System

A system that monitors and predicts online risks, providing real-time warnings and guidance, addresses the challenge of Internet crimes by enhancing user awareness and safety through data analysis and emotional intelligence.

JP2026019777APending Publication Date: 2026-02-05SOFTBANK GROUP CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024121525
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-26
Publication Date
2026-02-05

AI Technical Summary

Technical Problem

The rise of diverse Internet crimes, particularly affecting elderly and low-literacy individuals, necessitates methods to prevent unwitting involvement and deter intentional participation by providing risk awareness and preventive measures.

Method used

A system that collects user behavioral data, analyzes it in real-time, predicts crime risk, and issues warnings, providing information on crime types, avoidance methods, and consultation points, with emotional state consideration.

Benefits of technology

Enables users to understand and mitigate online risks, preventing unintended involvement and providing deterrent measures based on real-time analysis and emotional context.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026019777000001_ABST
    Figure 2026019777000001_ABST
Patent Text Reader

Abstract

A system is provided.SOLUTION: A system comprising: means for collecting behavioral data of a user; means for analyzing the collected behavioral data in real time and predicting a risk of a crime and damage; means for displaying a warning message to the user based on the predicted risk; means for providing information on a corresponding crime type and avoidance method; and means for providing consultation destination information to the user.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The technology of the present disclosure relates to a system. [Background technology]

[0002] Patent document 1 discloses a persona chatbot control method performed by at least one processor, the method including the steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to a description of the chatbot character, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Publication No. 2022-180282 Summary of the Invention [Problem to be solved by the invention]

[0004] Recently, crimes and damages via the Internet have become more diverse and are on the rise. In particular, there have been frequent cases of elderly people and minors with low literacy becoming involved in crimes such as fraud and phishing after coming into contact with malicious information or people. In this context, there is a need for methods to prevent users from unwittingly becoming involved in crimes, and to deter users who intentionally become involved by making them understand the risks in advance. [Means for solving the problem]

[0005] To solve this problem, the present invention provides the following system. First, a means for collecting user behavioral data is provided. Next, a means for analyzing the collected behavioral data in real time and predicting the risk of crime and victimization is provided. Next, a means for displaying a warning message to the user based on the predicted risk is provided, and at the same time, a means for providing information on the type of crime that may occur and how to avoid it is provided. A means for providing the user with information on where to seek advice is also provided, and, if the predicted risk exceeds a certain threshold, a means for displaying the type of crime that may occur and past cases of victimization is added. This allows users to understand the risks on the Internet and obtain concrete measures for using it safely.

[0006] "Behavioral data" refers to digital activity such as users' search keywords, website access history, and postings on the Internet.

[0007] "Real-time analysis" refers to the process of analyzing user behavior data almost instantly after it is received, and providing the results in a format that can be used immediately.

[0008] A "risk score" is a number calculated based on a predictive model, and is an indicator of the degree to which a particular behavior is likely to lead to crime or victimization.

[0009] A "warning message" is an alert that is displayed to a user based on a predicted risk, and refers to a message that includes information to encourage caution.

[0010] "Avoidance methods" refer to specific actions or measures that users should take to avoid becoming involved in crime or becoming victims.

[0011] "Consultation information" refers to the contact information of institutions or organizations (e.g., consumer centers, police, etc.) that users are recommended to contact if they become involved in a crime or become a victim.

[0012] "Database" refers to information storage where known crime-related information (e.g., fraudulent URLs, malicious keywords, etc.) is accumulated. [Brief explanation of the drawings]

[0013] [Figure 1] 1 is a conceptual diagram showing an example of the configuration of a data processing system according to a first embodiment. [Figure 2] 1 is a conceptual diagram showing an example of main functions of a data processing device and a smart device according to a first embodiment. [Figure 3] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a second embodiment. [Figure 4] FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and smart glasses according to a second embodiment. [Figure 5] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a third embodiment. [Figure 6] FIG. 11 is a conceptual diagram showing an example of main functions of a data processing device and a headset-type terminal according to a third embodiment. [Figure 7] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a fourth embodiment. [Figure 8] FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and a robot according to a fourth embodiment. [Figure 9] 1 shows an emotion map onto which multiple emotions are mapped. [Figure 10] 1 shows an emotion map onto which multiple emotions are mapped. [Figure 11] FIG. 3 is a sequence diagram illustrating a processing flow of the data processing system according to the first embodiment. [Figure 12] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system in Application Example 1. [Figure 13] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system according to the second embodiment when an emotion engine is combined. [Figure 14]FIG. 10 is a sequence diagram showing the flow of processing in the data processing system in Application Example 2 when an emotion engine is combined. DETAILED DESCRIPTION OF THE INVENTION

[0014] An example of an embodiment of a system according to the technology of the present disclosure will be described below with reference to the accompanying drawings.

[0015] First, the terms used in the following description will be explained.

[0016] In the following embodiments, a coded processor (hereinafter simply referred to as a "processor") may be a single arithmetic device or a combination of multiple arithmetic devices. Furthermore, a processor may be a single type of arithmetic device or a combination of multiple types of arithmetic devices. Examples of arithmetic devices include a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a GPGPU (General-Purpose computing on Graphics Processing Units), and an APU (Accelerated Processing Unit).

[0017] In the following embodiments, a coded RAM (Random Access Memory) is a memory in which information is temporarily stored and is used as a working memory by a processor.

[0018] In the following embodiments, the coded storage is one or more non-volatile storage devices that store various programs, various parameters, etc. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), and magnetic tapes.

[0019] In the following embodiments, a communication I / F (Interface) with a symbol is an interface including a communication processor, an antenna, etc. The communication I / F controls communication between multiple computers. Examples of communication standards applied to the communication I / F include wireless communication standards including 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), Bluetooth (registered trademark), etc.

[0020] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B." In other words, "A and / or B" means that it may be only A, only B, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" is also applied when three or more things are expressed connected by "and / or."

[0021] [First embodiment]

[0022] FIG. 1 shows an example of the configuration of a data processing system 10 according to the first embodiment.

[0023] 1, a data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.

[0024] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0025] The smart device 14 includes a computer 36, a reception device 38, an output device 40, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The reception device 38, the output device 40, and the camera 42 are also connected to the bus 52.

[0026] The reception device 38 includes a touch panel 38A, a microphone 38B, and the like, and receives user input. The touch panel 38A detects contact with an indicator (for example, a pen or a finger) to receive user input by the touch of the indicator. The microphone 38B detects the user's voice to receive user input by voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the data indicating the user input.

[0027] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user 20 by outputting the data in a form of expression that the user 20 can perceive (for example, audio and / or text). The display 40A displays visible information such as text and images in accordance with instructions from the processor 46. The speaker 40B outputs audio in accordance with instructions from the processor 46. The camera 42 is a compact digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.

[0028] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 control the exchange of various information between the processor 46 and the processor 28 via the network 54.

[0029] FIG. 2 shows an example of the main functions of the data processing device 12 and the smart device 14.

[0030] 2, in the data processing device 12, a specific process is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific process is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0031] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0032] In the smart device 14, the processor 46 performs the reception output process. The storage 50 stores a reception output program 60. The reception output program 60 is used in conjunction with the specific processing program 56 by the data processing system 10. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[0033] Next, a description will be given of the specific processing performed by the specific processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0034] Overall system overview

[0035] This invention is a system that monitors users' online behavior, predicts the risk of crime or harm, and issues a warning. This system aims to prevent users from unwittingly becoming involved in risks, and even if they do intentionally become involved, it aims to have a deterrent effect by making them understand the risks.

[0036] System Configuration

[0037] The system mainly consists of the following elements:

[0038] 1. Terminal: The device through which a user accesses the Internet (e.g., a computer or smartphone).

[0039] 2. Server: The core part of the system that collects and analyzes behavioral data and predicts and notifies users of risks.

[0040] 3. Database: Stores information such as known fraudulent URLs and dangerous keywords.

[0041] Program processing overview

[0042] 1. Data Collection

[0043] User:

[0044] Users use the terminal to access the Internet and perform searches, web browsing, and writing.

[0045] Device:

[0046] The device captures user behavior data (e.g., search keywords, accessed URLs, and posted content) in real time.

[0047] Send the captured data to the server.

[0048] 2. Data analysis and risk prediction

[0049] server:

[0050] The server quickly analyzes the received behavioral data, specifically preprocessing it using machine learning algorithms to extract features.

[0051] A risk score is calculated based on the extracted features and compared with a specific threshold.

[0052] If the risk score exceeds a threshold, the type of risk (e.g., phishing scam, malware) is identified.

[0053] 3. Generating and Displaying Warning Messages

[0054] server:

[0055] The server generates appropriate warning messages based on the detected risks.

[0056] If necessary, additional information will be generated about the type of crime involved, past victimization cases, and ways to avoid it.

[0057] Device:

[0058] The terminal displays the warning message received from the server to the user.

[0059] 4. Providing consultation information and guidelines

[0060] server:

[0061] Depending on the detected risk, the server generates information about contact points (e.g., consumer centers, police) for the user to contact.

[0062] Provide specific guidelines for users to take to avoid risks (e.g., do not click on URLs or enter personal information).

[0063] Device:

[0064] The device displays this information to the user in an easy-to-understand manner, encouraging immediate action.

[0065] Specific examples

[0066] Phishing detection and prevention

[0067] User:

[0068] A user attempts to access an internet shopping site, but it is actually a phishing site.

[0069] Device:

[0070] The device captures the accessed URL and sends it to the server.

[0071] server:

[0072] The server checks the received URL against a list of known dangerous URLs in a database in real time.

[0073] If a URL is detected as a phishing site, it is determined to be at high risk of phishing and a risk score is calculated.

[0074] Generate a phishing warning message because the risk score exceeds a threshold.

[0075] Device:

[0076] The device will display a warning message to the user saying, "This site may be a phishing scam. Do not enter any personal information."

[0077] server:

[0078] The server generates contact information for consumer centers and police and provides instructions such as "Click here for more information."

[0079] User:

[0080] Users should check the warning message, recognize that it is a fraudulent site, and avoid entering personal information.

[0081] This system allows users to understand the risks on the Internet and provides them with concrete steps to use it safely.

[0082] The processing flow will be explained below.

[0083] Step 1:

[0084] User: A user uses an internet browser to access a particular website or enters a search keyword on the internet.

[0085] Step 2:

[0086] Device: The device captures the user's search keywords and the URLs of the websites they visit in real time.

[0087] Step 3:

[0088] Terminal: Sends the captured behavioral data to the server through a specified endpoint.

[0089] Step 4:

[0090] Server: The server temporarily stores the received behavioral data and performs data cleaning, specifically removing unnecessary tags and special characters and converting it into an analyzable format.

[0091] Step 5:

[0092] Server: After data cleaning is complete, features (e.g., specific keywords, domains of accessed URLs, etc.) are extracted from user behavior data.

[0093] Step 6:

[0094] Server: Calculates a risk score based on the extracted features. Here, an existing machine learning model is used to predict the risk score.

[0095] Step 7:

[0096] Server: Evaluates whether the risk score exceeds a pre-set threshold.

[0097] Step 8:

[0098] Server: If the score exceeds a threshold, identify the appropriate risk category (e.g., phishing, malware).

[0099] Step 9:

[0100] Server: Generate appropriate warning messages based on the identified risk categories, e.g. "This site may be a phishing scam. Do not enter any personal information."

[0101] Step 10:

[0102] Server: Generate additional information about past exploits and mitigation strategies, if necessary.

[0103] Step 11:

[0104] Server: Sends generated warning messages and additional information to the device.

[0105] Step 12:

[0106] Terminal: Received warning messages are displayed to the user. Warning messages are displayed in a popup format to make them more visible to the user.

[0107] Step 13:

[0108] Server: Depending on the risk, it generates appropriate contact information for the user to contact (e.g., consumer center or police) and sends this information to the terminal.

[0109] Step 14:

[0110] Device: Along with the provided consultation information, detailed guidelines for action (e.g., do not click on URLs, do not enter personal information) are displayed to the user.

[0111] Step 15:

[0112] Users: Users can review the displayed warning messages and additional information and take appropriate measures to reduce the risk of becoming involved in crime or victimization.

[0113] Example 1

[0114] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0115] Conventional Internet security systems have difficulty preventing damage caused by users unknowingly visiting high-risk websites or entering fraudulent information. Even when risks are detected, they lack mechanisms for providing users with immediate, specific warnings or guidelines for action. This makes it difficult for users to predict the risk of online crime and harm and take concrete measures.

[0116] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[0117] In this invention, the server includes a means for collecting user behavioral data, a means for analyzing the collected behavioral data in real time, performing preprocessing and feature extraction, and a means for calculating a risk score from the analysis results and comparing the score with a specific threshold. This makes it possible to immediately identify risks based on the user's behavioral data and provide appropriate warnings to the user. Furthermore, if a risk is detected, additional information on the type of crime and how to avoid it, as well as information on where to seek advice, can be provided, allowing the user to obtain specific guidelines for using the Internet safely.

[0118] "User behavioral data" refers to digital activities such as search keywords used by users on the Internet, URLs accessed, and content posted.

[0119] "Real-time analysis" refers to the process of processing data and obtaining results immediately at the moment the data is generated.

[0120] "Preprocessing" refers to early stages of data processing, such as data cleansing and normalization, to convert raw data into an analyzable format.

[0121] "Feature extraction" refers to the process by which machine learning algorithms find important attributes and patterns in data.

[0122] A "risk score" is a numerical representation of the likelihood of crime or victimization based on a user's behavioral data.

[0123] A "threshold" refers to a reference value that a risk score must exceed before a specific action is triggered.

[0124] A "warning message" refers to a notification that notifies the user of an increased risk and urges caution.

[0125] "Additional information" refers to information including past cases of damage related to the detected risk and specific methods of avoiding it.

[0126] "Consultation information" refers to contact information for consumer centers, police, etc. that users can contact when they become aware of a risk.

[0127] "Risk types" specifically refer to categories of phishing, malware, and other cybercrime.

[0128] "Specific guidelines for action" refer to specific actions that should be taken to protect users from risks (e.g., not clicking on URLs, not entering personal information).

[0129] Overall system overview

[0130] This invention is a system that monitors users' online behavior, predicts the risk of crime or harm, and issues a warning. This system aims to prevent users from unwittingly becoming involved in risks, and even if they do intentionally become involved, it aims to have a deterrent effect by making them understand the risks.

[0131] System configuration

[0132] The system consists of the following main elements:

[0133] 1. Terminal: A device (e.g., PC, smartphone) that a user uses to access the Internet.

[0134] 2. Server: This is the core part of the system that collects and analyzes behavioral data and predicts and notifies users of risks.

[0135] 3. Database: Stores information such as known fraudulent URLs and dangerous keywords.

[0136] Data collection

[0137] User:

[0138] Users use the terminal to access the Internet and perform searches, web browsing, and writing.

[0139] Device:

[0140] The device captures user behavior data (e.g., search keywords, URLs accessed, and posted content) in real time, and the captured data is sent to the server.

[0141] Data analysis and risk prediction

[0142] server:

[0143] The server quickly analyzes the behavioral data received from the device. Specifically, it preprocesses the data using a machine learning algorithm (e.g., TensorFlow) and extracts features. It calculates a risk score based on the extracted features and compares the score with a specific threshold. If the risk score exceeds the threshold, it identifies the type of risk (e.g., phishing scam, malware).

[0144] Generate and display warning messages

[0145] server:

[0146] The server generates appropriate warning messages based on the detected risks, and, if necessary, provides additional information about the type of crime, past victim cases, and how to avoid them.

[0147] Device:

[0148] The terminal displays the warning message received from the server to the user.

[0149] Providing consultation information and guidelines

[0150] server:

[0151] Depending on the detected risk, the server generates contact information for the user to contact (e.g., consumer center, police), and provides specific guidelines for the user to take to avoid the risk (e.g., do not click on URLs, do not enter personal information).

[0152] Device:

[0153] The device displays this information to the user in an easy-to-understand manner, encouraging immediate action.

[0154] Specific examples

[0155] Phishing detection and prevention

[0156] User:

[0157] A user attempts to access an internet shopping site, but it is actually a phishing site.

[0158] Device:

[0159] The device captures the accessed URL and sends it to the server.

[0160] server:

[0161] The server checks the received URL against a list of known dangerous URLs in a database in real time. If the URL is detected as a phishing site, it determines that there is a high risk of phishing and calculates a risk score. If the risk score exceeds a threshold, a phishing warning message is generated.

[0162] Device:

[0163] The device will display a warning message to the user saying, "This site may be a phishing scam. Do not enter any personal information."

[0164] server:

[0165] The server generates contact information for consumer centers and police and provides instructions such as "Click here for more information."

[0166] User:

[0167] Users can view the warning message, recognize that the site is fraudulent, and avoid entering personal information. This system helps users understand the risks of using the Internet and provides concrete steps to stay safe.

[0168] Prompt Sentence Examples

[0169] Here are some example prompts to input to the generative AI model:

[0170] Explain the program flow that generates a warning message and alerts the user when they try to access a phishing site.

[0171] This allows you to understand the processing flow and operation of a specific program.

[0172] The flow of the identification process in the first embodiment will be described with reference to FIG.

[0173] Step 1:

[0174] User:

[0175] Users access the Internet using devices such as computers and smartphones to browse various websites, search for information using search engines, and post on message boards.

[0176] input:

[0177] User web browsing and search behavior data (e.g., search keywords, access URLs, and posted content)

[0178] Device:

[0179] The device captures this behavioral data in real time, encrypts it, and sends it to a server.

[0180] output:

[0181] Encrypted behavioral data

[0182] Specific behavior:

[0183] The device captures the information entered by the user in real time, encrypts it to prevent information leakage, and then transmits the encrypted data to the server.

[0184] Step 2:

[0185] server:

[0186] The server decrypts the encrypted behavioral data received from the device and performs preprocessing on the data, which involves removing noise data and standardizing the data format.

[0187] input:

[0188] Encrypted behavioral data

[0189] Specific behavior:

[0190] The server decrypts the received data, removes unnecessary and duplicate data, and converts it into a format suitable for analysis.

[0191] output:

[0192] Preprocessed behavioral data

[0193] Step 3:

[0194] server:

[0195] The server uses machine learning algorithms (e.g., TensorFlow) to extract features from the preprocessed behavioral data and calculates a risk score, which is then compared with a specific threshold.

[0196] input:

[0197] Preprocessed behavioral data

[0198] Specific behavior:

[0199] The server uses machine learning models to extract key features from the data, calculates a risk score based on them, and compares the result with a pre-defined threshold.

[0200] output:

[0201] Risk score (number)

[0202] Step 4:

[0203] server:

[0204] If the risk score exceeds a threshold, the server identifies the type of risk (e.g., phishing scam, malware) and generates an appropriate warning message.

[0205] input:

[0206] Risk Score

[0207] Specific behavior:

[0208] The server checks whether the risk score exceeds a threshold and generates an appropriate warning message based on pre-defined rules. For example, if it is a phishing scam, it creates a message such as "This site may be a phishing scam. Do not enter personal information."

[0209] output:

[0210] Warning message

[0211] Step 5:

[0212] Device:

[0213] The terminal displays the warning message received from the server to the user, and depending on the content of the warning message, it may suspend the user's operation.

[0214] input:

[0215] Warning message

[0216] Specific behavior:

[0217] The device immediately displays the warning message received from the server to the user, allowing the user to recognize the risk and blocking the user's operation if necessary.

[0218] output:

[0219] The warning message displayed to the user

[0220] Step 6:

[0221] server:

[0222] The server generates information on where to contact for advice depending on the risk (e.g., consumer centers, police) and provides specific guidelines for action (e.g., do not click on URLs, do not enter personal information).

[0223] input:

[0224] Types of Risk

[0225] Specific behavior:

[0226] The server generates appropriate information on where to contact for advice and a course of action based on the type of risk, and notifies the user. For example, it includes specific instructions such as "Here is the link to contact the consumer center."

[0227] output:

[0228] Consultation information and guidelines

[0229] Step 7:

[0230] Device:

[0231] The device displays this information on consultation points and guidelines for action in an easy-to-understand manner to the user, encouraging them to take immediate action.

[0232] input:

[0233] Consultation information and guidelines

[0234] Specific behavior:

[0235] The device displays specific guidelines for risk avoidance to the user, and provides an interface that allows them to access consultation services with one click if necessary.

[0236] output:

[0237] Consultation information and guidelines displayed to the user

[0238] (Application example 1)

[0239] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0240] Currently, Internet users are often unknowingly exposed to risks such as phishing scams and malware. Furthermore, there are currently insufficient systems in place to predict and provide early warnings when certain high-risk behaviors are involved. As a result, users are more likely to become victims of crime and are required to respond after the fact. Furthermore, it is currently difficult to learn about the risks involved, find specific ways to avoid them, or find information on where to seek advice. There is a need to solve these problems and provide an environment in which users can use the Internet safely and with peace of mind.

[0241] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[0242] In this invention, the server includes: means for collecting user behavioral data; means for analyzing the collected behavioral data in real time and predicting the risk of crime and victimization; means for displaying a warning message to the user based on the predicted risk; means for providing information on the type of crime and how to avoid it; means for providing the user with information on where to seek advice; means for determining in real time whether a specific user behavior poses a risk; and means for generating and providing a specific warning message to the user based on a risk score if the risk meets certain conditions. This allows users to recognize potential risks on the Internet in advance and take early action. Furthermore, providing appropriate information on where to seek advice and specific ways to avoid them further ensures user safety.

[0243] "User behavior data" is a general term for data such as search keywords, URLs accessed, and content posted by users on the Internet.

[0244] The "means for collecting" is a function for capturing user behavior data in real time and transmitting it to a server.

[0245] "Real-time analysis means" refers to an analytical function that instantly processes collected behavioral data and assesses risk.

[0246] "Predictive means" is a function that detects the risk of crime or harm that may occur in the future based on analyzed data.

[0247] The "means for displaying a warning message" is a function for visually presenting a message to inform the user of a risk.

[0248] The "means for providing information on the types of crimes that may occur and how to avoid them" is a function for conveying to the user information on the types of crimes that may occur and how to avoid them in response to detected risks.

[0249] The "means for providing information on where to contact for consultation" is a function for providing information on appropriate organizations and support desks that users should contact when a risk is detected.

[0250] "A means for determining in real time whether a particular action will pose a risk" is a function that instantly evaluates whether an action involves a risk each time a user takes an action.

[0251] "Means for generating a specific warning message based on the risk score and providing it to the user" is a function for quantifying the degree of risk, creating a detailed warning message based on that score, and conveying it to the user.

[0252] The embodiments of the present invention will be described in detail below.

[0253] Overall system configuration

[0254] This invention is a system that monitors users' online behavior, predicts the risk of crime or harm, and issues warnings. The system consists of a user device (terminal) and a server. The terminal captures user behavior data and sends it to the server. The server analyzes the data, predicts risks, generates warning messages, sends them to the terminal, and displays them to the user.

[0255] Hardware and software used

[0256] Device: A user device such as a smartphone, computer, or tablet.

[0257] Server: A central system that collects and analyzes data and generates warning messages, etc.

[0258] Software: The programming language Python and the library requests for sending HTTP requests are used.

[0259] Data collection

[0260] The device captures real-time behavioral data such as search keywords, URLs accessed, and posted content when a user searches online. This data is sent to a server when a certain amount of data is reached or a specific event occurs.

[0261] Data analysis and risk prediction

[0262] The server rapidly analyzes the received behavioral data using machine learning algorithms to preprocess the data and extract features, and then calculates a risk score based on the data and compares it with a specific threshold.

[0263] Determining risks and generating warning messages

[0264] If the risk score exceeds a certain threshold, the server identifies the type of risk and generates a specific warning message, which is then sent to the terminal in a user-friendly format and displayed to the user.

[0265] Specific examples

[0266] For example, if a user searches for "buy cheap medicines," the server analyzes the search keywords and detects the risk of accessing a fraudulent website selling cheap medicines. Also, if a user accesses the URL http: / / phishing.example.com, the server detects the risk of phishing and immediately displays a warning message.

[0267] Prompt Sentence Examples

[0268] Prompt your generative AI model with the following prompt:

[0269] "Monitor user behavior and calculate a risk score based on the following data:

[0270] Search keywords: 'buy cheap medicines', 'free crypto wallet'

[0271] Access URL: 'http: / / phishing.example.com', 'http: / / scam.example.com'"

[0272] This will realize a system that allows users to always ensure safety on the Internet and quickly take necessary measures.

[0273] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[0274] Step 1:

[0275] The device collects user behavior data. Specifically, it captures the keywords the user searches for, the URLs they access, and the content they post in real time. This data is temporarily stored on the device as session data.

[0276] Input: User search keywords, access URL, and post content

[0277] Output: Captured behavioral data

[0278] Step 2:

[0279] The device sends behavioral data to the server using an HTTP request when a certain amount of behavioral data has been collected or when a specific event occurs.

[0280] Input: Captured behavioral data

[0281] Output: Behavioral data sent to the server

[0282] Step 3:

[0283] The server analyzes the received data. First, it preprocesses the data using a machine learning algorithm and extracts features.

[0284] Input: Submitted behavioral data

[0285] Output: Extracted features

[0286] Step 4:

[0287] The server calculates a risk score based on the extracted features, using a pre-trained generative AI model.

[0288] Input: extracted features

[0289] Output: Calculated risk score

[0290] Step 5:

[0291] The server determines whether the risk score exceeds a certain threshold, and if so, identifies the type of risk (e.g., phishing, malware).

[0292] Input: Calculated risk score

[0293] Output: Identified risk types

[0294] Step 6:

[0295] The server generates a specific warning message based on the type of risk, including the type of crime, past victim cases, and how to avoid it.

[0296] Input: Type of risk identified

[0297] Output: Generated warning message

[0298] Step 7:

[0299] The server transmits the generated warning message and information on where to contact for advice to the terminal.

[0300] Input: Generated warning message, contact information

[0301] Output: Message sent to terminal

[0302] Step 8:

[0303] The device will then display the received warning message and information on where to contact for help to the user, who can then check the information on the screen and take appropriate measures.

[0304] Input: Warning message sent from the server, consultation information

[0305] Output: Displaying information to the user

[0306] This processing flow realizes a system in which user behavior data is monitored and analyzed in real time, and an immediate warning is issued if a risk is detected.

[0307] Furthermore, an emotion engine that estimates the user's emotion may be combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59 and perform identification processing using the user's emotion.

[0308] Overall system overview

[0309] This invention combines an emotion engine with a system that monitors users' online behavior, predicts the risk of crime or harm, and issues warnings. The system aims to prevent users from unwittingly becoming involved in risks, and even if they do intentionally become involved, to help them understand the risks and provide appropriate responses by taking into account the user's emotional state.

[0310] System Configuration

[0311] The system mainly consists of the following elements:

[0312] 1. Terminal: The device through which a user accesses the Internet (e.g., a computer or smartphone).

[0313] 2. Server: The core part of the system that collects and analyzes behavioral and emotional data, and predicts and notifies users of risks.

[0314] 3. Database: Storage for known fraudulent URLs, dangerous keywords, and sentiment data.

[0315] Program processing overview

[0316] 1. Data Collection

[0317] User:

[0318] Users use the terminal to access the Internet and perform searches, web browsing, and writing.

[0319] Device:

[0320] The device captures user behavior data (e.g., search keywords, accessed URLs, and posted content) in real time.

[0321] The device also uses a camera and microphone to capture emotional data from the user's facial expressions and tone of voice.

[0322] Send the captured data to the server.

[0323] 2. Data analysis and risk prediction

[0324] server:

[0325] The server quickly analyzes the received behavioral and emotional data, preprocessing the data using machine learning algorithms to extract features.

[0326] A risk score is calculated based on the extracted features and compared with a specific threshold.

[0327] If the risk score exceeds a threshold, the type of risk (e.g., phishing scam, malware) is identified.

[0328] 3. Emotional data analysis and response adjustment

[0329] server:

[0330] The server analyzes the emotion data to determine the user's current emotional state (e.g., anxiety, fear, joy).

[0331] It adjusts the content and presentation of warning messages based on the user's emotional state, for example, displaying more detailed explanations and a gentler tone of voice if the user is feeling anxious.

[0332] 4. Generating and Displaying Warning Messages

[0333] server:

[0334] The server generates appropriate warning messages based on the detected risks.

[0335] If necessary, additional information will be generated about the type of crime involved, past victimization cases, and ways to avoid it.

[0336] Device:

[0337] The terminal displays the warning message received from the server to the user, and the displayed message is adjusted according to the user's emotional state.

[0338] 5. Providing consultation information and guidelines

[0339] server:

[0340] Depending on the detected risk, the server generates information about contact points (e.g., consumer centers, police) for the user to contact.

[0341] Provide specific guidelines for users to take to avoid risks (e.g., do not click on URLs or enter personal information).

[0342] The display order and content of the information is adjusted according to the user's emotions.

[0343] Device:

[0344] The device displays this information to the user in an easy-to-understand manner, encouraging immediate action.

[0345] Specific examples

[0346] Phishing detection and prevention

[0347] User:

[0348] A user attempts to access an internet shopping site, but it is actually a phishing site.

[0349] Device:

[0350] The device captures the accessed URL and sends it to the server.

[0351] At the same time, the device captures the user's facial expressions with a camera and collects emotional data from voice tones.

[0352] server:

[0353] The server checks the received URL against a list of known dangerous URLs in a database in real time.

[0354] If a URL is detected as a phishing site, it is determined to be at high risk of phishing and a risk score is calculated.

[0355] Generate a phishing warning message because the risk score exceeds a threshold.

[0356] The server analyzes the user's emotional data and recognizes that the user is feeling anxious, and generates a warning message with detailed explanation and a gentle tone.

[0357] Device:

[0358] The device will display a warning message to the user saying, "This site may be a phishing scam. Do not enter any personal information."

[0359] server:

[0360] The server generates contact information for consumer centers and police and provides instructions such as "Click here for more information."

[0361] The server takes into consideration that the user is feeling strong anxiety and displays emergency consultation information with priority.

[0362] User:

[0363] Users should check the warning message, recognize that it is a fraudulent site, avoid entering personal information, and refer to emergency consultation information to take appropriate measures.

[0364] This system allows users to understand the risks on the Internet, provides concrete measures for safe use, and allows them to receive responses that take their emotional state into consideration.

[0365] The processing flow will be explained below.

[0366] Step 1:

[0367] User: A user uses an internet browser to access a particular website or enters a search keyword on the internet.

[0368] Step 2:

[0369] Device: The device captures the user's search keywords and the URLs of the websites they visit in real time.

[0370] Step 3:

[0371] On-device: Use the device's camera and microphone to capture emotional data from the user's facial expressions, tone of voice, and more.

[0372] Step 4:

[0373] Terminal: Sends the captured behavioral and emotional data to the server through a designated endpoint.

[0374] Step 5:

[0375] Server: The server stores the received behavioral and emotional data and performs data cleaning, removing unnecessary tags and special characters, and converting it into an analyzable format.

[0376] Step 6:

[0377] Server: After data cleaning is complete, features (e.g., specific keywords, domains of accessed URLs, changes in facial expressions, tone of voice, etc.) are extracted from the user's behavioral and emotional data.

[0378] Step 7:

[0379] Server: Calculates a risk score based on the extracted features. Here, an existing machine learning model is used to predict the risk score.

[0380] Step 8:

[0381] Server: Evaluates whether the risk score exceeds a pre-set threshold.

[0382] Step 9:

[0383] Server: If the score exceeds a threshold, identify the appropriate risk category (e.g., phishing, malware).

[0384] Step 10:

[0385] Server: Analyzes the user's emotional data and determines the user's current emotional state (e.g., anxiety, fear, joy).

[0386] Step 11:

[0387] Server: Adjust the content and presentation of warning messages based on the user's emotional state. For example, if the user is feeling anxious, display a more detailed message with a gentler tone.

[0388] Step 12:

[0389] Server: Generates a tailored warning message, such as "This site may be a phishing scam. Do not enter any personal information."

[0390] Step 13:

[0391] Server: Generates additional information about the type of crime, past victimization, and prevention methods, if necessary.

[0392] Step 14:

[0393] Server: Sends generated warning messages and additional information to the device.

[0394] Step 15:

[0395] Terminal: The received warning message is displayed to the user. The displayed message is adjusted according to the user's emotional state and presented in a pop-up format.

[0396] Step 16:

[0397] Server: Depending on the risk, generates appropriate contact information for the user to contact (e.g. consumer center, police) and sends this information to the terminal.

[0398] Step 17:

[0399] Device: Along with the provided consultation information, detailed guidelines for action (e.g., do not click on URLs, do not enter personal information) are displayed to the user.

[0400] Step 18:

[0401] Users: Users can review the displayed warning messages and additional information and take appropriate measures to reduce the risk of becoming involved in crime or victimization. Because the user's emotional state is taken into consideration, they can respond with greater peace of mind.

[0402] Example 2

[0403] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0404] With the spread of the Internet, users have gained access to a wide variety of information and services, but at the same time, they are being asked to respond appropriately to the increasing risks of online fraud and malware. However, current systems only provide uniform risk warnings to users and do not take into account their emotional state, which often prevents them from taking effective risk avoidance actions. In addition, due to insufficient calculation of risk scores and identification of risk types, there is a lack of information provided to users to enable them to take specific countermeasures. There is a need to solve these issues.

[0405] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.

[0406] In this invention, the server includes means for analyzing user behavioral data and emotional data in real time to predict the risk of crime and victimization, means for displaying a warning message to the user based on the predicted risk, and means for adjusting the content and display method of the warning message based on the user's emotional state, thereby making it possible to provide appropriate warnings and specific risk avoidance information according to the user's emotional state.

[0407] "User behavior data" refers to information such as search keywords, URLs accessed, and content posted by users on the Internet.

[0408] "Emotion data" is information that indicates the emotional state of the user, which can be obtained from facial expressions, tone of voice, and the like.

[0409] "Real-time analysis" means processing and analyzing data immediately as it is captured.

[0410] "Predicting the risk of crime and victimization" means assessing the likelihood that a user will be involved in a crime or victimization based on collected data.

[0411] "Displaying a warning message" means displaying a warning or alert to the user on the screen based on the predicted risk.

[0412] "Applicable crime type" refers to the specific crime category associated with the predicted risk (e.g., phishing scams or malware infections).

[0413] "Avoidance methods" is information that indicates specific actions or steps that a user should take to avoid a predicted risk.

[0414] "Consultation information" is contact information for organizations or institutions that users can contact or consult with if they are facing a risk.

[0415] "Emotional state" refers to the psychological or emotional state (e.g., anxiety, fear, joy) that a user expresses through a camera or microphone.

[0416] MODE FOR CARRYING OUT THE INVENTION

[0417] Overall system overview

[0418] This invention combines an emotion engine with a system that monitors users' online behavior, predicts the risk of crime or harm, and issues warnings. The system aims to prevent users from unwittingly becoming involved in risks, and even if they do intentionally become involved, to help them understand the risks and provide appropriate responses by taking into account the user's emotional state.

[0419] System Configuration

[0420] The system mainly consists of the following elements:

[0421] 1. Device: A device (e.g., a PC or smartphone) that allows a user to access the Internet. The device captures the user's behavioral and emotional data and transmits it to a server.

[0422] 2. Server: This is the core part of the system that collects and analyzes behavioral and emotional data, and predicts and notifies risks. The server analyzes the data using machine learning algorithms and deep learning models.

[0423] 3. Database: Storage for known fraudulent URLs, dangerous keywords, and sentiment data.

[0424] Hardware and Software

[0425] Device: The user's computer, smartphone, etc.

[0426] Camera and microphone: Devices for capturing your facial expressions and tone of voice.

[0427] Server: A high-performance data processing server is used, which uses Python, the pandas library, the scikit-learn library, OpenCV, and deep learning models for data processing.

[0428] Specific examples

[0429] Below is a specific example of how this system can be used.

[0430] Example: Phishing detection and countermeasures

[0431] User: A user attempts to access an internet shopping site, but it is actually a phishing site.

[0432] Device: The device captures the accessed URL and sends it to the server. It also captures the user's facial expressions with a camera and collects emotional data from voice tones.

[0433] server:

[0434] Incoming URLs are checked against a list of known dangerous URLs in a database in real time.

[0435] When a URL is detected as a phishing site, a risk score is calculated and a phishing warning message is generated if the risk score exceeds a threshold.

[0436] It analyzes emotional data, recognizes when the user is feeling anxious, and generates a warning message with detailed explanation and a gentle tone based on this.

[0437] Device: Show the user the warning message "This site may be a phishing scam. Do not enter any personal information."

[0438] Server: Generates contact information for consumer centers and police, and provides instructions such as "Click here for more information." If the user is feeling very anxious, the server prioritizes displaying emergency consultation information.

[0439] Users: Check the warning message, recognize that it is a fraudulent site, avoid entering personal information, and refer to the emergency contact information to take appropriate measures.

[0440] Prompt Sentence Examples

[0441] "The system detected a fraud risk. Please check the user data and risk score. Then generate a warning message and notify the user with an appropriate tone based on the sentiment data."

[0442] The flow of the identification process in the second embodiment will be described with reference to FIG.

[0443] System program processing flow

[0444] Step 1: Data collection

[0445] Step 1.1: Capture behavioral data

[0446] Device: The device captures the search keywords, URLs accessed, and postings made by users on the Internet in real time. For example, when a user visits a shopping site, the device captures the URL and saves it as a user operation log.

[0447] Input: User search keywords, access URL, and post content

[0448] Output: Captured behavioral data

[0449] Step 1.2: Capturing emotion data

[0450] On the device: Using a camera and microphone, emotional data is captured from the user's facial expressions and tone of voice. For example, if the user smiles at the camera, that facial expression data is captured in real time.

[0451] Input: User's facial expression, tone of voice

[0452] Output: Captured emotion data

[0453] Step 1.3: Send data

[0454] Device: The device sends the captured behavioral and emotional data to the server. The data is encrypted using SSL / TLS protocol during transmission to ensure security.

[0455] Input: Captured behavioral data, emotion data

[0456] Output: Data sent to the server

[0457] Step 2: Data analysis and risk prediction

[0458] Step 2.1: Data Preprocessing

[0459] Server: The server preprocesses the received behavioral and emotional data. Specifically, it cleans the data, fills in missing data, and removes noise. This process uses the Python pandas library.

[0460] Input: Received behavioral data, emotion data

[0461] Output: Preprocessed data

[0462] Step 2.2: Feature extraction

[0463] Server: The server extracts features from the preprocessed data. For example, it extracts the frequency of search keywords or patterns of accessed URLs. In this case, it uses the scikit-learn library to perform feature extraction.

[0464] Input: Preprocessed data

[0465] Output: Features

[0466] Step 2.3: Risk Score Calculation

[0467] Server: The server calculates a risk score based on the extracted features, for example, using a machine learning model such as a random forest or a support vector machine, and compares it with a specific threshold.

[0468] Input: Features

[0469] Output: Risk score

[0470] Step 2.4: Identify risk types

[0471] Server: If the risk score exceeds a threshold, the server identifies the type of risk (e.g., phishing, malware), consulting a database of known dangerous URLs and fraud patterns.

[0472] Input: Risk Score

[0473] Output: Risk type

[0474] Step 3: Analyze emotion data and adjust responses

[0475] Step 3.1: Emotion determination

[0476] Server: The server analyzes the received emotion data and determines the user's current emotional state. For example, if the user is frowning, it determines that they are feeling anxious. For emotion analysis, it uses OpenCV and a deep learning model for emotion recognition.

[0477] Input: Emotion data

[0478] Output: User's emotional state

[0479] Step 3.2: Adjust the warning message

[0480] Server: The server adjusts the content and presentation of the warning message based on the user's emotional state. For example, if the user is feeling anxious, it generates a gentle, detailed message such as "This site may be a phishing scam. Please be careful."

[0481] Input: Risk type, user emotional state

[0482] Output: Adjusted warning message

[0483] Step 4: Generate and display warning messages

[0484] Step 4.1: Generate a warning message

[0485] Server: The server generates appropriate warning messages based on the detected risks, adding specific information about the type of fraud, past victim cases, and how to avoid them.

[0486] Input: Risk type, user emotional state

[0487] Output: Warning message

[0488] Step 4.2: Send the message

[0489] Server: Generates and sends a warning message to the device. This message is adapted according to the user's emotional state.

[0490] Input: warning message

[0491] Output: Message sent to the terminal

[0492] Step 4.3: Displaying a warning message

[0493] On the device: Display the warning message received from the server to the user. For example, if a risk of a phishing site is detected, the message "This site may be a phishing scam. Do not enter personal information." will be displayed.

[0494] Input: Message sent to terminal

[0495] Output: The warning message displayed to the user.

[0496] Step 5: Providing consultation information and guidelines

[0497] Step 5.1: Generate consultation information

[0498] Server: Depending on the detected risk, the server generates contact information for consumer centers, police, etc. For example, it provides specific contact information such as "Here is the phone number for the consumer center."

[0499] Input: Risk type, user emotional state

[0500] Output: Consultation information

[0501] Step 5.2: Provide guidelines for action

[0502] Server: Generates specific guidelines for users to follow to avoid risks, such as "Do not click on unknown URLs" or "Do not enter personal information."

[0503] Input: Risk type, user emotional state

[0504] Output: Action Guidelines

[0505] Step 5.3: Display Information

[0506] Terminal: The generated consultation information and action guidelines are displayed to the user in an easy-to-understand manner. For example, a message such as "Here is the phone number for the consumer center. Please contact us immediately" is displayed to encourage immediate action.

[0507] Input: Consultation information, guidelines

[0508] Output: Information displayed to the user

[0509] (Application example 2)

[0510] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0511] Current security systems can monitor users' online behavioral data and predict risks, but they lack mechanisms for providing appropriate warnings and responses that take the user's emotional state into account. As a result, when users feel anxious, they may not receive appropriate warnings at the right time, and may not be able to fully avoid risks. To solve this problem, a security system that takes the user's emotional state into account is needed.

[0512] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for collecting user behavioral data, means for analyzing the collected behavioral data in real time and predicting the risk of crime and victimization, means for collecting emotional data from the user's facial expressions and voice tone, and means for analyzing the collected emotional data and adjusting the content of a warning message according to the user's emotional state. This makes it possible for a user to receive appropriate warnings and responses according to their emotional state when they face risks on the Internet.

[0513] "User behavior data" refers to information such as search keywords, URLs accessed, and content posted by users on the Internet.

[0514] "Analyzing in real time" means processing collected data instantly and performing operations to obtain results immediately.

[0515] "Risk of crime and harm" refers to illegal activities such as fraud, phishing, and malware, and the harm that may result from them.

[0516] "Warning message" means a notification to inform the user of a risk and urge caution.

[0517] "Emotional data" refers to the emotional state (e.g., anxiety, fear, joy) that can be read from the user's facial expression or tone of voice.

[0518] "Collection methods" refers to the devices and software used to collect user behavioral and emotional data.

[0519] "Analysis means" refers to the algorithms and software used to process collected data and extract meaningful information.

[0520] "Facial expressions and vocal tone" refers to the user's facial movements and tone of voice, and are indicators for reading emotions from them.

[0521] "Adjusting means" refers to a method or function for changing the content of a warning message depending on the user's emotional state.

[0522] System Overview

[0523] This invention is a system that monitors users' online behavior, predicts the risk of crime and victimization, and provides warnings and responses based on their emotional state. The system achieves this by collecting and analyzing users' behavioral and emotional data.

[0524] Hardware and software used

[0525] Hardware: smartphone, camera, microphone

[0526] Software: Machine learning algorithms (e.g., Scikit-learn, TensorFlow), speech recognition libraries (e.g., speech_recognition), emotion recognition libraries (e.g., OpenCV).

[0527] Data collection

[0528] User:

[0529] A user uses a smartphone to access the Internet and perform searches, web browsing, writing, etc. The smartphone's camera and microphone capture the user's facial expressions and voice tone.

[0530] Device:

[0531] The device captures user behavior data (e.g., search keywords, URLs accessed, and posted content) in real time. The device also uses a camera and microphone to collect emotional data from the user's facial expressions and tone of voice. The collected data is then sent to a server.

[0532] Data analysis and risk prediction

[0533] server:

[0534] The server quickly analyzes the received behavioral and emotional data. It preprocesses the data using machine learning algorithms to extract features. It calculates a risk score based on the extracted features and compares it with a specific threshold. If the risk score exceeds the threshold, it identifies the type of risk (e.g., phishing scam, malware).

[0535] Emotion data analysis and response adjustment

[0536] server:

[0537] The server analyzes the emotion data to determine the user's current emotional state (e.g., anxiety, fear, joy). Based on the emotional state, the server adjusts the content and presentation of the warning message. For example, if the user is feeling anxious, the server displays a more detailed message with a gentler tone.

[0538] Generate and display warning messages

[0539] server:

[0540] Based on the detected risks, the server generates appropriate warning messages, and if necessary, additional information about the type of crime, past victim cases, and how to avoid them.

[0541] Device:

[0542] The terminal displays the warning message received from the server to the user, and the displayed message is adjusted according to the user's emotional state.

[0543] Specific examples

[0544] Phishing detection and prevention

[0545] User:

[0546] A user attempts to access an internet shopping site, but it is actually a phishing site.

[0547] Device:

[0548] The device captures the accessed URL and sends it to the server. At the same time, the device captures the user's facial expressions with a camera and collects emotional data from voice tones.

[0549] server:

[0550] The server checks the received URL against a list of known dangerous URLs in a database in real time. If the URL is detected as a phishing site, it determines that there is a high risk of phishing and calculates a risk score. If the risk score exceeds a threshold, it generates a phishing warning message. The server analyzes the user's emotional data and recognizes that the user is feeling anxious. Based on this, it generates a warning message with a detailed explanation and a gentle tone.

[0551] Device:

[0552] The device will display a warning message to the user saying, "This site may be a phishing scam. Do not enter any personal information."

[0553] server:

[0554] The server generates contact information for consumer centers and police and provides instructions such as "Click here for more information." Considering that the user is feeling very anxious, the server prioritizes displaying information for emergency consultations.

[0555] User:

[0556] Users should check the warning message, recognize that it is a fraudulent site, avoid entering personal information, and refer to emergency consultation information to take appropriate measures.

[0557] Prompt Sentence Examples

[0558] "Generate a risk assessment and warning message based on user behavior data: {'url': 'http: / / example-phishing-site.com'}, user emotion data: {'expression': 'neutral', 'voice_tone': 'calm'}."

[0559] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[0560] Step 1:

[0561] Users use smartphones to access the Internet and perform searches, web browsing, and writing. The smartphone's camera and microphone capture the user's facial expressions and voice tone. As input, Internet behavior data (e.g., search keywords and accessed URLs) and emotional data (e.g., facial expressions and voice tone) are collected. This data is used for further processing.

[0562] Step 2:

[0563] The device captures user behavior data (e.g., search keywords, accessed URLs, and posted content) in real time and predicts the risk of crime and victimization based on this. The input is user behavior data, specifically text data and URLs. To analyze it, a machine learning algorithm (e.g., Scikit-learn) is used to preprocess the data and extract features. A risk score is obtained as output. If the risk score exceeds a certain threshold, the type of risk (e.g., phishing scam, malware) is identified.

[0564] Step 3:

[0565] The device uses a camera and microphone to capture emotional data from the user's facial expressions and tone of voice in real time. Image and audio data are input, which are then analyzed through emotion recognition software (e.g., OpenCV, speech_recognition). The output is the user's emotional state (e.g., anxiety, joy, fear).

[0566] Step 4:

[0567] The server calculates a risk score based on the behavioral and emotional data it receives. The input is the behavioral and emotional data sent from the device. The server preprocesses the data using a machine learning algorithm (e.g., TensorFlow), extracts features, and calculates a risk score. The output is a risk score and the type of risk.

[0568] Step 5:

[0569] The server analyzes the emotion data to determine the user's current emotional state. The input is emotion data, which includes facial expression data and vocal tone. An emotion recognition algorithm is used for the analysis. The output is the user's emotional state (e.g., anxiety, fear, joy).

[0570] Step 6:

[0571] The server generates an appropriate warning message if the risk score exceeds a threshold. The inputs are the risk score, the type of risk, and the user's emotional state. Based on these data, the server creates the warning message using a text generation algorithm (e.g., a generative AI model). As an output, a customized warning message is generated.

[0572] Step 7:

[0573] The terminal displays the warning message received from the server to the user. The input is the generated warning message. The terminal displays the message to the user and optionally displays additional information (e.g., the type of crime, past victim cases, and how to avoid it). The output includes a fade-in warning message and a link for more information.

[0574] Step 8:

[0575] The server provides the user with guidelines for avoiding risk and information on where to seek advice. The input is an information request based on the type of risk and emotional state. The server provides the user with appropriate guidelines for avoiding risk (e.g., do not click on URLs, do not enter personal information) and information on where to seek advice (e.g., consumer centers, police). The output is specific guidelines for avoiding risk and information on where to seek advice that the user can refer to.

[0576] This series of processes allows users to sense risks on the Internet in real time and receive appropriate warnings and countermeasures according to their emotional state.

[0577] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[0578] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[0579] In the above embodiment, an example in which the specific process is performed by the data processing device 12 has been given, but the technology of the present disclosure is not limited to this, and the specific process may be performed by the smart device 14.

[0580] [Second embodiment]

[0581] FIG. 3 shows an example of the configuration of a data processing system 210 according to the second embodiment.

[0582] 3, the data processing system 210 includes the data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.

[0583] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0584] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, and the camera 42 are also connected to the bus 52.

[0585] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.

[0586] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[0587] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[0588] Fig. 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Fig. 4, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[0589] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0590] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0591] In the smart glasses 214, the reception output process is performed by the processor 46. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[0592] Next, a description will be given of the identification process performed by the identification processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal."

[0593] Overall system overview

[0594] This invention is a system that monitors users' online behavior, predicts the risk of crime or harm, and issues a warning. This system aims to prevent users from unwittingly becoming involved in risks, and even if they do intentionally become involved, it aims to have a deterrent effect by making them understand the risks.

[0595] System Configuration

[0596] The system mainly consists of the following elements:

[0597] 1. Terminal: The device through which a user accesses the Internet (e.g., a computer or smartphone).

[0598] 2. Server: The core part of the system that collects and analyzes behavioral data and predicts and notifies users of risks.

[0599] 3. Database: Stores information such as known fraudulent URLs and dangerous keywords.

[0600] Program processing overview

[0601] 1. Data Collection

[0602] User:

[0603] Users use the terminal to access the Internet and perform searches, web browsing, and writing.

[0604] Device:

[0605] The device captures user behavior data (e.g., search keywords, accessed URLs, and posted content) in real time.

[0606] Send the captured data to the server.

[0607] 2. Data analysis and risk prediction

[0608] server:

[0609] The server quickly analyzes the received behavioral data, specifically preprocessing it using machine learning algorithms to extract features.

[0610] A risk score is calculated based on the extracted features and compared with a specific threshold.

[0611] If the risk score exceeds a threshold, the type of risk (e.g., phishing scam, malware) is identified.

[0612] 3. Generating and Displaying Warning Messages

[0613] server:

[0614] The server generates appropriate warning messages based on the detected risks.

[0615] If necessary, additional information will be generated about the type of crime involved, past victimization cases, and ways to avoid it.

[0616] Device:

[0617] The terminal displays the warning message received from the server to the user.

[0618] 4. Providing consultation information and guidelines

[0619] server:

[0620] Depending on the detected risk, the server generates information about contact points (e.g., consumer centers, police) for the user to contact.

[0621] Provide specific guidelines for users to take to avoid risks (e.g., do not click on URLs or enter personal information).

[0622] Device:

[0623] The device displays this information to the user in an easy-to-understand manner, encouraging immediate action.

[0624] Specific examples

[0625] Phishing detection and prevention

[0626] User:

[0627] A user attempts to access an internet shopping site, but it is actually a phishing site.

[0628] Device:

[0629] The device captures the accessed URL and sends it to the server.

[0630] server:

[0631] The server checks the received URL against a list of known dangerous URLs in a database in real time.

[0632] If a URL is detected as a phishing site, it is determined to be at high risk of phishing and a risk score is calculated.

[0633] Generate a phishing warning message because the risk score exceeds a threshold.

[0634] Device:

[0635] The device will display a warning message to the user saying, "This site may be a phishing scam. Do not enter any personal information."

[0636] server:

[0637] The server generates contact information for consumer centers and police and provides instructions such as "Click here for more information."

[0638] User:

[0639] Users should check the warning message, recognize that it is a fraudulent site, and avoid entering personal information.

[0640] This system allows users to understand the risks on the Internet and provides them with concrete steps to use it safely.

[0641] The processing flow will be explained below.

[0642] Step 1:

[0643] User: A user uses an internet browser to access a particular website or enters a search keyword on the internet.

[0644] Step 2:

[0645] Device: The device captures the user's search keywords and the URLs of the websites they visit in real time.

[0646] Step 3:

[0647] Terminal: Sends the captured behavioral data to the server through a specified endpoint.

[0648] Step 4:

[0649] Server: The server temporarily stores the received behavioral data and performs data cleaning, specifically removing unnecessary tags and special characters and converting it into an analyzable format.

[0650] Step 5:

[0651] Server: After data cleaning is complete, features (e.g., specific keywords, domains of accessed URLs, etc.) are extracted from user behavior data.

[0652] Step 6:

[0653] Server: Calculates a risk score based on the extracted features. Here, an existing machine learning model is used to predict the risk score.

[0654] Step 7:

[0655] Server: Evaluates whether the risk score exceeds a pre-set threshold.

[0656] Step 8:

[0657] Server: If the score exceeds a threshold, identify the appropriate risk category (e.g., phishing, malware).

[0658] Step 9:

[0659] Server: Generate appropriate warning messages based on the identified risk categories, e.g. "This site may be a phishing scam. Do not enter any personal information."

[0660] Step 10:

[0661] Server: Generate additional information about past exploits and mitigation strategies, if necessary.

[0662] Step 11:

[0663] Server: Sends generated warning messages and additional information to the device.

[0664] Step 12:

[0665] Terminal: Received warning messages are displayed to the user. Warning messages are displayed in a popup format to make them more visible to the user.

[0666] Step 13:

[0667] Server: Depending on the risk, it generates appropriate contact information for the user to contact (e.g., consumer center or police) and sends this information to the terminal.

[0668] Step 14:

[0669] Device: Along with the provided consultation information, detailed guidelines for action (e.g., do not click on URLs, do not enter personal information) are displayed to the user.

[0670] Step 15:

[0671] Users: Users can review the displayed warning messages and additional information and take appropriate measures to reduce the risk of becoming involved in crime or victimization.

[0672] Example 1

[0673] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0674] Conventional Internet security systems have difficulty preventing damage caused by users unknowingly visiting high-risk websites or entering fraudulent information. Even when risks are detected, they lack mechanisms for providing users with immediate, specific warnings or guidelines for action. This makes it difficult for users to predict the risk of online crime and harm and take concrete measures.

[0675] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[0676] In this invention, the server includes a means for collecting user behavioral data, a means for analyzing the collected behavioral data in real time, performing preprocessing and feature extraction, and a means for calculating a risk score from the analysis results and comparing the score with a specific threshold. This makes it possible to immediately identify risks based on the user's behavioral data and provide appropriate warnings to the user. Furthermore, if a risk is detected, additional information on the type of crime and how to avoid it, as well as information on where to seek advice, can be provided, allowing the user to obtain specific guidelines for using the Internet safely.

[0677] "User behavioral data" refers to digital activities such as search keywords used by users on the Internet, URLs accessed, and content posted.

[0678] "Real-time analysis" refers to the process of processing data and obtaining results immediately at the moment the data is generated.

[0679] "Preprocessing" refers to early stages of data processing, such as data cleansing and normalization, to convert raw data into an analyzable format.

[0680] "Feature extraction" refers to the process by which machine learning algorithms find important attributes and patterns in data.

[0681] A "risk score" is a numerical representation of the likelihood of crime or victimization based on a user's behavioral data.

[0682] A "threshold" refers to a reference value that a risk score must exceed before a specific action is triggered.

[0683] A "warning message" refers to a notification that notifies the user of an increased risk and urges caution.

[0684] "Additional information" refers to information including past cases of damage related to the detected risk and specific methods of avoiding it.

[0685] "Consultation information" refers to contact information for consumer centers, police, etc. that users can contact when they become aware of a risk.

[0686] "Risk types" specifically refer to categories of phishing, malware, and other cybercrime.

[0687] "Specific guidelines for action" refer to specific actions that should be taken to protect users from risks (e.g., not clicking on URLs, not entering personal information).

[0688] Overall system overview

[0689] This invention is a system that monitors users' online behavior, predicts the risk of crime or harm, and issues a warning. This system aims to prevent users from unwittingly becoming involved in risks, and even if they do intentionally become involved, it aims to have a deterrent effect by making them understand the risks.

[0690] System configuration

[0691] The system consists of the following main elements:

[0692] 1. Terminal: A device (e.g., PC, smartphone) that a user uses to access the Internet.

[0693] 2. Server: This is the core part of the system that collects and analyzes behavioral data and predicts and notifies users of risks.

[0694] 3. Database: Stores information such as known fraudulent URLs and dangerous keywords.

[0695] Data collection

[0696] User:

[0697] Users use the terminal to access the Internet and perform searches, web browsing, and writing.

[0698] Device:

[0699] The device captures user behavior data (e.g., search keywords, URLs accessed, and posted content) in real time, and the captured data is sent to the server.

[0700] Data analysis and risk prediction

[0701] server:

[0702] The server quickly analyzes the behavioral data received from the device. Specifically, it preprocesses the data using a machine learning algorithm (e.g., TensorFlow) and extracts features. It calculates a risk score based on the extracted features and compares the score with a specific threshold. If the risk score exceeds the threshold, it identifies the type of risk (e.g., phishing scam, malware).

[0703] Generate and display warning messages

[0704] server:

[0705] The server generates appropriate warning messages based on the detected risks, and, if necessary, provides additional information about the type of crime, past victim cases, and how to avoid them.

[0706] Device:

[0707] The terminal displays the warning message received from the server to the user.

[0708] Providing consultation information and guidelines

[0709] server:

[0710] Depending on the detected risk, the server generates contact information for the user to contact (e.g., consumer center, police), and provides specific guidelines for the user to take to avoid the risk (e.g., do not click on URLs, do not enter personal information).

[0711] Device:

[0712] The device displays this information to the user in an easy-to-understand manner, encouraging immediate action.

[0713] Specific examples

[0714] Phishing detection and prevention

[0715] User:

[0716] A user attempts to access an internet shopping site, but it is actually a phishing site.

[0717] Device:

[0718] The device captures the accessed URL and sends it to the server.

[0719] server:

[0720] The server checks the received URL against a list of known dangerous URLs in a database in real time. If the URL is detected as a phishing site, it determines that there is a high risk of phishing and calculates a risk score. If the risk score exceeds a threshold, a phishing warning message is generated.

[0721] Device:

[0722] The device will display a warning message to the user saying, "This site may be a phishing scam. Do not enter any personal information."

[0723] server:

[0724] The server generates contact information for consumer centers and police and provides instructions such as "Click here for more information."

[0725] User:

[0726] Users can view the warning message, recognize that the site is fraudulent, and avoid entering personal information. This system helps users understand the risks of using the Internet and provides concrete steps to stay safe.

[0727] Prompt Sentence Examples

[0728] Here are some example prompts to input to the generative AI model:

[0729] Explain the program flow that generates a warning message and alerts the user when they try to access a phishing site.

[0730] This allows you to understand the processing flow and operation of a specific program.

[0731] The flow of the identification process in the first embodiment will be described with reference to FIG.

[0732] Step 1:

[0733] User:

[0734] Users access the Internet using devices such as computers and smartphones to browse various websites, search for information using search engines, and post on message boards.

[0735] input:

[0736] User web browsing and search behavior data (e.g., search keywords, access URLs, and posted content)

[0737] Device:

[0738] The device captures this behavioral data in real time, encrypts it, and sends it to a server.

[0739] output:

[0740] Encrypted behavioral data

[0741] Specific behavior:

[0742] The device captures the information entered by the user in real time, encrypts it to prevent information leakage, and then transmits the encrypted data to the server.

[0743] Step 2:

[0744] server:

[0745] The server decrypts the encrypted behavioral data received from the device and performs preprocessing on the data, which involves removing noise data and standardizing the data format.

[0746] input:

[0747] Encrypted behavioral data

[0748] Specific behavior:

[0749] The server decrypts the received data, removes unnecessary and duplicate data, and converts it into a format suitable for analysis.

[0750] output:

[0751] Preprocessed behavioral data

[0752] Step 3:

[0753] server:

[0754] The server uses machine learning algorithms (e.g., TensorFlow) to extract features from the preprocessed behavioral data and calculates a risk score, which is then compared with a specific threshold.

[0755] input:

[0756] Preprocessed behavioral data

[0757] Specific behavior:

[0758] The server uses machine learning models to extract key features from the data, calculates a risk score based on them, and compares the result with a pre-defined threshold.

[0759] output:

[0760] Risk score (number)

[0761] Step 4:

[0762] server:

[0763] If the risk score exceeds a threshold, the server identifies the type of risk (e.g., phishing scam, malware) and generates an appropriate warning message.

[0764] input:

[0765] Risk Score

[0766] Specific behavior:

[0767] The server checks whether the risk score exceeds a threshold and generates an appropriate warning message based on pre-defined rules. For example, if it is a phishing scam, it creates a message such as "This site may be a phishing scam. Do not enter personal information."

[0768] output:

[0769] Warning message

[0770] Step 5:

[0771] Device:

[0772] The terminal displays the warning message received from the server to the user, and depending on the content of the warning message, it may suspend the user's operation.

[0773] input:

[0774] Warning message

[0775] Specific behavior:

[0776] The device immediately displays the warning message received from the server to the user, allowing the user to recognize the risk and blocking the user's operation if necessary.

[0777] output:

[0778] The warning message displayed to the user

[0779] Step 6:

[0780] server:

[0781] The server generates information on where to contact for advice depending on the risk (e.g., consumer centers, police) and provides specific guidelines for action (e.g., do not click on URLs, do not enter personal information).

[0782] input:

[0783] Types of Risk

[0784] Specific behavior:

[0785] The server generates appropriate information on where to contact for advice and a course of action based on the type of risk, and notifies the user. For example, it includes specific instructions such as "Here is the link to contact the consumer center."

[0786] output:

[0787] Consultation information and guidelines

[0788] Step 7:

[0789] Device:

[0790] The device displays this information on consultation points and guidelines for action in an easy-to-understand manner to the user, encouraging them to take immediate action.

[0791] input:

[0792] Consultation information and guidelines

[0793] Specific behavior:

[0794] The device displays specific guidelines for risk avoidance to the user, and provides an interface that allows them to access consultation services with one click if necessary.

[0795] output:

[0796] Consultation information and guidelines displayed to the user

[0797] (Application example 1)

[0798] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0799] Currently, Internet users are often unknowingly exposed to risks such as phishing scams and malware. Furthermore, there are currently insufficient systems in place to predict and provide early warnings when certain high-risk behaviors are involved. As a result, users are more likely to become victims of crime and are required to respond after the fact. Furthermore, it is currently difficult to learn about the risks involved, find specific ways to avoid them, or find information on where to seek advice. There is a need to solve these problems and provide an environment in which users can use the Internet safely and with peace of mind.

[0800] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[0801] In this invention, the server includes: means for collecting user behavioral data; means for analyzing the collected behavioral data in real time and predicting the risk of crime and victimization; means for displaying a warning message to the user based on the predicted risk; means for providing information on the type of crime and how to avoid it; means for providing the user with information on where to seek advice; means for determining in real time whether a specific user behavior poses a risk; and means for generating and providing a specific warning message to the user based on a risk score if the risk meets certain conditions. This allows users to recognize potential risks on the Internet in advance and take early action. Furthermore, providing appropriate information on where to seek advice and specific ways to avoid them further ensures user safety.

[0802] "User behavior data" is a general term for data such as search keywords, URLs accessed, and content posted by users on the Internet.

[0803] The "means for collecting" is a function for capturing user behavior data in real time and transmitting it to a server.

[0804] "Real-time analysis means" refers to an analytical function that instantly processes collected behavioral data and assesses risk.

[0805] "Predictive means" is a function that detects the risk of crime or harm that may occur in the future based on analyzed data.

[0806] The "means for displaying a warning message" is a function for visually presenting a message to inform the user of a risk.

[0807] The "means for providing information on the types of crimes that may occur and how to avoid them" is a function for conveying to the user information on the types of crimes that may occur and how to avoid them in response to detected risks.

[0808] The "means for providing information on where to contact for consultation" is a function for providing information on appropriate organizations and support desks that users should contact when a risk is detected.

[0809] "A means for determining in real time whether a particular action will pose a risk" is a function that instantly evaluates whether an action involves a risk each time a user takes an action.

[0810] "Means for generating a specific warning message based on the risk score and providing it to the user" is a function for quantifying the degree of risk, creating a detailed warning message based on that score, and conveying it to the user.

[0811] The embodiments of the present invention will be described in detail below.

[0812] Overall system configuration

[0813] This invention is a system that monitors users' online behavior, predicts the risk of crime or harm, and issues warnings. The system consists of a user device (terminal) and a server. The terminal captures user behavior data and sends it to the server. The server analyzes the data, predicts risks, generates warning messages, sends them to the terminal, and displays them to the user.

[0814] Hardware and software used

[0815] Device: A user device such as a smartphone, computer, or tablet.

[0816] Server: A central system that collects and analyzes data and generates warning messages, etc.

[0817] Software: The programming language Python and the library requests for sending HTTP requests are used.

[0818] Data collection

[0819] The device captures real-time behavioral data such as search keywords, URLs accessed, and posted content when a user searches online. This data is sent to a server when a certain amount of data is reached or a specific event occurs.

[0820] Data analysis and risk prediction

[0821] The server rapidly analyzes the received behavioral data using machine learning algorithms to preprocess the data and extract features, and then calculates a risk score based on the data and compares it with a specific threshold.

[0822] Determining risks and generating warning messages

[0823] If the risk score exceeds a certain threshold, the server identifies the type of risk and generates a specific warning message, which is then sent to the terminal in a user-friendly format and displayed to the user.

[0824] Specific examples

[0825] For example, if a user searches for "buy cheap medicines," the server analyzes the search keywords and detects the risk of accessing a fraudulent website selling cheap medicines. Also, if a user accesses the URL http: / / phishing.example.com, the server detects the risk of phishing and immediately displays a warning message.

[0826] Prompt Sentence Examples

[0827] Prompt your generative AI model with the following prompt:

[0828] "Monitor user behavior and calculate a risk score based on the following data:

[0829] Search keywords: 'buy cheap medicines', 'free crypto wallet'

[0830] Access URL: 'http: / / phishing.example.com', 'http: / / scam.example.com'"

[0831] This will realize a system that allows users to always ensure safety on the Internet and quickly take necessary measures.

[0832] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[0833] Step 1:

[0834] The device collects user behavior data. Specifically, it captures the keywords the user searches for, the URLs they access, and the content they post in real time. This data is temporarily stored on the device as session data.

[0835] Input: User search keywords, access URL, and post content

[0836] Output: Captured behavioral data

[0837] Step 2:

[0838] The device sends behavioral data to the server using an HTTP request when a certain amount of behavioral data has been collected or when a specific event occurs.

[0839] Input: Captured behavioral data

[0840] Output: Behavioral data sent to the server

[0841] Step 3:

[0842] The server analyzes the received data. First, it preprocesses the data using a machine learning algorithm and extracts features.

[0843] Input: Submitted behavioral data

[0844] Output: Extracted features

[0845] Step 4:

[0846] The server calculates a risk score based on the extracted features, using a pre-trained generative AI model.

[0847] Input: extracted features

[0848] Output: Calculated risk score

[0849] Step 5:

[0850] The server determines whether the risk score exceeds a certain threshold, and if so, identifies the type of risk (e.g., phishing, malware).

[0851] Input: Calculated risk score

[0852] Output: Identified risk types

[0853] Step 6:

[0854] The server generates a specific warning message based on the type of risk, including the type of crime, past victim cases, and how to avoid it.

[0855] Input: Type of risk identified

[0856] Output: Generated warning message

[0857] Step 7:

[0858] The server transmits the generated warning message and information on where to contact for advice to the terminal.

[0859] Input: Generated warning message, contact information

[0860] Output: Message sent to terminal

[0861] Step 8:

[0862] The device will then display the received warning message and information on where to contact for help to the user, who can then check the information on the screen and take appropriate measures.

[0863] Input: Warning message sent from the server, consultation information

[0864] Output: Displaying information to the user

[0865] This processing flow realizes a system in which user behavior data is monitored and analyzed in real time, and an immediate warning is issued if a risk is detected.

[0866] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.

[0867] Overall system overview

[0868] This invention combines an emotion engine with a system that monitors users' online behavior, predicts the risk of crime or harm, and issues warnings. The system aims to prevent users from unwittingly becoming involved in risks, and even if they do intentionally become involved, to help them understand the risks and provide appropriate responses by taking into account the user's emotional state.

[0869] System Configuration

[0870] The system mainly consists of the following elements:

[0871] 1. Terminal: The device through which a user accesses the Internet (e.g., a computer or smartphone).

[0872] 2. Server: The core part of the system that collects and analyzes behavioral and emotional data, and predicts and notifies users of risks.

[0873] 3. Database: Storage for known fraudulent URLs, dangerous keywords, and sentiment data.

[0874] Program processing overview

[0875] 1. Data Collection

[0876] User:

[0877] Users use the terminal to access the Internet and perform searches, web browsing, and writing.

[0878] Device:

[0879] The device captures user behavior data (e.g., search keywords, accessed URLs, and posted content) in real time.

[0880] The device also uses a camera and microphone to capture emotional data from the user's facial expressions and tone of voice.

[0881] Send the captured data to the server.

[0882] 2. Data analysis and risk prediction

[0883] server:

[0884] The server quickly analyzes the received behavioral and emotional data, preprocessing the data using machine learning algorithms to extract features.

[0885] A risk score is calculated based on the extracted features and compared with a specific threshold.

[0886] If the risk score exceeds a threshold, the type of risk (e.g., phishing scam, malware) is identified.

[0887] 3. Emotional data analysis and response adjustment

[0888] server:

[0889] The server analyzes the emotion data to determine the user's current emotional state (e.g., anxiety, fear, joy).

[0890] It adjusts the content and presentation of warning messages based on the user's emotional state, for example, displaying more detailed explanations and a gentler tone of voice if the user is feeling anxious.

[0891] 4. Generating and Displaying Warning Messages

[0892] server:

[0893] The server generates appropriate warning messages based on the detected risks.

[0894] If necessary, additional information will be generated about the type of crime involved, past victimization cases, and ways to avoid it.

[0895] Device:

[0896] The terminal displays the warning message received from the server to the user, and the displayed message is adjusted according to the user's emotional state.

[0897] 5. Providing consultation information and guidelines

[0898] server:

[0899] Depending on the detected risk, the server generates information about contact points (e.g., consumer centers, police) for the user to contact.

[0900] Provide specific guidelines for users to take to avoid risks (e.g., do not click on URLs or enter personal information).

[0901] The display order and content of the information is adjusted according to the user's emotions.

[0902] Device:

[0903] The device displays this information to the user in an easy-to-understand manner, encouraging immediate action.

[0904] Specific examples

[0905] Phishing detection and prevention

[0906] User:

[0907] A user attempts to access an internet shopping site, but it is actually a phishing site.

[0908] Device:

[0909] The device captures the accessed URL and sends it to the server.

[0910] At the same time, the device captures the user's facial expressions with a camera and collects emotional data from voice tones.

[0911] server:

[0912] The server checks the received URL against a list of known dangerous URLs in a database in real time.

[0913] If a URL is detected as a phishing site, it is determined to be at high risk of phishing and a risk score is calculated.

[0914] Generate a phishing warning message because the risk score exceeds a threshold.

[0915] The server analyzes the user's emotional data and recognizes that the user is feeling anxious, and generates a warning message with detailed explanation and a gentle tone.

[0916] Device:

[0917] The device will display a warning message to the user saying, "This site may be a phishing scam. Do not enter any personal information."

[0918] server:

[0919] The server generates contact information for consumer centers and police and provides instructions such as "Click here for more information."

[0920] The server takes into consideration that the user is feeling strong anxiety and displays emergency consultation information with priority.

[0921] User:

[0922] Users should check the warning message, recognize that it is a fraudulent site, avoid entering personal information, and refer to emergency consultation information to take appropriate measures.

[0923] This system allows users to understand the risks on the Internet, provides concrete measures for safe use, and allows them to receive responses that take their emotional state into consideration.

[0924] The processing flow will be explained below.

[0925] Step 1:

[0926] User: A user uses an internet browser to access a particular website or enters a search keyword on the internet.

[0927] Step 2:

[0928] Device: The device captures the user's search keywords and the URLs of the websites they visit in real time.

[0929] Step 3:

[0930] On-device: Use the device's camera and microphone to capture emotional data from the user's facial expressions, tone of voice, and more.

[0931] Step 4:

[0932] Terminal: Sends the captured behavioral and emotional data to the server through a designated endpoint.

[0933] Step 5:

[0934] Server: The server stores the received behavioral and emotional data and performs data cleaning, removing unnecessary tags and special characters, and converting it into an analyzable format.

[0935] Step 6:

[0936] Server: After data cleaning is complete, features (e.g., specific keywords, domains of accessed URLs, changes in facial expressions, tone of voice, etc.) are extracted from the user's behavioral and emotional data.

[0937] Step 7:

[0938] Server: Calculates a risk score based on the extracted features. Here, an existing machine learning model is used to predict the risk score.

[0939] Step 8:

[0940] Server: Evaluates whether the risk score exceeds a pre-set threshold.

[0941] Step 9:

[0942] Server: If the score exceeds a threshold, identify the appropriate risk category (e.g., phishing, malware).

[0943] Step 10:

[0944] Server: Analyzes the user's emotional data and determines the user's current emotional state (e.g., anxiety, fear, joy).

[0945] Step 11:

[0946] Server: Adjust the content and presentation of warning messages based on the user's emotional state. For example, if the user is feeling anxious, display a more detailed message with a gentler tone.

[0947] Step 12:

[0948] Server: Generates a tailored warning message, such as "This site may be a phishing scam. Do not enter any personal information."

[0949] Step 13:

[0950] Server: Generates additional information about the type of crime, past victimization, and prevention methods, if necessary.

[0951] Step 14:

[0952] Server: Sends generated warning messages and additional information to the device.

[0953] Step 15:

[0954] Terminal: The received warning message is displayed to the user. The displayed message is adjusted according to the user's emotional state and presented in a pop-up format.

[0955] Step 16:

[0956] Server: Depending on the risk, generates appropriate contact information for the user to contact (e.g. consumer center, police) and sends this information to the terminal.

[0957] Step 17:

[0958] Device: Along with the provided consultation information, detailed guidelines for action (e.g., do not click on URLs, do not enter personal information) are displayed to the user.

[0959] Step 18:

[0960] Users: Users can review the displayed warning messages and additional information and take appropriate measures to reduce the risk of becoming involved in crime or victimization. Because the user's emotional state is taken into consideration, they can respond with greater peace of mind.

[0961] Example 2

[0962] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0963] With the spread of the Internet, users have gained access to a wide variety of information and services, but at the same time, they are being asked to respond appropriately to the increasing risks of online fraud and malware. However, current systems only provide uniform risk warnings to users and do not take into account their emotional state, which often prevents them from taking effective risk avoidance actions. In addition, due to insufficient calculation of risk scores and identification of risk types, there is a lack of information provided to users to enable them to take specific countermeasures. There is a need to solve these issues.

[0964] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.

[0965] In this invention, the server includes means for analyzing user behavioral data and emotional data in real time to predict the risk of crime and victimization, means for displaying a warning message to the user based on the predicted risk, and means for adjusting the content and display method of the warning message based on the user's emotional state, thereby making it possible to provide appropriate warnings and specific risk avoidance information according to the user's emotional state.

[0966] "User behavior data" refers to information such as search keywords, URLs accessed, and content posted by users on the Internet.

[0967] "Emotion data" is information that indicates the emotional state of the user, which can be obtained from facial expressions, tone of voice, and the like.

[0968] "Real-time analysis" means processing and analyzing data immediately as it is captured.

[0969] "Predicting the risk of crime and victimization" means assessing the likelihood that a user will be involved in a crime or victimization based on collected data.

[0970] "Displaying a warning message" means displaying a warning or alert to the user on the screen based on the predicted risk.

[0971] "Applicable crime type" refers to the specific crime category associated with the predicted risk (e.g., phishing scams or malware infections).

[0972] "Avoidance methods" is information that indicates specific actions or steps that a user should take to avoid a predicted risk.

[0973] "Consultation information" is contact information for organizations or institutions that users can contact or consult with if they are facing a risk.

[0974] "Emotional state" refers to the psychological or emotional state (e.g., anxiety, fear, joy) that a user expresses through a camera or microphone.

[0975] MODE FOR CARRYING OUT THE INVENTION

[0976] Overall system overview

[0977] This invention combines an emotion engine with a system that monitors users' online behavior, predicts the risk of crime or harm, and issues warnings. The system aims to prevent users from unwittingly becoming involved in risks, and even if they do intentionally become involved, to help them understand the risks and provide appropriate responses by taking into account the user's emotional state.

[0978] System Configuration

[0979] The system mainly consists of the following elements:

[0980] 1. Device: A device (e.g., a PC or smartphone) that allows a user to access the Internet. The device captures the user's behavioral and emotional data and transmits it to a server.

[0981] 2. Server: This is the core part of the system that collects and analyzes behavioral and emotional data, and predicts and notifies risks. The server analyzes the data using machine learning algorithms and deep learning models.

[0982] 3. Database: Storage for known fraudulent URLs, dangerous keywords, and sentiment data.

[0983] Hardware and Software

[0984] Device: The user's computer, smartphone, etc.

[0985] Camera and microphone: Devices for capturing your facial expressions and tone of voice.

[0986] Server: A high-performance data processing server is used, which uses Python, the pandas library, the scikit-learn library, OpenCV, and deep learning models for data processing.

[0987] Specific examples

[0988] Below is a specific example of how this system can be used.

[0989] Example: Phishing detection and countermeasures

[0990] User: A user attempts to access an internet shopping site, but it is actually a phishing site.

[0991] Device: The device captures the accessed URL and sends it to the server. It also captures the user's facial expressions with a camera and collects emotional data from voice tones.

[0992] server:

[0993] Incoming URLs are checked against a list of known dangerous URLs in a database in real time.

[0994] When a URL is detected as a phishing site, a risk score is calculated and a phishing warning message is generated if the risk score exceeds a threshold.

[0995] It analyzes emotional data, recognizes when the user is feeling anxious, and generates a warning message with detailed explanation and a gentle tone based on this.

[0996] Device: Show the user the warning message "This site may be a phishing scam. Do not enter any personal information."

[0997] Server: Generates contact information for consumer centers and police, and provides instructions such as "Click here for more information." If the user is feeling very anxious, the server prioritizes displaying emergency consultation information.

[0998] Users: Check the warning message, recognize that it is a fraudulent site, avoid entering personal information, and refer to the emergency contact information to take appropriate measures.

[0999] Prompt Sentence Examples

[1000] "The system detected a fraud risk. Please check the user data and risk score. Then generate a warning message and notify the user with an appropriate tone based on the sentiment data."

[1001] The flow of the identification process in the second embodiment will be described with reference to FIG.

[1002] System program processing flow

[1003] Step 1: Data collection

[1004] Step 1.1: Capture behavioral data

[1005] Device: The device captures the search keywords, URLs accessed, and postings made by users on the Internet in real time. For example, when a user visits a shopping site, the device captures the URL and saves it as a user operation log.

[1006] Input: User search keywords, access URL, and post content

[1007] Output: Captured behavioral data

[1008] Step 1.2: Capturing emotion data

[1009] On the device: Using a camera and microphone, emotional data is captured from the user's facial expressions and tone of voice. For example, if the user smiles at the camera, that facial expression data is captured in real time.

[1010] Input: User's facial expression, tone of voice

[1011] Output: Captured emotion data

[1012] Step 1.3: Send data

[1013] Device: The device sends the captured behavioral and emotional data to the server. The data is encrypted using SSL / TLS protocol during transmission to ensure security.

[1014] Input: Captured behavioral data, emotion data

[1015] Output: Data sent to the server

[1016] Step 2: Data analysis and risk prediction

[1017] Step 2.1: Data Preprocessing

[1018] Server: The server preprocesses the received behavioral and emotional data. Specifically, it cleans the data, fills in missing data, and removes noise. This process uses the Python pandas library.

[1019] Input: Received behavioral data, emotion data

[1020] Output: Preprocessed data

[1021] Step 2.2: Feature extraction

[1022] Server: The server extracts features from the preprocessed data. For example, it extracts the frequency of search keywords or patterns of accessed URLs. In this case, it uses the scikit-learn library to perform feature extraction.

[1023] Input: Preprocessed data

[1024] Output: Features

[1025] Step 2.3: Risk Score Calculation

[1026] Server: The server calculates a risk score based on the extracted features, for example, using a machine learning model such as a random forest or a support vector machine, and compares it with a specific threshold.

[1027] Input: Features

[1028] Output: Risk score

[1029] Step 2.4: Identify risk types

[1030] Server: If the risk score exceeds a threshold, the server identifies the type of risk (e.g., phishing, malware), consulting a database of known dangerous URLs and fraud patterns.

[1031] Input: Risk Score

[1032] Output: Risk type

[1033] Step 3: Analyze emotion data and adjust responses

[1034] Step 3.1: Emotion determination

[1035] Server: The server analyzes the received emotion data and determines the user's current emotional state. For example, if the user is frowning, it determines that they are feeling anxious. For emotion analysis, it uses OpenCV and a deep learning model for emotion recognition.

[1036] Input: Emotion data

[1037] Output: User's emotional state

[1038] Step 3.2: Adjust the warning message

[1039] Server: The server adjusts the content and presentation of the warning message based on the user's emotional state. For example, if the user is feeling anxious, it generates a gentle, detailed message such as "This site may be a phishing scam. Please be careful."

[1040] Input: Risk type, user emotional state

[1041] Output: Adjusted warning message

[1042] Step 4: Generate and display warning messages

[1043] Step 4.1: Generate a warning message

[1044] Server: The server generates appropriate warning messages based on the detected risks, adding specific information about the type of fraud, past victim cases, and how to avoid them.

[1045] Input: Risk type, user emotional state

[1046] Output: Warning message

[1047] Step 4.2: Send the message

[1048] Server: Generates and sends a warning message to the device. This message is adapted according to the user's emotional state.

[1049] Input: warning message

[1050] Output: Message sent to the terminal

[1051] Step 4.3: Displaying a warning message

[1052] On the device: Display the warning message received from the server to the user. For example, if a risk of a phishing site is detected, the message "This site may be a phishing scam. Do not enter personal information." will be displayed.

[1053] Input: Message sent to terminal

[1054] Output: The warning message displayed to the user.

[1055] Step 5: Providing consultation information and guidelines

[1056] Step 5.1: Generate consultation information

[1057] Server: Depending on the detected risk, the server generates contact information for consumer centers, police, etc. For example, it provides specific contact information such as "Here is the phone number for the consumer center."

[1058] Input: Risk type, user emotional state

[1059] Output: Consultation information

[1060] Step 5.2: Provide guidelines for action

[1061] Server: Generates specific guidelines for users to follow to avoid risks, such as "Do not click on unknown URLs" or "Do not enter personal information."

[1062] Input: Risk type, user emotional state

[1063] Output: Action Guidelines

[1064] Step 5.3: Display Information

[1065] Terminal: The generated consultation information and action guidelines are displayed to the user in an easy-to-understand manner. For example, a message such as "Here is the phone number for the consumer center. Please contact us immediately" is displayed to encourage immediate action.

[1066] Input: Consultation information, guidelines

[1067] Output: Information displayed to the user

[1068] (Application example 2)

[1069] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[1070] Current security systems can monitor users' online behavioral data and predict risks, but they lack mechanisms for providing appropriate warnings and responses that take the user's emotional state into account. As a result, when users feel anxious, they may not receive appropriate warnings at the right time, and may not be able to fully avoid risks. To solve this problem, a security system that takes the user's emotional state into account is needed.

[1071] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for collecting user behavioral data, means for analyzing the collected behavioral data in real time and predicting the risk of crime and victimization, means for collecting emotional data from the user's facial expressions and voice tone, and means for analyzing the collected emotional data and adjusting the content of a warning message according to the user's emotional state. This makes it possible for a user to receive appropriate warnings and responses according to their emotional state when they face risks on the Internet.

[1072] "User behavior data" refers to information such as search keywords, URLs accessed, and content posted by users on the Internet.

[1073] "Analyzing in real time" means processing collected data instantly and performing operations to obtain results immediately.

[1074] "Risk of crime and harm" refers to illegal activities such as fraud, phishing, and malware, and the harm that may result from them.

[1075] "Warning message" means a notification to inform the user of a risk and urge caution.

[1076] "Emotional data" refers to the emotional state (e.g., anxiety, fear, joy) that can be read from the user's facial expression or tone of voice.

[1077] "Collection methods" refers to the devices and software used to collect user behavioral and emotional data.

[1078] "Analysis means" refers to the algorithms and software used to process collected data and extract meaningful information.

[1079] "Facial expressions and vocal tone" refers to the user's facial movements and tone of voice, and are indicators for reading emotions from them.

[1080] "Adjusting means" refers to a method or function for changing the content of a warning message depending on the user's emotional state.

[1081] System Overview

[1082] This invention is a system that monitors users' online behavior, predicts the risk of crime and victimization, and provides warnings and responses based on their emotional state. The system achieves this by collecting and analyzing users' behavioral and emotional data.

[1083] Hardware and software used

[1084] Hardware: smartphone, camera, microphone

[1085] Software: Machine learning algorithms (e.g., Scikit-learn, TensorFlow), speech recognition libraries (e.g., speech_recognition), emotion recognition libraries (e.g., OpenCV).

[1086] Data collection

[1087] User:

[1088] A user uses a smartphone to access the Internet and perform searches, web browsing, writing, etc. The smartphone's camera and microphone capture the user's facial expressions and voice tone.

[1089] Device:

[1090] The device captures user behavior data (e.g., search keywords, URLs accessed, and posted content) in real time. The device also uses a camera and microphone to collect emotional data from the user's facial expressions and tone of voice. The collected data is then sent to a server.

[1091] Data analysis and risk prediction

[1092] server:

[1093] The server quickly analyzes the received behavioral and emotional data. It preprocesses the data using machine learning algorithms to extract features. It calculates a risk score based on the extracted features and compares it with a specific threshold. If the risk score exceeds the threshold, it identifies the type of risk (e.g., phishing scam, malware).

[1094] Emotion data analysis and response adjustment

[1095] server:

[1096] The server analyzes the emotion data to determine the user's current emotional state (e.g., anxiety, fear, joy). Based on the emotional state, the server adjusts the content and presentation of the warning message. For example, if the user is feeling anxious, the server displays a more detailed message with a gentler tone.

[1097] Generate and display warning messages

[1098] server:

[1099] Based on the detected risks, the server generates appropriate warning messages, and if necessary, additional information about the type of crime, past victim cases, and how to avoid them.

[1100] Device:

[1101] The terminal displays the warning message received from the server to the user, and the displayed message is adjusted according to the user's emotional state.

[1102] Specific examples

[1103] Phishing detection and prevention

[1104] User:

[1105] A user attempts to access an internet shopping site, but it is actually a phishing site.

[1106] Device:

[1107] The device captures the accessed URL and sends it to the server. At the same time, the device captures the user's facial expressions with a camera and collects emotional data from voice tones.

[1108] server:

[1109] The server checks the received URL against a list of known dangerous URLs in a database in real time. If the URL is detected as a phishing site, it determines that there is a high risk of phishing and calculates a risk score. If the risk score exceeds a threshold, it generates a phishing warning message. The server analyzes the user's emotional data and recognizes that the user is feeling anxious. Based on this, it generates a warning message with a detailed explanation and a gentle tone.

[1110] Device:

[1111] The device will display a warning message to the user saying, "This site may be a phishing scam. Do not enter any personal information."

[1112] server:

[1113] The server generates contact information for consumer centers and police and provides instructions such as "Click here for more information." Considering that the user is feeling very anxious, the server prioritizes displaying information for emergency consultations.

[1114] User:

[1115] Users should check the warning message, recognize that it is a fraudulent site, avoid entering personal information, and refer to emergency consultation information to take appropriate measures.

[1116] Prompt Sentence Examples

[1117] "Generate a risk assessment and warning message based on user behavior data: {'url': 'http: / / example-phishing-site.com'}, user emotion data: {'expression': 'neutral', 'voice_tone': 'calm'}."

[1118] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[1119] Step 1:

[1120] Users use smartphones to access the Internet and perform searches, web browsing, and writing. The smartphone's camera and microphone capture the user's facial expressions and voice tone. As input, Internet behavior data (e.g., search keywords and accessed URLs) and emotional data (e.g., facial expressions and voice tone) are collected. This data is used for further processing.

[1121] Step 2:

[1122] The device captures user behavior data (e.g., search keywords, accessed URLs, and posted content) in real time and predicts the risk of crime and victimization based on this. The input is user behavior data, specifically text data and URLs. To analyze it, a machine learning algorithm (e.g., Scikit-learn) is used to preprocess the data and extract features. A risk score is obtained as output. If the risk score exceeds a certain threshold, the type of risk (e.g., phishing scam, malware) is identified.

[1123] Step 3:

[1124] The device uses a camera and microphone to capture emotional data from the user's facial expressions and tone of voice in real time. Image and audio data are input, which are then analyzed through emotion recognition software (e.g., OpenCV, speech_recognition). The output is the user's emotional state (e.g., anxiety, joy, fear).

[1125] Step 4:

[1126] The server calculates a risk score based on the behavioral and emotional data it receives. The input is the behavioral and emotional data sent from the device. The server preprocesses the data using a machine learning algorithm (e.g., TensorFlow), extracts features, and calculates a risk score. The output is a risk score and the type of risk.

[1127] Step 5:

[1128] The server analyzes the emotion data to determine the user's current emotional state. The input is emotion data, which includes facial expression data and vocal tone. An emotion recognition algorithm is used for the analysis. The output is the user's emotional state (e.g., anxiety, fear, joy).

[1129] Step 6:

[1130] The server generates an appropriate warning message if the risk score exceeds a threshold. The inputs are the risk score, the type of risk, and the user's emotional state. Based on these data, the server creates the warning message using a text generation algorithm (e.g., a generative AI model). As an output, a customized warning message is generated.

[1131] Step 7:

[1132] The terminal displays the warning message received from the server to the user. The input is the generated warning message. The terminal displays the message to the user and optionally displays additional information (e.g., the type of crime, past victim cases, and how to avoid it). The output includes a fade-in warning message and a link for more information.

[1133] Step 8:

[1134] The server provides the user with guidelines for avoiding risk and information on where to seek advice. The input is an information request based on the type of risk and emotional state. The server provides the user with appropriate guidelines for avoiding risk (e.g., do not click on URLs, do not enter personal information) and information on where to seek advice (e.g., consumer centers, police). The output is specific guidelines for avoiding risk and information on where to seek advice that the user can refer to.

[1135] This series of processes allows users to sense risks on the Internet in real time and receive appropriate warnings and countermeasures according to their emotional state.

[1136] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[1137] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[1138] In the above embodiment, an example in which the specific processing is performed by the data processing device 12 has been given, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the smart glasses 214.

[1139] [Third embodiment]

[1140] FIG. 5 shows an example of the configuration of a data processing system 310 according to the third embodiment.

[1141] 5, the data processing system 310 includes the data processing device 12 and a headset type terminal 314. An example of the data processing device 12 is a server.

[1142] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[1143] The headset type terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a display 343. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the display 343 are also connected to the bus 52.

[1144] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.

[1145] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[1146] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[1147] Fig. 6 shows an example of the main functions of the data processing device 12 and the headset type terminal 314. As shown in Fig. 6, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[1148] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[1149] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[1150] In the headset type terminal 314, a reception output process is performed by the processor 46. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[1151] Next, a description will be given of the identification process performed by the identification processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as the "server" and the headset type terminal 314 will be referred to as the "terminal."

[1152] Overall system overview

[1153] This invention is a system that monitors users' online behavior, predicts the risk of crime or harm, and issues a warning. This system aims to prevent users from unwittingly becoming involved in risks, and even if they do intentionally become involved, it aims to have a deterrent effect by making them understand the risks.

[1154] System Configuration

[1155] The system mainly consists of the following elements:

[1156] 1. Terminal: The device through which a user accesses the Internet (e.g., a computer or smartphone).

[1157] 2. Server: The core part of the system that collects and analyzes behavioral data and predicts and notifies users of risks.

[1158] 3. Database: Stores information such as known fraudulent URLs and dangerous keywords.

[1159] Program processing overview

[1160] 1. Data Collection

[1161] User:

[1162] Users use the terminal to access the Internet and perform searches, web browsing, and writing.

[1163] Device:

[1164] The device captures user behavior data (e.g., search keywords, accessed URLs, and posted content) in real time.

[1165] Send the captured data to the server.

[1166] 2. Data analysis and risk prediction

[1167] server:

[1168] The server quickly analyzes the received behavioral data, specifically preprocessing it using machine learning algorithms to extract features.

[1169] A risk score is calculated based on the extracted features and compared with a specific threshold.

[1170] If the risk score exceeds a threshold, the type of risk (e.g., phishing scam, malware) is identified.

[1171] 3. Generating and Displaying Warning Messages

[1172] server:

[1173] The server generates appropriate warning messages based on the detected risks.

[1174] If necessary, additional information will be generated about the type of crime involved, past victimization cases, and ways to avoid it.

[1175] Device:

[1176] The terminal displays the warning message received from the server to the user.

[1177] 4. Providing consultation information and guidelines

[1178] server:

[1179] Depending on the detected risk, the server generates information about contact points (e.g., consumer centers, police) for the user to contact.

[1180] Provide specific guidelines for users to take to avoid risks (e.g., do not click on URLs or enter personal information).

[1181] Device:

[1182] The device displays this information to the user in an easy-to-understand manner, encouraging immediate action.

[1183] Specific examples

[1184] Phishing detection and prevention

[1185] User:

[1186] A user attempts to access an internet shopping site, but it is actually a phishing site.

[1187] Device:

[1188] The device captures the accessed URL and sends it to the server.

[1189] server:

[1190] The server checks the received URL against a list of known dangerous URLs in a database in real time.

[1191] If a URL is detected as a phishing site, it is determined to be at high risk of phishing and a risk score is calculated.

[1192] Generate a phishing warning message because the risk score exceeds a threshold.

[1193] Device:

[1194] The device will display a warning message to the user saying, "This site may be a phishing scam. Do not enter any personal information."

[1195] server:

[1196] The server generates contact information for consumer centers and police and provides instructions such as "Click here for more information."

[1197] User:

[1198] Users should check the warning message, recognize that it is a fraudulent site, and avoid entering personal information.

[1199] This system allows users to understand the risks on the Internet and provides them with concrete steps to use it safely.

[1200] The processing flow will be explained below.

[1201] Step 1:

[1202] User: A user uses an internet browser to access a particular website or enters a search keyword on the internet.

[1203] Step 2:

[1204] Device: The device captures the user's search keywords and the URLs of the websites they visit in real time.

[1205] Step 3:

[1206] Terminal: Sends the captured behavioral data to the server through a specified endpoint.

[1207] Step 4:

[1208] Server: The server temporarily stores the received behavioral data and performs data cleaning, specifically removing unnecessary tags and special characters and converting it into an analyzable format.

[1209] Step 5:

[1210] Server: After data cleaning is complete, features (e.g., specific keywords, domains of accessed URLs, etc.) are extracted from user behavior data.

[1211] Step 6:

[1212] Server: Calculates a risk score based on the extracted features. Here, an existing machine learning model is used to predict the risk score.

[1213] Step 7:

[1214] Server: Evaluates whether the risk score exceeds a pre-set threshold.

[1215] Step 8:

[1216] Server: If the score exceeds a threshold, identify the appropriate risk category (e.g., phishing, malware).

[1217] Step 9:

[1218] Server: Generate appropriate warning messages based on the identified risk categories, e.g. "This site may be a phishing scam. Do not enter any personal information."

[1219] Step 10:

[1220] Server: Generate additional information about past exploits and mitigation strategies, if necessary.

[1221] Step 11:

[1222] Server: Sends generated warning messages and additional information to the device.

[1223] Step 12:

[1224] Terminal: Received warning messages are displayed to the user. Warning messages are displayed in a popup format to make them more visible to the user.

[1225] Step 13:

[1226] Server: Depending on the risk, it generates appropriate contact information for the user to contact (e.g., consumer center or police) and sends this information to the terminal.

[1227] Step 14:

[1228] Device: Along with the provided consultation information, detailed guidelines for action (e.g., do not click on URLs, do not enter personal information) are displayed to the user.

[1229] Step 15:

[1230] Users: Users can review the displayed warning messages and additional information and take appropriate measures to reduce the risk of becoming involved in crime or victimization.

[1231] Example 1

[1232] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[1233] Conventional Internet security systems have difficulty preventing damage caused by users unknowingly visiting high-risk websites or entering fraudulent information. Even when risks are detected, they lack mechanisms for providing users with immediate, specific warnings or guidelines for action. This makes it difficult for users to predict the risk of online crime and harm and take concrete measures.

[1234] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[1235] In this invention, the server includes a means for collecting user behavioral data, a means for analyzing the collected behavioral data in real time, performing preprocessing and feature extraction, and a means for calculating a risk score from the analysis results and comparing the score with a specific threshold. This makes it possible to immediately identify risks based on the user's behavioral data and provide appropriate warnings to the user. Furthermore, if a risk is detected, additional information on the type of crime and how to avoid it, as well as information on where to seek advice, can be provided, allowing the user to obtain specific guidelines for using the Internet safely.

[1236] "User behavioral data" refers to digital activities such as search keywords used by users on the Internet, URLs accessed, and content posted.

[1237] "Real-time analysis" refers to the process of processing data and obtaining results immediately at the moment the data is generated.

[1238] "Preprocessing" refers to early stages of data processing, such as data cleansing and normalization, to convert raw data into an analyzable format.

[1239] "Feature extraction" refers to the process by which machine learning algorithms find important attributes and patterns in data.

[1240] A "risk score" is a numerical representation of the likelihood of crime or victimization based on a user's behavioral data.

[1241] A "threshold" refers to a reference value that a risk score must exceed before a specific action is triggered.

[1242] A "warning message" refers to a notification that notifies the user of an increased risk and urges caution.

[1243] "Additional information" refers to information including past cases of damage related to the detected risk and specific methods of avoiding it.

[1244] "Consultation information" refers to contact information for consumer centers, police, etc. that users can contact when they become aware of a risk.

[1245] "Risk types" specifically refer to categories of phishing, malware, and other cybercrime.

[1246] "Specific guidelines for action" refer to specific actions that should be taken to protect users from risks (e.g., not clicking on URLs, not entering personal information).

[1247] Overall system overview

[1248] This invention is a system that monitors users' online behavior, predicts the risk of crime or harm, and issues a warning. This system aims to prevent users from unwittingly becoming involved in risks, and even if they do intentionally become involved, it aims to have a deterrent effect by making them understand the risks.

[1249] System configuration

[1250] The system consists of the following main elements:

[1251] 1. Terminal: A device (e.g., PC, smartphone) that a user uses to access the Internet.

[1252] 2. Server: This is the core part of the system that collects and analyzes behavioral data and predicts and notifies users of risks.

[1253] 3. Database: Stores information such as known fraudulent URLs and dangerous keywords.

[1254] Data collection

[1255] User:

[1256] Users use the terminal to access the Internet and perform searches, web browsing, and writing.

[1257] Device:

[1258] The device captures user behavior data (e.g., search keywords, URLs accessed, and posted content) in real time, and the captured data is sent to the server.

[1259] Data analysis and risk prediction

[1260] server:

[1261] The server quickly analyzes the behavioral data received from the device. Specifically, it preprocesses the data using a machine learning algorithm (e.g., TensorFlow) and extracts features. It calculates a risk score based on the extracted features and compares the score with a specific threshold. If the risk score exceeds the threshold, it identifies the type of risk (e.g., phishing scam, malware).

[1262] Generate and display warning messages

[1263] server:

[1264] The server generates appropriate warning messages based on the detected risks, and, if necessary, provides additional information about the type of crime, past victim cases, and how to avoid them.

[1265] Device:

[1266] The terminal displays the warning message received from the server to the user.

[1267] Providing consultation information and guidelines

[1268] server:

[1269] Depending on the detected risk, the server generates contact information for the user to contact (e.g., consumer center, police), and provides specific guidelines for the user to take to avoid the risk (e.g., do not click on URLs, do not enter personal information).

[1270] Device:

[1271] The device displays this information to the user in an easy-to-understand manner, encouraging immediate action.

[1272] Specific examples

[1273] Phishing detection and prevention

[1274] User:

[1275] A user attempts to access an internet shopping site, but it is actually a phishing site.

[1276] Device:

[1277] The device captures the accessed URL and sends it to the server.

[1278] server:

[1279] The server checks the received URL against a list of known dangerous URLs in a database in real time. If the URL is detected as a phishing site, it determines that there is a high risk of phishing and calculates a risk score. If the risk score exceeds a threshold, a phishing warning message is generated.

[1280] Device:

[1281] The device will display a warning message to the user saying, "This site may be a phishing scam. Do not enter any personal information."

[1282] server:

[1283] The server generates contact information for consumer centers and police and provides instructions such as "Click here for more information."

[1284] User:

[1285] Users can view the warning message, recognize that the site is fraudulent, and avoid entering personal information. This system helps users understand the risks of using the Internet and provides concrete steps to stay safe.

[1286] Prompt Sentence Examples

[1287] Here are some example prompts to input to the generative AI model:

[1288] Explain the program flow that generates a warning message and alerts the user when they try to access a phishing site.

[1289] This allows you to understand the processing flow and operation of a specific program.

[1290] The flow of the identification process in the first embodiment will be described with reference to FIG.

[1291] Step 1:

[1292] User:

[1293] Users access the Internet using devices such as computers and smartphones to browse various websites, search for information using search engines, and post on message boards.

[1294] input:

[1295] User web browsing and search behavior data (e.g., search keywords, access URLs, and posted content)

[1296] Device:

[1297] The device captures this behavioral data in real time, encrypts it, and sends it to a server.

[1298] output:

[1299] Encrypted behavioral data

[1300] Specific behavior:

[1301] The device captures the information entered by the user in real time, encrypts it to prevent information leakage, and then transmits the encrypted data to the server.

[1302] Step 2:

[1303] server:

[1304] The server decrypts the encrypted behavioral data received from the device and performs preprocessing on the data, which involves removing noise data and standardizing the data format.

[1305] input:

[1306] Encrypted behavioral data

[1307] Specific behavior:

[1308] The server decrypts the received data, removes unnecessary and duplicate data, and converts it into a format suitable for analysis.

[1309] output:

[1310] Preprocessed behavioral data

[1311] Step 3:

[1312] server:

[1313] The server uses machine learning algorithms (e.g., TensorFlow) to extract features from the preprocessed behavioral data and calculates a risk score, which is then compared with a specific threshold.

[1314] input:

[1315] Preprocessed behavioral data

[1316] Specific behavior:

[1317] The server uses machine learning models to extract key features from the data, calculates a risk score based on them, and compares the result with a pre-defined threshold.

[1318] output:

[1319] Risk score (number)

[1320] Step 4:

[1321] server:

[1322] If the risk score exceeds a threshold, the server identifies the type of risk (e.g., phishing scam, malware) and generates an appropriate warning message.

[1323] input:

[1324] Risk Score

[1325] Specific behavior:

[1326] The server checks whether the risk score exceeds a threshold and generates an appropriate warning message based on pre-defined rules. For example, if it is a phishing scam, it creates a message such as "This site may be a phishing scam. Do not enter personal information."

[1327] output:

[1328] Warning message

[1329] Step 5:

[1330] Device:

[1331] The terminal displays the warning message received from the server to the user, and depending on the content of the warning message, it may suspend the user's operation.

[1332] input:

[1333] Warning message

[1334] Specific behavior:

[1335] The device immediately displays the warning message received from the server to the user, allowing the user to recognize the risk and blocking the user's operation if necessary.

[1336] output:

[1337] The warning message displayed to the user

[1338] Step 6:

[1339] server:

[1340] The server generates information on where to contact for advice depending on the risk (e.g., consumer centers, police) and provides specific guidelines for action (e.g., do not click on URLs, do not enter personal information).

[1341] input:

[1342] Types of Risk

[1343] Specific behavior:

[1344] The server generates appropriate information on where to contact for advice and a course of action based on the type of risk, and notifies the user. For example, it includes specific instructions such as "Here is the link to contact the consumer center."

[1345] output:

[1346] Consultation information and guidelines

[1347] Step 7:

[1348] Device:

[1349] The device displays this information on consultation points and guidelines for action in an easy-to-understand manner to the user, encouraging them to take immediate action.

[1350] input:

[1351] Consultation information and guidelines

[1352] Specific behavior:

[1353] The device displays specific guidelines for risk avoidance to the user, and provides an interface that allows them to access consultation services with one click if necessary.

[1354] output:

[1355] Consultation information and guidelines displayed to the user

[1356] (Application example 1)

[1357] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[1358] Currently, Internet users are often unknowingly exposed to risks such as phishing scams and malware. Furthermore, there are currently insufficient systems in place to predict and provide early warnings when certain high-risk behaviors are involved. As a result, users are more likely to become victims of crime and are required to respond after the fact. Furthermore, it is currently difficult to learn about the risks involved, find specific ways to avoid them, or find information on where to seek advice. There is a need to solve these problems and provide an environment in which users can use the Internet safely and with peace of mind.

[1359] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[1360] In this invention, the server includes: means for collecting user behavioral data; means for analyzing the collected behavioral data in real time and predicting the risk of crime and victimization; means for displaying a warning message to the user based on the predicted risk; means for providing information on the type of crime and how to avoid it; means for providing the user with information on where to seek advice; means for determining in real time whether a specific user behavior poses a risk; and means for generating and providing a specific warning message to the user based on a risk score if the risk meets certain conditions. This allows users to recognize potential risks on the Internet in advance and take early action. Furthermore, providing appropriate information on where to seek advice and specific ways to avoid them further ensures user safety.

[1361] "User behavior data" is a general term for data such as search keywords, URLs accessed, and content posted by users on the Internet.

[1362] The "means for collecting" is a function for capturing user behavior data in real time and transmitting it to a server.

[1363] "Real-time analysis means" refers to an analytical function that instantly processes collected behavioral data and assesses risk.

[1364] "Predictive means" is a function that detects the risk of crime or harm that may occur in the future based on analyzed data.

[1365] The "means for displaying a warning message" is a function for visually presenting a message to inform the user of a risk.

[1366] The "means for providing information on the types of crimes that may occur and how to avoid them" is a function for conveying to the user information on the types of crimes that may occur and how to avoid them in response to detected risks.

[1367] The "means for providing information on where to contact for consultation" is a function for providing information on appropriate organizations and support desks that users should contact when a risk is detected.

[1368] "A means for determining in real time whether a particular action will pose a risk" is a function that instantly evaluates whether an action involves a risk each time a user takes an action.

[1369] "Means for generating a specific warning message based on the risk score and providing it to the user" is a function for quantifying the degree of risk, creating a detailed warning message based on that score, and conveying it to the user.

[1370] The embodiments of the present invention will be described in detail below.

[1371] Overall system configuration

[1372] This invention is a system that monitors users' online behavior, predicts the risk of crime or harm, and issues warnings. The system consists of a user device (terminal) and a server. The terminal captures user behavior data and sends it to the server. The server analyzes the data, predicts risks, generates warning messages, sends them to the terminal, and displays them to the user.

[1373] Hardware and software used

[1374] Device: A user device such as a smartphone, computer, or tablet.

[1375] Server: A central system that collects and analyzes data and generates warning messages, etc.

[1376] Software: The programming language Python and the library requests for sending HTTP requests are used.

[1377] Data collection

[1378] The device captures real-time behavioral data such as search keywords, URLs accessed, and posted content when a user searches online. This data is sent to a server when a certain amount of data is reached or a specific event occurs.

[1379] Data analysis and risk prediction

[1380] The server rapidly analyzes the received behavioral data using machine learning algorithms to preprocess the data and extract features, and then calculates a risk score based on the data and compares it with a specific threshold.

[1381] Determining risks and generating warning messages

[1382] If the risk score exceeds a certain threshold, the server identifies the type of risk and generates a specific warning message, which is then sent to the terminal in a user-friendly format and displayed to the user.

[1383] Specific examples

[1384] For example, if a user searches for "buy cheap medicines," the server analyzes the search keywords and detects the risk of accessing a fraudulent website selling cheap medicines. Also, if a user accesses the URL http: / / phishing.example.com, the server detects the risk of phishing and immediately displays a warning message.

[1385] Prompt Sentence Examples

[1386] Prompt your generative AI model with the following prompt:

[1387] "Monitor user behavior and calculate a risk score based on the following data:

[1388] Search keywords: 'buy cheap medicines', 'free crypto wallet'

[1389] Access URL: 'http: / / phishing.example.com', 'http: / / scam.example.com'"

[1390] This will realize a system that allows users to always ensure safety on the Internet and quickly take necessary measures.

[1391] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[1392] Step 1:

[1393] The device collects user behavior data. Specifically, it captures the keywords the user searches for, the URLs they access, and the content they post in real time. This data is temporarily stored on the device as session data.

[1394] Input: User search keywords, access URL, and post content

[1395] Output: Captured behavioral data

[1396] Step 2:

[1397] The device sends behavioral data to the server using an HTTP request when a certain amount of behavioral data has been collected or when a specific event occurs.

[1398] Input: Captured behavioral data

[1399] Output: Behavioral data sent to the server

[1400] Step 3:

[1401] The server analyzes the received data. First, it preprocesses the data using a machine learning algorithm and extracts features.

[1402] Input: Submitted behavioral data

[1403] Output: Extracted features

[1404] Step 4:

[1405] The server calculates a risk score based on the extracted features, using a pre-trained generative AI model.

[1406] Input: extracted features

[1407] Output: Calculated risk score

[1408] Step 5:

[1409] The server determines whether the risk score exceeds a certain threshold, and if so, identifies the type of risk (e.g., phishing, malware).

[1410] Input: Calculated risk score

[1411] Output: Identified risk types

[1412] Step 6:

[1413] The server generates a specific warning message based on the type of risk, including the type of crime, past victim cases, and how to avoid it.

[1414] Input: Type of risk identified

[1415] Output: Generated warning message

[1416] Step 7:

[1417] The server transmits the generated warning message and information on where to contact for advice to the terminal.

[1418] Input: Generated warning message, contact information

[1419] Output: Message sent to terminal

[1420] Step 8:

[1421] The device will then display the received warning message and information on where to contact for help to the user, who can then check the information on the screen and take appropriate measures.

[1422] Input: Warning message sent from the server, consultation information

[1423] Output: Displaying information to the user

[1424] This processing flow realizes a system in which user behavior data is monitored and analyzed in real time, and an immediate warning is issued if a risk is detected.

[1425] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.

[1426] Overall system overview

[1427] This invention combines an emotion engine with a system that monitors users' online behavior, predicts the risk of crime or harm, and issues warnings. The system aims to prevent users from unwittingly becoming involved in risks, and even if they do intentionally become involved, to help them understand the risks and provide appropriate responses by taking into account the user's emotional state.

[1428] System Configuration

[1429] The system mainly consists of the following elements:

[1430] 1. Terminal: The device through which a user accesses the Internet (e.g., a computer or smartphone).

[1431] 2. Server: The core part of the system that collects and analyzes behavioral and emotional data, and predicts and notifies users of risks.

[1432] 3. Database: Storage for known fraudulent URLs, dangerous keywords, and sentiment data.

[1433] Program processing overview

[1434] 1. Data Collection

[1435] User:

[1436] Users use the terminal to access the Internet and perform searches, web browsing, and writing.

[1437] Device:

[1438] The device captures user behavior data (e.g., search keywords, accessed URLs, and posted content) in real time.

[1439] The device also uses a camera and microphone to capture emotional data from the user's facial expressions and tone of voice.

[1440] Send the captured data to the server.

[1441] 2. Data analysis and risk prediction

[1442] server:

[1443] The server quickly analyzes the received behavioral and emotional data, preprocessing the data using machine learning algorithms to extract features.

[1444] A risk score is calculated based on the extracted features and compared with a specific threshold.

[1445] If the risk score exceeds a threshold, the type of risk (e.g., phishing scam, malware) is identified.

[1446] 3. Emotional data analysis and response adjustment

[1447] server:

[1448] The server analyzes the emotion data to determine the user's current emotional state (e.g., anxiety, fear, joy).

[1449] It adjusts the content and presentation of warning messages based on the user's emotional state, for example, displaying more detailed explanations and a gentler tone of voice if the user is feeling anxious.

[1450] 4. Generating and Displaying Warning Messages

[1451] server:

[1452] The server generates appropriate warning messages based on the detected risks.

[1453] If necessary, additional information will be generated about the type of crime involved, past victimization cases, and ways to avoid it.

[1454] Device:

[1455] The terminal displays the warning message received from the server to the user, and the displayed message is adjusted according to the user's emotional state.

[1456] 5. Providing consultation information and guidelines

[1457] server:

[1458] Depending on the detected risk, the server generates information about contact points (e.g., consumer centers, police) for the user to contact.

[1459] Provide specific guidelines for users to take to avoid risks (e.g., do not click on URLs or enter personal information).

[1460] The display order and content of the information is adjusted according to the user's emotions.

[1461] Device:

[1462] The device displays this information to the user in an easy-to-understand manner, encouraging immediate action.

[1463] Specific examples

[1464] Phishing detection and prevention

[1465] User:

[1466] A user attempts to access an internet shopping site, but it is actually a phishing site.

[1467] Device:

[1468] The device captures the accessed URL and sends it to the server.

[1469] At the same time, the device captures the user's facial expressions with a camera and collects emotional data from voice tones.

[1470] server:

[1471] The server checks the received URL against a list of known dangerous URLs in a database in real time.

[1472] If a URL is detected as a phishing site, it is determined to be at high risk of phishing and a risk score is calculated.

[1473] Generate a phishing warning message because the risk score exceeds a threshold.

[1474] The server analyzes the user's emotional data and recognizes that the user is feeling anxious, and generates a warning message with detailed explanation and a gentle tone.

[1475] Device:

[1476] The device will display a warning message to the user saying, "This site may be a phishing scam. Do not enter any personal information."

[1477] server:

[1478] The server generates contact information for consumer centers and police and provides instructions such as "Click here for more information."

[1479] The server takes into consideration that the user is feeling strong anxiety and displays emergency consultation information with priority.

[1480] User:

[1481] Users should check the warning message, recognize that it is a fraudulent site, avoid entering personal information, and refer to emergency consultation information to take appropriate measures.

[1482] This system allows users to understand the risks on the Internet, provides concrete measures for safe use, and allows them to receive responses that take their emotional state into consideration.

[1483] The processing flow will be explained below.

[1484] Step 1:

[1485] User: A user uses an internet browser to access a particular website or enters a search keyword on the internet.

[1486] Step 2:

[1487] Device: The device captures the user's search keywords and the URLs of the websites they visit in real time.

[1488] Step 3:

[1489] On-device: Use the device's camera and microphone to capture emotional data from the user's facial expressions, tone of voice, and more.

[1490] Step 4:

[1491] Terminal: Sends the captured behavioral and emotional data to the server through a designated endpoint.

[1492] Step 5:

[1493] Server: The server stores the received behavioral and emotional data and performs data cleaning, removing unnecessary tags and special characters, and converting it into an analyzable format.

[1494] Step 6:

[1495] Server: After data cleaning is complete, features (e.g., specific keywords, domains of accessed URLs, changes in facial expressions, tone of voice, etc.) are extracted from the user's behavioral and emotional data.

[1496] Step 7:

[1497] Server: Calculates a risk score based on the extracted features. Here, an existing machine learning model is used to predict the risk score.

[1498] Step 8:

[1499] Server: Evaluates whether the risk score exceeds a pre-set threshold.

[1500] Step 9:

[1501] Server: If the score exceeds a threshold, identify the appropriate risk category (e.g., phishing, malware).

[1502] Step 10:

[1503] Server: Analyzes the user's emotional data and determines the user's current emotional state (e.g., anxiety, fear, joy).

[1504] Step 11:

[1505] Server: Adjust the content and presentation of warning messages based on the user's emotional state. For example, if the user is feeling anxious, display a more detailed message with a gentler tone.

[1506] Step 12:

[1507] Server: Generates a tailored warning message, such as "This site may be a phishing scam. Do not enter any personal information."

[1508] Step 13:

[1509] Server: Generates additional information about the type of crime, past victimization, and prevention methods, if necessary.

[1510] Step 14:

[1511] Server: Sends generated warning messages and additional information to the device.

[1512] Step 15:

[1513] Terminal: The received warning message is displayed to the user. The displayed message is adjusted according to the user's emotional state and presented in a pop-up format.

[1514] Step 16:

[1515] Server: Depending on the risk, generates appropriate contact information for the user to contact (e.g. consumer center, police) and sends this information to the terminal.

[1516] Step 17:

[1517] Device: Along with the provided consultation information, detailed guidelines for action (e.g., do not click on URLs, do not enter personal information) are displayed to the user.

[1518] Step 18:

[1519] Users: Users can review the displayed warning messages and additional information and take appropriate measures to reduce the risk of becoming involved in crime or victimization. Because the user's emotional state is taken into consideration, they can respond with greater peace of mind.

[1520] Example 2

[1521] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[1522] With the spread of the Internet, users have gained access to a wide variety of information and services, but at the same time, they are being asked to respond appropriately to the increasing risks of online fraud and malware. However, current systems only provide uniform risk warnings to users and do not take into account their emotional state, which often prevents them from taking effective risk avoidance actions. In addition, due to insufficient calculation of risk scores and identification of risk types, there is a lack of information provided to users to enable them to take specific countermeasures. There is a need to solve these issues.

[1523] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.

[1524] In this invention, the server includes means for analyzing user behavioral data and emotional data in real time to predict the risk of crime and victimization, means for displaying a warning message to the user based on the predicted risk, and means for adjusting the content and display method of the warning message based on the user's emotional state, thereby making it possible to provide appropriate warnings and specific risk avoidance information according to the user's emotional state.

[1525] "User behavior data" refers to information such as search keywords, URLs accessed, and content posted by users on the Internet.

[1526] "Emotion data" is information that indicates the emotional state of the user, which can be obtained from facial expressions, tone of voice, and the like.

[1527] "Real-time analysis" means processing and analyzing data immediately as it is captured.

[1528] "Predicting the risk of crime and victimization" means assessing the likelihood that a user will be involved in a crime or victimization based on collected data.

[1529] "Displaying a warning message" means displaying a warning or alert to the user on the screen based on the predicted risk.

[1530] "Applicable crime type" refers to the specific crime category associated with the predicted risk (e.g., phishing scams or malware infections).

[1531] "Avoidance methods" is information that indicates specific actions or steps that a user should take to avoid a predicted risk.

[1532] "Consultation information" is contact information for organizations or institutions that users can contact or consult with if they are facing a risk.

[1533] "Emotional state" refers to the psychological or emotional state (e.g., anxiety, fear, joy) that a user expresses through a camera or microphone.

[1534] MODE FOR CARRYING OUT THE INVENTION

[1535] Overall system overview

[1536] This invention combines an emotion engine with a system that monitors users' online behavior, predicts the risk of crime or harm, and issues warnings. The system aims to prevent users from unwittingly becoming involved in risks, and even if they do intentionally become involved, to help them understand the risks and provide appropriate responses by taking into account the user's emotional state.

[1537] System Configuration

[1538] The system mainly consists of the following elements:

[1539] 1. Device: A device (e.g., a PC or smartphone) that allows a user to access the Internet. The device captures the user's behavioral and emotional data and transmits it to a server.

[1540] 2. Server: This is the core part of the system that collects and analyzes behavioral and emotional data, and predicts and notifies risks. The server analyzes the data using machine learning algorithms and deep learning models.

[1541] 3. Database: Storage for known fraudulent URLs, dangerous keywords, and sentiment data.

[1542] Hardware and Software

[1543] Device: The user's computer, smartphone, etc.

[1544] Camera and microphone: Devices for capturing your facial expressions and tone of voice.

[1545] Server: A high-performance data processing server is used, which uses Python, the pandas library, the scikit-learn library, OpenCV, and deep learning models for data processing.

[1546] Specific examples

[1547] Below is a specific example of how this system can be used.

[1548] Example: Phishing detection and countermeasures

[1549] User: A user attempts to access an internet shopping site, but it is actually a phishing site.

[1550] Device: The device captures the accessed URL and sends it to the server. It also captures the user's facial expressions with a camera and collects emotional data from voice tones.

[1551] server:

[1552] Incoming URLs are checked against a list of known dangerous URLs in a database in real time.

[1553] When a URL is detected as a phishing site, a risk score is calculated and a phishing warning message is generated if the risk score exceeds a threshold.

[1554] It analyzes emotional data, recognizes when the user is feeling anxious, and generates a warning message with detailed explanation and a gentle tone based on this.

[1555] Device: Show the user the warning message "This site may be a phishing scam. Do not enter any personal information."

[1556] Server: Generates contact information for consumer centers and police, and provides instructions such as "Click here for more information." If the user is feeling very anxious, the server prioritizes displaying emergency consultation information.

[1557] Users: Check the warning message, recognize that it is a fraudulent site, avoid entering personal information, and refer to the emergency contact information to take appropriate measures.

[1558] Prompt Sentence Examples

[1559] "The system detected a fraud risk. Please check the user data and risk score. Then generate a warning message and notify the user with an appropriate tone based on the sentiment data."

[1560] The flow of the identification process in the second embodiment will be described with reference to FIG.

[1561] System program processing flow

[1562] Step 1: Data collection

[1563] Step 1.1: Capture behavioral data

[1564] Device: The device captures the search keywords, URLs accessed, and postings made by users on the Internet in real time. For example, when a user visits a shopping site, the device captures the URL and saves it as a user operation log.

[1565] Input: User search keywords, access URL, and post content

[1566] Output: Captured behavioral data

[1567] Step 1.2: Capturing emotion data

[1568] On the device: Using a camera and microphone, emotional data is captured from the user's facial expressions and tone of voice. For example, if the user smiles at the camera, that facial expression data is captured in real time.

[1569] Input: User's facial expression, tone of voice

[1570] Output: Captured emotion data

[1571] Step 1.3: Send data

[1572] Device: The device sends the captured behavioral and emotional data to the server. The data is encrypted using SSL / TLS protocol during transmission to ensure security.

[1573] Input: Captured behavioral data, emotion data

[1574] Output: Data sent to the server

[1575] Step 2: Data analysis and risk prediction

[1576] Step 2.1: Data Preprocessing

[1577] Server: The server preprocesses the received behavioral and emotional data. Specifically, it cleans the data, fills in missing data, and removes noise. This process uses the Python pandas library.

[1578] Input: Received behavioral data, emotion data

[1579] Output: Preprocessed data

[1580] Step 2.2: Feature extraction

[1581] Server: The server extracts features from the preprocessed data. For example, it extracts the frequency of search keywords or patterns of accessed URLs. In this case, it uses the scikit-learn library to perform feature extraction.

[1582] Input: Preprocessed data

[1583] Output: Features

[1584] Step 2.3: Risk Score Calculation

[1585] Server: The server calculates a risk score based on the extracted features, for example, using a machine learning model such as a random forest or a support vector machine, and compares it with a specific threshold.

[1586] Input: Features

[1587] Output: Risk score

[1588] Step 2.4: Identify risk types

[1589] Server: If the risk score exceeds a threshold, the server identifies the type of risk (e.g., phishing, malware), consulting a database of known dangerous URLs and fraud patterns.

[1590] Input: Risk Score

[1591] Output: Risk type

[1592] Step 3: Analyze emotion data and adjust responses

[1593] Step 3.1: Emotion determination

[1594] Server: The server analyzes the received emotion data and determines the user's current emotional state. For example, if the user is frowning, it determines that they are feeling anxious. For emotion analysis, it uses OpenCV and a deep learning model for emotion recognition.

[1595] Input: Emotion data

[1596] Output: User's emotional state

[1597] Step 3.2: Adjust the warning message

[1598] Server: The server adjusts the content and presentation of the warning message based on the user's emotional state. For example, if the user is feeling anxious, it generates a gentle, detailed message such as "This site may be a phishing scam. Please be careful."

[1599] Input: Risk type, user emotional state

[1600] Output: Adjusted warning message

[1601] Step 4: Generate and display warning messages

[1602] Step 4.1: Generate a warning message

[1603] Server: The server generates appropriate warning messages based on the detected risks, adding specific information about the type of fraud, past victim cases, and how to avoid them.

[1604] Input: Risk type, user emotional state

[1605] Output: Warning message

[1606] Step 4.2: Send the message

[1607] Server: Generates and sends a warning message to the device. This message is adapted according to the user's emotional state.

[1608] Input: warning message

[1609] Output: Message sent to the terminal

[1610] Step 4.3: Displaying a warning message

[1611] On the device: Display the warning message received from the server to the user. For example, if a risk of a phishing site is detected, the message "This site may be a phishing scam. Do not enter personal information." will be displayed.

[1612] Input: Message sent to terminal

[1613] Output: The warning message displayed to the user.

[1614] Step 5: Providing consultation information and guidelines

[1615] Step 5.1: Generate consultation information

[1616] Server: Depending on the detected risk, the server generates contact information for consumer centers, police, etc. For example, it provides specific contact information such as "Here is the phone number for the consumer center."

[1617] Input: Risk type, user emotional state

[1618] Output: Consultation information

[1619] Step 5.2: Provide guidelines for action

[1620] Server: Generates specific guidelines for users to follow to avoid risks, such as "Do not click on unknown URLs" or "Do not enter personal information."

[1621] Input: Risk type, user emotional state

[1622] Output: Action Guidelines

[1623] Step 5.3: Display Information

[1624] Terminal: The generated consultation information and action guidelines are displayed to the user in an easy-to-understand manner. For example, a message such as "Here is the phone number for the consumer center. Please contact us immediately" is displayed to encourage immediate action.

[1625] Input: Consultation information, guidelines

[1626] Output: Information displayed to the user

[1627] (Application example 2)

[1628] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[1629] Current security systems can monitor users' online behavioral data and predict risks, but they lack mechanisms for providing appropriate warnings and responses that take the user's emotional state into account. As a result, when users feel anxious, they may not receive appropriate warnings at the right time, and may not be able to fully avoid risks. To solve this problem, a security system that takes the user's emotional state into account is needed.

[1630] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for collecting user behavioral data, means for analyzing the collected behavioral data in real time and predicting the risk of crime and victimization, means for collecting emotional data from the user's facial expressions and voice tone, and means for analyzing the collected emotional data and adjusting the content of a warning message according to the user's emotional state. This makes it possible for a user to receive appropriate warnings and responses according to their emotional state when they face risks on the Internet.

[1631] "User behavior data" refers to information such as search keywords, URLs accessed, and content posted by users on the Internet.

[1632] "Analyzing in real time" means processing collected data instantly and performing operations to obtain results immediately.

[1633] "Risk of crime and harm" refers to illegal activities such as fraud, phishing, and malware, and the harm that may result from them.

[1634] "Warning message" means a notification to inform the user of a risk and urge caution.

[1635] "Emotional data" refers to the emotional state (e.g., anxiety, fear, joy) that can be read from the user's facial expression or tone of voice.

[1636] "Collection methods" refers to the devices and software used to collect user behavioral and emotional data.

[1637] "Analysis means" refers to the algorithms and software used to process collected data and extract meaningful information.

[1638] "Facial expressions and vocal tone" refers to the user's facial movements and tone of voice, and are indicators for reading emotions from them.

[1639] "Adjusting means" refers to a method or function for changing the content of a warning message depending on the user's emotional state.

[1640] System Overview

[1641] This invention is a system that monitors users' online behavior, predicts the risk of crime and victimization, and provides warnings and responses based on their emotional state. The system achieves this by collecting and analyzing users' behavioral and emotional data.

[1642] Hardware and software used

[1643] Hardware: smartphone, camera, microphone

[1644] Software: Machine learning algorithms (e.g., Scikit-learn, TensorFlow), speech recognition libraries (e.g., speech_recognition), emotion recognition libraries (e.g., OpenCV).

[1645] Data collection

[1646] User:

[1647] A user uses a smartphone to access the Internet and perform searches, web browsing, writing, etc. The smartphone's camera and microphone capture the user's facial expressions and voice tone.

[1648] Device:

[1649] The device captures user behavior data (e.g., search keywords, URLs accessed, and posted content) in real time. The device also uses a camera and microphone to collect emotional data from the user's facial expressions and tone of voice. The collected data is then sent to a server.

[1650] Data analysis and risk prediction

[1651] server:

[1652] The server quickly analyzes the received behavioral and emotional data. It preprocesses the data using machine learning algorithms to extract features. It calculates a risk score based on the extracted features and compares it with a specific threshold. If the risk score exceeds the threshold, it identifies the type of risk (e.g., phishing scam, malware).

[1653] Emotion data analysis and response adjustment

[1654] server:

[1655] The server analyzes the emotion data to determine the user's current emotional state (e.g., anxiety, fear, joy). Based on the emotional state, the server adjusts the content and presentation of the warning message. For example, if the user is feeling anxious, the server displays a more detailed message with a gentler tone.

[1656] Generate and display warning messages

[1657] server:

[1658] Based on the detected risks, the server generates appropriate warning messages, and if necessary, additional information about the type of crime, past victim cases, and how to avoid them.

[1659] Device:

[1660] The terminal displays the warning message received from the server to the user, and the displayed message is adjusted according to the user's emotional state.

[1661] Specific examples

[1662] Phishing detection and prevention

[1663] User:

[1664] A user attempts to access an internet shopping site, but it is actually a phishing site.

[1665] Device:

[1666] The device captures the accessed URL and sends it to the server. At the same time, the device captures the user's facial expressions with a camera and collects emotional data from voice tones.

[1667] server:

[1668] The server checks the received URL against a list of known dangerous URLs in a database in real time. If the URL is detected as a phishing site, it determines that there is a high risk of phishing and calculates a risk score. If the risk score exceeds a threshold, it generates a phishing warning message. The server analyzes the user's emotional data and recognizes that the user is feeling anxious. Based on this, it generates a warning message with a detailed explanation and a gentle tone.

[1669] Device:

[1670] The device will display a warning message to the user saying, "This site may be a phishing scam. Do not enter any personal information."

[1671] server:

[1672] The server generates contact information for consumer centers and police and provides instructions such as "Click here for more information." Considering that the user is feeling very anxious, the server prioritizes displaying information for emergency consultations.

[1673] User:

[1674] Users should check the warning message, recognize that it is a fraudulent site, avoid entering personal information, and refer to emergency consultation information to take appropriate measures.

[1675] Prompt Sentence Examples

[1676] "Generate a risk assessment and warning message based on user behavior data: {'url': 'http: / / example-phishing-site.com'}, user emotion data: {'expression': 'neutral', 'voice_tone': 'calm'}."

[1677] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[1678] Step 1:

[1679] Users use smartphones to access the Internet and perform searches, web browsing, and writing. The smartphone's camera and microphone capture the user's facial expressions and voice tone. As input, Internet behavior data (e.g., search keywords and accessed URLs) and emotional data (e.g., facial expressions and voice tone) are collected. This data is used for further processing.

[1680] Step 2:

[1681] The device captures user behavior data (e.g., search keywords, accessed URLs, and posted content) in real time and predicts the risk of crime and victimization based on this. The input is user behavior data, specifically text data and URLs. To analyze it, a machine learning algorithm (e.g., Scikit-learn) is used to preprocess the data and extract features. A risk score is obtained as output. If the risk score exceeds a certain threshold, the type of risk (e.g., phishing scam, malware) is identified.

[1682] Step 3:

[1683] The device uses a camera and microphone to capture emotional data from the user's facial expressions and tone of voice in real time. Image and audio data are input, which are then analyzed through emotion recognition software (e.g., OpenCV, speech_recognition). The output is the user's emotional state (e.g., anxiety, joy, fear).

[1684] Step 4:

[1685] The server calculates a risk score based on the behavioral and emotional data it receives. The input is the behavioral and emotional data sent from the device. The server preprocesses the data using a machine learning algorithm (e.g., TensorFlow), extracts features, and calculates a risk score. The output is a risk score and the type of risk.

[1686] Step 5:

[1687] The server analyzes the emotion data to determine the user's current emotional state. The input is emotion data, which includes facial expression data and vocal tone. An emotion recognition algorithm is used for the analysis. The output is the user's emotional state (e.g., anxiety, fear, joy).

[1688] Step 6:

[1689] The server generates an appropriate warning message if the risk score exceeds a threshold. The inputs are the risk score, the type of risk, and the user's emotional state. Based on these data, the server creates the warning message using a text generation algorithm (e.g., a generative AI model). As an output, a customized warning message is generated.

[1690] Step 7:

[1691] The terminal displays the warning message received from the server to the user. The input is the generated warning message. The terminal displays the message to the user and optionally displays additional information (e.g., the type of crime, past victim cases, and how to avoid it). The output includes a fade-in warning message and a link for more information.

[1692] Step 8:

[1693] The server provides the user with guidelines for avoiding risk and information on where to seek advice. The input is an information request based on the type of risk and emotional state. The server provides the user with appropriate guidelines for avoiding risk (e.g., do not click on URLs, do not enter personal information) and information on where to seek advice (e.g., consumer centers, police). The output is specific guidelines for avoiding risk and information on where to seek advice that the user can refer to.

[1694] This series of processes allows users to sense risks on the Internet in real time and receive appropriate warnings and countermeasures according to their emotional state.

[1695] The specific processing unit 290 transmits the result of the specific processing to the headset type terminal 314. In the headset type terminal 314, the control unit 46A causes the speaker 240 and the display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[1696] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[1697] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the headset type terminal 314.

[1698] [Fourth embodiment]

[1699] FIG. 7 shows an example of the configuration of a data processing system 410 according to the fourth embodiment.

[1700] 7, a data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.

[1701] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[1702] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a control target 443. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the control target 443 are also connected to the bus 52.

[1703] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.

[1704] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[1705] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[1706] The control object 443 includes a display device, LEDs in the eyes, and motors for driving the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the emotions of the robot 414 can be expressed by controlling these motors. In addition, the facial expressions of the robot 414 can also be expressed by controlling the light emission state of the LEDs in the eyes of the robot 414.

[1707] Fig. 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Fig. 8, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[1708] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[1709] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[1710] In the robot 414, the processor 46 performs the reception output process. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[1711] Next, a description will be given of the specific processing performed by the specific processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1712] Overall system overview

[1713] This invention is a system that monitors users' online behavior, predicts the risk of crime or harm, and issues a warning. This system aims to prevent users from unwittingly becoming involved in risks, and even if they do intentionally become involved, it aims to have a deterrent effect by making them understand the risks.

[1714] System Configuration

[1715] The system mainly consists of the following elements:

[1716] 1. Terminal: The device through which a user accesses the Internet (e.g., a computer or smartphone).

[1717] 2. Server: The core part of the system that collects and analyzes behavioral data and predicts and notifies users of risks.

[1718] 3. Database: Stores information such as known fraudulent URLs and dangerous keywords.

[1719] Program processing overview

[1720] 1. Data Collection

[1721] User:

[1722] Users use the terminal to access the Internet and perform searches, web browsing, and writing.

[1723] Device:

[1724] The device captures user behavior data (e.g., search keywords, accessed URLs, and posted content) in real time.

[1725] Send the captured data to the server.

[1726] 2. Data analysis and risk prediction

[1727] server:

[1728] The server quickly analyzes the received behavioral data, specifically preprocessing it using machine learning algorithms to extract features.

[1729] A risk score is calculated based on the extracted features and compared with a specific threshold.

[1730] If the risk score exceeds a threshold, the type of risk (e.g., phishing scam, malware) is identified.

[1731] 3. Generating and Displaying Warning Messages

[1732] server:

[1733] The server generates appropriate warning messages based on the detected risks.

[1734] If necessary, additional information will be generated about the type of crime involved, past victimization cases, and ways to avoid it.

[1735] Device:

[1736] The terminal displays the warning message received from the server to the user.

[1737] 4. Providing consultation information and guidelines

[1738] server:

[1739] Depending on the detected risk, the server generates information about contact points (e.g., consumer centers, police) for the user to contact.

[1740] Provide specific guidelines for users to take to avoid risks (e.g., do not click on URLs or enter personal information).

[1741] Device:

[1742] The device displays this information to the user in an easy-to-understand manner, encouraging immediate action.

[1743] Specific examples

[1744] Phishing detection and prevention

[1745] User:

[1746] A user attempts to access an internet shopping site, but it is actually a phishing site.

[1747] Device:

[1748] The device captures the accessed URL and sends it to the server.

[1749] server:

[1750] The server checks the received URL against a list of known dangerous URLs in a database in real time.

[1751] If a URL is detected as a phishing site, it is determined to be at high risk of phishing and a risk score is calculated.

[1752] Generate a phishing warning message because the risk score exceeds a threshold.

[1753] Device:

[1754] The device will display a warning message to the user saying, "This site may be a phishing scam. Do not enter any personal information."

[1755] server:

[1756] The server generates contact information for consumer centers and police and provides instructions such as "Click here for more information."

[1757] User:

[1758] Users should check the warning message, recognize that it is a fraudulent site, and avoid entering personal information.

[1759] This system allows users to understand the risks on the Internet and provides them with concrete steps to use it safely.

[1760] The processing flow will be explained below.

[1761] Step 1:

[1762] User: A user uses an internet browser to access a particular website or enters a search keyword on the internet.

[1763] Step 2:

[1764] Device: The device captures the user's search keywords and the URLs of the websites they visit in real time.

[1765] Step 3:

[1766] Terminal: Sends the captured behavioral data to the server through a specified endpoint.

[1767] Step 4:

[1768] Server: The server temporarily stores the received behavioral data and performs data cleaning, specifically removing unnecessary tags and special characters and converting it into an analyzable format.

[1769] Step 5:

[1770] Server: After data cleaning is complete, features (e.g., specific keywords, domains of accessed URLs, etc.) are extracted from user behavior data.

[1771] Step 6:

[1772] Server: Calculates a risk score based on the extracted features. Here, an existing machine learning model is used to predict the risk score.

[1773] Step 7:

[1774] Server: Evaluates whether the risk score exceeds a pre-set threshold.

[1775] Step 8:

[1776] Server: If the score exceeds a threshold, identify the appropriate risk category (e.g., phishing, malware).

[1777] Step 9:

[1778] Server: Generate appropriate warning messages based on the identified risk categories, e.g. "This site may be a phishing scam. Do not enter any personal information."

[1779] Step 10:

[1780] Server: Generate additional information about past exploits and mitigation strategies, if necessary.

[1781] Step 11:

[1782] Server: Sends generated warning messages and additional information to the device.

[1783] Step 12:

[1784] Terminal: Received warning messages are displayed to the user. Warning messages are displayed in a popup format to make them more visible to the user.

[1785] Step 13:

[1786] Server: Depending on the risk, it generates appropriate contact information for the user to contact (e.g., consumer center or police) and sends this information to the terminal.

[1787] Step 14:

[1788] Device: Along with the provided consultation information, detailed guidelines for action (e.g., do not click on URLs, do not enter personal information) are displayed to the user.

[1789] Step 15:

[1790] Users: Users can review the displayed warning messages and additional information and take appropriate measures to reduce the risk of becoming involved in crime or victimization.

[1791] Example 1

[1792] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1793] Conventional Internet security systems have difficulty preventing damage caused by users unknowingly visiting high-risk websites or entering fraudulent information. Even when risks are detected, they lack mechanisms for providing users with immediate, specific warnings or guidelines for action. This makes it difficult for users to predict the risk of online crime and harm and take concrete measures.

[1794] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[1795] In this invention, the server includes a means for collecting user behavioral data, a means for analyzing the collected behavioral data in real time, performing preprocessing and feature extraction, and a means for calculating a risk score from the analysis results and comparing the score with a specific threshold. This makes it possible to immediately identify risks based on the user's behavioral data and provide appropriate warnings to the user. Furthermore, if a risk is detected, additional information on the type of crime and how to avoid it, as well as information on where to seek advice, can be provided, allowing the user to obtain specific guidelines for using the Internet safely.

[1796] "User behavioral data" refers to digital activities such as search keywords used by users on the Internet, URLs accessed, and content posted.

[1797] "Real-time analysis" refers to the process of processing data and obtaining results immediately at the moment the data is generated.

[1798] "Preprocessing" refers to early stages of data processing, such as data cleansing and normalization, to convert raw data into an analyzable format.

[1799] "Feature extraction" refers to the process by which machine learning algorithms find important attributes and patterns in data.

[1800] A "risk score" is a numerical representation of the likelihood of crime or victimization based on a user's behavioral data.

[1801] A "threshold" refers to a reference value that a risk score must exceed before a specific action is triggered.

[1802] A "warning message" refers to a notification that notifies the user of an increased risk and urges caution.

[1803] "Additional information" refers to information including past cases of damage related to the detected risk and specific methods of avoiding it.

[1804] "Consultation information" refers to contact information for consumer centers, police, etc. that users can contact when they become aware of a risk.

[1805] "Risk types" specifically refer to categories of phishing, malware, and other cybercrime.

[1806] "Specific guidelines for action" refer to specific actions that should be taken to protect users from risks (e.g., not clicking on URLs, not entering personal information).

[1807] Overall system overview

[1808] This invention is a system that monitors users' online behavior, predicts the risk of crime or harm, and issues a warning. This system aims to prevent users from unwittingly becoming involved in risks, and even if they do intentionally become involved, it aims to have a deterrent effect by making them understand the risks.

[1809] System configuration

[1810] The system consists of the following main elements:

[1811] 1. Terminal: A device (e.g., PC, smartphone) that a user uses to access the Internet.

[1812] 2. Server: This is the core part of the system that collects and analyzes behavioral data and predicts and notifies users of risks.

[1813] 3. Database: Stores information such as known fraudulent URLs and dangerous keywords.

[1814] Data collection

[1815] User:

[1816] Users use the terminal to access the Internet and perform searches, web browsing, and writing.

[1817] Device:

[1818] The device captures user behavior data (e.g., search keywords, URLs accessed, and posted content) in real time, and the captured data is sent to the server.

[1819] Data analysis and risk prediction

[1820] server:

[1821] The server quickly analyzes the behavioral data received from the device. Specifically, it preprocesses the data using a machine learning algorithm (e.g., TensorFlow) and extracts features. It calculates a risk score based on the extracted features and compares the score with a specific threshold. If the risk score exceeds the threshold, it identifies the type of risk (e.g., phishing scam, malware).

[1822] Generate and display warning messages

[1823] server:

[1824] The server generates appropriate warning messages based on the detected risks, and, if necessary, provides additional information about the type of crime, past victim cases, and how to avoid them.

[1825] Device:

[1826] The terminal displays the warning message received from the server to the user.

[1827] Providing consultation information and guidelines

[1828] server:

[1829] Depending on the detected risk, the server generates contact information for the user to contact (e.g., consumer center, police), and provides specific guidelines for the user to take to avoid the risk (e.g., do not click on URLs, do not enter personal information).

[1830] Device:

[1831] The device displays this information to the user in an easy-to-understand manner, encouraging immediate action.

[1832] Specific examples

[1833] Phishing detection and prevention

[1834] User:

[1835] A user attempts to access an internet shopping site, but it is actually a phishing site.

[1836] Device:

[1837] The device captures the accessed URL and sends it to the server.

[1838] server:

[1839] The server checks the received URL against a list of known dangerous URLs in a database in real time. If the URL is detected as a phishing site, it determines that there is a high risk of phishing and calculates a risk score. If the risk score exceeds a threshold, a phishing warning message is generated.

[1840] Device:

[1841] The device will display a warning message to the user saying, "This site may be a phishing scam. Do not enter any personal information."

[1842] server:

[1843] The server generates contact information for consumer centers and police and provides instructions such as "Click here for more information."

[1844] User:

[1845] Users can view the warning message, recognize that the site is fraudulent, and avoid entering personal information. This system helps users understand the risks of using the Internet and provides concrete steps to stay safe.

[1846] Prompt Sentence Examples

[1847] Here are some example prompts to input to the generative AI model:

[1848] Explain the program flow that generates a warning message and alerts the user when they try to access a phishing site.

[1849] This allows you to understand the processing flow and operation of a specific program.

[1850] The flow of the identification process in the first embodiment will be described with reference to FIG.

[1851] Step 1:

[1852] User:

[1853] Users access the Internet using devices such as computers and smartphones to browse various websites, search for information using search engines, and post on message boards.

[1854] input:

[1855] User web browsing and search behavior data (e.g., search keywords, access URLs, and posted content)

[1856] Device:

[1857] The device captures this behavioral data in real time, encrypts it, and sends it to a server.

[1858] output:

[1859] Encrypted behavioral data

[1860] Specific behavior:

[1861] The device captures the information entered by the user in real time, encrypts it to prevent information leakage, and then transmits the encrypted data to the server.

[1862] Step 2:

[1863] server:

[1864] The server decrypts the encrypted behavioral data received from the device and performs preprocessing on the data, which involves removing noise data and standardizing the data format.

[1865] input:

[1866] Encrypted behavioral data

[1867] Specific behavior:

[1868] The server decrypts the received data, removes unnecessary and duplicate data, and converts it into a format suitable for analysis.

[1869] output:

[1870] Preprocessed behavioral data

[1871] Step 3:

[1872] server:

[1873] The server uses machine learning algorithms (e.g., TensorFlow) to extract features from the preprocessed behavioral data and calculates a risk score, which is then compared with a specific threshold.

[1874] input:

[1875] Preprocessed behavioral data

[1876] Specific behavior:

[1877] The server uses machine learning models to extract key features from the data, calculates a risk score based on them, and compares the result with a pre-defined threshold.

[1878] output:

[1879] Risk score (number)

[1880] Step 4:

[1881] server:

[1882] If the risk score exceeds a threshold, the server identifies the type of risk (e.g., phishing scam, malware) and generates an appropriate warning message.

[1883] input:

[1884] Risk Score

[1885] Specific behavior:

[1886] The server checks whether the risk score exceeds a threshold and generates an appropriate warning message based on pre-defined rules. For example, if it is a phishing scam, it creates a message such as "This site may be a phishing scam. Do not enter personal information."

[1887] output:

[1888] Warning message

[1889] Step 5:

[1890] Device:

[1891] The terminal displays the warning message received from the server to the user, and depending on the content of the warning message, it may suspend the user's operation.

[1892] input:

[1893] Warning message

[1894] Specific behavior:

[1895] The device immediately displays the warning message received from the server to the user, allowing the user to recognize the risk and blocking the user's operation if necessary.

[1896] output:

[1897] The warning message displayed to the user

[1898] Step 6:

[1899] server:

[1900] The server generates information on where to contact for advice depending on the risk (e.g., consumer centers, police) and provides specific guidelines for action (e.g., do not click on URLs, do not enter personal information).

[1901] input:

[1902] Types of Risk

[1903] Specific behavior:

[1904] The server generates appropriate information on where to contact for advice and a course of action based on the type of risk, and notifies the user. For example, it includes specific instructions such as "Here is the link to contact the consumer center."

[1905] output:

[1906] Consultation information and guidelines

[1907] Step 7:

[1908] Device:

[1909] The device displays this information on consultation points and guidelines for action in an easy-to-understand manner to the user, encouraging them to take immediate action.

[1910] input:

[1911] Consultation information and guidelines

[1912] Specific behavior:

[1913] The device displays specific guidelines for risk avoidance to the user, and provides an interface that allows them to access consultation services with one click if necessary.

[1914] output:

[1915] Consultation information and guidelines displayed to the user

[1916] (Application example 1)

[1917] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1918] Currently, Internet users are often unknowingly exposed to risks such as phishing scams and malware. Furthermore, there are currently insufficient systems in place to predict and provide early warnings when certain high-risk behaviors are involved. As a result, users are more likely to become victims of crime and are required to respond after the fact. Furthermore, it is currently difficult to learn about the risks involved, find specific ways to avoid them, or find information on where to seek advice. There is a need to solve these problems and provide an environment in which users can use the Internet safely and with peace of mind.

[1919] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[1920] In this invention, the server includes: means for collecting user behavioral data; means for analyzing the collected behavioral data in real time and predicting the risk of crime and victimization; means for displaying a warning message to the user based on the predicted risk; means for providing information on the type of crime and how to avoid it; means for providing the user with information on where to seek advice; means for determining in real time whether a specific user behavior poses a risk; and means for generating and providing a specific warning message to the user based on a risk score if the risk meets certain conditions. This allows users to recognize potential risks on the Internet in advance and take early action. Furthermore, providing appropriate information on where to seek advice and specific ways to avoid them further ensures user safety.

[1921] "User behavior data" is a general term for data such as search keywords, URLs accessed, and content posted by users on the Internet.

[1922] The "means for collecting" is a function for capturing user behavior data in real time and transmitting it to a server.

[1923] "Real-time analysis means" refers to an analytical function that instantly processes collected behavioral data and assesses risk.

[1924] "Predictive means" is a function that detects the risk of crime or harm that may occur in the future based on analyzed data.

[1925] The "means for displaying a warning message" is a function for visually presenting a message to inform the user of a risk.

[1926] The "means for providing information on the types of crimes that may occur and how to avoid them" is a function for conveying to the user information on the types of crimes that may occur and how to avoid them in response to detected risks.

[1927] The "means for providing information on where to contact for consultation" is a function for providing information on appropriate organizations and support desks that users should contact when a risk is detected.

[1928] "A means for determining in real time whether a particular action will pose a risk" is a function that instantly evaluates whether an action involves a risk each time a user takes an action.

[1929] "Means for generating a specific warning message based on the risk score and providing it to the user" is a function for quantifying the degree of risk, creating a detailed warning message based on that score, and conveying it to the user.

[1930] The embodiments of the present invention will be described in detail below.

[1931] Overall system configuration

[1932] This invention is a system that monitors users' online behavior, predicts the risk of crime or harm, and issues warnings. The system consists of a user device (terminal) and a server. The terminal captures user behavior data and sends it to the server. The server analyzes the data, predicts risks, generates warning messages, sends them to the terminal, and displays them to the user.

[1933] Hardware and software used

[1934] Device: A user device such as a smartphone, computer, or tablet.

[1935] Server: A central system that collects and analyzes data and generates warning messages, etc.

[1936] Software: The programming language Python and the library requests for sending HTTP requests are used.

[1937] Data collection

[1938] The device captures real-time behavioral data such as search keywords, URLs accessed, and posted content when a user searches online. This data is sent to a server when a certain amount of data is reached or a specific event occurs.

[1939] Data analysis and risk prediction

[1940] The server rapidly analyzes the received behavioral data using machine learning algorithms to preprocess the data and extract features, and then calculates a risk score based on the data and compares it with a specific threshold.

[1941] Determining risks and generating warning messages

[1942] If the risk score exceeds a certain threshold, the server identifies the type of risk and generates a specific warning message, which is then sent to the terminal in a user-friendly format and displayed to the user.

[1943] Specific examples

[1944] For example, if a user searches for "buy cheap medicines," the server analyzes the search keywords and detects the risk of accessing a fraudulent website selling cheap medicines. Also, if a user accesses the URL http: / / phishing.example.com, the server detects the risk of phishing and immediately displays a warning message.

[1945] Prompt Sentence Examples

[1946] Prompt your generative AI model with the following prompt:

[1947] "Monitor user behavior and calculate a risk score based on the following data:

[1948] Search keywords: 'buy cheap medicines', 'free crypto wallet'

[1949] Access URL: 'http: / / phishing.example.com', 'http: / / scam.example.com'"

[1950] This will realize a system that allows users to always ensure safety on the Internet and quickly take necessary measures.

[1951] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[1952] Step 1:

[1953] The device collects user behavior data. Specifically, it captures the keywords the user searches for, the URLs they access, and the content they post in real time. This data is temporarily stored on the device as session data.

[1954] Input: User search keywords, access URL, and post content

[1955] Output: Captured behavioral data

[1956] Step 2:

[1957] The device sends behavioral data to the server using an HTTP request when a certain amount of behavioral data has been collected or when a specific event occurs.

[1958] Input: Captured behavioral data

[1959] Output: Behavioral data sent to the server

[1960] Step 3:

[1961] The server analyzes the received data. First, it preprocesses the data using a machine learning algorithm and extracts features.

[1962] Input: Submitted behavioral data

[1963] Output: Extracted features

[1964] Step 4:

[1965] The server calculates a risk score based on the extracted features, using a pre-trained generative AI model.

[1966] Input: extracted features

[1967] Output: Calculated risk score

[1968] Step 5:

[1969] The server determines whether the risk score exceeds a certain threshold, and if so, identifies the type of risk (e.g., phishing, malware).

[1970] Input: Calculated risk score

[1971] Output: Identified risk types

[1972] Step 6:

[1973] The server generates a specific warning message based on the type of risk, including the type of crime, past victim cases, and how to avoid it.

[1974] Input: Type of risk identified

[1975] Output: Generated warning message

[1976] Step 7:

[1977] The server transmits the generated warning message and information on where to contact for advice to the terminal.

[1978] Input: Generated warning message, contact information

[1979] Output: Message sent to terminal

[1980] Step 8:

[1981] The device will then display the received warning message and information on where to contact for help to the user, who can then check the information on the screen and take appropriate measures.

[1982] Input: Warning message sent from the server, consultation information

[1983] Output: Displaying information to the user

[1984] This processing flow realizes a system in which user behavior data is monitored and analyzed in real time, and an immediate warning is issued if a risk is detected.

[1985] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.

[1986] Overall system overview

[1987] This invention combines an emotion engine with a system that monitors users' online behavior, predicts the risk of crime or harm, and issues warnings. The system aims to prevent users from unwittingly becoming involved in risks, and even if they do intentionally become involved, to help them understand the risks and provide appropriate responses by taking into account the user's emotional state.

[1988] System Configuration

[1989] The system mainly consists of the following elements:

[1990] 1. Terminal: The device through which a user accesses the Internet (e.g., a computer or smartphone).

[1991] 2. Server: The core part of the system that collects and analyzes behavioral and emotional data, and predicts and notifies users of risks.

[1992] 3. Database: Storage for known fraudulent URLs, dangerous keywords, and sentiment data.

[1993] Program processing overview

[1994] 1. Data Collection

[1995] User:

[1996] Users use the terminal to access the Internet and perform searches, web browsing, and writing.

[1997] Device:

[1998] The device captures user behavior data (e.g., search keywords, accessed URLs, and posted content) in real time.

[1999] The device also uses a camera and microphone to capture emotional data from the user's facial expressions and tone of voice.

[2000] Send the captured data to the server.

[2001] 2. Data analysis and risk prediction

[2002] server:

[2003] The server quickly analyzes the received behavioral and emotional data, preprocessing the data using machine learning algorithms to extract features.

[2004] A risk score is calculated based on the extracted features and compared with a specific threshold.

[2005] If the risk score exceeds a threshold, the type of risk (e.g., phishing scam, malware) is identified.

[2006] 3. Emotional data analysis and response adjustment

[2007] server:

[2008] The server analyzes the emotion data to determine the user's current emotional state (e.g., anxiety, fear, joy).

[2009] It adjusts the content and presentation of warning messages based on the user's emotional state, for example, displaying more detailed explanations and a gentler tone of voice if the user is feeling anxious.

[2010] 4. Generating and Displaying Warning Messages

[2011] server:

[2012] The server generates appropriate warning messages based on the detected risks.

[2013] If necessary, additional information will be generated about the type of crime involved, past victimization cases, and ways to avoid it.

[2014] Device:

[2015] The terminal displays the warning message received from the server to the user, and the displayed message is adjusted according to the user's emotional state.

[2016] 5. Providing consultation information and guidelines

[2017] server:

[2018] Depending on the detected risk, the server generates information about contact points (e.g., consumer centers, police) for the user to contact.

[2019] Provide specific guidelines for users to take to avoid risks (e.g., do not click on URLs or enter personal information).

[2020] The display order and content of the information is adjusted according to the user's emotions.

[2021] Device:

[2022] The device displays this information to the user in an easy-to-understand manner, encouraging immediate action.

[2023] Specific examples

[2024] Phishing detection and prevention

[2025] User:

[2026] A user attempts to access an internet shopping site, but it is actually a phishing site.

[2027] Device:

[2028] The device captures the accessed URL and sends it to the server.

[2029] At the same time, the device captures the user's facial expressions with a camera and collects emotional data from voice tones.

[2030] server:

[2031] The server checks the received URL against a list of known dangerous URLs in a database in real time.

[2032] If a URL is detected as a phishing site, it is determined to be at high risk of phishing and a risk score is calculated.

[2033] Generate a phishing warning message because the risk score exceeds a threshold.

[2034] The server analyzes the user's emotional data and recognizes that the user is feeling anxious, and generates a warning message with detailed explanation and a gentle tone.

[2035] Device:

[2036] The device will display a warning message to the user saying, "This site may be a phishing scam. Do not enter any personal information."

[2037] server:

[2038] The server generates contact information for consumer centers and police and provides instructions such as "Click here for more information."

[2039] The server takes into consideration that the user is feeling strong anxiety and displays emergency consultation information with priority.

[2040] User:

[2041] Users should check the warning message, recognize that it is a fraudulent site, avoid entering personal information, and refer to emergency consultation information to take appropriate measures.

[2042] This system allows users to understand the risks on the Internet, provides concrete measures for safe use, and allows them to receive responses that take their emotional state into consideration.

[2043] The processing flow will be explained below.

[2044] Step 1:

[2045] User: A user uses an internet browser to access a particular website or enters a search keyword on the internet.

[2046] Step 2:

[2047] Device: The device captures the user's search keywords and the URLs of the websites they visit in real time.

[2048] Step 3:

[2049] On-device: Use the device's camera and microphone to capture emotional data from the user's facial expressions, tone of voice, and more.

[2050] Step 4:

[2051] Terminal: Sends the captured behavioral and emotional data to the server through a designated endpoint.

[2052] Step 5:

[2053] Server: The server stores the received behavioral and emotional data and performs data cleaning, removing unnecessary tags and special characters, and converting it into an analyzable format.

[2054] Step 6:

[2055] Server: After data cleaning is complete, features (e.g., specific keywords, domains of accessed URLs, changes in facial expressions, tone of voice, etc.) are extracted from the user's behavioral and emotional data.

[2056] Step 7:

[2057] Server: Calculates a risk score based on the extracted features. Here, an existing machine learning model is used to predict the risk score.

[2058] Step 8:

[2059] Server: Evaluates whether the risk score exceeds a pre-set threshold.

[2060] Step 9:

[2061] Server: If the score exceeds a threshold, identify the appropriate risk category (e.g., phishing, malware).

[2062] Step 10:

[2063] Server: Analyzes the user's emotional data and determines the user's current emotional state (e.g., anxiety, fear, joy).

[2064] Step 11:

[2065] Server: Adjust the content and presentation of warning messages based on the user's emotional state. For example, if the user is feeling anxious, display a more detailed message with a gentler tone.

[2066] Step 12:

[2067] Server: Generates a tailored warning message, such as "This site may be a phishing scam. Do not enter any personal information."

[2068] Step 13:

[2069] Server: Generates additional information about the type of crime, past victimization, and prevention methods, if necessary.

[2070] Step 14:

[2071] Server: Sends generated warning messages and additional information to the device.

[2072] Step 15:

[2073] Terminal: The received warning message is displayed to the user. The displayed message is adjusted according to the user's emotional state and presented in a pop-up format.

[2074] Step 16:

[2075] Server: Depending on the risk, generates appropriate contact information for the user to contact (e.g. consumer center, police) and sends this information to the terminal.

[2076] Step 17:

[2077] Device: Along with the provided consultation information, detailed guidelines for action (e.g., do not click on URLs, do not enter personal information) are displayed to the user.

[2078] Step 18:

[2079] Users: Users can review the displayed warning messages and additional information and take appropriate measures to reduce the risk of becoming involved in crime or victimization. Because the user's emotional state is taken into consideration, they can respond with greater peace of mind.

[2080] Example 2

[2081] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[2082] With the spread of the Internet, users have gained access to a wide variety of information and services, but at the same time, they are being asked to respond appropriately to the increasing risks of online fraud and malware. However, current systems only provide uniform risk warnings to users and do not take into account their emotional state, which often prevents them from taking effective risk avoidance actions. In addition, due to insufficient calculation of risk scores and identification of risk types, there is a lack of information provided to users to enable them to take specific countermeasures. There is a need to solve these issues.

[2083] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.

[2084] In this invention, the server includes means for analyzing user behavioral data and emotional data in real time to predict the risk of crime and victimization, means for displaying a warning message to the user based on the predicted risk, and means for adjusting the content and display method of the warning message based on the user's emotional state, thereby making it possible to provide appropriate warnings and specific risk avoidance information according to the user's emotional state.

[2085] "User behavior data" refers to information such as search keywords, URLs accessed, and content posted by users on the Internet.

[2086] "Emotion data" is information that indicates the emotional state of the user, which can be obtained from facial expressions, tone of voice, and the like.

[2087] "Real-time analysis" means processing and analyzing data immediately as it is captured.

[2088] "Predicting the risk of crime and victimization" means assessing the likelihood that a user will be involved in a crime or victimization based on collected data.

[2089] "Displaying a warning message" means displaying a warning or alert to the user on the screen based on the predicted risk.

[2090] "Applicable crime type" refers to the specific crime category associated with the predicted risk (e.g., phishing scams or malware infections).

[2091] "Avoidance methods" is information that indicates specific actions or steps that a user should take to avoid a predicted risk.

[2092] "Consultation information" is contact information for organizations or institutions that users can contact or consult with if they are facing a risk.

[2093] "Emotional state" refers to the psychological or emotional state (e.g., anxiety, fear, joy) that a user expresses through a camera or microphone.

[2094] MODE FOR CARRYING OUT THE INVENTION

[2095] Overall system overview

[2096] This invention combines an emotion engine with a system that monitors users' online behavior, predicts the risk of crime or harm, and issues warnings. The system aims to prevent users from unwittingly becoming involved in risks, and even if they do intentionally become involved, to help them understand the risks and provide appropriate responses by taking into account the user's emotional state.

[2097] System Configuration

[2098] The system mainly consists of the following elements:

[2099] 1. Device: A device (e.g., a PC or smartphone) that allows a user to access the Internet. The device captures the user's behavioral and emotional data and transmits it to a server.

[2100] 2. Server: This is the core part of the system that collects and analyzes behavioral and emotional data, and predicts and notifies risks. The server analyzes the data using machine learning algorithms and deep learning models.

[2101] 3. Database: Storage for known fraudulent URLs, dangerous keywords, and sentiment data.

[2102] Hardware and Software

[2103] Device: The user's computer, smartphone, etc.

[2104] Camera and microphone: Devices for capturing your facial expressions and tone of voice.

[2105] Server: A high-performance data processing server is used, which uses Python, the pandas library, the scikit-learn library, OpenCV, and deep learning models for data processing.

[2106] Specific examples

[2107] Below is a specific example of how this system can be used.

[2108] Example: Phishing detection and countermeasures

[2109] User: A user attempts to access an internet shopping site, but it is actually a phishing site.

[2110] Device: The device captures the accessed URL and sends it to the server. It also captures the user's facial expressions with a camera and collects emotional data from voice tones.

[2111] server:

[2112] Incoming URLs are checked against a list of known dangerous URLs in a database in real time.

[2113] When a URL is detected as a phishing site, a risk score is calculated and a phishing warning message is generated if the risk score exceeds a threshold.

[2114] It analyzes emotional data, recognizes when the user is feeling anxious, and generates a warning message with detailed explanation and a gentle tone based on this.

[2115] Device: Show the user the warning message "This site may be a phishing scam. Do not enter any personal information."

[2116] Server: Generates contact information for consumer centers and police, and provides instructions such as "Click here for more information." If the user is feeling very anxious, the server prioritizes displaying emergency consultation information.

[2117] Users: Check the warning message, recognize that it is a fraudulent site, avoid entering personal information, and refer to the emergency contact information to take appropriate measures.

[2118] Prompt Sentence Examples

[2119] "The system detected a fraud risk. Please check the user data and risk score. Then generate a warning message and notify the user with an appropriate tone based on the sentiment data."

[2120] The flow of the identification process in the second embodiment will be described with reference to FIG.

[2121] System program processing flow

[2122] Step 1: Data collection

[2123] Step 1.1: Capture behavioral data

[2124] Device: The device captures the search keywords, URLs accessed, and postings made by users on the Internet in real time. For example, when a user visits a shopping site, the device captures the URL and saves it as a user operation log.

[2125] Input: User search keywords, access URL, and post content

[2126] Output: Captured behavioral data

[2127] Step 1.2: Capturing emotion data

[2128] On the device: Using a camera and microphone, emotional data is captured from the user's facial expressions and tone of voice. For example, if the user smiles at the camera, that facial expression data is captured in real time.

[2129] Input: User's facial expression, tone of voice

[2130] Output: Captured emotion data

[2131] Step 1.3: Send data

[2132] Device: The device sends the captured behavioral and emotional data to the server. The data is encrypted using SSL / TLS protocol during transmission to ensure security.

[2133] Input: Captured behavioral data, emotion data

[2134] Output: Data sent to the server

[2135] Step 2: Data analysis and risk prediction

[2136] Step 2.1: Data Preprocessing

[2137] Server: The server preprocesses the received behavioral and emotional data. Specifically, it cleans the data, fills in missing data, and removes noise. This process uses the Python pandas library.

[2138] Input: Received behavioral data, emotion data

[2139] Output: Preprocessed data

[2140] Step 2.2: Feature extraction

[2141] Server: The server extracts features from the preprocessed data. For example, it extracts the frequency of search keywords or patterns of accessed URLs. In this case, it uses the scikit-learn library to perform feature extraction.

[2142] Input: Preprocessed data

[2143] Output: Features

[2144] Step 2.3: Risk Score Calculation

[2145] Server: The server calculates a risk score based on the extracted features, for example, using a machine learning model such as a random forest or a support vector machine, and compares it with a specific threshold.

[2146] Input: Features

[2147] Output: Risk score

[2148] Step 2.4: Identify risk types

[2149] Server: If the risk score exceeds a threshold, the server identifies the type of risk (e.g., phishing, malware), consulting a database of known dangerous URLs and fraud patterns.

[2150] Input: Risk Score

[2151] Output: Risk type

[2152] Step 3: Analyze emotion data and adjust responses

[2153] Step 3.1: Emotion determination

[2154] Server: The server analyzes the received emotion data and determines the user's current emotional state. For example, if the user is frowning, it determines that they are feeling anxious. For emotion analysis, it uses OpenCV and a deep learning model for emotion recognition.

[2155] Input: Emotion data

[2156] Output: User's emotional state

[2157] Step 3.2: Adjust the warning message

[2158] Server: The server adjusts the content and presentation of the warning message based on the user's emotional state. For example, if the user is feeling anxious, it generates a gentle, detailed message such as "This site may be a phishing scam. Please be careful."

[2159] Input: Risk type, user emotional state

[2160] Output: Adjusted warning message

[2161] Step 4: Generate and display warning messages

[2162] Step 4.1: Generate a warning message

[2163] Server: The server generates appropriate warning messages based on the detected risks, adding specific information about the type of fraud, past victim cases, and how to avoid them.

[2164] Input: Risk type, user emotional state

[2165] Output: Warning message

[2166] Step 4.2: Send the message

[2167] Server: Generates and sends a warning message to the device. This message is adapted according to the user's emotional state.

[2168] Input: warning message

[2169] Output: Message sent to the terminal

[2170] Step 4.3: Displaying a warning message

[2171] On the device: Display the warning message received from the server to the user. For example, if a risk of a phishing site is detected, the message "This site may be a phishing scam. Do not enter personal information." will be displayed.

[2172] Input: Message sent to terminal

[2173] Output: The warning message displayed to the user.

[2174] Step 5: Providing consultation information and guidelines

[2175] Step 5.1: Generate consultation information

[2176] Server: Depending on the detected risk, the server generates contact information for consumer centers, police, etc. For example, it provides specific contact information such as "Here is the phone number for the consumer center."

[2177] Input: Risk type, user emotional state

[2178] Output: Consultation information

[2179] Step 5.2: Provide guidelines for action

[2180] Server: Generates specific guidelines for users to follow to avoid risks, such as "Do not click on unknown URLs" or "Do not enter personal information."

[2181] Input: Risk type, user emotional state

[2182] Output: Action Guidelines

[2183] Step 5.3: Display Information

[2184] Terminal: The generated consultation information and action guidelines are displayed to the user in an easy-to-understand manner. For example, a message such as "Here is the phone number for the consumer center. Please contact us immediately" is displayed to encourage immediate action.

[2185] Input: Consultation information, guidelines

[2186] Output: Information displayed to the user

[2187] (Application example 2)

[2188] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[2189] Current security systems can monitor users' online behavioral data and predict risks, but they lack mechanisms for providing appropriate warnings and responses that take the user's emotional state into account. As a result, when users feel anxious, they may not receive appropriate warnings at the right time, and may not be able to fully avoid risks. To solve this problem, a security system that takes the user's emotional state into account is needed.

[2190] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for collecting user behavioral data, means for analyzing the collected behavioral data in real time and predicting the risk of crime and victimization, means for collecting emotional data from the user's facial expressions and voice tone, and means for analyzing the collected emotional data and adjusting the content of a warning message according to the user's emotional state. This makes it possible for a user to receive appropriate warnings and responses according to their emotional state when they face risks on the Internet.

[2191] "User behavior data" refers to information such as search keywords, URLs accessed, and content posted by users on the Internet.

[2192] "Analyzing in real time" means processing collected data instantly and performing operations to obtain results immediately.

[2193] "Risk of crime and harm" refers to illegal activities such as fraud, phishing, and malware, and the harm that may result from them.

[2194] "Warning message" means a notification to inform the user of a risk and urge caution.

[2195] "Emotional data" refers to the emotional state (e.g., anxiety, fear, joy) that can be read from the user's facial expression or tone of voice.

[2196] "Collection methods" refers to the devices and software used to collect user behavioral and emotional data.

[2197] "Analysis means" refers to the algorithms and software used to process collected data and extract meaningful information.

[2198] "Facial expressions and vocal tone" refers to the user's facial movements and tone of voice, and are indicators for reading emotions from them.

[2199] "Adjusting means" refers to a method or function for changing the content of a warning message depending on the user's emotional state.

[2200] System Overview

[2201] This invention is a system that monitors users' online behavior, predicts the risk of crime and victimization, and provides warnings and responses based on their emotional state. The system achieves this by collecting and analyzing users' behavioral and emotional data.

[2202] Hardware and software used

[2203] Hardware: smartphone, camera, microphone

[2204] Software: Machine learning algorithms (e.g., Scikit-learn, TensorFlow), speech recognition libraries (e.g., speech_recognition), emotion recognition libraries (e.g., OpenCV).

[2205] Data collection

[2206] User:

[2207] A user uses a smartphone to access the Internet and perform searches, web browsing, writing, etc. The smartphone's camera and microphone capture the user's facial expressions and voice tone.

[2208] Device:

[2209] The device captures user behavior data (e.g., search keywords, URLs accessed, and posted content) in real time. The device also uses a camera and microphone to collect emotional data from the user's facial expressions and tone of voice. The collected data is then sent to a server.

[2210] Data analysis and risk prediction

[2211] server:

[2212] The server quickly analyzes the received behavioral and emotional data. It preprocesses the data using machine learning algorithms to extract features. It calculates a risk score based on the extracted features and compares it with a specific threshold. If the risk score exceeds the threshold, it identifies the type of risk (e.g., phishing scam, malware).

[2213] Emotion data analysis and response adjustment

[2214] server:

[2215] The server analyzes the emotion data to determine the user's current emotional state (e.g., anxiety, fear, joy). Based on the emotional state, the server adjusts the content and presentation of the warning message. For example, if the user is feeling anxious, the server displays a more detailed message with a gentler tone.

[2216] Generate and display warning messages

[2217] server:

[2218] Based on the detected risks, the server generates appropriate warning messages, and if necessary, additional information about the type of crime, past victim cases, and how to avoid them.

[2219] Device:

[2220] The terminal displays the warning message received from the server to the user, and the displayed message is adjusted according to the user's emotional state.

[2221] Specific examples

[2222] Phishing detection and prevention

[2223] User:

[2224] A user attempts to access an internet shopping site, but it is actually a phishing site.

[2225] Device:

[2226] The device captures the accessed URL and sends it to the server. At the same time, the device captures the user's facial expressions with a camera and collects emotional data from voice tones.

[2227] server:

[2228] The server checks the received URL against a list of known dangerous URLs in a database in real time. If the URL is detected as a phishing site, it determines that there is a high risk of phishing and calculates a risk score. If the risk score exceeds a threshold, it generates a phishing warning message. The server analyzes the user's emotional data and recognizes that the user is feeling anxious. Based on this, it generates a warning message with a detailed explanation and a gentle tone.

[2229] Device:

[2230] The device will display a warning message to the user saying, "This site may be a phishing scam. Do not enter any personal information."

[2231] server:

[2232] The server generates contact information for consumer centers and police and provides instructions such as "Click here for more information." Considering that the user is feeling very anxious, the server prioritizes displaying information for emergency consultations.

[2233] User:

[2234] Users should check the warning message, recognize that it is a fraudulent site, avoid entering personal information, and refer to emergency consultation information to take appropriate measures.

[2235] Prompt Sentence Examples

[2236] "Generate a risk assessment and warning message based on user behavior data: {'url': 'http: / / example-phishing-site.com'}, user emotion data: {'expression': 'neutral', 'voice_tone': 'calm'}."

[2237] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[2238] Step 1:

[2239] Users use smartphones to access the Internet and perform searches, web browsing, and writing. The smartphone's camera and microphone capture the user's facial expressions and voice tone. As input, Internet behavior data (e.g., search keywords and accessed URLs) and emotional data (e.g., facial expressions and voice tone) are collected. This data is used for further processing.

[2240] Step 2:

[2241] The device captures user behavior data (e.g., search keywords, accessed URLs, and posted content) in real time and predicts the risk of crime and victimization based on this. The input is user behavior data, specifically text data and URLs. To analyze it, a machine learning algorithm (e.g., Scikit-learn) is used to preprocess the data and extract features. A risk score is obtained as output. If the risk score exceeds a certain threshold, the type of risk (e.g., phishing scam, malware) is identified.

[2242] Step 3:

[2243] The device uses a camera and microphone to capture emotional data from the user's facial expressions and tone of voice in real time. Image and audio data are input, which are then analyzed through emotion recognition software (e.g., OpenCV, speech_recognition). The output is the user's emotional state (e.g., anxiety, joy, fear).

[2244] Step 4:

[2245] The server calculates a risk score based on the behavioral and emotional data it receives. The input is the behavioral and emotional data sent from the device. The server preprocesses the data using a machine learning algorithm (e.g., TensorFlow), extracts features, and calculates a risk score. The output is a risk score and the type of risk.

[2246] Step 5:

[2247] The server analyzes the emotion data to determine the user's current emotional state. The input is emotion data, which includes facial expression data and vocal tone. An emotion recognition algorithm is used for the analysis. The output is the user's emotional state (e.g., anxiety, fear, joy).

[2248] Step 6:

[2249] The server generates an appropriate warning message if the risk score exceeds a threshold. The inputs are the risk score, the type of risk, and the user's emotional state. Based on these data, the server creates the warning message using a text generation algorithm (e.g., a generative AI model). As an output, a customized warning message is generated.

[2250] Step 7:

[2251] The terminal displays the warning message received from the server to the user. The input is the generated warning message. The terminal displays the message to the user and optionally displays additional information (e.g., the type of crime, past victim cases, and how to avoid it). The output includes a fade-in warning message and a link for more information.

[2252] Step 8:

[2253] The server provides the user with guidelines for avoiding risk and information on where to seek advice. The input is an information request based on the type of risk and emotional state. The server provides the user with appropriate guidelines for avoiding risk (e.g., do not click on URLs, do not enter personal information) and information on where to seek advice (e.g., consumer centers, police). The output is specific guidelines for avoiding risk and information on where to seek advice that the user can refer to.

[2254] This series of processes allows users to sense risks on the Internet in real time and receive appropriate warnings and countermeasures according to their emotional state.

[2255] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the control target 443 to output the result of the specific processing. The microphone 238 acquires voice indicating a user input regarding the result of the specific processing. The control unit 46A transmits voice data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the voice data.

[2256] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[2257] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the robot 414.

[2258] The emotion identification model 59 as an emotion engine may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to an emotion map (see FIG. 9), which is a specific mapping. Similarly, the emotion identification model 59 may determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.

[2259] FIG. 9 is a diagram illustrating an emotion map 400 on which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. Emotions closer to the center of the concentric circles are more primitive. Emotions representing states and actions arising from a state of mind are arranged on the outer edges of the concentric circles. The concept of emotion includes both affect and mental states. Emotions generally generated from reactions occurring in the brain are arranged on the left side of the concentric circles. Emotions generally induced by situational judgment are arranged on the right side of the concentric circles. Emotions generally generated from reactions occurring in the brain and induced by situational judgment are arranged on the upper and lower sides of the concentric circles. Furthermore, the emotion of "pleasure" is arranged on the upper side of the concentric circles, and the emotion of "discomfort" is arranged on the lower side. In this way, in the emotion map 400, multiple emotions are mapped based on the structure by which emotions are generated, and emotions that tend to occur simultaneously are mapped close to each other.

[2260] These emotions are distributed in the 3 o'clock direction on emotion map 400, and typically fluctuate between relief and anxiety. In the right half of emotion map 400, situational awareness dominates over internal sensations, resulting in a sense of calm.

[2261] The inside of emotion map 400 represents what is going on in the mind, and the outside of emotion map 400 represents behavior, so the further you go outside emotion map 400, the more visible the emotions become (the more they are expressed in behavior).

[2262] Human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, a state of discomfort is indicated, and when they approach the ideal, a state of pleasure is indicated. Emotions can also be created for robots, automobiles, and motorcycles, based on various balances, such as posture and remaining battery life. When these balances deviate from the ideal, a state of discomfort is indicated, and when they approach the ideal, a state of pleasure is indicated. An emotion map can be generated, for example, based on Dr. Mitsuyoshi's emotion map (Research on Voice Emotion Recognition and Emotional Brain Physiological Signal Analysis Systems, Tokushima University, Doctoral Dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map lists emotions belonging to the "reaction" domain, where sensation is dominant. The right half of the emotion map lists emotions belonging to the "situation" domain, where situational awareness is dominant.

[2263] The emotion map defines two emotions that promote learning. One is a negative emotion on the situation side, around the middle of "repentance" or "reflection." In other words, this occurs when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is a positive emotion on the response side, around "desire." In other words, this occurs when the robot experiences positive feelings such as "I want more" or "I want to know more."

[2264] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values ​​indicating each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple pieces of training data that are combinations of user input and emotion values ​​indicating each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions that are located close to each other have similar values, as in the emotion map 900 shown in FIG. 10. FIG. 10 shows an example in which multiple emotions, "relieved," "calm," and "reassuring," have similar emotion values.

[2265] The system according to the present disclosure has been described above mainly with respect to the functions of the data processing device 12, but the system according to the present disclosure is not necessarily implemented on a server. The system according to the present disclosure may be implemented as a general information processing system. The present disclosure may be implemented, for example, as a software program running on a personal computer or an application running on a smartphone, etc. The method according to the present disclosure may be provided to users in the form of SaaS (Software as a Service).

[2266] In the above embodiment, an example was given in which the specific processing is performed by one computer 22, but the technology of the present disclosure is not limited to this, and the specific processing may be distributed and performed by a plurality of computers including the computer 22. For example, the data generation model 58 may be provided in an external device of the data processing device 12, and data may be generated in the external device in accordance with input data.

[2267] In the above embodiment, an example in which the specific processing program 56 is stored in the storage 32 has been described, but the technology of the present disclosure is not limited to this. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-transitory storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-transitory storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes the specific processing in accordance with the specific processing program 56.

[2268] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.

[2269] It is not necessary to store all of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store all of the specific processing program 56 in the storage 32; only a portion of the specific processing program 56 may be stored.

[2270] The hardware resource for executing a specific process can be any of the following processors: An example of a processor is a CPU, which is a general-purpose processor that functions as a hardware resource for executing a specific process by executing software, i.e., a program. Another example of a processor is a dedicated electrical circuit, such as an FPGA (Field-Programmable Gate Array), a PLD (Programmable Logic Device), or an ASIC (Application Specific Integrated Circuit), which is a processor with a circuit configuration designed specifically for executing a specific process. Each processor has built-in or connected memory, and each processor uses the memory to execute the specific process.

[2271] The hardware resource that executes the specific processing may be configured with one of these various processors, or may be configured with a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Also, the hardware resource that executes the specific processing may be a single processor.

[2272] As an example of a system configured with a single processor, first, one processor is configured by combining one or more CPUs and software, and this processor functions as a hardware resource that executes a specific process. Second, there is a system that uses a processor that realizes the functions of an entire system including multiple hardware resources that execute a specific process on a single IC chip, as typified by SoC (System-on-a-chip). In this way, a specific process is realized using one or more of the above-mentioned various processors as hardware resources.

[2273] Furthermore, the hardware structure of these various processors can be, more specifically, an electric circuit that combines circuit elements such as semiconductor devices. The specific processing described above is merely an example. Therefore, it goes without saying that unnecessary steps may be deleted, new steps may be added, or the processing order may be rearranged, without departing from the spirit of the invention.

[2274] The above-described description and illustrations are a detailed explanation of the parts related to the technology of the present disclosure and are merely an example of the technology of the present disclosure. For example, the above description of the configuration, functions, actions, and effects is an explanation of an example of the configuration, functions, actions, and effects of the parts related to the technology of the present disclosure. Therefore, it goes without saying that unnecessary parts may be deleted, new elements may be added, or replacements may be made to the above-described description and illustrations within the scope of the gist of the technology of the present disclosure. Furthermore, to avoid confusion and facilitate understanding of the parts related to the technology of the present disclosure, the above-described description and illustrations omit explanations of common technical knowledge that do not require particular explanation to enable the implementation of the technology of the present disclosure.

[2275] All publications, patent applications, and technical standards mentioned in this specification are herein incorporated by reference to the same extent as if each individual publication, patent application, or technical standard was specifically and individually indicated to be incorporated by reference.

[2276] The following is further disclosed regarding the above embodiment.

[2277] (Claim 1)

[2278] a means for collecting user behavior data;

[2279] A means of analyzing collected behavioral data in real time to predict the risk of crime and victimization;

[2280] means for displaying a warning message to a user based on the predicted risk;

[2281] means of providing information about the types of crimes involved and how to avoid them;

[2282] A means for providing consultation information to a user;

[2283] A system including:

[2284] (Claim 2)

[2285] 10. The system of claim 1, further comprising means for displaying the type of crime and past victimization cases when the predicted risk exceeds a certain threshold.

[2286] (Claim 3)

[2287] 10. The system of claim 1, further comprising means for classifying specific risk categories, such as fraud, phishing, or malware, from user behavioral data.

[2288] (Claim 4)

[2289] 10. The system of claim 1, further comprising means for suggesting links to trusted websites and safe actions.

[2290] (Claim 5)

[2291] 10. The system of claim 1, further comprising means for maintaining a list of known fraudulent URLs and dangerous keywords in a database and for matching in real time.

[2292] "Example 1"

[2293] (Claim 1)

[2294] a means for collecting user behavior data;

[2295] A means to analyze the collected behavioral data in real time, and perform preprocessing and feature extraction.

[2296] a means for calculating a risk score from the analysis results and comparing the score to a specified threshold;

[2297] a means for identifying the type of risk if the risk score exceeds a threshold;

[2298] means for displaying a warning message to a user based on the identified risk;

[2299] means for generating additional information regarding applicable crime types and methods of avoidance;

[2300] A means for providing consultation information to a user;

[2301] A system including:

[2302] (Claim 2)

[2303] 10. The system of claim 1, further comprising means for displaying the type of crime and past victimization cases when the predicted risk exceeds a certain threshold.

[2304] (Claim 3)

[2305] 10. The system of claim 1, further comprising means for classifying specific risk categories, such as fraud, phishing, or malware, from user behavioral data.

[2306] "Application Example 1"

[2307] (Claim 1)

[2308] a means for collecting user behavior data;

[2309] A means of analyzing collected behavioral data in real time to predict the risk of crime and victimization;

[2310] means for displaying a warning message to a user based on the predicted risk;

[2311] means of providing information about the types of crimes involved and how to avoid them;

[2312] A means for providing consultation information to a user;

[2313] A means for determining in real time whether a user's specific behavior will pose a risk when that behavior occurs;

[2314] means for generating and providing a specific warning message to a user based on the risk score when the risk meets a specific condition;

[2315] A system including:

[2316] (Claim 2)

[2317] 2. The system according to claim 1, further comprising means for displaying the type of crime and past victim cases when the predicted risk exceeds a specific threshold.

[2318] (Claim 3)

[2319] 10. The system of claim 1, further comprising means for classifying user behavior data into specific risk categories such as fraud, phishing, and malware.

[2320] "Example 2: Combining Emotion Engines"

[2321] (Claim 1)

[2322] a means for collecting user behavior data;

[2323] A means of analyzing collected behavioral and emotional data in real time to predict the risk of crime and victimization;

[2324] means for displaying a warning message to a user based on the predicted risk;

[2325] means of providing information about the types of crimes involved and how to avoid them;

[2326] A means for providing consultation information to a user;

[2327] means for adjusting the content and display manner of the warning message based on the emotional state of the user;

[2328] A system including:

[2329] (Claim 2)

[2330] 10. The system of claim 1, further comprising means for displaying the type of crime and past victimization cases when the predicted risk exceeds a certain threshold.

[2331] (Claim 3)

[2332] 10. The system of claim 1, further comprising means for classifying specific risk categories, such as fraud, phishing, or malware, from the user's behavioral and emotional data.

[2333] "Application example 2 when combining emotion engines"

[2334] (Claim 1)

[2335] a means for collecting user behavior data;

[2336] A means of analyzing collected behavioral data in real time to predict the risk of crime and victimization;

[2337] means for displaying a warning message to a user based on the predicted risk;

[2338] means of providing information about the types of crimes involved and how to avoid them;

[2339] A means for providing consultation information to a user;

[2340] means for collecting emotion data from a user's facial expressions and vocal tone;

[2341] means for analyzing the collected emotion data and adjusting the content of the warning message according to the user's emotional state;

[2342] A system including:

[2343] (Claim 2)

[2344] 10. The system of claim 1, further comprising means for displaying the type of crime and past victimization cases when the predicted risk exceeds a certain threshold.

[2345] (Claim 3)

[2346] 10. The system of claim 1, further comprising means for classifying specific risk categories, such as fraud, phishing, or malware, from user behavioral data. [Explanation of symbols]

[2347] 10, 210, 310, 410 Data Processing Systems 12 Data Processing Device 14 Smart Devices 214 Smart Glasses 314 Headset-type terminal 414 Robot< / url:> < / url:> < / url:> < / url:>

Claims

1. a means for collecting user behavior data; A means of analyzing collected behavioral data in real time to predict the risk of crime and victimization; means for displaying a warning message to a user based on the predicted risk; means of providing information about the types of crimes involved and how to avoid them; A means for providing consultation information to a user; A system including:

2. The system of claim 1 , further comprising means for displaying the type of crime and past victimization cases when the predicted risk exceeds a specific threshold.

3. The system of claim 1 , further comprising means for classifying specific risk categories, such as fraud, phishing, or malware, from user behavioral data.

4. The system of claim 1 further comprising means for suggesting links to trusted websites and safe ways of doing things.

5. 10. The system of claim 1, further comprising means for maintaining a list of known fraudulent URLs and dangerous keywords in a database and for performing real-time matching.

Citation Information

Patent Citations

  • Persona chatbot control method and system

    JP2022180282A