system

The system addresses phishing via SMS by employing AI-driven analysis and notification to block and alert users of potential leaks, enhancing security measures against phishing.

JP2026018589APending Publication Date: 2026-02-05SOFTBANK GROUP CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024119911
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-25
Publication Date
2026-02-05

AI Technical Summary

Technical Problem

Conventional technologies do not provide sufficient countermeasures against phishing sites via SMS, posing a high risk of leaking confidential and personal information.

Method used

A system comprising a text analysis unit, link analysis unit, file analysis unit, risk blocking unit, and notification unit, utilizing generative AI to analyze SMS text, linked messages, and attachments for phishing patterns, and block potential leaks while notifying users of suspicious points.

Benefits of technology

Reduces the risk of confidential and personal information leakage via SMS by detecting phishing attempts through multifaceted analysis and providing timely notifications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026018589000001_ABST
    Figure 2026018589000001_ABST
Patent Text Reader

Abstract

An object of a system according to an embodiment is to reduce the risk of leakage of confidential information and personal information in SMS.SOLUTION: A system includes a text analysis part, a link analysis part, a file analysis part, a risk block part, and a notification part. The text analysis unit analyzes the text of the SMS. The link analysis unit analyzes a sentence of a link destination of the SMS analyzed by the text analysis unit. The file analysis unit analyzes the content of the attached file of the SMS analyzed by the link analysis unit. The risk block unit blocks a risk of leakage of confidential information and personal information based on a result of the analysis by the file analysis unit. The notifier notifies the user of the suspect points based on the results blocked by the risk blocker.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The technology of the present disclosure relates to a system. [Background technology]

[0002] Patent document 1 discloses a persona chatbot control method performed by at least one processor, the method including the steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to a description of the chatbot character, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Publication No. 2022-180282 Summary of the Invention [Problem to be solved by the invention]

[0004] Conventional technology did not provide sufficient countermeasures against phishing sites via SMS, posing a high risk of leaking confidential and personal information.

[0005] The system according to the embodiment aims to reduce the risk of leakage of confidential information and personal information via SMS. [Means for solving the problem]

[0006] The system according to the embodiment includes a text analysis unit, a link analysis unit, a file analysis unit, a risk blocking unit, and a notification unit. The text analysis unit analyzes the text of the SMS. The link analysis unit analyzes the text of the SMS linked to by the text analysis unit. The file analysis unit analyzes the contents of the SMS attachment analyzed by the link analysis unit. The risk blocking unit blocks the risk of leakage of confidential information and personal information based on the results of the analysis by the file analysis unit. The notification unit notifies the user of suspicious points based on the results of blocking by the risk blocking unit. [Effects of the Invention]

[0007] The system according to the embodiment can reduce the risk of confidential information and personal information being leaked via SMS. [Brief explanation of the drawings]

[0008] [Figure 1] 1 is a conceptual diagram showing an example of the configuration of a data processing system according to a first embodiment. [Figure 2] 1 is a conceptual diagram showing an example of main functions of a data processing device and a smart device according to a first embodiment. [Figure 3] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a second embodiment. [Figure 4] FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and smart glasses according to a second embodiment. [Figure 5] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a third embodiment. [Figure 6] FIG. 11 is a conceptual diagram showing an example of main functions of a data processing device and a headset-type terminal according to a third embodiment. [Figure 7] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a fourth embodiment. [Figure 8] FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and a robot according to a fourth embodiment. [Figure 9]1 shows an emotion map onto which multiple emotions are mapped. [Figure 10] 1 shows an emotion map onto which multiple emotions are mapped. DETAILED DESCRIPTION OF THE INVENTION

[0009] An example of an embodiment of a system according to the technology of the present disclosure will be described below with reference to the accompanying drawings.

[0010] First, the terms used in the following description will be explained.

[0011] In the following embodiments, a coded processor (hereinafter simply referred to as a "processor") may be a single arithmetic device or a combination of multiple arithmetic devices. Furthermore, the processor may be a single type of arithmetic device or a combination of multiple types of arithmetic devices. Examples of arithmetic devices include a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a GPGPU (General-Purpose computing on Graphics Processing Units), an APU (Accelerated Processing Unit), or a TPU (Tensor Processing Unit).

[0012] In the following embodiments, a coded RAM (Random Access Memory) is a memory in which information is temporarily stored and is used as a working memory by a processor.

[0013] In the following embodiments, the coded storage is one or more nonvolatile storage devices that store various programs, various parameters, etc. Examples of nonvolatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), and magnetic tapes.

[0014] In the following embodiments, a communication I / F (Interface) with a symbol is an interface including a communication processor, an antenna, etc. The communication I / F controls communication between multiple computers. Examples of communication standards applied to the communication I / F include wireless communication standards including 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), and Bluetooth (registered trademark).

[0015] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B." In other words, "A and / or B" means that it may be only A, only B, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" is also applied when three or more things are expressed connected by "and / or."

[0016] [First embodiment] FIG. 1 shows an example of the configuration of a data processing system 10 according to the first embodiment.

[0017] 1, a data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.

[0018] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0019] The smart device 14 includes a computer 36, a reception device 38, an output device 40, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The reception device 38, the output device 40, and the camera 42 are also connected to the bus 52.

[0020] The reception device 38 includes a touch panel 38A and a microphone 38B, and receives user input. The touch panel 38A detects contact with a pointer (for example, a pen or a finger) to receive user input by the touch of the pointer. The microphone 38B detects the user's voice to receive user input by voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 (see FIG. 2) acquires the data indicating the user input.

[0021] Output device 40 includes a display 40A and a speaker 40B, and presents data to a user by outputting the data in a form of expression that the user can perceive (e.g., audio and / or text). Display 40A displays visible information such as text and images in accordance with instructions from processor 46. Speaker 40B outputs audio in accordance with instructions from processor 46. Camera 42 is a compact digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.

[0022] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 control the exchange of various information between the processor 46 and the processor 28 via the network 54.

[0023] FIG. 2 shows an example of the main functions of the data processing device 12 and the smart device 14.

[0024] 2, in the data processing device 12, a specific process is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific process is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0025] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotion using the emotion identification model 59 and perform identification processing using the user's emotion.

[0026] In the smart device 14, the specific processing is performed by the processor 46. The storage 50 stores a specific processing program 60. The specific processing program 60 is used together with the specific processing program 56 by the data processing system 10. The processor 46 reads the specific processing program 60 from the storage 50 and executes the read specific processing program 60 on the RAM 48. The specific processing is realized by the processor 46 operating as the control unit 46A in accordance with the specific processing program 60 executed on the RAM 48. Note that the smart device 14 may have a data generation model and an emotion identification model similar to the data generation model 58 and the emotion identification model 59.

[0027] Note that a device other than the data processing device 12 may have the data generation model 58. For example, a server device (e.g., a generation server) may have the data generation model 58. In this case, the data processing device 12 obtains a processing result (prediction result, etc.) using the data generation model 58 by communicating with the server device having the data generation model 58. Furthermore, the data processing device 12 may be a server device, or may be a terminal device owned by a user (e.g., a mobile phone, a robot, a home appliance, etc.). Next, an example of processing by the data processing system 10 according to the first embodiment will be described.

[0028] (Example 1) The anti-phishing system according to the embodiment of the present invention performs multifaceted analysis of the text of SMS, the text of linked messages, and the contents of attached files to block the risk of leaking confidential or personal information and notify the user of any suspicious points. This strengthens the anti-phishing measures against SMS and reduces the risk of leaking confidential or personal information of users.

[0029] The phishing prevention system according to the embodiment includes a text analysis unit, a link analysis unit, a file analysis unit, a risk blocking unit, and a notification unit. The text analysis unit analyzes the text of an SMS message. For example, the text analysis unit uses a generation AI to analyze the context of the SMS text and determine whether it is likely to be phishing. The text analysis unit can also refer to the sender's past message history to detect abnormal patterns. The text analysis unit can also use an emotion estimation function to analyze the emotional tone of the SMS text and identify messages that incite fear or urgency. The link analysis unit analyzes the text of the links in the SMS analyzed by the text analysis unit. For example, the link analysis unit uses a generation AI to analyze the HTML structure of the linked page and detect code patterns specific to phishing sites. The link analysis unit can also refer to past versions of the linked page and analyze changes to identify signs of phishing. The link analysis unit can also use an emotion estimation function to analyze the emotional impact of the content of the linked page on the user and evaluate the likelihood of phishing. The file analyzer analyzes the contents of SMS attachments analyzed by the link analyzer. For example, the file analyzer uses generative AI to analyze the metadata of the attachment and identify signs of phishing. The file analyzer can also compare the contents of the attachment with those of other phishing emails to detect common patterns. Furthermore, the file analyzer can use emotion estimation to analyze the emotional impact of the attachment's contents on the user and evaluate the likelihood of phishing. The risk blocker blocks the risk of confidential and personal information leakage based on the results of the file analyzer's analysis. For example, the risk blocker uses generative AI to evaluate and block the risk of confidential and personal information leakage in real time based on the analysis results. The risk blocker can also evaluate and block the risk of confidential and personal information leakage by comparing it with past leak cases. Furthermore, the risk blocker can use emotion estimation to analyze the user's emotional response and block if the risk is high.The notification unit notifies the user of suspicious points based on the results of blocking by the risk blocking unit. For example, the notification unit uses a generation AI to generate a notification that details the suspicious points based on the analysis results. The notification unit can also provide specific examples in the suspicious point notification by referencing past phishing cases. Furthermore, the notification unit can analyze the user's emotional reaction using an emotion estimation function and notify in an appropriate tone. This enables the anti-phishing system according to the embodiment to strengthen phishing countermeasures against SMS and reduce the risk of leakage of the user's confidential information and personal information. For example, the output unit displays the notification results to the user via a web application or mobile application. If the user desires feedback in paper form, the output unit prints the results using a printer. Sending the results via email provides quick feedback by sending the results directly to the user.

[0030] The text analysis unit uses generative AI to analyze the context of the SMS text and compare it with past phishing patterns to detect new phishing techniques. For example, the text analysis unit uses generative AI to analyze the context of the SMS text and compare it with past phishing patterns. For example, if a specific keyword or phrase is included, the pattern is matched with past data to detect new phishing techniques. The generative AI analyzes the context using models such as GPT-3 or BERT. A context analysis algorithm is used to evaluate the relevance of the SMS text and identify the possibility of phishing. This improves the accuracy of phishing countermeasures by detecting new phishing techniques.

[0031] The message body analysis unit can detect abnormal patterns by referencing the sender's past message history. For example, when analyzing an SMS body, the message body analysis unit references the sender's past message history to detect abnormal patterns. For example, if a message contains a style or content that differs from that of a normal message, the abnormality is identified. The sender's past message history is referenced based on, for example, the message storage period and storage format. An abnormal pattern in the message is identified using an anomaly detection algorithm. This makes it easier to detect abnormal patterns by referencing the sender's past message history.

[0032] The link analysis unit can use generation AI to analyze the HTML structure of the linked page and detect code patterns specific to phishing sites. The link analysis unit, for example, uses generation AI to analyze the HTML structure of the linked page and detects code patterns specific to phishing sites. For example, if a specific script or style sheet is included, the phishing site is identified based on that pattern. The HTML structure is analyzed based on, for example, DOM analysis and tag detection. Code patterns specific to phishing sites are detected based on the format of specific scripts and links. This makes it easier to identify phishing sites by detecting code patterns specific to phishing sites.

[0033] The link analysis unit can identify signs of phishing by referencing past versions of the linked page and analyzing the changes. The link analysis unit, for example, refers to past versions of the linked page and analyzes the changes to identify signs of phishing. For example, if there is a sudden design change or new content, signs of phishing can be identified based on those changes. Past versions are referenced based on, for example, web archives or version control systems. Changes are analyzed based on differential analysis and comparison of change history. Signs of phishing are detected based on specific behavioral patterns and abnormal links. This makes it easier to identify signs of phishing by comparing with past versions.

[0034] The file analysis unit can use generation AI to analyze the metadata of an attachment and identify signs of phishing. The file analysis unit, for example, uses generation AI to analyze the metadata of an attachment and identify signs of phishing. For example, if the file creator or creation date and time is unnatural, signs of phishing can be identified based on that metadata. Metadata is analyzed based on the file creation date and creator information. This makes it easier to identify signs of phishing by analyzing the metadata.

[0035] The file analysis unit can compare the contents of the attachment with those of other phishing emails to detect common patterns. For example, the file analysis unit compares the contents of the attachment with those of other phishing emails to detect common patterns. For example, if a specific keyword or phrase is included, signs of phishing are identified based on that pattern. Common patterns are detected based on similarities in specific file formats and content. This makes it easier to identify signs of phishing by detecting common patterns.

[0036] The risk blocking unit can use generative AI to assess and block the risk of confidential information and personal information leakage in real time based on the analysis results. The risk blocking unit, for example, uses generative AI to assess and block the risk of confidential information and personal information leakage in real time based on the analysis results. For example, if a specific keyword or phrase is included, the risk is evaluated and blocked. To perform the assessment in real time, real-time data processing and evaluation algorithms are used. This enhances the protection of confidential information and personal information by evaluating and blocking the risk of leakage in real time.

[0037] The risk blocking unit can compare the risk of confidential information or personal information leakage with past leakage cases and block it. The risk blocking unit, for example, compares the risk of confidential information or personal information leakage with past leakage cases and block it. For example, it evaluates and blocks the current risk based on cases where similar risks occurred in the past. Past leakage cases are referenced based on the construction of a database and the classification of cases. This improves the accuracy of the leakage risk assessment by comparing with past leakage cases.

[0038] The risk blocking unit can apply the function for blocking the risk of confidential information and personal information leaks to other communication means (e.g., email and chat apps) to provide unified security measures. The risk blocking unit can apply the function for blocking the risk of confidential information and personal information leaks to other communication means (e.g., email and chat apps) to provide unified security measures. For example, messages that pose a similar risk can be blocked all at once. Other communication means are applied based on the specific type and application method, such as email, chat apps, and SNS. In this way, unified security measures can be provided by applying the function to other communication means.

[0039] The risk blocking unit can detect abnormal behavioral patterns by comparing the function for blocking the risk of confidential information or personal information leaks with the user's behavioral history. The risk blocking unit, for example, compares the function for blocking the risk of confidential information or personal information leaks with the user's behavioral history to detect abnormal behavioral patterns. For example, if there is an unusual behavior or access, the abnormality is identified. The behavioral history is referenced based on the storage of log data and the analysis of behavioral patterns. This makes it easier to detect abnormal behavioral patterns by comparing it with the user's behavioral history.

[0040] The notification unit can use generation AI to generate a notification that explains suspicious points in detail based on the analysis results. The notification unit, for example, uses generation AI to generate a notification that explains suspicious points in detail based on the analysis results. For example, it generates a notification such as, "This SMS may be phishing. The linked page is disguised as a bank login page." In order to provide a detailed explanation, the content and format of the explanation are clearly defined. This makes it easier for users to understand the risks by explaining suspicious points in detail.

[0041] The notification unit can refer to past phishing cases and provide specific examples when notifying users of suspicious points. For example, the notification unit can generate a notification such as, "This SMS may be phishing. Similar messages have been sent in the past and have resulted in damage." Past phishing cases are referenced based on the construction of a database and the classification of cases. By referencing past phishing cases, users can more easily understand the risks in concrete terms.

[0042] The notification unit can apply the suspicious point notification function to other communication means (e.g., email and chat apps) to provide a unified notification system. The notification unit can, for example, apply the suspicious point notification function to other communication means (e.g., email and chat apps) to provide a unified notification system. For example, messages with similar risks can be notified all at once. Other communication means are applied based on the specific type and application method, such as email, chat apps, and SNS. In this way, a unified notification system can be provided by applying the function to other communication means.

[0043] The notification unit can compare the suspicious point notification function with the user's behavioral history and generate an individually customized notification. The notification unit, for example, compares the suspicious point notification function with the user's behavioral history and generates an individually customized notification. For example, if a similar risk occurred in the past, a customized notification is generated based on that risk. The behavioral history is referenced based on saved log data and behavioral pattern analysis. In this way, by comparing it with the user's behavioral history, an individually customized notification can be generated.

[0044] The system according to the embodiment is not limited to the above-described example, and various modifications are possible, for example, as follows.

[0045] The phishing prevention system can further include a behavior analysis unit that analyzes the user's behavior history. The behavior analysis unit analyzes the user's past behavior patterns and detects abnormal behavior. For example, if there is access during a time when access is not normally performed or if there is access from a device that is not normally used, the abnormality is identified. The behavior analysis unit detects abnormalities based on the saved log data and the analysis of behavior patterns. In this way, the risk of phishing can be further reduced by analyzing the user's behavior history.

[0046] The phishing prevention system can further include a device analysis unit that analyzes user device information. The device analysis unit collects information about devices used by users and detects access from abnormal devices. For example, if there is access from a device that is not normally used, the abnormality is identified. The device analysis unit analyzes information such as the device's IP address, MAC address, and device type. By analyzing device information, the risk of phishing can be further reduced.

[0047] The anti-phishing system can further include a location analysis unit that analyzes the user's location information. The location analysis unit analyzes the user's current location and past location information to detect access from an abnormal location. For example, if there is access from an area that is not normally accessed, the abnormality is identified. The location analysis unit analyzes location information such as GPS data and IP addresses. This analysis of location information can further reduce the risk of phishing.

[0048] The anti-phishing system may further include a traffic analysis unit that analyzes the user's network traffic. The traffic analysis unit monitors the user's network traffic and detects abnormal traffic patterns. For example, if there is data transfer that exceeds the normal traffic volume, the abnormality is identified. The traffic analysis unit detects the abnormality based on network packet analysis and traffic statistics. In this way, the risk of phishing can be further reduced by analyzing the network traffic.

[0049] The anti-phishing system may further include a browser analysis unit that analyzes the user's browser history. The browser analysis unit analyzes the user's browser history to detect abnormal access patterns. For example, if a user accesses a website that is not normally accessed, the abnormality is identified. The browser analysis unit analyzes browser history data and cookie information. In this way, analyzing the browser history can further reduce the risk of phishing.

[0050] The processing flow of the first embodiment will be briefly explained below.

[0051] Step 1: The text analyzer analyzes the text of the SMS. For example, the text analyzer uses generative AI to analyze the context of the SMS text to determine whether it is likely to be phishing. The text analyzer can also reference the sender's past message history to detect abnormal patterns. Furthermore, the text analyzer can use emotion estimation to analyze the emotional tone of the SMS text and identify messages that incite fear or urgency. Step 2: The link analyzer analyzes the text of the linked SMS message analyzed by the text analyzer. For example, the link analyzer uses generative AI to analyze the HTML structure of the linked page and detect code patterns specific to phishing sites. The link analyzer can also refer to past versions of the linked page and analyze changes to identify signs of phishing. Furthermore, the link analyzer can use emotion estimation to analyze the emotional impact of the content of the linked page on the user and evaluate the possibility of phishing. Step 3: The file analyzer analyzes the contents of the SMS attachment analyzed by the link analyzer. For example, the file analyzer uses generative AI to analyze the metadata of the attachment and identify signs of phishing. The file analyzer can also compare the contents of the attachment with those of other phishing emails to detect common patterns. Furthermore, the file analyzer can use emotion estimation to analyze the emotional impact of the attachment's contents on the user and evaluate the likelihood of phishing. Step 4: The risk blocking unit blocks the risk of confidential information and personal information leaks based on the results of the analysis by the file analysis unit. For example, the risk blocking unit uses generative AI to evaluate the risk of confidential information and personal information leaks in real time based on the analysis results and blocks them. The risk blocking unit can also evaluate and block the risk of confidential information and personal information leaks by comparing them with past leak cases. Furthermore, the risk blocking unit can analyze the user's emotional response using an emotion estimation function and block them if the risk is high. Step 5: The notification unit notifies the user of suspicious points based on the results of blocking by the risk blocking unit. For example, the notification unit uses a generation AI to generate a notification that explains the suspicious points in detail based on the analysis results. The notification unit can also provide specific examples in the notification of suspicious points by referencing past phishing cases. Furthermore, the notification unit can use an emotion estimation function to analyze the user's emotional response and notify them in an appropriate tone.

[0052] (Example 2) The anti-phishing system according to the embodiment of the present invention performs multifaceted analysis of the text of SMS, the text of linked messages, and the contents of attached files to block the risk of leaking confidential or personal information and notify the user of any suspicious points. This strengthens the anti-phishing measures against SMS and reduces the risk of leaking confidential or personal information of users.

[0053] The phishing prevention system according to the embodiment includes a text analysis unit, a link analysis unit, a file analysis unit, a risk blocking unit, and a notification unit. The text analysis unit analyzes the text of an SMS message. For example, the text analysis unit uses a generation AI to analyze the context of the SMS text and determine whether it is likely to be phishing. The text analysis unit can also refer to the sender's past message history to detect abnormal patterns. The text analysis unit can also use an emotion estimation function to analyze the emotional tone of the SMS text and identify messages that incite fear or urgency. The link analysis unit analyzes the text of the links in the SMS analyzed by the text analysis unit. For example, the link analysis unit uses a generation AI to analyze the HTML structure of the linked page and detect code patterns specific to phishing sites. The link analysis unit can also refer to past versions of the linked page and analyze changes to identify signs of phishing. The link analysis unit can also use an emotion estimation function to analyze the emotional impact of the content of the linked page on the user and evaluate the likelihood of phishing. The file analyzer analyzes the contents of SMS attachments analyzed by the link analyzer. For example, the file analyzer uses generative AI to analyze the metadata of the attachment and identify signs of phishing. The file analyzer can also compare the contents of the attachment with those of other phishing emails to detect common patterns. Furthermore, the file analyzer can use emotion estimation to analyze the emotional impact of the attachment's contents on the user and evaluate the likelihood of phishing. The risk blocker blocks the risk of confidential and personal information leakage based on the results of the file analyzer's analysis. For example, the risk blocker uses generative AI to evaluate and block the risk of confidential and personal information leakage in real time based on the analysis results. The risk blocker can also evaluate and block the risk of confidential and personal information leakage by comparing it with past leak cases. Furthermore, the risk blocker can use emotion estimation to analyze the user's emotional response and block if the risk is high.The notification unit notifies the user of suspicious points based on the results of blocking by the risk blocking unit. For example, the notification unit uses a generation AI to generate a notification that details the suspicious points based on the analysis results. The notification unit can also provide specific examples in the suspicious point notification by referencing past phishing cases. Furthermore, the notification unit can analyze the user's emotional reaction using an emotion estimation function and notify in an appropriate tone. This enables the anti-phishing system according to the embodiment to strengthen phishing countermeasures against SMS and reduce the risk of leakage of the user's confidential information and personal information. For example, the output unit displays the notification results to the user via a web application or mobile application. If the user desires feedback in paper form, the output unit prints the results using a printer. Sending the results via email provides quick feedback by sending the results directly to the user.

[0054] The text analysis unit uses generative AI to analyze the context of the SMS text and compare it with past phishing patterns to detect new phishing techniques. For example, the text analysis unit uses generative AI to analyze the context of the SMS text and compare it with past phishing patterns. For example, if a specific keyword or phrase is included, the pattern is matched with past data to detect new phishing techniques. The generative AI analyzes the context using models such as GPT-3 or BERT. A context analysis algorithm is used to evaluate the relevance of the SMS text and identify the possibility of phishing. This improves the accuracy of phishing countermeasures by detecting new phishing techniques.

[0055] The message body analysis unit can detect abnormal patterns by referencing the sender's past message history. For example, when analyzing an SMS body, the message body analysis unit references the sender's past message history to detect abnormal patterns. For example, if a message contains a style or content that differs from that of a normal message, the abnormality is identified. The sender's past message history is referenced based on, for example, the message storage period and storage format. An abnormal pattern in the message is identified using an anomaly detection algorithm. This makes it easier to detect abnormal patterns by referencing the sender's past message history.

[0056] The body analysis unit can use the emotion estimation function to analyze the emotional tone of the SMS body and identify messages that incite fear or urgency. For example, the body analysis unit can use the emotion estimation function to analyze the emotional tone of the SMS body and identify messages that incite fear or urgency. For example, it can detect messages such as "Your account will be frozen if you do not respond immediately." The emotion estimation function can analyze the emotional tone using, for example, an emotion analysis algorithm. The emotional tone is evaluated based on classifications such as positive, negative, and neutral. Messages that incite fear or urgency are detected based on specific keywords and context analysis. This allows messages that incite fear or urgency to be identified and attract the user's attention.

[0057] The link analysis unit can use generation AI to analyze the HTML structure of the linked page and detect code patterns specific to phishing sites. The link analysis unit, for example, uses generation AI to analyze the HTML structure of the linked page and detects code patterns specific to phishing sites. For example, if a specific script or style sheet is included, the phishing site is identified based on that pattern. The HTML structure is analyzed based on, for example, DOM analysis and tag detection. Code patterns specific to phishing sites are detected based on the format of specific scripts and links. This makes it easier to identify phishing sites by detecting code patterns specific to phishing sites.

[0058] The link analysis unit can identify signs of phishing by referencing past versions of the linked page and analyzing the changes. The link analysis unit, for example, refers to past versions of the linked page and analyzes the changes to identify signs of phishing. For example, if there is a sudden design change or new content, signs of phishing can be identified based on those changes. Past versions are referenced based on, for example, web archives or version control systems. Changes are analyzed based on differential analysis and comparison of change history. Signs of phishing are detected based on specific behavioral patterns and abnormal links. This makes it easier to identify signs of phishing by comparing with past versions.

[0059] The link analysis unit can use the emotion estimation function to analyze the emotional impact that the content of the linked page has on the user and evaluate the possibility of phishing. The link analysis unit, for example, uses the emotion estimation function to analyze the emotional impact that the content of the linked page has on the user and evaluates the possibility of phishing. For example, if the linked page contains content that incites fear or urgency, the possibility of phishing is evaluated based on that impact. The emotional impact is analyzed based on the calculation of an emotion score and an evaluation of the impact. The possibility of phishing is evaluated based on the calculation of a risk score and a comparison with past cases. In this way, by analyzing the emotional impact, the possibility of phishing can be evaluated more accurately.

[0060] The file analysis unit can use generation AI to analyze the metadata of an attachment and identify signs of phishing. The file analysis unit, for example, uses generation AI to analyze the metadata of an attachment and identify signs of phishing. For example, if the file creator or creation date and time is unnatural, signs of phishing can be identified based on that metadata. Metadata is analyzed based on the file creation date and creator information. This makes it easier to identify signs of phishing by analyzing the metadata.

[0061] The file analysis unit can compare the contents of the attachment with those of other phishing emails to detect common patterns. For example, the file analysis unit compares the contents of the attachment with those of other phishing emails to detect common patterns. For example, if a specific keyword or phrase is included, signs of phishing are identified based on that pattern. Common patterns are detected based on similarities in specific file formats and content. This makes it easier to identify signs of phishing by detecting common patterns.

[0062] The file analysis unit can use the emotion estimation function to analyze the emotional impact that the contents of the attachment have on the user and assess the possibility of phishing. The file analysis unit, for example, uses the emotion estimation function to analyze the emotional impact that the contents of the attachment have on the user and assess the possibility of phishing. For example, if the attachment contains content that incites fear or urgency, the possibility of phishing is assessed based on that impact. The emotional impact is analyzed based on the calculation of an emotion score and an assessment of the impact. The possibility of phishing is assessed based on the calculation of a risk score and a comparison with past cases. In this way, by analyzing the emotional impact, the possibility of phishing can be assessed more accurately.

[0063] The risk blocking unit can use generative AI to assess and block the risk of confidential information and personal information leakage in real time based on the analysis results. The risk blocking unit, for example, uses generative AI to assess and block the risk of confidential information and personal information leakage in real time based on the analysis results. For example, if a specific keyword or phrase is included, the risk is evaluated and blocked. To perform the assessment in real time, real-time data processing and evaluation algorithms are used. This enhances the protection of confidential information and personal information by evaluating and blocking the risk of leakage in real time.

[0064] The risk blocking unit can compare the risk of confidential information or personal information leakage with past leakage cases and block it. The risk blocking unit, for example, compares the risk of confidential information or personal information leakage with past leakage cases and block it. For example, it evaluates and blocks the current risk based on cases where similar risks occurred in the past. Past leakage cases are referenced based on the construction of a database and the classification of cases. This improves the accuracy of the leakage risk assessment by comparing with past leakage cases.

[0065] The risk blocking unit can use the emotion estimation function to analyze the user's emotional response and block messages if the risk is high. For example, the risk blocking unit uses the emotion estimation function to analyze the user's emotional response and block messages if the risk is high. For example, if a message that incites fear or urgency is detected, the risk is evaluated and the message is blocked. The emotional response is analyzed based on the calculation of an emotion score and the classification of the response. This allows for a quick response if the risk is high by analyzing the user's emotional response.

[0066] The risk blocking unit can apply the function for blocking the risk of confidential information and personal information leaks to other communication means (e.g., email and chat apps) to provide unified security measures. The risk blocking unit can apply the function for blocking the risk of confidential information and personal information leaks to other communication means (e.g., email and chat apps) to provide unified security measures. For example, messages that pose a similar risk can be blocked all at once. Other communication means are applied based on the specific type and application method, such as email, chat apps, and SNS. In this way, unified security measures can be provided by applying the function to other communication means.

[0067] The risk blocking unit can detect abnormal behavioral patterns by comparing the function for blocking the risk of confidential information or personal information leaks with the user's behavioral history. The risk blocking unit, for example, compares the function for blocking the risk of confidential information or personal information leaks with the user's behavioral history to detect abnormal behavioral patterns. For example, if there is an unusual behavior or access, the abnormality is identified. The behavioral history is referenced based on the storage of log data and the analysis of behavioral patterns. This makes it easier to detect abnormal behavioral patterns by comparing it with the user's behavioral history.

[0068] The risk blocking unit can use an emotion estimation function to analyze the user's emotional response in real time and block messages if the risk is high. The risk blocking unit, for example, uses the emotion estimation function to analyze the user's emotional response in real time and block messages if the risk is high. For example, if a message that incites fear or urgency is detected, the risk is evaluated and the message is blocked. Real-time analysis is performed using real-time data processing and analysis algorithms. This allows for a quick response if the risk is high by analyzing the user's emotional response in real time.

[0069] The notification unit can use generation AI to generate a notification that explains suspicious points in detail based on the analysis results. The notification unit, for example, uses generation AI to generate a notification that explains suspicious points in detail based on the analysis results. For example, it generates a notification such as, "This SMS may be phishing. The linked page is disguised as a bank login page." In order to provide a detailed explanation, the content and format of the explanation are clearly defined. This makes it easier for users to understand the risks by explaining suspicious points in detail.

[0070] The notification unit can refer to past phishing cases and provide specific examples when notifying users of suspicious points. For example, the notification unit can generate a notification such as, "This SMS may be phishing. Similar messages have been sent in the past and have resulted in damage." Past phishing cases are referenced based on the construction of a database and the classification of cases. By referencing past phishing cases, users can more easily understand the risks in concrete terms.

[0071] The notification unit can analyze the user's emotional response using the emotion estimation function and provide a notification in an appropriate tone. The notification unit, for example, can analyze the user's emotional response using the emotion estimation function and provide a notification in an appropriate tone. For example, the notification can be provided in a calm tone so as not to incite fear or urgency. The emotional response is analyzed based on the calculation of an emotion score and the classification of the response. In this way, by analyzing the user's emotional response, a notification can be provided in an appropriate tone.

[0072] The notification unit can apply the suspicious point notification function to other communication means (e.g., email and chat apps) to provide a unified notification system. The notification unit can, for example, apply the suspicious point notification function to other communication means (e.g., email and chat apps) to provide a unified notification system. For example, messages with similar risks can be notified all at once. Other communication means are applied based on the specific type and application method, such as email, chat apps, and SNS. In this way, a unified notification system can be provided by applying the function to other communication means.

[0073] The notification unit can compare the suspicious point notification function with the user's behavioral history and generate an individually customized notification. The notification unit, for example, compares the suspicious point notification function with the user's behavioral history and generates an individually customized notification. For example, if a similar risk occurred in the past, a customized notification is generated based on that risk. The behavioral history is referenced based on saved log data and behavioral pattern analysis. In this way, by comparing it with the user's behavioral history, an individually customized notification can be generated.

[0074] The notification unit can use the emotion estimation function to analyze the user's emotional response in real time and provide a notification in an appropriate tone. The notification unit, for example, can use the emotion estimation function to analyze the user's emotional response in real time and provide a notification in an appropriate tone. For example, the notification can be provided in a calm tone so as not to incite fear or urgency. Real-time analysis is performed using real-time data processing and analysis algorithms. This allows the user's emotional response to be analyzed in real time and a notification to be provided in an appropriate tone.

[0075] The system according to the embodiment is not limited to the above-described example, and various modifications are possible, for example, as follows.

[0076] The phishing prevention system can further include a behavior analysis unit that analyzes the user's behavior history. The behavior analysis unit analyzes the user's past behavior patterns and detects abnormal behavior. For example, if there is access during a time when access is not normally performed or if there is access from a device that is not normally used, the abnormality is identified. The behavior analysis unit detects abnormalities based on the saved log data and the analysis of behavior patterns. In this way, the risk of phishing can be further reduced by analyzing the user's behavior history.

[0077] The phishing prevention system can further include a device analysis unit that analyzes user device information. The device analysis unit collects information about devices used by users and detects access from abnormal devices. For example, if there is access from a device that is not normally used, the abnormality is identified. The device analysis unit analyzes information such as the device's IP address, MAC address, and device type. By analyzing device information, the risk of phishing can be further reduced.

[0078] The anti-phishing system can further include a location analysis unit that analyzes the user's location information. The location analysis unit analyzes the user's current location and past location information to detect access from an abnormal location. For example, if there is access from an area that is not normally accessed, the abnormality is identified. The location analysis unit analyzes location information such as GPS data and IP addresses. This analysis of location information can further reduce the risk of phishing.

[0079] The anti-phishing system may further include a traffic analysis unit that analyzes the user's network traffic. The traffic analysis unit monitors the user's network traffic and detects abnormal traffic patterns. For example, if there is data transfer that exceeds the normal traffic volume, the abnormality is identified. The traffic analysis unit detects the abnormality based on network packet analysis and traffic statistics. In this way, the risk of phishing can be further reduced by analyzing the network traffic.

[0080] The anti-phishing system may further include a browser analysis unit that analyzes the user's browser history. The browser analysis unit analyzes the user's browser history to detect abnormal access patterns. For example, if a user accesses a website that is not normally accessed, the abnormality is identified. The browser analysis unit analyzes browser history data and cookie information. In this way, analyzing the browser history can further reduce the risk of phishing.

[0081] The anti-phishing system may further include a notification customization unit that estimates the user's emotions and customizes the notification content based on the estimated emotions. The notification customization unit estimates the user's emotions and adjusts the tone and content of the notification based on the estimated emotions. For example, if the user is feeling anxious, the notification may be sent in a calm tone. The emotion estimation is performed based on the user's behavior and the message content. This allows the notification to be sent with consideration for the user's emotions, thereby improving the effectiveness of the anti-phishing measures.

[0082] The anti-phishing system may further include a risk assessment unit that estimates the user's emotions and performs risk assessment based on the estimated emotions. The risk assessment unit estimates the user's emotions and assesses the level of risk based on the estimated emotions. For example, if the user feels fear, the risk is assessed as high. The emotion estimation is performed based on the user's behavior and the message content. This allows for risk assessment based on the user's emotions, thereby improving the accuracy of anti-phishing measures.

[0083] The anti-phishing system may further include a phishing evaluation unit that estimates a user's emotions and evaluates the likelihood of phishing based on the estimated emotions. The phishing evaluation unit estimates a user's emotions and evaluates the likelihood of phishing based on the estimated emotions. For example, if the user feels a sense of urgency, the likelihood of phishing is evaluated as high. The emotion estimation is performed based on the user's behavior and the message content. This allows for phishing evaluation based on the user's emotions, thereby improving the accuracy of phishing countermeasures.

[0084] The anti-phishing system may further include a symptom identification unit that estimates a user's emotions and identifies symptoms of phishing based on the estimated emotions. The symptom identification unit estimates a user's emotions and identifies symptoms of phishing based on the estimated emotions. For example, if the user is feeling anxious, the symptom is identified. Emotion estimation is performed based on the user's behavior and message content. In this way, by identifying symptoms of phishing based on the user's emotions, the accuracy of phishing countermeasures can be improved.

[0085] The anti-phishing system may further include a risk assessment unit that estimates a user's emotions and assesses the risk of phishing based on the estimated emotions. The risk assessment unit estimates a user's emotions and assesses the risk of phishing based on the estimated emotions. For example, if the user feels fear, the risk is assessed as high. The emotion estimation is performed based on the user's behavior and the message content. This allows for an improved accuracy of phishing countermeasures by assessing the risk of phishing based on the user's emotions.

[0086] The processing flow of the second embodiment will be briefly explained below.

[0087] Step 1: The text analyzer analyzes the text of the SMS. For example, the text analyzer uses generative AI to analyze the context of the SMS text to determine whether it is likely to be phishing. The text analyzer can also reference the sender's past message history to detect abnormal patterns. Furthermore, the text analyzer can use emotion estimation to analyze the emotional tone of the SMS text and identify messages that incite fear or urgency. Step 2: The link analyzer analyzes the text of the linked SMS message analyzed by the text analyzer. For example, the link analyzer uses generative AI to analyze the HTML structure of the linked page and detect code patterns specific to phishing sites. The link analyzer can also refer to past versions of the linked page and analyze changes to identify signs of phishing. Furthermore, the link analyzer can use emotion estimation to analyze the emotional impact of the content of the linked page on the user and evaluate the possibility of phishing. Step 3: The file analyzer analyzes the contents of the SMS attachment analyzed by the link analyzer. For example, the file analyzer uses generative AI to analyze the metadata of the attachment and identify signs of phishing. The file analyzer can also compare the contents of the attachment with those of other phishing emails to detect common patterns. Furthermore, the file analyzer can use emotion estimation to analyze the emotional impact of the attachment's contents on the user and evaluate the likelihood of phishing. Step 4: The risk blocking unit blocks the risk of confidential information and personal information leaks based on the results of the analysis by the file analysis unit. For example, the risk blocking unit uses generative AI to evaluate the risk of confidential information and personal information leaks in real time based on the analysis results and blocks them. The risk blocking unit can also evaluate and block the risk of confidential information and personal information leaks by comparing them with past leak cases. Furthermore, the risk blocking unit can analyze the user's emotional response using an emotion estimation function and block them if the risk is high. Step 5: The notification unit notifies the user of suspicious points based on the results of blocking by the risk blocking unit. For example, the notification unit uses a generation AI to generate a notification that explains the suspicious points in detail based on the analysis results. The notification unit can also provide specific examples in the notification of suspicious points by referencing past phishing cases. Furthermore, the notification unit can use an emotion estimation function to analyze the user's emotional response and notify them in an appropriate tone.

[0088] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[0089] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> Examples of generative AIs include the data generation model 58, such as a neural network model (e.g., a neural network model), and a neural network model (e.g., a neural network model). The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating speech, text data indicating text, and image data indicating an image is also input to the data generation model 58. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specification processing unit 290 performs the above-mentioned specification processing using the data generation model 58. The data generation model 58 may be a fine-tuned model so as to output an inference result from a prompt that does not include an instruction. In this case, the data generation model 58 can output an inference result from a prompt that does not include an instruction. The data processing device 12 and the like include multiple types of data generation models 58, and the data generation model 58 includes AIs other than the generative AI. The AI ​​other than the generative AI may be, for example, linear regression, logistic regression, decision tree, random forest, support vector machine (SVM), k-means clustering, convolutional neural network (CNN), recurrent neural network (RNN), generative adversarial network (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. The AI ​​may also be an AI agent. When the processes of each of the above-mentioned parts are performed by AI, the processes may be performed in part or entirely by AI, but are not limited to these examples. The processes performed by AI, including the generative AI, may be replaced with rule-based processes.

[0090] Furthermore, the processing by the data processing system 10 described above is executed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the smart device 14, but may also be executed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the smart device 14. Furthermore, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the smart device 14 or an external device, and the smart device 14 acquires or collects information necessary for processing from the data processing device 12 or an external device.

[0091] [Second embodiment] FIG. 3 shows an example of the configuration of a data processing system 210 according to the second embodiment.

[0092] 3, the data processing system 210 includes a data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.

[0093] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN and / or a LAN.

[0094] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, and the camera 42 are also connected to the bus 52.

[0095] The microphone 238 receives instructions and the like from the user by receiving voice uttered by the user. The microphone 238 captures the voice uttered by the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to instructions from the processor 46.

[0096] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the user's surroundings (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[0097] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[0098] Fig. 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Fig. 4, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[0099] The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0100] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotion using the emotion identification model 59 and perform identification processing using the user's emotion.

[0101] In the smart glasses 214, the specific processing is performed by the processor 46. A specific processing program 60 is stored in the storage 50. The processor 46 reads the specific processing program 60 from the storage 50 and executes the read specific processing program 60 on the RAM 48. The specific processing is realized by the processor 46 operating as the control unit 46A in accordance with the specific processing program 60 executed on the RAM 48. Note that the smart glasses 214 may have a data generation model and an emotion identification model similar to the data generation model 58 and the emotion identification model 59.

[0102] Note that a device other than the data processing device 12 may have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 communicates with the server device having the data generation model 58 to obtain a processing result (such as a prediction result) using the data generation model 58. Furthermore, the data processing device 12 may be a server device, or may be a terminal device (for example, a mobile phone, a robot, a home appliance, etc.) owned by a user.

[0103] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[0104] The data generation model 58 is a so-called generative AI. An example of the data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 receives a prompt containing an instruction, as well as inference data such as voice data representing speech, text data representing text, and image data representing an image. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The identification processing unit 290 performs the above-mentioned identification processing using the data generation model 58. The data generation model 58 may be a fine-tuned model so as to output an inference result from a prompt that does not include an instruction. In this case, the data generation model 58 can output an inference result from a prompt that does not include an instruction. The data processing device 12 and the like include multiple types of data generation models 58, and the data generation model 58 includes AIs other than the generative AI. The AI ​​other than the generative AI may be, for example, linear regression, logistic regression, decision tree, random forest, support vector machine (SVM), k-means clustering, convolutional neural network (CNN), recurrent neural network (RNN), generative adversarial network (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. The AI ​​may also be an AI agent. When the processes of each of the above-mentioned parts are performed by AI, the processes may be performed in part or entirely by AI, but are not limited to these examples. The processes performed by AI, including the generative AI, may be replaced with rule-based processes.

[0105] The data processing system 210 according to the second embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 210 is executed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the smart glasses 214, but may also be executed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the smart glasses 214. Furthermore, the specific processing unit 290 of the data processing device 12 acquires or collects information required for processing from the smart glasses 214 or an external device, etc., and the smart glasses 214 acquires or collects information required for processing from the data processing device 12 or an external device, etc.

[0106] [Third embodiment] FIG. 5 shows an example of the configuration of a data processing system 310 according to the third embodiment.

[0107] 5, the data processing system 310 includes the data processing device 12 and a headset terminal 314. An example of the data processing device 12 is a server.

[0108] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN and / or a LAN.

[0109] The headset type terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a display 343. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the display 343 are also connected to the bus 52.

[0110] The microphone 238 receives instructions and the like from the user by receiving voice uttered by the user. The microphone 238 captures the voice uttered by the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to instructions from the processor 46.

[0111] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the user's surroundings (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[0112] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[0113] Fig. 6 shows an example of the main functions of the data processing device 12 and the headset terminal 314. As shown in Fig. 6, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[0114] The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0115] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotion using the emotion identification model 59 and perform identification processing using the user's emotion.

[0116] In the headset type terminal 314, the identification process is performed by the processor 46. A identification program 60 is stored in the storage 50. The processor 46 reads the identification program 60 from the storage 50 and executes the read identification program 60 on the RAM 48. The identification process is realized by the processor 46 operating as a control unit 46A in accordance with the identification program 60 executed on the RAM 48. Note that the headset type terminal 314 may also have a data generation model and an emotion identification model similar to the data generation model 58 and the emotion identification model 59.

[0117] Note that a device other than the data processing device 12 may have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 communicates with the server device having the data generation model 58 to obtain a processing result (such as a prediction result) using the data generation model 58. Furthermore, the data processing device 12 may be a server device, or may be a terminal device (for example, a mobile phone, a robot, a home appliance, etc.) owned by a user.

[0118] The specific processing unit 290 transmits the result of the specific processing to the headset type terminal 314. In the headset type terminal 314, the control unit 46A causes the speaker 240 and the display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[0119] The data generation model 58 is a so-called generative AI. An example of the data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 receives a prompt containing an instruction, as well as inference data such as voice data representing speech, text data representing text, and image data representing an image. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The identification processing unit 290 performs the above-mentioned identification processing using the data generation model 58. The data generation model 58 may be a fine-tuned model so as to output an inference result from a prompt that does not include an instruction. In this case, the data generation model 58 can output an inference result from a prompt that does not include an instruction. The data processing device 12 and the like include multiple types of data generation models 58, and the data generation model 58 includes AIs other than the generative AI. The AI ​​other than the generative AI may be, for example, linear regression, logistic regression, decision tree, random forest, support vector machine (SVM), k-means clustering, convolutional neural network (CNN), recurrent neural network (RNN), generative adversarial network (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. The AI ​​may also be an AI agent. When the processes of each of the above-mentioned parts are performed by AI, the processes may be performed in part or entirely by AI, but are not limited to these examples. The processes performed by AI, including the generative AI, may be replaced with rule-based processes.

[0120] The data processing system 310 according to the third embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 310 is executed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the headset type terminal 314, but may also be executed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the headset type terminal 314. Furthermore, the specific processing unit 290 of the data processing device 12 acquires or collects information required for processing from the headset type terminal 314 or an external device, etc., and the headset type terminal 314 acquires or collects information required for processing from the data processing device 12 or an external device, etc.

[0121] [Fourth embodiment] FIG. 7 shows an example of the configuration of a data processing system 410 according to the fourth embodiment.

[0122] 7, the data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.

[0123] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN and / or a LAN.

[0124] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a control target 443. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the control target 443 are also connected to the bus 52.

[0125] The microphone 238 receives instructions and the like from the user by receiving voice uttered by the user. The microphone 238 captures the voice uttered by the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to instructions from the processor 46.

[0126] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS image sensor or a CCD image sensor, and captures images of the user's surroundings (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[0127] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[0128] The control object 443 includes a display device, LEDs in the eyes, and motors that drive the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the emotions of the robot 414 can be expressed by controlling these motors. In addition, the facial expressions of the robot 414 can also be expressed by controlling the light emission state of the LEDs in the eyes of the robot 414.

[0129] Fig. 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Fig. 8, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[0130] The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0131] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotion using the emotion identification model 59 and perform identification processing using the user's emotion.

[0132] In the robot 414, the processor 46 performs the identification process. A identification program 60 is stored in the storage 50. The processor 46 reads the identification program 60 from the storage 50 and executes the read identification program 60 on the RAM 48. The identification process is realized by the processor 46 operating as a control unit 46A in accordance with the identification program 60 executed on the RAM 48. The robot 414 may have a data generation model and an emotion identification model similar to the data generation model 58 and the emotion identification model 59.

[0133] Note that a device other than the data processing device 12 may have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 communicates with the server device having the data generation model 58 to obtain a processing result (such as a prediction result) using the data generation model 58. Furthermore, the data processing device 12 may be a server device, or may be a terminal device (for example, a mobile phone, a robot, a home appliance, etc.) owned by a user.

[0134] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the control target 443 to output the result of the specific processing. The microphone 238 acquires voice indicating a user input regarding the result of the specific processing. The control unit 46A transmits voice data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the voice data.

[0135] The data generation model 58 is a so-called generative AI. An example of the data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 receives a prompt containing an instruction, as well as inference data such as voice data representing speech, text data representing text, and image data representing an image. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The identification processing unit 290 performs the above-mentioned identification processing using the data generation model 58. The data generation model 58 may be a fine-tuned model so as to output an inference result from a prompt that does not include an instruction. In this case, the data generation model 58 can output an inference result from a prompt that does not include an instruction. The data processing device 12 and the like include multiple types of data generation models 58, and the data generation model 58 includes AIs other than the generative AI. The AI ​​other than the generative AI may be, for example, linear regression, logistic regression, decision tree, random forest, support vector machine (SVM), k-means clustering, convolutional neural network (CNN), recurrent neural network (RNN), generative adversarial network (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. The AI ​​may also be an AI agent. When the processes of each of the above-mentioned parts are performed by AI, the processes may be performed in part or entirely by AI, but are not limited to these examples. The processes performed by AI, including the generative AI, may be replaced with rule-based processes.

[0136] The data processing system 410 according to the fourth embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 410 is executed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the robot 414, but may also be executed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the robot 414. Furthermore, the specific processing unit 290 of the data processing device 12 acquires or collects information required for processing from the robot 414 or an external device, etc., and the robot 414 acquires or collects information required for processing from the data processing device 12 or an external device, etc.

[0137] The emotion identification model 59 as an emotion engine may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to an emotion map (see FIG. 9), which is a specific mapping. Similarly, the emotion identification model 59 may determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.

[0138] FIG. 9 illustrates an emotion map 400 on which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. Emotions closer to the center of the concentric circles are more primitive. Emotions representing states and behaviors arising from a state of mind are arranged on the outer edges of the concentric circles. The concept of emotion encompasses both emotions and mental states. Emotions generally generated from reactions occurring in the brain are arranged on the left side of the concentric circles. Emotions generally induced by situational judgment are arranged on the right side of the concentric circles. Emotions generally generated from reactions occurring in the brain and induced by situational judgment are arranged on the upper and lower sides of the concentric circles. Furthermore, the emotion of "pleasure" is arranged on the upper side of the concentric circles, and the emotion of "discomfort" is arranged on the lower side. In this way, in the emotion map 400, multiple emotions are mapped based on the structure by which emotions are generated, and emotions that tend to occur simultaneously are mapped close to each other.

[0139] These emotions are distributed in the 3 o'clock direction on emotion map 400, and typically fluctuate between relief and anxiety. In the right half of emotion map 400, situational awareness dominates over internal sensations, resulting in a sense of calm.

[0140] The inside of emotion map 400 represents what is going on in the mind, and the outside of emotion map 400 represents behavior, so the further you go outside emotion map 400, the more visible the emotions become (the more they are expressed in behavior).

[0141] Human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, a state of discomfort is expressed, and when they approach the ideal, a state of pleasure is expressed. Emotions can also be created for robots, cars, and motorcycles, based on various balances, such as posture and remaining battery life. When these balances deviate from the ideal, a state of discomfort is expressed, and when they approach the ideal, a state of pleasure is expressed. An emotion map can be generated, for example, based on Dr. Mitsuyoshi's emotion map (Research on speech emotion recognition and brain physiological signal analysis systems for emotions, Tokushima University, doctoral dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map lists emotions belonging to the area called "reaction," where sensation is dominant. The right half of the emotion map lists emotions belonging to the area called "situation," where situational awareness is dominant.

[0142] The emotion map defines two emotions that promote learning. One is a negative emotion on the situation side, around the middle of "repentance" or "reflection." In other words, this occurs when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is a positive emotion on the response side, around "desire." In other words, this occurs when the robot experiences positive feelings such as "I want more" or "I want to know more."

[0143] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values ​​indicating each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple pieces of training data that are combinations of user input and emotion values ​​indicating each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions that are located close to each other have similar values, as in the emotion map 900 shown in FIG. 10. FIG. 10 shows an example in which multiple emotions, "relieved," "calm," and "reassuring," have similar emotion values.

[0144] In the above embodiment, an example was given in which a specific process is performed by one computer 22, but the technology disclosed herein is not limited to this, and distributed processing of the specific process may be performed by multiple computers including computer 22.

[0145] In the above embodiment, an example in which the specific processing program 56 is stored in the storage 32 has been described, but the technology of the present disclosure is not limited to this. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-transitory storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-transitory storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes the specific processing in accordance with the specific processing program 56.

[0146] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.

[0147] It is not necessary to store all of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store all of the specific processing program 56 in the storage 32; only a portion of the specific processing program 56 may be stored.

[0148] The hardware resource for executing a specific process can be any of the following processors: A CPU is a general-purpose processor that functions as a hardware resource for executing a specific process by executing software, i.e., a program. A dedicated electrical circuit, such as a field-programmable gate array (FPGA), a programmable logic device (PLD), or an application-specific integrated circuit (ASIC), is a processor with a circuit configuration specifically designed to execute a specific process. Each processor has built-in or connected memory, and uses the memory to execute the specific process.

[0149] The hardware resource that executes the specific process may be configured with one of these various processors, or may be configured with a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Also, the hardware resource that executes the specific process may be a single processor.

[0150] As an example of a system configured with a single processor, first, one processor is configured by combining one or more CPUs and software, and this processor functions as a hardware resource that executes a specific process. Second, there is a system that uses a processor that realizes the functions of an entire system including multiple hardware resources that execute a specific process on a single IC chip, as typified by SoC (System-on-a-chip). In this way, a specific process is realized using one or more of the above-mentioned various processors as hardware resources.

[0151] Furthermore, the hardware structure of these various processors can be, more specifically, an electric circuit that combines circuit elements such as semiconductor devices. The specific processing described above is merely an example. Therefore, it goes without saying that unnecessary steps may be deleted, new steps may be added, or the processing order may be rearranged, without departing from the spirit of the invention.

[0152] In the above example, the first to fourth embodiments have been described separately, but some or all of these embodiments may be combined. The smart device 14, smart glasses 214, headset terminal 314, and robot 414 are merely examples, and they may be combined, or other devices may be used. In the above example, the first and second embodiments have been described separately, but they may be combined.

[0153] The above-described description and illustrations are a detailed explanation of the parts related to the technology of the present disclosure and are merely an example of the technology of the present disclosure. For example, the above description of the configuration, functions, actions, and effects is an explanation of an example of the configuration, functions, actions, and effects of the parts related to the technology of the present disclosure. Therefore, it goes without saying that unnecessary parts may be deleted, new elements may be added, or replacements may be made to the above-described description and illustrations within the scope of the gist of the technology of the present disclosure. Furthermore, to avoid confusion and facilitate understanding of the parts related to the technology of the present disclosure, the above-described description and illustrations omit explanations of common technical knowledge that do not require particular explanation to enable the implementation of the technology of the present disclosure.

[0154] All publications, patent applications, and technical standards mentioned in this specification are herein incorporated by reference to the same extent as if each individual publication, patent application, or technical standard was specifically and individually indicated to be incorporated by reference. [Explanation of symbols]

[0155] 10, 210, 310, 410 Data Processing Systems 12 Data Processing Device 14 Smart Devices 214 Smart Glasses 314 Headset-type terminal 414 Robot

Claims

1. a text analysis unit that analyzes the text of the SMS; a link analysis unit that analyzes the text of the link destination of the SMS analyzed by the text analysis unit; a file analysis unit that analyzes the contents of the SMS attachment analyzed by the link analysis unit; a risk blocking unit that blocks the risk of leakage of confidential information and personal information based on the results of the analysis by the file analyzing unit; a notification unit that notifies a user of suspicious points based on the results of blocking by the risk blocking unit. A system characterized by:

2. The text analysis unit Generative AI is used to analyze the context of the SMS text and compare it with past phishing patterns to detect new phishing techniques. The system of claim 1 .

3. The link analysis unit Analyzing the HTML structure of the linked page using a generative AI to detect code patterns specific to phishing sites. The system of claim 1 .

4. The file analysis unit Using generative AI to analyze the metadata of said attachments to identify indicators of phishing. The system of claim 1 .

5. The risk block section is Using a generating AI to evaluate and block the risk of leakage of the confidential information or personal information in real time based on the analysis results. The system of claim 1 .

6. The notification unit Using emotion estimation functionality to analyze the user's emotional response and deliver the notification in an appropriate tone. The system of claim 1 .

7. The text analysis unit Using emotion estimation to analyze the emotional tone of the SMS text, we identify messages that incite fear and urgency. The system of claim 1 .

8. The link analysis unit Using an emotion estimation function, the emotional impact of the content of the linked page on the user is analyzed to assess the possibility of phishing. The system of claim 1 .

Citation Information

Patent Citations

  • Persona chatbot control method and system

    JP2022180282A