panel, such as Control 180, detects that the AI detection agent is not running. The AI detection agent may be able to observe specific functions called in scripts written in Python, Perl, Bash, and other languages.
[0027] In some examples, multiple options can be provided for performing AI agent detection on certain programs, such as compiled programs that do not have AI detection agents. In some examples, instructions can reference programs. One option can be library construction. According to this option, a software library is constructed that includes a dynamic link library and / or a module configured with AI detection capabilities. The module can be a software element that provides specific functionality, such as AI detection. The library can then be included in a build package of a compiled program. This allows the library to become part of the compiled program, enabling the program to use the AI detection capabilities provided by the constructed library.According to another option in a different example, an analysis can be performed to identify patterns based on the inputs and outputs of a compiled program. These patterns can then be used to determine the probability that the program's outputs are generated by a computer science model, such as a large language model (LLM). In some examples, this alternative option may employ a method that utilizes semantic proximity to perform the analysis.
[0028] In some examples, if a function or application is deterministic, the outputs corresponding to a given set of identical inputs can be deterministic. For example, if each of a set of identical inputs contains the values 2 and 3, and the function is an addition function, then all outputs should be deterministic; each value should always be 5.
[0029] Fig.Figure 3 shows a flowchart of an example of data processing by a function. According to Fig. Three input data points, "X", contain data such as "Area: Approval of an order. Requester ID=777, Item ID=a56a, Date=03012024, Amount=$23.12. Do you agree?", which are provided to the function using three AI assistants, which can be three AI models. The output data is then "Yes, approved ID=234902". The three AI assistants are unknown to the system control panel, such as Control Panel 180. To detect whether the function uses any AI model, the AI detection agent can collect inputs from the function over a period of time and analyze the return values, as described in Fig. 3 shown for semantic proximity.
[0030] In some examples, some information regarding the observation of the application or function is known, and some information is unknown, where "known" might mean that a proposed software monitoring agent is capable of observing this data and information, and "unknown" might mean the opposite. In other examples, the inputs and outputs of a program entity, which could be an application or function, are known, and one or more decision-making functions that could be used for the inputs are unknown.
[0031] In some examples, software monitoring, which may be the AI detection agent or another entity or a section thereof, can observe interactions of a compiled program with one or more other programs through several methods.
[0032] In some examples, the process may include several procedures: • Intercepting system calls: The monitoring system can intercept and log system calls made by the program. This can provide information about the program's interactions with the operating system and other software components. This method requires deep integration with the operating system. • Network traffic monitoring: If the program communicates with external systems via a network (such as APls), the monitoring system can observe the network traffic. This can be done at various levels, from simple packet sniffing to more complex protocol analysis. • API Hooks: The monitoring system can use API hooks to intercept calls to specific APIs and log their parameters and return values. This can provide detailed information about the program's interactions with these APIs. • Process monitoring: The monitoring system can observe the process state of the program, including its memory usage, CPU usage, open files, and other resources. This can provide information about the overall behavior and resource consumption of the program. • Binary instrumentation: The monitoring system can use binary instrumentation to inject additional code into the program's binary file. This code can log information about the program's behavior and its interactions with other systems. • Log analysis: If the program creates logs, the monitoring system can analyze these logs to gather information about its behavior and interactions.
[0033] Fig. Figure 4 shows a flowchart of an example function that uses information sources. As in Fig.As shown in Figure 4, the input data of the function can be a variable X, and information sources, designated a, b and c, can be used by the function to output the output variable Y.
[0034] In some examples, a simple decision tree can be applied to an information source. If the result of the decision tree indicates that further analysis should be performed on the information source to determine whether the information source uses AI, the further analysis can be carried out accordingly. Decision tree
[0035] In some examples, the AI detection agent can identify or map information sources, also called sources of information, which may be located either inside or outside of network 100A. In some examples where an information source is located inside network 100A, the AI detection agent can consult a governance or control system, such as control 180, to determine if a software system managing the information source has its own AI detection agent. If not, then the information source or the software system managing or using the information source can be flagged for analysis to determine if it uses AI.In some examples where an information source is located outside of Network 100A, such as a resource accessible via a public Uniform Resource Locator (URL), if an external software system managing the external information source is not registered with a governance system of Network 100A, the information source outside of Network 100A or the external software system managing the resource may be flagged for analysis to determine if it uses AI. Further analysis on Kl
[0036] In some examples, to determine whether an information source generates information using AI, the AI detection agent may need to quantify the deterministic probability of the return value "Y" for the input value "X". Several methods can be used to quantify determinism. These functions might include, for example, mathematical functions, which are always deterministic; language functions, which are "sometimes" deterministic; image functions, which are "sometimes" deterministic; and Boolean operations, which are "sometimes" deterministic.
[0037] In some examples, the "decision tree" can be seen as a first step in identifying some "suspicious" information sources. "Further analysis on AI" can be considered a second step in which the determinism of information sources is quantified. In some examples, monitoring a suspected AI agent, which can essentially be represented by one or more information sources, can be performed by the AI detection agent, which may be a section of a steering system running on controller 180 of network 100A.
[0038] In some examples, when a consistent input "X," such as repeated strings of "Hello World," is passed to a presumed AI agent, the resulting output "Y" may either vary or remain uniform. In large language models (LLMs), this variability can be influenced by a parameter called "temperature," which controls the randomness of the outputs. Observing the variance in "Y" for a constant "X" can help quantify the determinism of the system, indicating whether the system is an AI agent, uses one, or relies on one. However, in some examples, it may require numerous observations to gather enough data to accurately assess this behavior.Therefore, in some examples, to avoid numerous observations, AI agents can be identified by inferring the underlying structure of the information source based on how it responds to inputs. Additionally, rule-based systems, such as those using "if / then / else" logic, can sometimes mimic LLM behavior, making it difficult to distinguish between AI and non-AI systems. In some examples, the following mathematical and machine learning techniques can be used to draw this conclusion. • Bayesian inference: This is a statistical inference technique that uses Bayes' theorem to update the probability of a hypothesis as more evidence or information becomes available. Bayesian inference is widely used in machine learning and statistics to estimate parameters and make predictions. • Maximum Likelihood Estimation (MLE) method: This is a method for estimating the parameters of a statistical model given observations. In the context of your problem, MLE could be used to estimate the parameters of the function that produces output Y, given input X. • Expectation-Maximization Algorithm (EM Algorithm): This is an iterative procedure for finding maximum-probability or maximum a posteriori (MAP) estimates of parameters in statistical models where the model depends on unobserved latent variables. The EM iteration alternates between performing an expectation (E) step, which generates a function for the expected log-likelihood, evaluated using the current estimate for the parameters, and a maximization (M) step, which computes parameters that maximize the expected log-likelihood found in the E step. • Markov Chain Monte Carlo (MCMC) Method: This is a class of algorithms for taking samples from a probability distribution. By constructing a Markov chain that has the desired distribution as its equilibrium distribution, a sample of the desired distribution can be obtained by recording states from the string. The more steps the chain contains, the closer the distribution of the samples matches the actual desired distribution. • Entropy measurements and information theory: Entropy measurements can be used to quantify randomness in outputs. This can be done using various entropy measures, such as Shannon entropy, Renyi entropy, or Kolmogorov complexity. Information theory, which is the study of the quantification, storage, and communication of information, could also be used here. • Supervised machine learning models: If you have a labeled dataset, you could use supervised learning models to predict the output Y given the input X. This could be a regression model if Y is a continuous variable, or a classification model if Y is a categorical variable. • Unsupervised machine learning models: If no labeled dataset is available, unsupervised learning models could be used to discover the underlying structure of the data. This could involve clustering observations based on their input X and output Y, or using dimensionality reduction techniques to visualize the data in a lower-dimensional space.
[0039] In some examples, these techniques can be used individually or in combination. For example, a system is provided that uses Bayesian inference (Bl), entropy measurements (EM), and supervised machine learning (ML) models to generate a deterministic probability that evolves over time; the procedure is called the BI:EM:ML method for deterministic quantification.
[0040] In some examples, the above procedure is used to monitor the behavior of an information source and determine whether a computer agent is using a computer model, such as an LLM. The procedure can observe the inputs and outputs of the information source over time and employ a combination of Bayesian inference, entropy measurements, and supervised machine learning models.
[0041] Bayesian inference can be used to update the probability that the information source is an AI agent as more observations are made. This allows the system that could be the AI detection agent to learn from the data and improve its predictions over time.
[0042] Entropy measurements can be used to quantify the randomness in the output of the information source, also referred to as the source. High entropy can indicate a high degree of randomness, which is a characteristic of LLMs (Limited Libraries).
[0043] Supervised machine learning models can be used to predict, based on their observed behavior, whether an information source is an AI agent. These models can be trained on a labeled dataset of known AI agents and non-AI agents and can also be used to classify new information sources.
[0044] The procedure can combine these three methods to generate a deterministic probability that the information source is a clin agent or is based on one. This probability can evolve over time as more observations are made. If the probability exceeds a certain threshold, the system can classify the information source as a clin agent and set a flag "is_a_clin_agent = 1".
[0045] The process flow can proceed as follows in some examples: 1. Monitoring the information source and collecting observations of its inputs and outputs. 2. Applying Bayesian inference to update the probability that the source is a Kl agent, based on the new observations. 3. Calculate the entropy of the source's expenditures to quantify the randomness of the expenditures. 4. Using a supervised machine learning model to predict, based on its observed behavior, whether the source is an AI agent. 5. Combining the results of Bayesian inference, entropy measurements, and the supervised machine learning model to generate a deterministic probability that the source is a Kl agent. 6. Check if the deterministic probability exceeds a certain threshold. If so, the system classifies the source as a Kl agent and sets "is_a_Kl_agent = 1". 7. Continuous monitoring of the source and updating the deterministic probability as new observations are made.
[0046] This process can adapt to the behavior of the information source over time and improve its accuracy in identifying AI agents. Table 1 X (Inputs) Y (expenses) Order no. 123: Express delivery requested Prioritize order for express shipping Item XYZ out of stock Reorder item XYZ from another supplier Shipment from supplier ABC delayed Notify production teams of a possible delay Invoice received for order no. 456 Review invoice details and process for payment. Delivery planned for tomorrow Reception area for preparing incoming goods Production stopped due to a defect Initiate quality control investigation Low stock warning for SKUN number 789 Send backorder for SKU No. 789 Price increase by supplier XYZ Evaluate alternative suppliers with regard to better prices Quantity changed in order no. 789 Update production plan accordingly Contract termination by provider A Identify alternative suppliers for current orders Express shipping requested Coordinate logistics for priority processing Return of item ABC requested Initiate the return process and issue a credit note. Production line shut down for maintenance Replan manufacturing tasks accordingly Payment terms renegotiated Update financial records and payment plans New supplier added Update supplier database and contact details Discontinued item SKU No. 123 Adjust inventory and notify sales team Order no. 456 delayed due to weather Monitor weather conditions and adjust plans Complaint regarding the quality of item received Investigate quality problems and correct defects The package was received damaged. Report the damage to the shipping company and reorder the damaged items. Supplier B bankrupt Identify alternative suppliers for current orders
[0047] In some examples, Table 1 includes multiple inputs and corresponding outputs from an information source, a function, or an application that uses the information source. In some examples, the data set Table 1 simulates scenarios where short text strings can represent various situations or events related to supply chain or order processing that may require a large language model (LLM) to make informed decisions or take appropriate actions based on the provided inputs. In some examples, the BI:EM:ML procedure described above can be used for deterministic quantification based on the data provided in Table 1.
[0048] The following could be a simplified Python script that stores data in a list, analyzes each row, and makes a preliminary determination of whether the Y value was likely generated by an LLM: <code>import math # Defining the dataset table_1 = [ {"X": "Order No. 123: Rush delivery requested", "Y": "Prioritize order for express shipping"}, {"X": "Item XYZ out of stock", "Y": "Reorder item XYZ from another supplier"}, {"X": "Shipping from supplier ABC delayed", "Y": "Notify production teams of potential delay"}, {"X": "Invoice received for order no. 456", "Y": "Review invoice details and process for payment"}, {"X": "Delivery scheduled for tomorrow", "Y": "Prepare receiving area for incoming goods"}, {"X": "Production stopped due to a defect", "Y": "Initiate quality control investigation"}, {"X": "Low stock alert for SKU No. 789", "Y": "Send reorder for SKU No. 789"}, {"X": "Price increase by supplier XYZ", "Y": "Evaluate alternative suppliers with regard to better prices"}, {"X": "Quantity in order no.789 changed", "Y": "Update production plan accordingly"}, {"X": "Contract termination by supplier A", "Y": "Identify replacement supplier for current orders"), {"X": "Express shipping requested", "Y": "Coordinate with logistics for priority fulfillment"}, {"X": "Return of item ABC requested", "Y": "Initiate return process and issue credit note"}, {"X": "Production line shut down for maintenance", "Y": "Reschedule manufacturing tasks accordingly"}, {"X": "Payment terms renegotiated", "Y": "Update financial records and payment plans"}, {"X": "New supplier added", "Y": "Update supplier database and contact details"}, {"X": "Discontinued item SKU No. 123", "Y": "Adjust inventory and notify sales team"}, {"X": "Order No.456 delayed due to weather", "Y": "Monitor weather conditions and adjust plans"}, {"X": "Received a complaint about the quality of item DEF", "Y": "Investigate quality issues and correct defects"}, {"X": "Shipment received damaged", "Y": "Report damage to carrier and reorder damaged items"}, {"X": "Supplier B bankrupt", "Y": "Identify alternative suppliers for current orders") ] # Function to calculate the entropy of a string def calculate_entropy(s): if not s: return 0 entropy = 0 for char in set(s): p = float(s.count(char)) / len(s) entropy -= p * math.log2(p) return entropy # Function to determine if the y value is likely to be from an LLM, based on entropy def is_llm_generated_entropy(y_value): entropy_threshold = 3.0 # Adjust threshold if necessary entropy = calculate_entropy (y_value) return entropy > entropy_threshold # Analyze each row and output the result for entry in table_1: x_value = entry["X"] y_value = entry["Y"] is_llm = is_llm_generated(x_value, y_value) is_llm_entropy = is_llm_generated_entropy(y_value) print(f"X: {x_value}") print(f"Y: {y_value}") print(f"Probably generated by LLM (keyword analysis): {is_llm}") print(f"Probably generated by LLM (entropy analysis): {is_llm_entropy}") print ().< / code>
[0049] In some examples, the script above includes a function, such as `calculate_entropy`, which can calculate the Shannon entropy of a given string. Shannon entropy can measure the uncertainty or randomness within a string of symbols, such as characters in a text string.
[0050] In some examples, the function can work as follows. 1. The function can accept a string s as its input. 2. It can begin by checking if the string is empty. If the string is empty, the entropy can be defined as 0, since there is no uncertainty or randomness in an empty string. 3. The function can then initialize a variable, entropy, to 0. This variable can accumulate the entropy value as the function iterates through the characters in the string. 4. For each unique character in the string, identified by converting the string into a set, the function can calculate the probability p that this character appears in the string. This can be done by dividing the number of times the character occurs by the total length of the string. 5. Using the Shannon entropy formula, -p * log2(p), the function can calculate the contribution of each character to the total entropy and add it to the entropy variable. 6. Finally, the function can return the total entropy value, which is the sum of the contributions from all unique characters in the string.
[0051] In some examples, the `calculate_entropy` function can determine the Shannon entropy of a string by analyzing the frequency of each unique character and quantifying the uncertainty or randomness in the string based on these frequencies. Higher entropy values can indicate greater unpredictability or randomness in the string.
[0052] In some examples, management or control can be performed on all AI agents or on some AI agents deemed to be at risk. Procedures for detecting AI agents deemed to be at risk are provided in some examples. AI agents deemed to be at risk may be AI agents that evolve spontaneously and then perform actions based on the expectation or control of network management. AI agents deemed to be at risk may also be referred to as abnormal AI agents, since their actions are unpredictable and therefore not considered normal.
[0053] In some examples, high-risk AI agents can be identified using methods associated with semantic proximity. Some of these methods can be used for ongoing evaluation of responses regarding accuracy and potential AI agent development. These methods have the advantage of "knowing" the AI agent. In some examples, methods based on logic pinging and / or behavioral observation models can be used for identification.
[0054] In some examples, logic pinging can be integrated into a function, enabling the function to provide valuable insights into the behavior of an AI agent used by the function. This can facilitate more effective monitoring and control of the AI agent's behavior. Integrated logic pinging can give any nondeterministic function an audit log capability, allowing the AI agent to respond to an authorized information request. In some examples, in response to one or more ping requests, the AI agent can provide details about the logic learning module (LLM) responsible for processing the inputs, such as the ping requests themselves, and the decision context used, such as the specific configuration or settings employed by the retrieval augmented generation model for that decision.
[0055] In some examples, integrating logic pinging into a function may require one or more modifications to the standard function design. Some modifications in certain examples are listed below. • Function design: Functions that may be non-deterministic (e.g., those involving an AI agent) would need to be designed or modified to support logic pinging. This could mean that the function can accept a special "ping" input and produce a corresponding "ping" output in addition to its usual inputs and outputs. • Ping Input: The ping input can act as a signal or request that triggers the function to provide details about a first AI model, such as a large language model (LLM), and the specific configuration or settings used by a second AI model, such as a retrieval augmented generation (RAG) model, which works in conjunction with the first AI model to make a particular decision. This input can be a specific value, a value type, or an additional input parameter. • Ping output: The ping output can provide the requested information about the first KL model and the configuration or settings of the second KL model. This information can be returned as a separate output or embedded in standard output in a way that allows for easy extraction. • Access control: To ensure that only authorized users can initiate a logic ping in some examples, the function may include access control measures. This may involve checking the source of the request or implementing more complex authentication mechanisms. • Audit Log: Maintain an audit log of all logic pings, recording input, output, and other relevant details. This information could be stored in a log file, database, or other suitable storage system. Based on the stored information, an application or function can determine its decision-making logic. The determined logic can indicate whether the application or function uses a computer intelligence (CL) model to make decisions. • Error handling: Managing situations where the logic ping cannot be completed successfully. This could involve returning a specific error code or error message, or triggering a fallback mechanism.
[0056] In a process associated with logic pinging, a variety of requirements can be processed over a period of time by a controller, such as the 180 controller in Fig.1. Requests are sent to an AI agent. These requests can be sent to request that the AI agent's logic make a decision. In response to the requests, the AI agent can send a variety of logic elements, used to make the decision over time, to the controller. Based on the received variety of logic elements used by the AI agent to make decisions, the controller can identify variations of these logic elements. The controller can then further determine, based on these variations, whether the identified AI agent is manageable. In some examples, the variety of requests might consist of a variety of logic pings, where each logic ping can be a ping packet. In some examples, the decision-making logic can be identified based on the audit protocol described above and related techniques.
[0057] In some examples, the multitude of requirements may necessitate a wide range of AI agent configuration information over time. This requested configuration information, along with the required logic, can be used to determine whether the detected AI agent is manageable. In some examples, the configuration information is determined and / or obtained using the ping output technique described above and other related techniques. In some examples, the configuration information may include global parameters, interaction parameters, message types, and so on. Having this configuration information would make the determination more accurate.
[0058] In some examples, a behavioral observation model-based approach can be used to identify the AI agents to be managed, such as those with risks or abnormal behavior. In some examples, the behavioral observation model-based approach can employ anomaly detection, behavioral profiling, and continuous validation to identify whether an AI agent has evolved and is behaving in an unintended manner.
[0059] In some examples, anomaly detection may involve monitoring the outputs of AI agents to identify anomalies. Anomalies can be detected when actual outputs deviate significantly from expected behavior or outputs. This detection can be achieved using statistical methods, machine learning algorithms, or a combination of both. Anomaly detection may need to define what constitutes an "anomaly" based on the intended behavior of the AI agent and the specific context.
[0060] In some examples, behavioral profiling is used to detect anomalies or deviations in current behaviors. These current behaviors, in some examples, refer to real-world behaviors. Behavioral profiling can involve continuously profiling the AI agent's behavior over time, creating a reference profile of normal behavior. This reference profile can be built based on the AI agent's past behaviors. For example, the reference profile might include metrics such as the range and / or distribution of outputs, the frequency of output generation, and / or the relationships between inputs and outputs. Regarding frequency, the frequency of generating a specific type of output might be used in some examples. The AI agent's current behavior can be regularly compared to this reference to identify deviations.
[0061] Continuous validation can mean that the AI agent is regularly tested with a set of validation inputs. The outputs generated by the AI agent can then be compared with the expected outputs. These validation tests can be designed to be varied and comprehensive, ensuring a thorough assessment of the AI agent's capabilities.
[0062] In some cases, if the behavioral observation model detects an anomaly, a significant deviation from the reference profile, or a discrepancy during continuous validation, it may flag the AI agent as potentially more advanced. This can trigger a more detailed investigation or corrective action if necessary.
[0063] In some examples, the method for detecting high-risk AI agents is adaptive and self-learning. It can continuously update its reference profiles and validation tests based on the AI agent's behavior. This allows the method to evolve alongside the AI agent, ensuring robust and dynamic monitoring over time.
[0064] In some examples, security keys, such as application programming interface (API) keys, can be assigned to applications that include one or more AI agents to control access to the applications. AI agents included in the applications can be referred to as the applications' AI agents. The AI agents can be embedded or encapsulated within the applications, or included in the applications in other forms, as long as the AI agents are attached to or part of the application. In some examples, the application can include one or more functions, and the AI agents can be used by the functions to generate output. In some examples, the security keys can be considered as being used to control the AI agents within the applications.In some examples, the security keys assigned to applications refer to security keys assigned to KL agents within the applications.
[0065] Fig. Figure 5 shows a flowchart of an example of Procedure 500 for performing access control for an application on a network. In some examples, Procedure 500 may include: Determining 510 a security key assignment capability of an access control of a Kl model outside the application; and Assigning 530, based on the security key assignment capability of an access control, a security key to the application.
[0066] In some examples, the security key assignment capability of an access control may refer to the security key assignment capability of the AI model outside the application. In some examples, the AI model outside the application may refer to AI model 160 or 170 in Fig. Be 1.
[0067] In some examples, the security key assignment capability of an access control may mean whether the access control has the capability of dynamic security key assignment or whether it has the capability of static security key assignment.
[0068] In some examples where access control has the capability for dynamic security key assignment, security keys can be assigned to applications that are managed dynamically. The security keys can be valid for a predetermined period and can be changed or revoked on a rotating basis according to a network security policy, such as that of an IT environment provided by network 100A.
[0069] In some examples, a dynamic key controller can send an initial dynamic security key to an application that needs the security key to access the KL model from outside the application. At a first interval, the dynamic key controller can send a second dynamic security key to the same application. The second dynamic security key can be used to replace the first dynamic security key and can be used to allow the application to access the KL model at a second interval. The first dynamic security key can also be sent by the dynamic key controller to another application that is also logging in to access the KL model. In this way, dynamic security keys can be rotated between different applications to prevent security key forgery.
[0070] In some examples, the access control system has the capability of static security key assignment. In such a situation, the assignment of security keys can be implemented in various static ways. For example, static keys can be assigned via encryption or via a proxy.
[0071] In some examples associated with encryption, a key manager can assign a static security key to the application. The assignment can be initiated in response to a request for a key for the application or triggered by a pre-configured rule managed by the key manager itself. The assigned static security key can then be encrypted and sent to the application. Because the security key is encrypted, the application might not receive it. Therefore, in some examples, the encrypted security key is hidden from the application.
[0072] In some examples, the key manager is a local key manager that stores and manages static security keys. In some examples, the static security keys can be obtained by the local key manager based on communications with the access control of the AI model outside the application or with the AI model itself. In some examples, the key manager may reside on the machine where the application is running and provide a key allocation service only for applications running on that machine.
[0073] In some examples, key management is a centralized key management system that provides services to applications running on different machines. This can reduce the number of key management systems in a network. In some examples, the machines might be devices 110 in Fig.1. In some examples, the centralized key management can determine the security keys based on communications with the access control, such as control 18 in Fig. 1. The key management of the KL model is obtained outside the application, or the KL model itself. In some other examples, the centralized key management is itself the access control of the KL model outside the application.
[0074] In some examples, the encrypted security keys assigned to applications can be sent to the access control of the AI model, allowing the access control to determine whether an access request associated with an encrypted security key, such as carrying an encrypted security key, is authorized to access the AI model. In some examples, the access control can decrypt the encrypted security key and perform the determination based on the decrypted security key. In some examples, the access control can negotiate the encryption algorithm with the key manager before implementing encryption, or it can inform the key manager about the encryption algorithm.In some examples, the access control of the Kl model outside the application and the key manager can negotiate to determine security keys that are valid for both. In some examples, both the Kl model's access control and the application can receive identical security keys for a third entity. Based on these types of security key assignments, the access control can determine whether to deny or accept an access request that includes a security key.
[0075] In some examples, a proxy mode based on a key proxy can be implemented. For instance, the key proxy can receive an access request for an application and, in response to the request, assign a security key to the application. The access request might be a request to access the Kl model outside the application. The key proxy can receive a variety of static security keys before receiving a variety of access requests for different applications and then assign some security keys to certain access requests in response. For example, the key proxy can include a static security key in a received access request and send the access request, including the static security key, to the access request's destination.The goal can be the access control of the AI model outside of the application or any other device with similar access control functions.
[0076] Fig. Figure 6 shows a flowchart of an example of a procedure 600 for performing access control on an access request that includes an encrypted security key.
[0077] In some examples, key management may reside in a secure, isolated memory area within a computer's CPU. Key management is provided with a protected environment for executing sensitive code and handling confidential data, ensuring that this data remains protected even if the rest of the system is compromised.
[0078] In some examples, the interface application can be a set of tools, drivers, and APLs that enable operating systems and applications to utilize a set of safety-related instruction codes integrated into CPUs to create a secure execution environment within an application.
[0079] In some examples, procedure 600 may include the following operations.
[0080] 610. The application 601 can send a request for an encrypted Apl key to the interface application 602, the interface application 602 being designed to implement communications between the application 601 and the key controller 603.
[0081] 620. The interface application 602 can forward the request to the key controller 603.
[0082] 630. The key controller 603 can encrypt a static Apl key and an expiration date of the key 630. The static Apl key can be assigned by the key controller in some examples.
[0083] 640. The key controller 603 can send the encrypted Apl key and the expiry date to the interface application 602.
[0084] 650. The interface application 602 can forward the encrypted APL key and expiry date to the application 601.
[0085] 660. Application 601 can send a request to LLM service 604 using the encrypted APL key and the expiration date. In some examples, LLM service 604 may be an LLM. Other Kl models may replace LLM service 604 in some examples.
[0086] 670. Upon receiving the request, the LLM service 604 can decrypt the encrypted API key and expiration date and then proceed with the decrypted API key and expiration date. In some examples, since the request is to request access to the LLM service, the next step might be to determine whether the LLM service could be accessed by the application 601. In some examples, the LLM service 604 might provide an example of a Kl service based on the Kl model 160 or an example of a Kl service based on the Kl model 170. Fig. Be 1.
[0087] 680. The LLM service 604 can send a result of the further procedure to application 601. The result could be, for example, whether application 601 is allowed to access the LLM service.
[0088] In some examples, the LLM service 604 may include an LLM model and one or more control components. The operations performed by the LLM service 604 may be carried out by a component of the LLM service, such as an access control, designed to manage application access to the LLM model, either independently or in conjunction with other components, such as the LLM model itself.
[0089] Fig. Figure 7 shows a flowchart of an example of a procedure 700 for the procedure of KL agents based on APL keys.
[0090] 710. In some examples, a controller, such as controller 180, can determine whether an AI model, such as AI models 160 or 170, supports dynamic API key assignment. If the AI model supports dynamic API key assignment, the process can proceed to 720; if the AI model does not support dynamic API key assignment, the process can proceed to 730. 720. If, in some examples, the AI model supports dynamic API key assignment, an API key manager can be used to assign dynamic API keys to control access by an AI agent, where access can refer to access requested by an application that includes the AI agent, and where the API keys can be rotated among different AI agents or applications using the AI agents.In some examples, the API receives a message from the controller, informing the API key manager about the dynamic assignment of the API key. In response, the API key manager begins dynamically assigning the API key.
[0091] 730. If the Kl model does not support dynamic API key assignment in some examples, a solution for assigning static APL keys can be selected, for example, by the controller. The available solution can include proxy mode 740, local mode 750, and centralized mode 760.
[0092] 740. In proxy mode, API calls or APL access requests can be routed through a proxy. Some details of this mode are described in some of the examples above associated with the key proxy.
[0093] 750. In local mode, an application can request an encrypted APL key from a local key manager to access an LLM. Some details about requesting the key may be described in some of the examples above associated with local allocation.
[0094] 760. In centralized mode, an application using a Kl agent can request an encrypted Apl key from a local key manager to access an LLM. In some examples, because a Kl agent included in an application can cause the application to perform operations based on the Kl agent's output, the application may be interpreted as using the Kl agent. Some details regarding requesting the key may be found in some of the examples above associated with centralized allocation.
[0095] 770. After the application has received the encrypted APL key from either the local key repository or the centralized key repository, it can send an access request containing the encrypted APL key to the LLM. The LLM can decrypt the encrypted APL key. In some examples, the decryption may be performed by an access control mechanism of the LLM, which may be a section of the LLM, the LLM itself, or an entity independent of the LLM. Some details of the decryption process may be described in some of the examples above.
[0096] 780. The LLM's access control can manage the AI agents based on the APL key included in the access request. Management can include allowing access to the LLM, denying access to the LLM, or requiring the application to perform further authentication or checks. Although the management applies to the application, it can be interpreted as management of the AI agent, since the AI agent can influence or control the application's actions. Some details of the management may be described in some of the examples above.
[0097] Fig. Figure 8 shows a block diagram of an example of the 800 unit. In some examples, the 800 unit can control the 180 unit. Fig.1. In some examples, the facility 800 can be a Kl recognition agent. In some other examples, the facility 800 can be a different entity in each individual example of the revelation.
[0098] In some examples, the device 800 may include interfaces 820, such as 820a and 820b, and a processing circuit arrangement 840. The device 800 may be designed, based on the cooperation between one or more tangible, machine-readable non-volatile storage media 850 and one or more processors 860 of the processing circuit arrangement 840, to perform operations and / or functionalities relating to the Fig. 1, Fig. 2, Fig. 3, Fig. 4, Fig. 5, Fig.6 and / or 7 are described, and / or to implement one or more operations described herein that are associated with the control 180, the detection of AI agents, the detection of risky AI agents from the detected AI agents, the management of AI agents based on security keys and / or the access control of AI models 160 or 170.
[0099] In some examples, the device 800 can perform the above implementations if the computer-executable instructions, such as the logic or computer program 870, are executed by one or more processors 860. In some examples, the interfaces 820 are interface means 820, and the processing circuit arrangement 840 is a processing means 840. In some examples, the device 800 may be located in a computer system 800A, which may include other devices.
[0100] In some examples, the 820 interfaces may be configured to communicate with other entities. For example, the entities in System 100 may be both inside and outside the 100A network. In some examples, the 820 interfaces may include one or more wireless interfaces, including antennas such as MIMO antennas, and / or wired interfaces such as serial USB interfaces and / or RJ45 interfaces. The wireless interfaces may be configured to transmit and / or receive Wi-Fi signals, 3GPP signals, and / or other wireless signals. The wired interfaces may be configured to receive signals transmitted over fiber, coaxial cable, and other media.
[0101] In some examples, the one or more processors may be 860 general-purpose CPUs, mobile processors, server and data center processors, embedded processors, graphics processing units (GPUs), specialized processors, microcontrollers, field-programmable gate arrays (FPGAs), digital signal processors (DSPs), application-specific integrated circuits (ASICs), integrated circuits (ICs) and / or other circuit arrangements that have the capability to perform the operations of the control in each individual example of this disclosure.
[0102] In some examples, the term "computer-readable non-volatile storage media" may be intended to include all machine- and / or computer-readable media, with the sole exception of a volatile propagation signal.
[0103] In some examples, the Storage Medium 850 may include one or more types of computer-readable storage media capable of storing data, including volatile memory, non-volatile memory, removable or non-removable memory, erasable or non-erasable memory, writable or rewritable memory, and the like. For example, the Storage Medium 850 may include: RAM, DRAM, Double Data Rate DRAM (DDR-DRAM), SDRAM, Static RAM (SRAM), ROM, Programmable ROM (PROM), Erasable Programmable ROM (EPROM), Electrically Erasable Programmable ROM (EEPROM), Compact Disk ROM (CD-ROM), Compact Disk Recordable (CD-R), Compact Disk Rewriteable (CD-RW), Flash memory (e.g., USB flash drive).NOR or NAND flash memory, content-addressable memory (CAM), polymer memory, phase-change memory, ferroelectric memory, silicon oxide nitride oxide silicon (SONOS) memory, a disk, a floppy disk, a hard disk drive, an optical disk, a magnetic disk, a card, a magnetic card, an optical card, a tape, a cassette, and the like. The computer-readable storage medium may include any suitable media involved in downloading or transmitting a computer program from a remotely located computer to a requesting computer, carried by data signals embodied in a carrier wave or other propagation medium over a communication link, such as a modem, radio, or network connection.
[0104] In some examples, the logic or computer program 870 may include instructions, data, and / or code which, when executed by a machine, for example, implemented by one or more processors in an establishment, may cause the machine to perform a procedure, process, and / or operations as described herein, such as the examples, operations, and / or functionalities that comprise the examples, operations, and / or functions of the AI recognition agent or the controller 180, which are connected with Fig. 1, Fig. 2, Fig. 3, Fig. 4, Fig. 5, Fig.6 and / or 7 are associated. The machine may, for example, include any suitable processing platform, computing platform, computing device, processing device, any computing system, processing system, any computer, processor, or the like, and may be implemented using any suitable combination of hardware, software, firmware, and the like.
[0105] In some examples, each of the components 820, 840, 850, 860, and 870 is implemented in the 800 device by a corresponding means capable of implementing the functions of the above components. In some examples, the storage medium 850 is not included in the 800 device because the 860 processors, logic, or the 870 computer program can read from a storage medium within the 800 device.
[0106] In some examples, the logic or computer program may include or be implemented as software, a software module, an application, a program, a subroutine, instructions, a set of instructions, data processing code, words, values, symbols, and the like. The instructions may include any suitable type of code, such as source code, compiled code, interpreted code, executable code, static code, dynamic code, and the like. The instructions may be implemented according to a predefined computer language, manner, or syntax for instructing a processor to perform a specific function. The instructions may be implemented using any suitable object-oriented, visual, compiled, and / or interpreted programming language, high-level and / or low-level, such as C, C++, Java, BASIC, Matlab, Pascal, Visual BASIC, assembly language, machine code, and the like.
[0107] In some examples, the 820 interfaces, the 850 storage media, and the 860 processors communicate with each other via a bus. In some other examples, some of these entities have direct communication links with each other.
[0108] In some examples, the facility 800 can be used to implement any entity, such as a controller, proxy, device, or AI model, in some or all of the examples. To implement different entities, the facility 800 can be configured to store and execute appropriate logic or a computer program 870.
[0109] The following are some examples of a proposed concept: One example (e.g., Example 1) concerns a method for detecting an artificial intelligence (AI) agent of an application in a network. The method involves identifying variants of a multitude of application outputs that correspond to a multitude of identical inputs provided to the application. The method may further involve detecting, based on the variants of the multitude of outputs, an AI agent of the application, where the AI agent comprises an AI model that provides the application with AI-based resource information to generate the multitude of outputs.
[0110] An example (e.g., Example 2) refers to a previously described example (e.g., Example 1) or to any of the examples described herein, where the multitude of identical inputs to the application is provided over an initial period.
[0111] An example (e.g., Example 3) refers to a previously described example (e.g., Example 1 or 2) or to any of the examples described herein, wherein the variants of the multitude of outputs comprise a first multitude of groups of variants determined on the basis of the first multitude of respective analysis procedures performed on the multitude of outputs.
[0112] An example (e.g., Example 4) refers to a previously described example (e.g., Example 3) or to any of the examples described herein, wherein the first set of respective analysis procedures is carried out in parallel and / or sequentially on the set of outputs.
[0113] An example (e.g., Example 5) refers to a previously described example (e.g., one of Examples 1 to 4) or to any of the examples described herein, wherein the application includes one or more functions, and wherein the AI-based resource information supplied by the AI agent is used by at least one of the functions to generate outputs of the at least one of the functions.
[0114] An example (e.g., Example 6) refers to a previously described example (e.g., one of Examples 1 to 5) or to any of the examples described herein, the procedure further comprising: Determine whether the identified AI agent can be managed.
[0115] An example (e.g., Example 7) refers to a previously described example (e.g., Example 6) or to any of the examples described herein, wherein determining whether the detected AI agent is manageable comprises: sending a variety of requests to the AI agent over a second period, wherein the requests call for logic to make a decision; receiving a variety of logic elements from the AI agent to make the decision over the second period, wherein the variety of logic elements is a response to the variety of requests; and determining, based on variations of the variety of logic elements, whether the detected AI agent is manageable.
[0116] An example (e.g., Example 8) refers to a previously described example (e.g., Example 7) or to any of the examples described herein, wherein the multitude of requirements further require a multitude of configuration information of the detected Kl agent over the second period, and wherein the requested multitude of configuration information, together with the requested logic, is used to determine whether the detected Kl agent is manageable.
[0117] An example (e.g., Example 9) refers to a previously described example (e.g., one of Examples 6 to 8) or to any of the examples described herein, wherein determining whether the detected AI agent is manageable includes: generating a reference profile based on past behaviors of the detected AI agent; and determining whether the detected AI agent is manageable based on current behaviors of the detected AI agent and the reference profile.
[0118] An example (e.g., Example 10) refers to a previously described example (e.g., Example 9) or to any of the examples described herein, where the past behaviors used to generate the reference profile include: the range and / or distribution of outputs from the detected AI agent and / or the frequency of output generation from the detected AI agent.
[0119] An example (e.g., Example 11) refers to a previously described example (e.g., one of Examples 1 to 10) or to any of the examples described herein, wherein the procedure further comprises: assigning, based on a security key provisioning capability of an access control of an AI model outside the network, a security key to the application.
[0120] An example (e.g., Example 12) refers to a previously described example (e.g., Example 11) or to any of the examples described herein, wherein the assignment, based on a security key provisioning capability of an access control of a Kl model outside the network, of a security key to the application includes: in response to a capability to provide a static security key of the access control, assigning a static security key to the application.
[0121] An example (e.g., Example 13) refers to a previously described example (e.g., Example 12) or to any of the examples described herein, wherein assigning a static security key to the application comprises: assigning, through a key manager, a static security key to the application; encrypting the static security key; and sending an encrypted static security key to the application, the encrypted static security key being hidden from the application.
[0122] An example (e.g., Example 14) refers to a previously described example (e.g., Example 13) or to any of the examples described herein, wherein the key management is a local key management system located in a machine on which the application is run and provides a key allocation service only for applications running on that machine, or wherein the key management system is a centralized key management system that provides a key allocation service to applications running on different machines.
[0123] An example (e.g., Example 15) refers to a previously described example (e.g., Example 12) or to any of the examples described herein, wherein assigning a static security key to the application comprises: receiving, through a key proxy, an access request from the application; including, through the key proxy, the static security key assigned to the application in the access request; and sending the access request, including the static security key, to a destination of the access request.
[0124] An example (e.g., Example 16) refers to a previously described example (e.g.,Example 11) or any of the examples described herein, wherein the assignment, based on a security key provisioning capability of an access controller of a Kl model outside the network, comprises: in response to a dynamic security key provisioning capability of the access controller, sending, by a dynamic key controller, a first dynamic security key to the application; sending, by the dynamic key controller, a second dynamic security key to the application, the second dynamic security key being used to replace the first dynamic key; and sending, by the dynamic security key, the first dynamic security key to another application to alternate in the use of the first dynamic security key.
[0125] An example (e.g., Example 17) refers to a previously described example (e.g., one of Examples 1 to 16) or to any of the examples described herein, where the security key is an Application Programming Interface (API) key.
[0126] An example (e.g., Example 18) relates to a procedure for performing access control for an application on a network. The procedure may include determining the security key assignment capability of an access control of a Kl model outside the application. The procedure may further include assigning a security key to the application based on the security key assignment capability of the access control.
[0127] An example (e.g., Example 19) refers to a previously described example (e.g., Example 18) or to any of the examples described herein, wherein the assignment, based on a security key assignment capability of an access control, of a security key to the application includes: in response to a static security key assignment capability of the access control, assigning a static security key to the application.
[0128] An example (e.g., Example 20) refers to a previously described example (e.g., Example 19) or to any of the examples described herein, wherein assigning a static security key to the application comprises: assigning, through a key manager, a static security key to the application; encrypting the static security key; and sending an encrypted static security key to the application, the encrypted static security key being hidden from the application.
[0129] An example (e.g., Example 21) refers to a previously described example (e.g., Example 20) or to any of the examples described herein, wherein the key management is a local key management system located in a machine on which the application is running and provides a key allocation service only for applications running on that machine; or wherein the key management system is a centralized key management system that provides a key allocation service to applications running on different machines.
[0130] An example (e.g., Example 22) refers to a previously described example (e.g., Example 19) or to any of the examples described herein, wherein assigning a static security key to the application comprises: receiving, through a key proxy, an access request for the application; including, through the key proxy, the static security key assigned to the application in the access request; and sending the access request, including the static security key, to a destination of the access request.
[0131] An example (e.g., Example 23) refers to a previously described example (e.g., Example 18) or to any of the examples described herein, wherein the assignment, based on a security key assignment capability of an access controller, comprises: in response to a dynamic security key provisioning capability of the access controller, sending, by a dynamic key controller, a first dynamic security key to the application; sending, by the dynamic key controller, a second dynamic security key to the application, the second dynamic security key being used to replace the first dynamic key; and sending, by the dynamic security key, the first dynamic security key to another application to alternate in the use of the first dynamic security key.
[0132] An example (e.g., Example 24) refers to a previously described example (e.g., one of Examples 18 to 23) or to any of the examples described herein, where the security key is an Application Programming Interface (API) key.
[0133] An example (e.g., Example 25) refers to a facility 800 comprising an interface 820 and a processing circuit arrangement 840. The facility 800 includes machine-readable instructions 870. The processing circuit arrangement 840 is configured with a trusted execution environment to execute the machine-readable instructions 870 within the trusted execution environment to perform the procedure according to one of Examples 1 through 17.
[0134] An example (e.g., Example 26) refers to a facility 800 comprising an interface 820 and a processing circuit arrangement 840. The facility 800 includes machine-readable instructions 870. The processing circuit arrangement 840 is configured with a trusted execution environment to execute the machine-readable instructions 870 within the trusted execution environment to perform the procedure according to one of Examples 18 to 24.
[0135] An example (e.g., Example 27) refers to a facility 800 comprising an interface 820 and a processing circuit arrangement 840. The facility 800 includes machine-readable instructions 870. The processing circuit arrangement 840 is configured with a trusted execution environment to execute the machine-readable instructions 870 within the trusted execution environment to determine variants of a multitude of application outputs, each corresponding to a multitude of identical inputs supplied by the application. The processing circuit arrangement 840 is further designed to detect an application AI agent based on the variants of the multitude of outputs, the AI agent comprising an AI model that provides the application with AI-based resource information to generate the multitude of outputs.
[0136] An example (e.g., Example 28) refers to a facility 800 comprising an interface 820 and a processing circuit arrangement 840. The facility 800 includes machine-readable instructions 870. The processing circuit arrangement 840 is configured with a trusted execution environment to execute the machine-readable instructions 870 within the trusted execution environment to perform access control for an application on a network. The access control includes determining the security key assignment capability of an access controller of a Kl model outside the application. The access control may further include assigning a security key to the application based on the security key assignment capability of an access controller.
[0137] An example (e.g., Example 29) refers to a system that includes the facility 800 as described in Example 25 or 27.
[0138] An example (e.g., Example 30) refers to a system that includes the facility 800 as described in Example 26 or 28.
[0139] An example (e.g., Example 31) refers to an Access Control Facility 800 based on the locations of user devices. The facility includes an Interface Facility 820 and a Processing Facility 840. The Processing Facility 840 is used to identify variants of a multitude of application outputs corresponding to a multitude of identical inputs provided to the application. The Processing Facility 840 is further used to identify, based on the variants of the multitude of outputs, an AI agent of the application, wherein the AI agent comprises an AI model that provides the application with AI-based resource information to generate the multitude of outputs.
[0140] An example (e.g., Example 32) refers to an access control device 800 based on the locations of user devices. The device includes an interface device 820 and a processing device 840. The processing device 840 is used to determine the security key assignment capability of an access control device of a Kl model outside the application. The processing device 840 is further used to assign a security key to the application based on the security key assignment capability of an access control device.
[0141] An example (e.g., Example 33) refers to a system that includes the facility 800 as described in Example 31 or in any other example.
[0142] An example (e.g., Example 34) refers to a system that includes the facility 800 as described in Example 32 or in any other example.
[0143] An example (e.g., Example 35) refers to a computer system that includes one of the facilities 800 from Example 25 (or according to another example), the facility 800 from Example 27 (or according to another example), the facility 800 from Example 29 (or according to another example), or the facility 800 from Example 31 (or according to another example).
[0144] An example (e.g., Example 36) refers to a computer system that includes one of the facilities 800 from Example 26 (or according to another example), the facility 800 from Example 28 (or according to another example), the facility 800 from Example 30 (or according to another example), or the facility 800 from Example 32 (or according to another example).
[0145] An example (e.g., Example 37) refers to a computer system designed to perform the procedure of any of Examples 1 to 17 (or according to any other example).
[0146] An example (e.g., Example 38) refers to a computer system designed to perform the procedure of any of Examples 18 to 24 (or according to any other example).
[0147] An example (e.g., Example 39) refers to a non-volatile, machine-readable storage medium containing program code which, when executed, causes a machine to perform the procedure of any one of Examples 1 to 17 (or according to another example) or the procedure of any one of Examples 18 to 24 (or according to another example).
[0148] An example (e.g., Example 40) refers to a computer program with program code for performing the procedure of any of Examples 1 to 17 (or any other example) or the procedure of any of Examples 18 to 24 (or any other example) when the computer program is executed on a computer, a processor, or a programmable hardware component.
[0149] An example (e.g., Example 41) refers to a machine-readable memory containing machine-readable instructions which, when executed, implement a procedure or realize a facility as claimed in any of the attached examples.
[0150] The aspects and features described in relation to a particular of the previous examples can also be combined with one or more of the further examples to replace an identical or similar feature of that further example or to additionally introduce the features into the further example.
[0151] Examples may also include a (computer) program with program code to execute one or more of the above procedures, when the program is executed on a computer, processor, or other programmable hardware component. Thus, steps, operations, or processes of different procedures described above may also be executed by programmed computers, processors, or other programmable hardware components. Examples may also include program storage devices, such as digital data storage media, that are machine-, processor-, or computer-readable and can encode and / or contain machine-executable, processor-executable, or computer-executable programs and instructions. Program storage devices may include, for example, digital storage devices, magnetic storage media such as magnetic disks and tapes, hard disks, or optically readable digital data storage media.Other examples may include computers, processors, control units, (field-)programmable logic arrays ((F)PLAs), (field-)programmable gate arrays ((F)PGAs), graphics processing units (GPUs), application-specific integrated circuits (ASICs), integrated circuits (ICs), or system-on-a-chip (SoC) systems programmed to perform the steps of the procedures described above.
[0152] It is further understood that the disclosure of multiple steps, processes, operations, or functions in the description or claims is not to be interpreted as implying that these operations necessarily depend on the described sequence, unless explicitly stated in a specific case or required for technical reasons. Therefore, the preceding description does not restrict the execution of multiple steps or functions to a specific sequence. Furthermore, in other examples, a single step, function, process, or operation may include and / or be subdivided into multiple sub-steps, functions, processes, or operations.
[0153] If certain aspects relating to a device or system have been described, these aspects should also be understood as a description of the corresponding procedure. For example, a block, device, or functional aspect of the device or system may correspond to a feature, such as a process step, of the corresponding procedure. Accordingly, aspects described in relation to a procedure should also be understood as a description of a corresponding block, element, property, or functional feature of a corresponding device or system.
[0154] As used herein, the term "module" refers to logic that may be implemented in a hardware component or device, software or firmware running on a processing unit, or a combination thereof, to perform one or more operations consistent with the present disclosure. Software and firmware may be implemented as instructions and / or data stored on non-volatile, computer-readable storage media. As used herein, the term "circuit arrangement" alone or in any combination may include: a non-programmable (hard-wired) circuit arrangement, a programmable circuit arrangement such as processing units, a state machine circuit arrangement, and / or firmware that stores instructions executable by a programmable circuit arrangement.The modules described herein can be embodied collectively or individually as a circuit arrangement that forms part of a computing system. Thus, any of the modules can be implemented as a circuit arrangement. A computing system described as being programmed to perform a procedure can be programmed to perform the procedure using software, hardware, firmware, or combinations thereof.
[0155] Any of the disclosed methods (or any part thereof) may be implemented as computer-executable instructions or a computer program product. Such instructions can cause a computing system or one or more processing units capable of executing computer-executable instructions to perform any of the disclosed methods. As used herein, the term "computer" refers to any computing system or device described or mentioned herein. Thus, the term "computer-executable instructions" refers to instructions that can be executed by any computing system or device described or mentioned herein.
[0156] The computer-executable instructions can be, for example, part of the operating system of the computing system, an application stored locally on the computing system, or a remote application accessible to the computing system (e.g., via a web browser). Any of the procedures described herein can be performed by computer-executable instructions carried out by a single computing system or by one or more networked computing systems operating in a network environment. Computer-executable instructions and updates to computer-executable instructions can be downloaded to a computing system from a remote server.
[0157] Furthermore, it is understood that an implementation of the disclosed technologies is not limited to any specific computer language or computer program. For example, the disclosed technologies can be implemented by software written in C++, C#, Java, Perl, Python, JavaScript, Adobe Flash, assembly language, or any other programming language. Likewise, the disclosed technologies are not limited to any particular computer system or type of hardware.
[0158] Furthermore, any of the software-based examples (which include, for example, computer-executable instructions for causing a computer to perform any of the disclosed methods) can be uploaded, downloaded, or remotely accessed via suitable means of communication. Such suitable means of communication include, for example, the Internet, the World Wide Web, an intranet, cables (including fiber optic cables), magnetic communication, electromagnetic communication (including RF, microwave, ultrasonic, and infrared communication), electronic communication, or other such means of communication.
[0159] The disclosed methods, devices, and systems are not to be understood as being restrictive in any way. Instead, the present disclosure applies to all novel and non-obvious features and aspects of the various disclosed examples, both individually and in various combinations and sub-combinations. The disclosed methods, devices, and systems are not limited to any specific aspect or feature, nor do the disclosed embodiments require that any specific advantages or problems be solved.
[0160] Operating theories, scientific principles, or other theoretical descriptions presented herein with reference to the devices or methods of this disclosure are provided for convenience only and are not intended to limit the scope. The devices and methods in the appended claims are not limited to those devices and methods that operate in the manner described by such operating theories.
[0161] The following claims are hereby incorporated into the detailed description, each claim standing independently as a separate example. It should also be noted that, although in the claims a dependent claim refers to a specific combination with one or more other claims, other examples may also include a combination of the dependent claim with the subject matter of any other dependent or independent claim. Such combinations are hereby expressly suggested unless it is stated in a particular case that a specific combination is not intended. Furthermore, features of a claim should also be included for any other independent claim, even if that claim is not directly defined as dependent on that other independent claim.
Claims
[1] Procedure, encompassing: Identifying variants of a multitude of application outputs that correspond to a multitude of identical inputs provided to the application; and Recognizing, based on the variations of the multitude of outputs, an artificial intelligence (AI) agent of the application, wherein the AI agent comprises an AI model that provides the application with AI-based resource information to generate the multitude of outputs. [2] Method according to claim 1, wherein the plurality of identical inputs to the application is supplied over a first period of time. [3] Method according to claim 1 or 2, wherein the variants of the plurality of outputs comprise a first plurality of groups of variants determined on the basis of the first plurality of respective analysis methods carried out on the plurality of outputs. [4] Method according to claim 3, wherein the first plurality of respective analysis methods is carried out in parallel and / or in series on the plurality of outputs. [5] Method according to any one of claims 1 to 4, wherein the application includes one or more functions, and wherein the AI-based resource information supplied by the AI agent is used by at least one of the functions to generate outputs of the at least one of the functions. [6] Method according to any one of claims 1 to 5, wherein the method further comprises: Determine whether the identified AI agent can be managed. [7] Method according to claim 6, wherein determining whether the identified AI agent is to be managed comprises: Sending a large number of requests to the AI agent over a second period, with the requests requiring logic to make a decision; Receiving a multitude of logic elements from the AI agent to make the decision about the second period, where the multitude of logic elements is a response to the multitude of requirements; and Determine, based on variations of the multitude of logic elements, whether the detected AI agent can be managed. [8] Method according to claim 7, wherein the plurality of requirements further require a plurality of configuration information of the detected AI agent over the second period and wherein the requested plurality of configuration information is used together with the requested logic to determine whether the detected AI agent is manageable. [9] Method according to any one of claims 6 to 8, wherein determining whether the identified AI agent is to be managed comprises: Generating a reference profile based on past behaviors of the detected AI agent; and Determine whether the detected AI agent can be managed, based on the current behavior of the detected AI agent and the reference profile. [10] Method according to any one of claims 1 to 9, wherein the method further comprises: assigning, on the basis of a security key provision capability of an access control of a KL model outside the network, a security key to the application. [11] Method according to claim 10, wherein the assignment, based on a security key provisioning capability of an access control of an AI model outside the network, comprises: Assigning, in response to an ability to provide a static security key for access control, a static security key for the application. [12] Method according to claim 11, wherein the assignment of a static security key comprises: Assigning, through a key management system, a static security key for the application; Encrypting the static security key; and Sending an encrypted static security key to the application, where the encrypted static security key is hidden from the application. [13] Method according to claim 11, wherein the assignment of a static security key comprises: Received, through a key proxy, an access request from the application; Include, through the key proxy, the static security key assigned to the application in the access request; and Sending the access request, including the static security key, to an access request destination. [14] Non-transient machine-readable storage medium containing program code which, when executed, causes a machine to perform the method according to any one of claims 1 to 13. [15] Procedures, including: Determining a security key assignment capability of an access control system of an artificial intelligence (AI) model outside of an application; and Assign a security key to the application based on the security key assignment capability of an access control. [16] Method according to claim 15, wherein the assignment of the security key to the application, based on a security key assignment capability of an access control, comprises: Assigning, in response to an ability to assign a static security key to the access control, a static security key for the application. [17] Method according to claim 16, wherein the assignment of a static security key comprises: Assigning, through a key management system, a static security key for the application; Encrypting the static security key; and Sending an encrypted static security key to the application, where the encrypted static security key is hidden from the application. [18] Method according to claim 17, where the key management is a local key management system located on a machine where the application is running, and provides a key allocation service only for applications running on that machine; or where the key management is a centralized key management system that provides a key allocation service to applications running on different machines. [19] Non-volatile machine-readable storage medium containing program code which, when executed, causes a machine to perform the method according to any one of claims 15 to 18. [20] Device comprising an interface means and a processing means, wherein the processing means is designed to identify variants of a multitude of application outputs corresponding to a multitude of identical inputs provided to the application, and The processing means is designed to identify an AI agent of the application based on the variants of the multitude of outputs, wherein the AI agent comprises an AI model that provides the application with AI-based resource information to generate the multitude of outputs.