system

The system automatically evaluates email and SMS messages for fraud using AI, generating warnings to prevent users from engaging with phishing attempts, addressing the inefficiencies of manual fraud assessment.

JP2026062138APending Publication Date: 2026-04-09SOFTBANK GROUP CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-30
Publication Date
2026-04-09

AI Technical Summary

Technical Problem

Users are burdened with manually assessing the risk of fraud in emails, requiring technical knowledge and time, and conventional methods are ineffective in preventing fraud from sophisticated phishing emails.

Method used

A system that automatically evaluates the risk of fraud in carrier emails and SMS messages using AI to extract keywords, perform web searches, and generate HTML warnings if the risk is high, reducing user burden and preventing fraud.

Benefits of technology

Automatically identifies fraudulent messages and provides timely warnings, protecting users from falling victim to phishing attempts by reducing the risk of clicking malicious links.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026062138000001_ABST
    Figure 2026062138000001_ABST
Patent Text Reader

Abstract

We provide the system. [Solution] A system comprising: means for receiving the body and header information of a message received via carrier email or short message service; means for extracting the received message information; means for transmitting the extracted message information to a central processing unit; means for the central processing unit to transmit the message information to an automatically generated artificial intelligence system for evaluation; means for the automatically generated artificial intelligence system to perform a web search based on the message information and evaluate the possibility of fraud; means for receiving the evaluation results; means for generating warning information if there is a high possibility of fraud; means for transmitting the generated warning information to a terminal; and means for displaying the transmitted warning information to the user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0005] ,

[0001] The technology of the present disclosure relates to a system.

Background Art

[0002] Patent Document 1 discloses a method for controlling a persona chatbot, which is performed by at least one processor, including the steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to an explanation of the chatbot's character, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] In recent years, the damage caused by fraud emails and phishing emails has been increasing rapidly, and the risk that users who receive these emails will be involved in fraud has been rising. Such fraud emails are sophisticated and difficult for users to distinguish by themselves. Therefore, there is a need for a system that automatically evaluates the risk of such emails when a user receives them and gives appropriate warnings. In the conventional method, it was necessary for the user to check the content of the email and the sender information by themselves to judge the possibility of fraud, but this required technical knowledge and time and was not effective. This invention aims to reduce the burden on users and prevent damage caused by fraud emails.

Means for Solving the Problems

[0005] This invention solves the above problem by the following means: It includes means for receiving the body and header information of messages received via carrier email or short message service, means for extracting the received message information, and means for transmitting the extracted message information to a central processing unit. The central processing unit also has means for transmitting the message information to an automatically generated artificial intelligence system for evaluation. The automatically generated artificial intelligence system has means for performing a web search based on the message information and evaluating the likelihood of fraud. The central processing unit is also provided with means for receiving this evaluation result and, if the likelihood of fraud is high, has means for generating warning information. It also includes means for transmitting the generated warning information to a terminal and means for displaying that information to the user. To evaluate the likelihood of fraud, the automatically generated artificial intelligence system extracts keywords from the message information and performs a web search based on the extracted keywords. The warning information is generated in HTML format, including the sender of the message, subject, body, and a notification indicating the likelihood of fraud. In this way, the burden on the user can be reduced, and damage from fraudulent emails can be effectively prevented.

[0006] "Carrier email" refers to email services provided by mobile phone carriers.

[0007] Short Message Service (SMS) is a communication service that allows users to send and receive short text messages using mobile phones and smartphones.

[0008] The "message body" refers to the part of a received carrier email or short message service message that contains the sender's intended message.

[0009] "Header information" refers to data that includes information about the email itself, such as the sender, recipient, subject, and date and time of sending.

[0010] "Means of extraction" refers to a mechanism or process for extracting specific information (body and header information) from a received message.

[0011] A "central processing unit" is the main computer device within a system that processes received message information and determines whether an email is fraudulent.

[0012] An "automatic generation artificial intelligence system" is a system that uses machine learning and natural language processing techniques to analyze message information and assess the likelihood of fraud.

[0013] "Web search" refers to the act of searching for information on the internet based on specific keywords and obtaining relevant information.

[0014] "Means of evaluation" refers to the process or mechanism for determining whether a message is likely to be fraudulent based on the information obtained.

[0015] "Scoring" refers to the process of numerically representing evaluation results and establishing criteria for determining the likelihood of fraud.

[0016] "Warning information" refers to information intended to alert users to messages that are highly likely to be fraudulent.

[0017] "HTML format" is an abbreviation for HyperText Markup Language, a markup language used to display information on the web.

[0018] "Keywords" are important words or phrases extracted from message information to assess the likelihood of fraud.

[0019] A "user" is someone who receives carrier emails or short message services.

[0020] The "terminal" refers to a device used by a user to receive and display carrier emails and short message services.

[0021] The "means for generating" refers to a process or mechanism for creating alert information based on evaluation results.

[0022] The "means for transmitting" refers to a mechanism or process for sending the extracted information or generated alert information to other devices or systems.

[0023] The "means for displaying" refers to a process or mechanism for visually presenting alert information to a user.

Brief Description of the Drawings

[0024] [Figure 1] It is a conceptual diagram showing an example of the configuration of a data processing system according to the first embodiment. [Figure 2] It is a conceptual diagram showing an example of the main functions of a data processing device and a smart device according to the first embodiment. [Figure 3] It is a conceptual diagram showing an example of the configuration of a data processing system according to the second embodiment. [Figure 4] It is a conceptual diagram showing an example of the main functions of a data processing device and smart glasses according to the second embodiment. [Figure 5] It is a conceptual diagram showing an example of the configuration of a data processing system according to the third embodiment. [Figure 6] It is a conceptual diagram showing an example of the main functions of a data processing device and a headset-type terminal according to the third embodiment. [Figure 7] It is a conceptual diagram showing an example of the configuration of a data processing system according to the fourth embodiment. [Figure 8] It is a conceptual diagram showing an example of the main functions of a data processing device and a robot according to the fourth embodiment. [Figure 9] It shows an emotion map to which a plurality of emotions are mapped. [Figure 10]This shows an emotion map where multiple emotions are mapped. [Figure 11] This is a sequence diagram showing the processing flow of the data processing system in Example 1. [Figure 12] This is a sequence diagram showing the processing flow of the data processing system in Application Example 1. [Figure 13] This is a sequence diagram showing the processing flow of the data processing system in Example 2, which incorporates an emotion engine. [Figure 14] This is a sequence diagram showing the processing flow of the data processing system in Application Example 2, which combines an emotion engine. [Modes for carrying out the invention]

[0025] Hereinafter, an example of an embodiment of the system relating to the technology of this disclosure will be described with reference to the attached drawings.

[0026] First, let's explain the terminology used in the following explanation.

[0027] In the following embodiments, the signed processor (hereinafter simply referred to as "processor") may be a single arithmetic unit or a combination of multiple arithmetic units. Furthermore, the processor may be a single type of arithmetic unit or a combination of multiple types of arithmetic units. Examples of arithmetic units include CPU (Central Processing Unit), GPU (Graphics Processing Unit), GPGPU (General-Purpose computing on Graphics Processing Units), and APU (Accelerated Processing Unit).

[0028] In the following embodiments, signed RAM (Random Access Memory) is a memory that temporarily stores information and is used as work memory by the processor.

[0029] In the following embodiments, the signed storage is one or more non-volatile storage devices that store various programs and various parameters. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), or magnetic tapes.

[0030] In the following embodiments, the signed communication interface (I / F) is an interface that includes a communication processor and an antenna, etc. The communication interface manages communication between multiple computers. Examples of communication standards applicable to the communication interface include wireless communication standards such as 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), or Bluetooth (registered trademark).

[0031] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B." That is, "A and / or B" means that it may be A alone, or B alone, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" applies when expressing three or more things linked by "and / or."

[0032] [First Embodiment]

[0033] Figure 1 shows an example of the configuration of the data processing system 10 according to the first embodiment.

[0034] As shown in Figure 1, the data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.

[0035] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0036] The smart device 14 comprises a computer 36, a reception device 38, an output device 40, a camera 42, and a communication interface 44. The computer 36 comprises a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The reception device 38, output device 40, and camera 42 are also connected to the bus 52.

[0037] The reception device 38 is equipped with a touch panel 38A and a microphone 38B, etc., and receives user input. The touch panel 38A receives user input by detecting contact with an object (e.g., a pen or finger). The microphone 38B receives user input by detecting the user's voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the data indicating the user input.

[0038] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user 20 by outputting the data in a form perceptible to the user 20 (e.g., audio and / or text). The display 40A displays visible information such as text and images according to instructions from the processor 46. The speaker 40B outputs audio according to instructions from the processor 46. The camera 42 is a small digital camera equipped with an optical system such as a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.

[0039] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various types of information between processor 46 and processor 28 via network 54.

[0040] Figure 2 shows an example of the main functions of the data processing device 12 and the smart device 14.

[0041] As shown in Figure 2, in the data processing device 12, a specific processing is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" related to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.

[0042] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0043] In the smart device 14, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The reception output program 60 is used in conjunction with a specific processing program 56 by the data processing system 10. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.

[0044] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the smart device 14 as the "terminal".

[0045] This invention is a system for automatically evaluating the fraudulent nature of messages received via carrier email or short message service and, if necessary, alerting the user. The system of this invention mainly consists of three elements: a terminal, a server, and a user.

[0046] Receiving and extracting emails

[0047] The device receives messages sent to carrier email or short message service. For example, suppose the following message is received:

[0048] From: 12345

[0049] Subject: (Urgent) Unauthorized access to your account has been detected

[0050] Body: Please click the following link to verify your account: http: / / example.com

[0051] The terminal extracts the message body and header information (sender, subject, etc.). This allows the message content and its associated metadata to be separated and extracted.

[0052] Message analysis

[0053] The extracted message information is sent from the terminal to the server. The server receives this information and forwards it to an automated artificial intelligence system. This system performs a web search to assess the likelihood of fraud based on the message information.

[0054] The automated artificial intelligence system extracts keywords from the message body and header information, and then searches the internet for related information based on those keywords. For example, it might extract keywords such as "unauthorized account access" and "example.com". In this way, the search results confirm that there are numerous reports and warnings of similar phishing emails.

[0055] Determination and notification of potential fraud

[0056] The server receives results from an automated artificial intelligence system and scores the likelihood of fraud. Based on this scoring, it determines whether the information is likely to be fraudulent.

[0057] If the server determines that there is a high probability of fraud, it will generate an HTML-formatted warning message to alert the user. The generated warning message will contain the following information:

[0058] html

[0059]

[0060]

[0061] <h2> Caution: This may be a phishing email.< / h2>

[0062] The following email is likely a scam. Do not click on the link.

[0063] Sender: 12345

[0064] Subject: (Urgent) Unauthorized access to your account has been detected

[0065] Text: Click the following link to verify your account: http: / / example.com

[0066]

[0067]

[0068] User notifications

[0069] The server sends the generated warning HTML to the device. The device displays the received HTML to the user. This display allows the user to recognize that the received message is likely to be fraudulent and to avoid taking actions such as clicking on links.

[0070] For example, the risk of a user unknowingly clicking on a link like "http: / / example.com" is reduced. In this way, users are protected from becoming victims of fraud.

[0071] As described above, this invention provides a system that automatically identifies fraudulent messages sent via carrier email and short message services, and promptly and appropriately warns users, thereby preventing damage from fraud.

[0072] The following describes the processing flow.

[0073] Step 1:

[0074] The device receives new messages that have arrived via carrier email or short message service. For example, consider a message with the following content.

[0075] From: 12345

[0076] Subject: (Urgent) Unauthorized access to your account has been detected

[0077] Body: Please click the following link to verify your account: http: / / example.com

[0078] Step 2:

[0079] The device extracts the message body and header information (sender, subject, etc.) from the received message. Specifically, it retrieves information such as "From: 12345", "Subject: (Urgent) Unauthorized access to your account has been detected", and "Body: Click the link below to verify your account: http: / / example.com".

[0080] Step 3:

[0081] The terminal sends the extracted message information to the server. It uses communication methods such as HTTP POST requests to send the message information to the server.

[0082] Step 4:

[0083] The server forwards the received message information to the automated artificial intelligence system. The system converts the message information into a format that it can process and then makes an API call.

[0084] Step 5:

[0085] The automated artificial intelligence system extracts keywords from the message body and header information. For example, it extracts keywords such as "unauthorized access to account" and "example.com".

[0086] Step 6:

[0087] The automated artificial intelligence system performs a web search based on extracted keywords. This search is conducted on the internet, gathering information on similar messages.

[0088] Step 7:

[0089] The automated artificial intelligence system evaluates web search results and scores their likelihood of being a scam. This includes similar scam reports and risk assessments.

[0090] Step 8:

[0091] The server receives results from an automatically generated artificial intelligence system and determines whether there is a high probability of fraud based on a scoring system. For example, if the score exceeds a certain level, it is determined to be "highly likely to be a phishing email."

[0092] Step 9:

[0093] If a message is determined to be highly likely to be a scam, the server generates a warning. This information is in HTML format and includes the sender, subject, and body of the received message, as well as a notice indicating the possibility of fraud.

[0094] Step 10:

[0095] The server sends the generated warning HTML to the device.

[0096] Step 11:

[0097] The device displays the received alert HTML to the user. This display is done through the user interface, warning the user of the danger of the message.

[0098] Step 12:

[0099] Users can check the warning HTML displayed on their device and recognize that the received message is likely to be fraudulent. This allows users to avoid actions such as clicking on links.

[0100] (Example 1)

[0101] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."

[0102] In modern society, fraudulent activities targeting users of carrier email and short message services are on the rise. Consequently, there is a growing need for systems that can reliably detect fraudulent emails and issue prompt and appropriate warnings to users. However, traditional manual methods for detecting fraudulent emails are often ineffective in preventing timely responses and failing to prevent damage. Therefore, there is a demand for automated systems that can quickly detect fraudulent emails and provide appropriate warnings to users.

[0103] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.

[0104] In this invention, the server includes means for receiving the body and header information of messages received via carrier email or short message service, means for extracting the received message information, means for transmitting the extracted message information to a central processing unit, and means for an automatically generated artificial intelligence system to perform a web search based on the message information and evaluate the likelihood of fraud. This enables automatic detection of fraudulent emails and rapid warning.

[0105] "Carrier email" refers to email services provided by telecommunications carriers.

[0106] Short Message Service (SSS) is a communication service for sending and receiving short text messages between mobile devices.

[0107] "Message information" refers to data that includes the body and header information of an email or short message.

[0108] The "main text" refers to the part of the message that describes its main content.

[0109] "Header information" refers to information that includes metadata such as the sender of the message, the subject, and the date and time it was sent.

[0110] "Terminal" refers to an electronic device used by a user, and includes, for example, smartphones and tablets.

[0111] A "server" is a computer system that performs central processing.

[0112] An "automatic generation artificial intelligence system" is a system that uses artificial intelligence technology to analyze the content of messages and assess the likelihood of fraud.

[0113] "Web search" refers to the act of searching for information on the internet using a search engine.

[0114] "Assessing the likelihood of fraud" refers to performing a series of analytical processes to determine whether a message is fraudulent.

[0115] "Warning information" refers to information that warns users about the possibility of receiving a fraudulent email.

[0116] "HTML format" refers to a format that uses HTML, a markup language for describing web pages.

[0117] "User" refers to the general consumer who uses the system.

[0118] This invention is a system for automatically evaluating the fraudulent nature of messages received via carrier email or short message service and, if necessary, alerting the user. The system of this invention mainly consists of three elements: a terminal, a server, and a user.

[0119] Receiving and extracting emails

[0120] The device receives messages sent to carrier email or short message service. For example, suppose the following message is received:

[0121] From: 12345

[0122] Subject: (Urgent) Unauthorized access to your account has been detected

[0123] Body: Please click the following link to verify your account: http: / / example.com

[0124] When such a message arrives, the device extracts the message body and header information (sender, subject, etc.). The extracted data will have the following structure:

[0125] Message body: Please click the following link to verify your account: http: / / example.com

[0126] Sender: 12345

[0127] Subject: (Urgent) Unauthorized access to your account has been detected

[0128] Message information transfer and analysis

[0129] The terminal sends the extracted message information to the server. The server forwards the received information to an automated artificial intelligence system. This system evaluates the likelihood of fraud based on the message information. For example, the system extracts keywords such as "unauthorized account access" and "example.com" from the message body and header information and performs a search on the internet.

[0130] For example, if keywords such as "unauthorized access to an account" and "example.com" are extracted, and numerous similar fraud reports and warnings are found on the internet, it will be determined that there is a possibility of fraud.

[0131] Determining the possibility of fraud

[0132] The server receives and analyzes search results from an automated artificial intelligence system. If the analysis reveals numerous fraud reports or warnings, the server scores the likelihood of fraud. For example, if the search results indicate that "example.com" is included in a list of malicious domains, its score will be high.

[0133] Generating warning information

[0134] If the server determines that there is a high probability of fraud, it will generate an HTML-formatted warning message to alert the user. For example, the following HTML content will be generated:

[0135] html

[0136]

[0137]

[0138] <h2> Caution: This may be a phishing email.< / h2>

[0139] The following email is likely a scam. Do not click on the link.

[0140] Sender: 12345

[0141] Subject: (Urgent) Unauthorized access to your account has been detected

[0142] Text: Click the following link to verify your account: http: / / example.com

[0143]

[0144]

[0145] User notifications

[0146] After the warning HTML is generated, the server sends this information to the device. The device displays the received HTML to the user. This display allows the user to recognize that the received message is likely fraudulent and avoid the risk of clicking the link.

[0147] For example, the risk of a user unknowingly clicking on a link like "http: / / example.com" is reduced. In this way, users are protected from becoming victims of fraud.

[0148] As an example of a prompt, the following text can be input to the generating AI model:

[0149] Please check if messages containing phrases like "unauthorized access to your account" or "example.com" are likely to be phishing emails, and generate a warning if they are.

[0150] As described above, this invention provides a system that automatically identifies fraudulent messages sent via carrier email and short message services, and promptly and appropriately warns users, thereby preventing damage from fraud.

[0151] The flow of the specific processing in Example 1 will be explained using Figure 11.

[0152] Step 1:

[0153] The device receives messages sent via carrier email or short message service. These messages include sender information, subject, and body text, which serve as input data.

[0154] Specifically, consider the following message as an example:

[0155] From: 12345

[0156] Subject: (Urgent) Unauthorized access to your account has been detected

[0157] Body: Please click the following link to verify your account: http: / / example.com

[0158] The device receives this message in its original format.

[0159] Step 2:

[0160] The terminal extracts the message body and header information (sender, subject, etc.) from the received message information. The input data is the entire message received in step 1.

[0161] As for specific data processing, the following information will be extracted and output from the message:

[0162] Message body: Please click the following link to verify your account: http: / / example.com

[0163] Sender: 12345

[0164] Subject: (Urgent) Unauthorized access to your account has been detected

[0165] Step 3:

[0166] The terminal sends the extracted message information (body and header information) to the server. The input data is the data extracted in step 2, which is packaged into a packet and sent to the server.

[0167] Specifically, the device sends the following data to the server over the network:

[0168] {

[0169] "Body text": "Click the following link to verify your account: http: / / example.com",

[0170] "Sender": "12345",

[0171] Subject: (Urgent) Unauthorized access to your account has been detected.

[0172] }

[0173] Step 4:

[0174] The server forwards the received message information to the automated artificial intelligence system. The input data is the data received in step 3.

[0175] The server analyzes the data, extracts the necessary keywords, and passes them directly to the automated generation artificial intelligence system.

[0176] For example, extract and submit the following keywords:

[0177] Keywords: ["Unauthorized access to an account", "example.com"]

[0178] Step 5:

[0179] The automated artificial intelligence system performs a web search based on the received keywords and evaluates the likelihood of fraud. The input data is the keywords submitted in step 4.

[0180] The automated artificial intelligence system collects reports and warnings about fraud from the web, scores the likelihood of fraud, and outputs the results.

[0181] For example, the following scoring results will be output:

[0182] Score: 85 (Highly likely to be a scam)

[0183] Step 6:

[0184] The server receives scoring results from an automatically generated artificial intelligence system and generates a warning if it determines that there is a high probability of fraud. The input data is the scoring results obtained in step 5.

[0185] Based on this, a warning message in HTML format is generated and output.

[0186] Specifically, the following content will be generated:

[0187] html

[0188]

[0189]

[0190] <h2> Caution: This may be a phishing email.< / h2>

[0191] The following email is likely a scam. Do not click on the link.

[0192] Sender: 12345

[0193] Subject: (Urgent) Unauthorized access to your account has been detected

[0194] Text: Click the following link to verify your account: http: / / example.com

[0195]

[0196]

[0197] Step 7:

[0198] The server sends the generated alert information to the terminal. The input data is the HTML-formatted alert information generated in step 6.

[0199] Specifically, the server sends this information to the terminal via the network.

[0200] Step 8:

[0201] The terminal displays the received alert information to the user. The input data is HTML-formatted information received from the server in step 7.

[0202] Specifically, the terminal displays the received HTML on the user interface and issues a warning to the user.

[0203] This allows users to identify potentially fraudulent messages and choose to take action, such as not clicking on links.

[0204] By coordinating the above specific actions, the system of the present invention can prevent damage from fraud.

[0205] (Application Example 1)

[0206] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."

[0207] Messages received via carrier email or short message services may contain malicious content designed to lure users into fraud, putting them at risk of becoming victims. A system is needed to quickly identify such fraudulent messages and warn users. However, conventional methods have struggled to evaluate message content in real time and provide appropriate warnings. Therefore, the challenge lies in providing a system that automatically evaluates the fraudulent nature of messages received by users and delivers necessary warnings quickly and effectively.

[0208] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.

[0209] In this invention, the server includes means for receiving the body and header information of messages received via carrier email or short message service; means for extracting the received message information; means for transmitting the extracted message information to a central processing unit; means for transmitting the message information to an artificial intelligence system automatically generated by the central processing unit for evaluating the message information; means for the automatically generated artificial intelligence system to perform a web search based on the message information and evaluate the likelihood of fraud; means for receiving the evaluation results; means for generating warning information if there is a high possibility of fraud; means for transmitting the generated warning information to a terminal; means for displaying the transmitted warning information to the user; and means implemented as a smartphone application for receiving and evaluating messages and notifying the user. This makes it possible to automatically evaluate the fraudulent nature of messages received by the user and provide necessary warnings quickly and effectively.

[0210] "Carrier email" refers to the email service provided by mobile phone carriers.

[0211] "Short Message Service" refers to a service that allows users to send and receive short messages using a mobile phone network.

[0212] "Message body" refers to the main content portion of a message that a user sends or receives.

[0213] "Header information" refers to metadata attached to a message, such as the sender and subject.

[0214] "Means of receiving" refers to functions and devices for obtaining messages via carrier email or short message service.

[0215] "Means of extraction" refers to functions or devices that extract and separate the message body and header information.

[0216] A "central processing unit" refers to a computer system used to analyze and process received message data.

[0217] An "automatically generated artificial intelligence system" refers to machine learning models or algorithms trained to analyze message information and assess the likelihood of fraud.

[0218] "Means of performing a web search" refers to functions or devices that search for keywords on the internet and obtain related information.

[0219] "Means of assessing the possibility of fraud" refers to functions or devices that determine whether a received message has an illegitimate purpose based on its content.

[0220] "Means of receiving evaluation results" refers to functions or devices that receive analysis results from artificial intelligence systems.

[0221] "Warning information" refers to information intended to alert users that a message is highly likely to be a scam.

[0222] "Means of generation" refers to functions or devices that create warning messages when a situation is deemed highly likely to be fraudulent.

[0223] "Terminal" refers to devices such as smartphones and tablets that are directly operated by the user.

[0224] A "smartphone application" refers to a dedicated software program that runs on a smartphone.

[0225] This invention is a system that automatically evaluates the fraudulent nature of messages received via carrier email or short message service and alerts the user if necessary, and is implemented as a smartphone application.

[0226] Configuration and Operation Overview

[0227] Receiving and extracting messages

[0228] The device (smartphone) receives the body and header information of messages received via carrier email or short message service. A dedicated application running on the smartphone handles this task. For example, suppose the following message is received:

[0229] From: 12345

[0230] Subject: (Urgent) Unauthorized access to your account has been detected

[0231] Body: Please click the following link to verify your account: http: / / example.com

[0232] The terminal extracts the message body and header information.

[0233] Message analysis

[0234] The extracted message information is sent from the terminal to the server. The server receives the message information and forwards it to an automatically generated artificial intelligence system. This AI system performs an evaluation to assess the likelihood of fraud based on the message information. Specifically, it extracts keywords from the message body and header information and searches the internet for related information based on those keywords. For example, keywords such as "unauthorized account access" and "example.com" may be extracted. This method allows the system to check the search results to see if there are many reports or warnings of similar fraudulent emails.

[0235] Determination and notification of potential fraud

[0236] The server receives results from an automatically generated artificial intelligence system and scores the likelihood of fraud. Based on this scoring, it determines whether the situation is likely to be fraudulent. If it is determined to be likely to be fraudulent, the server generates an HTML-formatted warning message to alert the user. The generated warning message will contain the following information:

[0237] html

[0238]

[0239]

[0240] <h2> Caution: This may be a phishing email.< / h2>

[0241] The following email is likely a scam. Do not click on the link.

[0242] Sender: 12345

[0243] Subject: (Urgent) Unauthorized access to your account has been detected

[0244] Text: Click the following link to verify your account: http: / / example.com

[0245]

[0246]

[0247] This information will be notified to the user via a smartphone application.

[0248] The technologies used

[0249] The following technologies will be used to implement this system:

[0250] Smartphone application: A dedicated software program designed to run on a smartphone. Kotlin (Android®) and Swift (iOS) are commonly used.

[0251] Cloud server: A server that processes message information and returns evaluation results. Python and Flask (web framework) are used.

[0252] Artificial intelligence system: Machine learning models and algorithms for analyzing message information and assessing the likelihood of fraud. TENSORFLOW® and BeautifulSoup are used.

[0253] Database: A database for storing message data. PostgreSQL is used.

[0254] Specific example

[0255] Consider a scenario where a user receives the following message:

[0256] Example of a prompt:

[0257] Message body: Please click the following link to verify your account: http: / / example.com

[0258] Sender: 12345

[0259] Subject: (Urgent) Unauthorized access to your account has been detected

[0260] Based on this prompt, the artificial intelligence system evaluates the message's fraudulent nature and, if it determines it is highly likely to be fraudulent, displays a warning to the user. This system reduces the risk of users clicking on suspicious links and protects them from becoming victims of fraud.

[0261] The flow of a specific process in Application Example 1 will be explained using Figure 12.

[0262] Step 1:

[0263] The device (smartphone) receives messages via carrier email or short message service. The body and header information (sender, subject, etc.) of the received message are extracted. Specifically, a dedicated application analyzes the message content and extracts the necessary information. The input is the received message data, and the output is the extracted body and header information.

[0264] Step 2:

[0265] The terminal sends the extracted message information to the server. The input is the extracted message information, and the output is the data sent to the server. A dedicated communication protocol is used to transmit the data.

[0266] Step 3:

[0267] The server sends the received message information to an automatically generated artificial intelligence system. The input is the received message information, and the output is the data passed to the AI ​​system. A Python script is used to transfer the data to the AI ​​model.

[0268] Step 4:

[0269] An automatically generated artificial intelligence system extracts keywords from message information and performs a web search. The input is message information, and the output is search results. Specifically, it uses TensorFlow for keyword extraction and BeautifulSoup to collect relevant information from the internet.

[0270] Step 5:

[0271] The server scores the likelihood of fraud based on the search results. The input is the search results, and the output is the fraud score. The AI ​​model learns patterns of fraudulent activity based on past data and calculates the score accordingly.

[0272] Step 6:

[0273] The server receives a fraud score and generates HTML-formatted information for alerting when the likelihood of fraud is high. The input is the fraud score and the output is a warning message. Use a Python script to generate an HTML document.

[0274] Step 7:

[0275] The server sends the generated alert information to the terminal. The input is the alert information and the output is the warning message sent to the terminal. Use a dedicated communication protocol to send the data.

[0276] Step 8:

[0277] The terminal displays the received alert information to the user. The input is the received warning message and the output is the warning information displayed to the user. A dedicated application presents the HTML-formatted warning message to the user.

[0278] Through these processing flows, the user can evaluate suspicious messages in real time and receive appropriate warnings to prevent fraud damage.

[0279] Furthermore, an emotion engine for estimating the user's emotions may be combined. That is, the specific processing unit 290 may estimate the user's emotions using the emotion recognition model 59 and perform specific processing using the user's emotions.

[0280] This invention is a system for automatically evaluating the fraudulence of messages received by carrier mail and short message services and prompting the user to pay attention as needed. The system of this invention is mainly composed of three elements: a terminal, a server, and a user. And by combining an emotion engine that recognizes the user's emotions and adjusts the response, the damage caused by fraud emails can be more effectively prevented.

[0281] Receiving and Extracting Emails

[0282] The device receives new messages that have arrived via carrier email or short message service. For example, consider the following message:

[0283] From: 12345

[0284] Subject: (Urgent) Unauthorized access to your account has been detected

[0285] Body: Please click the following link to verify your account: http: / / example.com

[0286] The terminal extracts the message body and header information (sender, subject, etc.). This allows the message content and its associated metadata to be separated and extracted.

[0287] Message analysis

[0288] The extracted message information is sent from the terminal to the server. The server receives this information and forwards it to an automated artificial intelligence system. This system performs a web search to assess the likelihood of fraud based on the message information.

[0289] The automated artificial intelligence system extracts keywords from the message body and header information, and then searches the internet for related information based on those keywords. For example, it might extract keywords such as "unauthorized account access" and "example.com". In this way, the search results confirm that there are numerous reports and warnings of similar phishing emails.

[0290] Determination and notification of potential fraud

[0291] The server receives results from an automated artificial intelligence system and scores the likelihood of fraud. Based on this scoring, it determines whether the information is likely to be fraudulent.

[0292] If it is determined that there is a high possibility of fraud, the server generates alert information. This information is in HTML format and includes a notification indicating the sender, subject, body of the received message, and the possibility of fraud. For example, the following alert information is generated:

[0293] html

[0294]

[0295]

[0296] <h2> Caution: This may be a phishing email.< / h2>

[0297] The following email is likely a scam. Do not click on the link.

[0298] Sender: 12345

[0299] Subject: (Urgent) Unauthorized access to your account has been detected

[0300] Text: Click the following link to verify your account: http: / / example.com

[0301]

[0302]

[0303] Response adjustment using the emotion engine

[0304] Before transmitting the generated alert information, the emotion engine recognizes the user's emotion. The emotion engine determines the user's emotion by analyzing the user's facial expressions, voice tone, input patterns, etc. Based on the recognized emotion, the content and display method of the alert information are adjusted.

[0305] > For example, if the user shows stress or anxiety, the server provides additional support information and guidance. Specifically, a message such as "This email may be fraudulent. Please stay calm and handle it. If you have any questions, please contact the support center." is displayed.

[0306] User notifications

[0307] The server sends the generated warning HTML to the device. The device displays the received HTML to the user. This display allows the user to recognize that the received message is likely to be fraudulent and to avoid taking actions such as clicking on links.

[0308] For example, the risk of a user unknowingly clicking on a link like "http: / / example.com" is reduced. In this way, users are protected from becoming victims of fraud.

[0309] As described above, this invention provides a system that automatically identifies fraudulent messages sent via carrier email and short message services, and promptly and appropriately warns users, thereby preventing damage from fraud. Furthermore, by using an emotion engine, it can respond in a way that takes the user's emotions into consideration, thereby protecting users more effectively.

[0310] The following describes the processing flow.

[0311] Step 1:

[0312] The device receives new messages that have arrived via carrier email or short message service. For example, suppose a message like the following is received:

[0313] From: 12345

[0314] Subject: (Urgent) Unauthorized access to your account has been detected

[0315] Body: Please click the following link to verify your account: http: / / example.com

[0316] Step 2:

[0317] The terminal extracts the body and header information (sender, subject, etc.) of the received message. Specifically, it retrieves information such as "From: 12345", "Subject: (Urgent) Unauthorized access to your account has been detected", and "Body: Click the link below to verify your account: http: / / example.com".

[0318] Step 3:

[0319] The terminal sends the extracted message information to the server. It uses communication methods such as HTTP POST requests to send the message information to the server.

[0320] Step 4:

[0321] The server forwards the received message information to the automated artificial intelligence system. The system converts the message information into a format that it can process and then makes an API call.

[0322] Step 5:

[0323] The automated artificial intelligence system extracts keywords from the message body and header information. For example, it extracts keywords such as "unauthorized access to account" and "example.com".

[0324] Step 6:

[0325] The automated artificial intelligence system performs a web search based on extracted keywords. This search is conducted on the internet, gathering information on similar messages.

[0326] Step 7:

[0327] The automated artificial intelligence system evaluates web search results and scores their likelihood of being a scam. This includes similar scam reports and risk assessments.

[0328] Step 8:

[0329] The server receives results from an automatically generated artificial intelligence system and determines whether there is a high probability of fraud based on a scoring system. For example, if the score exceeds a certain level, it is determined to be "highly likely to be a phishing email."

[0330] Step 9:

[0331] If a message is determined to be highly likely to be a scam, the server generates a warning. This information is in HTML format and includes the sender, subject, and body of the received message, as well as a notice indicating the possibility of fraud.

[0332] Step 10:

[0333] The server sends the generated alert HTML to the device.

[0334] Step 11:

[0335] The device activates the emotion engine before displaying the received alert HTML. The emotion engine provides a means to analyze and recognize the user's emotions. The emotion engine analyzes the user's facial expressions, voice tone, input patterns, etc., and evaluates the user's emotional state.

[0336] Step 12:

[0337] If the emotion engine detects that a user is exhibiting stress or anxiety, the server adjusts the content and display of the alert information. For example, it may include more detailed explanations or additional support.

[0338] Step 13:

[0339] The device displays a customized warning HTML to the user. This display allows the user to recognize the risk of receiving a phishing email and understand how to deal with it safely.

[0340] Step 14:

[0341] Users can check the warning HTML displayed on their device and recognize that the received message is likely to be fraudulent. This allows them to avoid actions such as clicking on links.

[0342] This series of steps not only protects users from phishing emails, but also provides more user-friendly warnings and support through the workings of an emotion engine.

[0343] (Example 2)

[0344] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the smart device 14 as the "terminal".

[0345] The risk of receiving fraudulent messages via email and short message services remains high. Many users fall victim to these messages, partly due to the lack of systems that accurately identify and quickly warn against fraudulent messages. Another problem is that the inability to respond appropriately to users' emotions leads to panic and an inability to take appropriate action.

[0346] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.

[0347] In this invention, the server includes means for receiving the body and header information of messages received via carrier email or short message service, means for extracting the received message information, means for transmitting the extracted message information to a central processing unit, means for transmitting the message information to an automatically generated artificial intelligence system, means for the automatically generated artificial intelligence system to perform a web search based on the message information and evaluate the possibility of fraud, means for receiving the evaluation results, means for generating warning information if there is a high possibility of fraud, means for transmitting the generated warning information to a terminal, means for displaying the transmitted warning information to the user, and an emotion engine that recognizes the user's emotions and adjusts the content and display method of the warning information. This makes it possible to automatically identify fraudulent messages and issue warnings to users quickly and accurately. Furthermore, because appropriate responses can be taken according to the user's emotional state, users can receive information with peace of mind.

[0348] "Carrier email" refers to the email service provided by mobile phone carriers.

[0349] "Short Message Service" refers to a service that allows users to send and receive short text messages using their mobile phones.

[0350] "Message body" refers to the main text content included in carrier emails and short message services.

[0351] "Header information" refers to metadata such as the sender and recipient of a message, the subject, and the date and time it was sent.

[0352] A "terminal" refers to an electronic device that receives and sends carrier emails and short message services.

[0353] A "central processing unit" refers to a computer device that controls and processes data for the entire system.

[0354] An "automatic generation artificial intelligence system" refers to a system that uses artificial intelligence technology to analyze information and make decisions.

[0355] "Web search" refers to the act of using the internet to search for information related to specific keywords or topics.

[0356] "Potential fraud" refers to the probability that the received message is fraudulent or not.

[0357] "Warning information" refers to messages intended to inform users of specific risks or warnings.

[0358] An "emotion engine" refers to a system that recognizes a user's emotional state and adjusts responses and message content based on that state.

[0359] "HTML format" refers to a document format that uses the hypertext markup language.

[0360] This invention is a system for automatically evaluating the fraudulent nature of messages received via carrier email and short message services, and for alerting users as necessary. The system of this invention mainly consists of three elements: a terminal, a server, and a user. Furthermore, by incorporating an emotion engine that recognizes the user's emotions and adjusts its response accordingly, it can more effectively prevent damage from fraudulent emails.

[0361] Receiving and extracting emails

[0362] The device receives new messages that have arrived via carrier email or short message service. For example, consider the following message:

[0363] From: 12345

[0364] Subject: (Urgent) Unauthorized access to your account has been detected

[0365] Body: Please click the following link to verify your account: http: / / example.com

[0366] The terminal extracts the message body and header information (sender, subject, etc.). This allows the message content and its associated metadata to be separated and extracted.

[0367] Message analysis

[0368] The extracted message information is sent from the terminal to the server. The server receives this information and forwards it to an automated artificial intelligence system. This system performs a web search to assess the likelihood of fraud based on the message information.

[0369] The automated artificial intelligence system extracts keywords from the message body and header information, and then searches the internet for related information based on those keywords. For example, it might extract keywords such as "unauthorized account access" and "example.com". In this way, the search results confirm that there are numerous reports and warnings of similar phishing emails.

[0370] Determination and notification of potential fraud

[0371] The server receives results from an automated artificial intelligence system and scores the likelihood of fraud. Based on this scoring, it determines whether the information is likely to be fraudulent.

[0372] If a message is determined to be highly likely to be fraudulent, the server generates a warning. This information, in HTML format, includes the sender, subject, and body of the received message, as well as a notice indicating the possibility of fraud. For example, the following warning information may be generated:

[0373] html

[0374]

[0375]

[0376] <h2> Caution: This may be a phishing email.< / h2>

[0377] The following email is likely a scam. Do not click on the link.

[0378] Sender: 12345

[0379] Subject: (Urgent) Unauthorized access to your account has been detected

[0380] Text: Click the following link to verify your account: http: / / example.com

[0381]

[0382]

[0383] Adjusting responses using an emotional engine

[0384] Before sending the generated alert information, the emotion engine recognizes the user's emotions. The emotion engine determines the user's emotions by analyzing the user's facial expressions, tone of voice, input patterns, etc. Based on the recognized emotions, it adjusts the content and display method of the alert information.

[0385] For example, if a user indicates stress or anxiety, the server will provide additional support information and guidance. Specifically, it might display a message such as, "This email may be a scam. Please remain calm. If you have any questions, please contact our support center."

[0386] User notifications

[0387] The server sends the generated warning HTML to the device. The device displays the received HTML to the user. This display allows the user to recognize that the received message is likely to be fraudulent and to avoid taking actions such as clicking on links.

[0388] A concrete example would be inputting the following prompt into an automated AI model:

[0389] To assess the likelihood of a scam message regarding unauthorized access to your account, search the internet for information and check for similar scam reports. Keywords to look for are "unauthorized account access" and "example.com".

[0390] Using this prompt, an automated artificial intelligence system performs an internet search and evaluates the likelihood of fraud.

[0391] As described above, this invention provides a system that automatically identifies fraudulent messages sent via carrier email and short message services, and promptly and appropriately warns users, thereby preventing damage from fraud. Furthermore, by using an emotion engine, it can respond in a way that takes the user's emotions into consideration, thereby protecting users more effectively.

[0392] The flow of the specific processing in Example 2 will be explained using Figure 13.

[0393] Step 1: Receiving emails

[0394] The device monitors and receives new messages in carrier email and short message service (SMS) in real time. This monitoring utilizes services such as the notification listener service of the Android OS. When a new message arrives, the device immediately retrieves the information.

[0395] Input: Messages sent via carrier email or SMS

[0396] Output: Received message data

[0397] Specific operation: When a new message is sent, the terminal immediately captures its metadata and text content.

[0398] Step 2: Message Extraction

[0399] The terminal analyzes and extracts the body and header information (sender, subject, etc.) of the received message. This includes, for example, using regular expressions to analyze the email sender and subject according to a specific format.

[0400] Input: Received message data

[0401] Output: Header information of the extracted message (sender, subject), body.

[0402] Specific operation: The terminal uses regular expressions to extract the sender's address, subject, and body. For example, it identifies fields such as "From:" and "Subject:" and retrieves their values.

[0403] Step 3: Send message information

[0404] The terminal sends the extracted message information (sender, subject, and body) to the server. This transmission uses an HTTP POST request. The server receives this information and proceeds to the next processing step.

[0405] Input: Header information and body of the extracted message

[0406] Output: Sending message information to the server

[0407] Specific operation: The terminal generates an HTTP POST request and sends message information to the server. The request is constructed including the destination URL and authentication information.

[0408] Step 4: Analyze message information

[0409] The server forwards the received message information to an automated artificial intelligence system (e.g., a BERT or GPT model). This system extracts keywords from the message information to assess the likelihood of fraud and performs a web search based on these keywords.

[0410] Input: Message information sent to the server

[0411] Output: Search results and related information to assess the likelihood of fraud.

[0412] Specific operation: The automated artificial intelligence system extracts specific keywords from the body and header information of received messages. This is done using natural language processing techniques. Next, it uses these keywords to perform a web search on the internet and collect relevant information.

[0413] Step 5: Determining the possibility of fraud

[0414] The server scores the likelihood of fraud based on search results and related information from an automatically generated artificial intelligence system. This scoring uses a continuous scale, for example, ranging from 0 to 1, with a score of 0.7 or higher indicating a high probability of fraud.

[0415] Input: Search results and related information from an automatically generated artificial intelligence system.

[0416] Output: Fraud Probability Score

[0417] Specific operation: The server scores the search results based on factors such as frequency of results, the degree of matching with past fraud databases, and warning information, and assesses the likelihood of fraud.

[0418] Step 6: Generating a warning message

[0419] If a message is determined to be highly likely to be a scam, the server generates a warning in HTML format. This information includes the sender, subject, and body of the received message, as well as a notification indicating the possibility of fraud.

[0420] Input: Message information and score that are likely to be fraudulent.

[0421] Output: HTML document containing a warning message.

[0422] Specific operation: The server uses a template engine to generate a warning message in HTML format. For example, it might insert text such as, "This may be a scam. Do not click the link."

[0423] Step 7: Adjusting responses using the emotional engine

[0424] Before sending the generated alert information, the emotion engine recognizes the user's emotions. The emotion engine analyzes the user's facial expressions, tone of voice, input patterns, etc., to determine the user's emotions. Based on the recognized emotions, the content and display method of the alert information are adjusted.

[0425] Input: User emotional data (facial expressions, voice tone, input patterns)

[0426] Output: Adjusted warning information

[0427] Specific operation: The emotion engine uses the camera and microphone to analyze the user's emotional state in real time, and if the user shows signs of anxiety, it provides additional supportive information.

[0428] Step 8: User Notifications

[0429] The server sends the generated warning HTML to the device. The device receives this HTML and displays it to the user. This display allows the user to recognize the risk of fraud and avoid actions such as clicking on links.

[0430] Input: Warning HTML from the server

[0431] Output: Warning information displayed to the user

[0432] Specific operation: The device displays the received HTML to the user using WebView or browser components, visually conveying the warning content.

[0433] This allows users to take appropriate action against fraudulent messages and prevent becoming a victim. For example, users can avoid becoming a victim of fraud by not clicking on links such as "http: / / example.com".

[0434] (Application Example 2)

[0435] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."

[0436] In recent years, fraudulent activities using carrier email and short message services have become rampant, and effective countermeasures are needed. Furthermore, in autonomous vehicles, it is difficult to take appropriate measures when passengers receive fraudulent messages. In addition, there is a need for responses that take into account the emotional state of passengers in response to fraudulent messages, but such systems do not yet exist. To solve these problems, a system is needed that evaluates messages and takes appropriate responses based on the emotions involved.

[0437] In Application Example 2, the identification processing by the identification processing unit 290 of the data processing device 12 is realized by the following means. In this invention, the server includes means for receiving the body and header information of messages received via carrier mail or short message service, means for extracting the received message information, means for transmitting the extracted message information to a central processing device, means for transmitting the message information to an automatically generated artificial intelligence system for the central processing device to evaluate the message information, means for the automatically generated artificial intelligence system to perform a web search based on the message information and evaluate the possibility of fraud, means for receiving the evaluation results, means for generating warning information if there is a high possibility of fraud, means for transmitting the generated warning information to a terminal, means for displaying the transmitted warning information to the user, means for recognizing the user's emotions and adjusting the response, and means for coordinating with the in-vehicle information system of an autonomous vehicle to evaluate the fraudulent nature of messages received by passengers in the vehicle and notify them. This makes it possible to efficiently evaluate the fraudulent nature of messages received by passengers and provide appropriate warnings. Furthermore, by adjusting the response based on the passenger's emotional state, it becomes possible to effectively prevent fraud damage.

[0438] "Carrier email" refers to email services provided by telecommunications carriers, and is typically sent and received using mobile phones or smartphones.

[0439] Short Message Service (SMS) is a communication service that allows users to send and receive short messages via mobile phones and smartphones.

[0440] "Message body" refers to the actual content written in carrier emails and short message services.

[0441] "Message header information" refers to the part of the message that contains information related to its management, such as the sender, recipient, subject, date and time, etc.

[0442] A "central processing unit" is the central part of a computer system that performs data processing. It receives data from other systems and devices, and then analyzes and makes decisions based on that data.

[0443] An "automatic generation artificial intelligence system" is a system that uses artificial intelligence technology to automatically generate and analyze data.

[0444] "Web search" refers to the act of finding information on the internet using a search engine.

[0445] "Potential fraud" refers to the possibility that a message could be used for malicious purposes, such as fraudulent activities.

[0446] "Warning information" is information intended to alert users and is presented when there is a possibility of fraud.

[0447] A "terminal" refers to an information device that the user directly operates, and includes personal computers, smartphones, tablets, and other similar devices.

[0448] A "user" refers to a person who uses this system.

[0449] "Means of recognizing emotions" refer to methods and technologies for analyzing a user's facial expressions, tone of voice, etc., to understand their emotional state.

[0450] An "autonomous vehicle" is a vehicle that has the function to drive itself without a human driver.

[0451] An "in-vehicle information system" refers to an information processing system installed in a vehicle, providing functions such as navigation, entertainment, and communication.

[0452] This invention is a system that automatically evaluates the fraudulent nature of messages received via carrier email or short message service and alerts the user as needed. In particular, it works in conjunction with the in-vehicle information system of autonomous vehicles to evaluate the likelihood of fraud in messages received by passengers in the vehicle and provide a response that takes the user's feelings into consideration.

[0453] Receiving and extracting emails

[0454] The device receives new messages via carrier email or short message service. For example, consider the following message:

[0455] From: 12345

[0456] Subject: (Urgent) Unauthorized access to your account has been detected

[0457] Body: Click the following link to verify your account: http: / / example.com

[0458] The terminal extracts the message body and header information (sender, subject, etc.). This allows the message content and its associated metadata to be separated and extracted.

[0459] Analysis and evaluation of message information

[0460] The extracted message information is sent from the terminal to the central processing unit. The central processing unit receives this information and forwards it to the automated artificial intelligence system. The automated artificial intelligence system performs a web search to evaluate the likelihood of fraud based on the message information.

[0461] The automated artificial intelligence system extracts keywords from the message body and header information, and then searches the internet for related information based on those keywords. For example, it might extract keywords such as "unauthorized account access" and "example.com". In this way, the search results confirm that there are numerous reports and warnings of similar phishing emails.

[0462] Determination and notification of potential fraud

[0463] The central processing unit receives results from the automatically generated artificial intelligence system and scores the likelihood of fraud. Based on this scoring, it determines whether the likelihood of fraud is high.

[0464] If a message is determined to be highly likely to be fraudulent, the central processing unit generates a warning. This information, in HTML format, includes the sender, subject, and body of the received message, as well as a notification indicating the possibility of fraud. For example, the following warning information may be generated:

[0465] html

[0466]

[0467]

[0468] <h2> Caution: This may be a phishing email.< / h2>

[0469] The following email is likely a scam. Do not click on the link.

[0470] Sender: 12345

[0471] Subject: (Urgent) Unauthorized access to your account has been detected

[0472] Text: Click the following link to verify your account: http: / / example.com

[0473]

[0474]

[0475] Adjusting responses using an emotional engine

[0476] Before sending the generated alert information, the emotion engine recognizes the user's emotions. The emotion engine determines the user's emotions by analyzing the user's facial expressions, tone of voice, input patterns, etc. Based on the recognized emotions, the content and display method of the alert information are adjusted. For example, if the user is showing signs of stress or anxiety, the central processing unit provides additional support information and guidance. Specifically, it might display a message such as, "This email may be a scam. Please remain calm. If you have any questions, please contact our support center."

[0477] User notifications

[0478] The central processing unit sends the generated warning HTML to the terminal. The terminal displays the received HTML to the user. This display allows the user to recognize that the received message is likely to be fraudulent and to avoid actions such as clicking on links. For example, the risk of a user unknowingly clicking on a link such as "http: / / example.com" is reduced. In this way, the user is protected from becoming a victim of fraud.

[0479] Specific example

[0480] If a passenger receives a fraudulent email while in an autonomous vehicle, the system analyzes the message and determines that it is likely to be a scam. At the same time, if the emotion engine detects that the passenger is feeling stressed, it will display a reassuring message such as "Please stay calm and deal with this calmly" as a warning.

[0481] Example of a prompt

[0482] Please evaluate the fraudulent nature of the following message:

[0483] Email sender: 12345

[0484] Subject: (Urgent) Unauthorized access to your account has been detected

[0485] Text: Click the following link to verify your account: http: / / example.com

[0486] Additionally, if the system determines that the user is emotionally unstable, please generate a gentle and reassuring message.

[0487] The flow of a specific process in Application Example 2 will be explained using Figure 14.

[0488] Program processing flow

[0489] Step 1:

[0490] The device receives new messages from carrier email or short message service. The input includes the message body and header information (sender, subject, etc.). Data processing involves extracting the message body and header information. The output is the extracted message information.

[0491] Step 2:

[0492] The terminal transmits the extracted message information to the central processing unit. The extracted message information is required as input. The data processing involves transmitting the information. The output is the message information received by the central processing unit.

[0493] Step 3:

[0494] The central processing unit transmits message information to the automated artificial intelligence system. Its input includes message information received from the terminal. As a data calculation, it reprocesses the message information and transmits it. The output is the message information received by the automated artificial intelligence system.

[0495] Step 4:

[0496] The automated artificial intelligence system performs a web search based on message information and evaluates the likelihood of fraud. The input includes keywords extracted from the message body and header information. Data processing involves keyword extraction and web search. The output is an evaluation of the likelihood of fraud.

[0497] Step 5:

[0498] The central processing unit receives evaluation results from an automatically generated artificial intelligence system and scores the likelihood of fraud. The input includes the evaluation results. The data calculation is performed as a scoring process. The output is a score regarding the likelihood of fraud.

[0499] Step 6:

[0500] If a fraudulent activity is determined to be highly likely, the central processing unit generates a warning. The input includes a score indicating the likelihood of fraud. The data processing generates a warning in HTML format. The output is the generated warning.

[0501] Step 7:

[0502] Before sending the generated alert information, the emotion engine recognizes the user's emotions. Inputs include the user's facial expressions and tone of voice. The data calculation involves emotion recognition. The output is the recognized emotional state of the user.

[0503] Step 8:

[0504] The system adjusts the content and display method of alert information based on the user's emotions recognized by the emotion engine. Input includes the recognized emotional state and alert information. Data processing involves adjusting the information. Output is the adjusted alert information.

[0505] Step 9:

[0506] The central processing unit transmits the adjusted alert information to the terminal. The input includes the adjusted alert information. The data processing involves transmitting the information. The output is the adjusted alert information received by the terminal.

[0507] Step 10:

[0508] The device displays the received, adjusted alert information to the user. The input includes the adjusted alert information. The data calculation process displays the information. The output is the alert information displayed to the user. This allows the user to recognize that the received message is likely fraudulent and take appropriate action.

[0509] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[0510] Data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of data generation model 58 is ChatGPT (registered trademark) (Internet search).<URL: https: / / openai.com / blog / chatgpt> ), Gemini (registered trademark) (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[0511] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the smart device 14.

[0512] [Second Embodiment]

[0513] Figure 3 shows an example of the configuration of the data processing system 210 according to the second embodiment.

[0514] As shown in Figure 3, the data processing system 210 includes a data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.

[0515] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0516] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication interface 44. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, and camera 42 are also connected to the bus 52.

[0517] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.

[0518] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).

[0519] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.

[0520] Figure 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Figure 4, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.

[0521] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0522] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0523] In the smart glasses 214, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.

[0524] Next, the identification processing performed by the identification processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".

[0525] This invention is a system for automatically evaluating the fraudulent nature of messages received via carrier email or short message service and, if necessary, alerting the user. The system of this invention mainly consists of three elements: a terminal, a server, and a user.

[0526] Receiving and extracting emails

[0527] The device receives messages sent to carrier email or short message service. For example, suppose the following message is received:

[0528] From: 12345

[0529] Subject: (Urgent) Unauthorized access to your account has been detected

[0530] Body: Please click the following link to verify your account: http: / / example.com

[0531] The terminal extracts the message body and header information (sender, subject, etc.). This allows the message content and its associated metadata to be separated and extracted.

[0532] Message analysis

[0533] The extracted message information is sent from the terminal to the server. The server receives this information and forwards it to an automated artificial intelligence system. This system performs a web search to assess the likelihood of fraud based on the message information.

[0534] The automated artificial intelligence system extracts keywords from the message body and header information, and then searches the internet for related information based on those keywords. For example, it might extract keywords such as "unauthorized account access" and "example.com". In this way, the search results confirm that there are numerous reports and warnings of similar phishing emails.

[0535] Determination and notification of potential fraud

[0536] The server receives results from an automated artificial intelligence system and scores the likelihood of fraud. Based on this scoring, it determines whether the information is likely to be fraudulent.

[0537] If the server determines that there is a high probability of fraud, it will generate an HTML-formatted warning message to alert the user. The generated warning message will contain the following information:

[0538] html

[0539]

[0540]

[0541] <h2> Caution: This may be a phishing email.< / h2>

[0542] The following email is likely a scam. Do not click on the link.

[0543] Sender: 12345

[0544] Subject: (Urgent) Unauthorized access to your account has been detected

[0545] Text: Click the following link to verify your account: http: / / example.com

[0546]

[0547]

[0548] User notifications

[0549] The server sends the generated warning HTML to the device. The device displays the received HTML to the user. This display allows the user to recognize that the received message is likely to be fraudulent and to avoid taking actions such as clicking on links.

[0550] For example, the risk of a user unknowingly clicking on a link like "http: / / example.com" is reduced. In this way, users are protected from becoming victims of fraud.

[0551] As described above, this invention provides a system that automatically identifies fraudulent messages sent via carrier email and short message services, and promptly and appropriately warns users, thereby preventing damage from fraud.

[0552] The following describes the processing flow.

[0553] Step 1:

[0554] The device receives new messages that have arrived via carrier email or short message service. For example, consider a message with the following content.

[0555] From: 12345

[0556] Subject: (Urgent) Unauthorized access to your account has been detected

[0557] Body: Please click the following link to verify your account: http: / / example.com

[0558] Step 2:

[0559] The device extracts the message body and header information (sender, subject, etc.) from the received message. Specifically, it retrieves information such as "From: 12345", "Subject: (Urgent) Unauthorized access to your account has been detected", and "Body: Click the link below to verify your account: http: / / example.com".

[0560] Step 3:

[0561] The terminal sends the extracted message information to the server. It uses communication methods such as HTTP POST requests to send the message information to the server.

[0562] Step 4:

[0563] The server forwards the received message information to the automated artificial intelligence system. The system converts the message information into a format that it can process and then makes an API call.

[0564] Step 5:

[0565] The automated artificial intelligence system extracts keywords from the message body and header information. For example, it extracts keywords such as "unauthorized access to account" and "example.com".

[0566] Step 6:

[0567] The automated artificial intelligence system performs a web search based on extracted keywords. This search is conducted on the internet, gathering information on similar messages.

[0568] Step 7:

[0569] The automated artificial intelligence system evaluates web search results and scores their likelihood of being a scam. This includes similar scam reports and risk assessments.

[0570] Step 8:

[0571] The server receives results from an automatically generated artificial intelligence system and determines whether there is a high probability of fraud based on a scoring system. For example, if the score exceeds a certain level, it is determined to be "highly likely to be a phishing email."

[0572] Step 9:

[0573] If a message is determined to be highly likely to be a scam, the server generates a warning. This information is in HTML format and includes the sender, subject, and body of the received message, as well as a notice indicating the possibility of fraud.

[0574] Step 10:

[0575] The server sends the generated warning HTML to the device.

[0576] Step 11:

[0577] The device displays the received alert HTML to the user. This display is done through the user interface, warning the user of the danger of the message.

[0578] Step 12:

[0579] Users can check the warning HTML displayed on their device and recognize that the received message is likely to be fraudulent. This allows users to avoid actions such as clicking on links.

[0580] (Example 1)

[0581] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".

[0582] In modern society, fraudulent activities targeting users of carrier email and short message services are on the rise. Consequently, there is a growing need for systems that can reliably detect fraudulent emails and issue prompt and appropriate warnings to users. However, traditional manual methods for detecting fraudulent emails are often ineffective in preventing timely responses and failing to prevent damage. Therefore, there is a demand for automated systems that can quickly detect fraudulent emails and provide appropriate warnings to users.

[0583] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.

[0584] In this invention, the server includes means for receiving the body and header information of messages received via carrier email or short message service, means for extracting the received message information, means for transmitting the extracted message information to a central processing unit, and means for an automatically generated artificial intelligence system to perform a web search based on the message information and evaluate the likelihood of fraud. This enables automatic detection of fraudulent emails and rapid warning.

[0585] "Carrier email" refers to email services provided by telecommunications carriers.

[0586] Short Message Service (SSS) is a communication service for sending and receiving short text messages between mobile devices.

[0587] "Message information" refers to data that includes the body and header information of an email or short message.

[0588] The "main text" refers to the part of the message that describes its main content.

[0589] "Header information" refers to information that includes metadata such as the sender of the message, the subject, and the date and time it was sent.

[0590] "Terminal" refers to an electronic device used by a user, and includes, for example, smartphones and tablets.

[0591] A "server" is a computer system that performs central processing.

[0592] An "automatic generation artificial intelligence system" is a system that uses artificial intelligence technology to analyze the content of messages and assess the likelihood of fraud.

[0593] "Web search" refers to the act of searching for information on the internet using a search engine.

[0594] "Assessing the likelihood of fraud" refers to performing a series of analytical processes to determine whether a message is fraudulent.

[0595] "Warning information" refers to information that warns users about the possibility of receiving a fraudulent email.

[0596] "HTML format" refers to a format that uses HTML, a markup language for describing web pages.

[0597] "User" refers to the general consumer who uses the system.

[0598] This invention is a system for automatically evaluating the fraudulent nature of messages received via carrier email or short message service and, if necessary, alerting the user. The system of this invention mainly consists of three elements: a terminal, a server, and a user.

[0599] Receiving and extracting emails

[0600] The device receives messages sent to carrier email or short message service. For example, suppose the following message is received:

[0601] From: 12345

[0602] Subject: (Urgent) Unauthorized access to your account has been detected

[0603] Body: Please click the following link to verify your account: http: / / example.com

[0604] When such a message arrives, the device extracts the message body and header information (sender, subject, etc.). The extracted data will have the following structure:

[0605] Message body: Please click the following link to verify your account: http: / / example.com

[0606] Sender: 12345

[0607] Subject: (Urgent) Unauthorized access to your account has been detected

[0608] Message information transfer and analysis

[0609] The terminal sends the extracted message information to the server. The server forwards the received information to an automated artificial intelligence system. This system evaluates the likelihood of fraud based on the message information. For example, the system extracts keywords such as "unauthorized account access" and "example.com" from the message body and header information and performs a search on the internet.

[0610] For example, if keywords such as "unauthorized access to an account" and "example.com" are extracted, and numerous similar fraud reports and warnings are found on the internet, it will be determined that there is a possibility of fraud.

[0611] Determining the possibility of fraud

[0612] The server receives and analyzes search results from an automated artificial intelligence system. If the analysis reveals numerous fraud reports or warnings, the server scores the likelihood of fraud. For example, if the search results indicate that "example.com" is included in a list of malicious domains, its score will be high.

[0613] Generating warning information

[0614] If the server determines that there is a high probability of fraud, it will generate an HTML-formatted warning message to alert the user. For example, the following HTML content will be generated:

[0615] html

[0616]

[0617]

[0618] <h2> Caution: This may be a phishing email.< / h2>

[0619] The following email is likely a scam. Do not click on the link.

[0620] Sender: 12345

[0621] Subject: (Urgent) Unauthorized access to your account has been detected

[0622] Text: Click the following link to verify your account: http: / / example.com

[0623]

[0624]

[0625] User notifications

[0626] After the warning HTML is generated, the server sends this information to the device. The device displays the received HTML to the user. This display allows the user to recognize that the received message is likely fraudulent and avoid the risk of clicking the link.

[0627] For example, the risk of a user unknowingly clicking on a link like "http: / / example.com" is reduced. In this way, users are protected from becoming victims of fraud.

[0628] As an example of a prompt, the following text can be input to the generating AI model:

[0629] Please check if messages containing phrases like "unauthorized access to your account" or "example.com" are likely to be phishing emails, and generate a warning if they are.

[0630] As described above, this invention provides a system that automatically identifies fraudulent messages sent via carrier email and short message services, and promptly and appropriately warns users, thereby preventing damage from fraud.

[0631] The flow of the specific processing in Example 1 will be explained using Figure 11.

[0632] Step 1:

[0633] The device receives messages sent via carrier email or short message service. These messages include sender information, subject, and body text, which serve as input data.

[0634] Specifically, consider the following message as an example:

[0635] From: 12345

[0636] Subject: (Urgent) Unauthorized access to your account has been detected

[0637] Body: Please click the following link to verify your account: http: / / example.com

[0638] The device receives this message in its original format.

[0639] Step 2:

[0640] The terminal extracts the message body and header information (sender, subject, etc.) from the received message information. The input data is the entire message received in step 1.

[0641] As for specific data processing, the following information will be extracted and output from the message:

[0642] Message body: Please click the following link to verify your account: http: / / example.com

[0643] Sender: 12345

[0644] Subject: (Urgent) Unauthorized access to your account has been detected

[0645] Step 3:

[0646] The terminal sends the extracted message information (body and header information) to the server. The input data is the data extracted in step 2, which is packaged into a packet and sent to the server.

[0647] Specifically, the device sends the following data to the server over the network:

[0648] {

[0649] "Body text": "Click the following link to verify your account: http: / / example.com",

[0650] "Sender": "12345",

[0651] Subject: (Urgent) Unauthorized access to your account has been detected.

[0652] }

[0653] Step 4:

[0654] The server forwards the received message information to the automated artificial intelligence system. The input data is the data received in step 3.

[0655] The server analyzes the data, extracts the necessary keywords, and passes them directly to the automated generation artificial intelligence system.

[0656] For example, extract and submit the following keywords:

[0657] Keywords: ["Unauthorized access to an account", "example.com"]

[0658] Step 5:

[0659] The automated artificial intelligence system performs a web search based on the received keywords and evaluates the likelihood of fraud. The input data is the keywords submitted in step 4.

[0660] The automated artificial intelligence system collects reports and warnings about fraud from the web, scores the likelihood of fraud, and outputs the results.

[0661] For example, the following scoring results will be output:

[0662] Score: 85 (Highly likely to be a scam)

[0663] Step 6:

[0664] The server receives scoring results from an automatically generated artificial intelligence system and generates a warning if it determines that there is a high probability of fraud. The input data is the scoring results obtained in step 5.

[0665] Based on this, a warning message in HTML format is generated and output.

[0666] Specifically, the following content will be generated:

[0667] html

[0668]

[0669]

[0670] <h2> Caution: This may be a phishing email.< / h2>

[0671] The following email is likely a scam. Do not click on the link.

[0672] Sender: 12345

[0673] Subject: (Urgent) Unauthorized access to your account has been detected

[0674] Text: Click the following link to verify your account: http: / / example.com

[0675]

[0676]

[0677] Step 7:

[0678] The server sends the generated alert information to the terminal. The input data is the HTML-formatted alert information generated in step 6.

[0679] Specifically, the server sends this information to the terminal via the network.

[0680] Step 8:

[0681] The terminal displays the received alert information to the user. The input data is HTML-formatted information received from the server in step 7.

[0682] Specifically, the terminal displays the received HTML on the user interface and issues a warning to the user.

[0683] This allows users to identify potentially fraudulent messages and choose to take action, such as not clicking on links.

[0684] By coordinating the above specific actions, the system of the present invention can prevent damage from fraud.

[0685] (Application Example 1)

[0686] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."

[0687] Messages received via carrier email or short message services may contain malicious content designed to lure users into fraud, putting them at risk of becoming victims. A system is needed to quickly identify such fraudulent messages and warn users. However, conventional methods have struggled to evaluate message content in real time and provide appropriate warnings. Therefore, the challenge lies in providing a system that automatically evaluates the fraudulent nature of messages received by users and delivers necessary warnings quickly and effectively.

[0688] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.

[0689] In this invention, the server includes means for receiving the body and header information of messages received via carrier email or short message service; means for extracting the received message information; means for transmitting the extracted message information to a central processing unit; means for transmitting the message information to an artificial intelligence system automatically generated by the central processing unit for evaluating the message information; means for the automatically generated artificial intelligence system to perform a web search based on the message information and evaluate the likelihood of fraud; means for receiving the evaluation results; means for generating warning information if there is a high possibility of fraud; means for transmitting the generated warning information to a terminal; means for displaying the transmitted warning information to the user; and means implemented as a smartphone application for receiving and evaluating messages and notifying the user. This makes it possible to automatically evaluate the fraudulent nature of messages received by the user and provide necessary warnings quickly and effectively.

[0690] "Carrier email" refers to the email service provided by mobile phone carriers.

[0691] "Short Message Service" refers to a service that allows users to send and receive short messages using a mobile phone network.

[0692] "Message body" refers to the main content portion of a message that a user sends or receives.

[0693] "Header information" refers to metadata attached to a message, such as the sender and subject.

[0694] "Means of receiving" refers to functions and devices for obtaining messages via carrier email or short message service.

[0695] "Means of extraction" refers to functions or devices that extract and separate the message body and header information.

[0696] A "central processing unit" refers to a computer system used to analyze and process received message data.

[0697] An "automatically generated artificial intelligence system" refers to machine learning models or algorithms trained to analyze message information and assess the likelihood of fraud.

[0698] "Means of performing a web search" refers to functions or devices that search for keywords on the internet and obtain related information.

[0699] "Means of assessing the possibility of fraud" refers to functions or devices that determine whether a received message has an illegitimate purpose based on its content.

[0700] "Means of receiving evaluation results" refers to functions or devices that receive analysis results from artificial intelligence systems.

[0701] "Warning information" refers to information intended to alert users that a message is highly likely to be a scam.

[0702] "Means of generation" refers to functions or devices that create warning messages when a situation is deemed highly likely to be fraudulent.

[0703] "Terminal" refers to devices such as smartphones and tablets that are directly operated by the user.

[0704] A "smartphone application" refers to a dedicated software program that runs on a smartphone.

[0705] This invention is a system that automatically evaluates the fraudulent nature of messages received via carrier email or short message service and alerts the user if necessary, and is implemented as a smartphone application.

[0706] Configuration and Operation Overview

[0707] Receiving and extracting messages

[0708] The device (smartphone) receives the body and header information of messages received via carrier email or short message service. A dedicated application running on the smartphone handles this task. For example, suppose the following message is received:

[0709] From: 12345

[0710] Subject: (Urgent) Unauthorized access to your account has been detected

[0711] Body: Please click the following link to verify your account: http: / / example.com

[0712] The terminal extracts the message body and header information.

[0713] Message analysis

[0714] The extracted message information is sent from the terminal to the server. The server receives the message information and forwards it to an automatically generated artificial intelligence system. This AI system performs an evaluation to assess the likelihood of fraud based on the message information. Specifically, it extracts keywords from the message body and header information and searches the internet for related information based on those keywords. For example, keywords such as "unauthorized account access" and "example.com" may be extracted. This method allows the system to check the search results to see if there are many reports or warnings of similar fraudulent emails.

[0715] Determination and notification of potential fraud

[0716] The server receives results from an automatically generated artificial intelligence system and scores the likelihood of fraud. Based on this scoring, it determines whether the situation is likely to be fraudulent. If it is determined to be likely to be fraudulent, the server generates an HTML-formatted warning message to alert the user. The generated warning message will contain the following information:

[0717] html

[0718]

[0719]

[0720] <h2> Caution: This may be a phishing email.< / h2>

[0721] The following email is likely a scam. Do not click on the link.

[0722] Sender: 12345

[0723] Subject: (Urgent) Unauthorized access to your account has been detected

[0724] Text: Click the following link to verify your account: http: / / example.com

[0725]

[0726]

[0727] This information will be notified to the user via a smartphone application.

[0728] The technologies used

[0729] The following technologies will be used to implement this system:

[0730] Smartphone application: A dedicated software program designed to run on a smartphone. Kotlin (Android) and Swift (iOS) are commonly used.

[0731] Cloud server: A server that processes message information and returns evaluation results. Python and Flask (web framework) are used.

[0732] Artificial intelligence system: Machine learning models and algorithms for analyzing message information and assessing the likelihood of fraud. TensorFlow and BeautifulSoup are used.

[0733] Database: A database for storing message data. PostgreSQL is used.

[0734] Specific example

[0735] Consider a scenario where a user receives the following message:

[0736] Example of a prompt:

[0737] Message body: Please click the following link to verify your account: http: / / example.com

[0738] Sender: 12345

[0739] Subject: (Urgent) Unauthorized access to your account has been detected

[0740] Based on this prompt, the artificial intelligence system evaluates the message's fraudulent nature and, if it determines it is highly likely to be fraudulent, displays a warning to the user. This system reduces the risk of users clicking on suspicious links and protects them from becoming victims of fraud.

[0741] The flow of a specific process in Application Example 1 will be explained using Figure 12.

[0742] Step 1:

[0743] The device (smartphone) receives messages via carrier email or short message service. The body and header information (sender, subject, etc.) of the received message are extracted. Specifically, a dedicated application analyzes the message content and extracts the necessary information. The input is the received message data, and the output is the extracted body and header information.

[0744] Step 2:

[0745] The terminal sends the extracted message information to the server. The input is the extracted message information, and the output is the data sent to the server. A dedicated communication protocol is used to transmit the data.

[0746] Step 3:

[0747] The server sends the received message information to an automatically generated artificial intelligence system. The input is the received message information, and the output is the data passed to the AI ​​system. A Python script is used to transfer the data to the AI ​​model.

[0748] Step 4:

[0749] An automatically generated artificial intelligence system extracts keywords from message information and performs a web search. The input is message information, and the output is search results. Specifically, it uses TensorFlow for keyword extraction and BeautifulSoup to collect relevant information from the internet.

[0750] Step 5:

[0751] The server scores the likelihood of fraud based on the search results. The input is the search results, and the output is the fraud score. The AI ​​model learns patterns of fraudulent activity based on past data and calculates the score accordingly.

[0752] Step 6:

[0753] The server receives a fraud score and generates HTML-formatted information to alert users if there is a high probability of fraud. The input is the fraud score, and the output is a warning message. A Python script is used to generate the HTML document.

[0754] Step 7:

[0755] The server sends generated alert information to the terminal. The input is the alert information, and the output is the warning message sent to the terminal. A dedicated communication protocol is used to transmit the data.

[0756] Step 8:

[0757] The terminal displays received warning information to the user. The input is the received warning message, and the output is the warning information displayed to the user. A dedicated application presents the warning message to the user in HTML format.

[0758] Through these processing flows, users can evaluate suspicious messages in real time and receive appropriate warnings to prevent fraud.

[0759] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.

[0760] This invention is a system for automatically evaluating the fraudulent nature of messages received via carrier email and short message services, and for alerting users as necessary. The system of this invention mainly consists of three elements: a terminal, a server, and a user. Furthermore, by incorporating an emotion engine that recognizes the user's emotions and adjusts its response accordingly, it can more effectively prevent damage from fraudulent emails.

[0761] Receiving and extracting emails

[0762] The device receives new messages that have arrived via carrier email or short message service. For example, consider the following message:

[0763] From: 12345

[0764] Subject: (Urgent) Unauthorized access to your account has been detected

[0765] Body: Please click the following link to verify your account: http: / / example.com

[0766] The terminal extracts the message body and header information (sender, subject, etc.). This allows the message content and its associated metadata to be separated and extracted.

[0767] Message analysis

[0768] The extracted message information is sent from the terminal to the server. The server receives this information and forwards it to an automated artificial intelligence system. This system performs a web search to assess the likelihood of fraud based on the message information.

[0769] The automated artificial intelligence system extracts keywords from the message body and header information, and then searches the internet for related information based on those keywords. For example, it might extract keywords such as "unauthorized account access" and "example.com". In this way, the search results confirm that there are numerous reports and warnings of similar phishing emails.

[0770] Determination and notification of potential fraud

[0771] The server receives results from an automated artificial intelligence system and scores the likelihood of fraud. Based on this scoring, it determines whether the information is likely to be fraudulent.

[0772] If a message is determined to be highly likely to be fraudulent, the server generates a warning. This information, in HTML format, includes the sender, subject, and body of the received message, as well as a notice indicating the possibility of fraud. For example, the following warning information may be generated:

[0773] html

[0774]

[0775]

[0776] <h2> Caution: This may be a phishing email.< / h2>

[0777] The following email is likely a scam. Do not click on the link.

[0778] Sender: 12345

[0779] Subject: (Urgent) Unauthorized access to your account has been detected

[0780] Text: Click the following link to verify your account: http: / / example.com

[0781]

[0782]

[0783] Adjusting responses using an emotional engine

[0784] Before sending the generated alert information, the emotion engine recognizes the user's emotions. The emotion engine determines the user's emotions by analyzing the user's facial expressions, tone of voice, input patterns, etc. Based on the recognized emotions, it adjusts the content and display method of the alert information.

[0785] For example, if a user indicates stress or anxiety, the server will provide additional support information and guidance. Specifically, it might display a message such as, "This email may be a scam. Please remain calm. If you have any questions, please contact our support center."

[0786] User notifications

[0787] The server sends the generated warning HTML to the device. The device displays the received HTML to the user. This display allows the user to recognize that the received message is likely to be fraudulent and to avoid taking actions such as clicking on links.

[0788] For example, the risk of a user unknowingly clicking on a link like "http: / / example.com" is reduced. In this way, users are protected from becoming victims of fraud.

[0789] As described above, this invention provides a system that automatically identifies fraudulent messages sent via carrier email and short message services, and promptly and appropriately warns users, thereby preventing damage from fraud. Furthermore, by using an emotion engine, it can respond in a way that takes the user's emotions into consideration, thereby protecting users more effectively.

[0790] The following describes the processing flow.

[0791] Step 1:

[0792] The device receives new messages that have arrived via carrier email or short message service. For example, suppose a message like the following is received:

[0793] From: 12345

[0794] Subject: (Urgent) Unauthorized access to your account has been detected

[0795] Body: Please click the following link to verify your account: http: / / example.com

[0796] Step 2:

[0797] The terminal extracts the body and header information (sender, subject, etc.) of the received message. Specifically, it retrieves information such as "From: 12345", "Subject: (Urgent) Unauthorized access to your account has been detected", and "Body: Click the link below to verify your account: http: / / example.com".

[0798] Step 3:

[0799] The terminal sends the extracted message information to the server. It uses communication methods such as HTTP POST requests to send the message information to the server.

[0800] Step 4:

[0801] The server forwards the received message information to the automated artificial intelligence system. The system converts the message information into a format that it can process and then makes an API call.

[0802] Step 5:

[0803] The automated artificial intelligence system extracts keywords from the message body and header information. For example, it extracts keywords such as "unauthorized access to account" and "example.com".

[0804] Step 6:

[0805] The automated artificial intelligence system performs a web search based on extracted keywords. This search is conducted on the internet, gathering information on similar messages.

[0806] Step 7:

[0807] The automated artificial intelligence system evaluates web search results and scores their likelihood of being a scam. This includes similar scam reports and risk assessments.

[0808] Step 8:

[0809] The server receives results from an automatically generated artificial intelligence system and determines whether there is a high probability of fraud based on a scoring system. For example, if the score exceeds a certain level, it is determined to be "highly likely to be a phishing email."

[0810] Step 9:

[0811] If a message is determined to be highly likely to be a scam, the server generates a warning. This information is in HTML format and includes the sender, subject, and body of the received message, as well as a notice indicating the possibility of fraud.

[0812] Step 10:

[0813] The server sends the generated alert HTML to the device.

[0814] Step 11:

[0815] The device activates the emotion engine before displaying the received alert HTML. The emotion engine provides a means to analyze and recognize the user's emotions. The emotion engine analyzes the user's facial expressions, voice tone, input patterns, etc., and evaluates the user's emotional state.

[0816] Step 12:

[0817] If the emotion engine detects that a user is exhibiting stress or anxiety, the server adjusts the content and display of the alert information. For example, it may include more detailed explanations or additional support.

[0818] Step 13:

[0819] The device displays a customized warning HTML to the user. This display allows the user to recognize the risk of receiving a phishing email and understand how to deal with it safely.

[0820] Step 14:

[0821] Users can check the warning HTML displayed on their device and recognize that the received message is likely to be fraudulent. This allows them to avoid actions such as clicking on links.

[0822] This series of steps not only protects users from phishing emails, but also provides more user-friendly warnings and support through the workings of an emotion engine.

[0823] (Example 2)

[0824] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".

[0825] The risk of receiving fraudulent messages via email and short message services remains high. Many users fall victim to these messages, partly due to the lack of systems that accurately identify and quickly warn against fraudulent messages. Another problem is that the inability to respond appropriately to users' emotions leads to panic and an inability to take appropriate action.

[0826] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.

[0827] In this invention, the server includes means for receiving the body and header information of messages received via carrier email or short message service, means for extracting the received message information, means for transmitting the extracted message information to a central processing unit, means for transmitting the message information to an automatically generated artificial intelligence system, means for the automatically generated artificial intelligence system to perform a web search based on the message information and evaluate the possibility of fraud, means for receiving the evaluation results, means for generating warning information if there is a high possibility of fraud, means for transmitting the generated warning information to a terminal, means for displaying the transmitted warning information to the user, and an emotion engine that recognizes the user's emotions and adjusts the content and display method of the warning information. This makes it possible to automatically identify fraudulent messages and issue warnings to users quickly and accurately. Furthermore, because appropriate responses can be taken according to the user's emotional state, users can receive information with peace of mind.

[0828] "Carrier email" refers to the email service provided by mobile phone carriers.

[0829] "Short Message Service" refers to a service that allows users to send and receive short text messages using their mobile phones.

[0830] "Message body" refers to the main text content included in carrier emails and short message services.

[0831] "Header information" refers to metadata such as the sender and recipient of a message, the subject, and the date and time it was sent.

[0832] A "terminal" refers to an electronic device that receives and sends carrier emails and short message services.

[0833] A "central processing unit" refers to a computer device that controls and processes data for the entire system.

[0834] An "automatic generation artificial intelligence system" refers to a system that uses artificial intelligence technology to analyze information and make decisions.

[0835] "Web search" refers to the act of using the internet to search for information related to specific keywords or topics.

[0836] "Potential fraud" refers to the probability that the received message is fraudulent or not.

[0837] "Warning information" refers to messages intended to inform users of specific risks or warnings.

[0838] An "emotion engine" refers to a system that recognizes a user's emotional state and adjusts responses and message content based on that state.

[0839] "HTML format" refers to a document format that uses the hypertext markup language.

[0840] This invention is a system for automatically evaluating the fraudulent nature of messages received via carrier email and short message services, and for alerting users as necessary. The system of this invention mainly consists of three elements: a terminal, a server, and a user. Furthermore, by incorporating an emotion engine that recognizes the user's emotions and adjusts its response accordingly, it can more effectively prevent damage from fraudulent emails.

[0841] Receiving and extracting emails

[0842] The device receives new messages that have arrived via carrier email or short message service. For example, consider the following message:

[0843] From: 12345

[0844] Subject: (Urgent) Unauthorized access to your account has been detected

[0845] Body: Please click the following link to verify your account: http: / / example.com

[0846] The terminal extracts the message body and header information (sender, subject, etc.). This allows the message content and its associated metadata to be separated and extracted.

[0847] Message analysis

[0848] The extracted message information is sent from the terminal to the server. The server receives this information and forwards it to an automated artificial intelligence system. This system performs a web search to assess the likelihood of fraud based on the message information.

[0849] The automated artificial intelligence system extracts keywords from the message body and header information, and then searches the internet for related information based on those keywords. For example, it might extract keywords such as "unauthorized account access" and "example.com". In this way, the search results confirm that there are numerous reports and warnings of similar phishing emails.

[0850] Determination and notification of potential fraud

[0851] The server receives results from an automated artificial intelligence system and scores the likelihood of fraud. Based on this scoring, it determines whether the information is likely to be fraudulent.

[0852] If a message is determined to be highly likely to be fraudulent, the server generates a warning. This information, in HTML format, includes the sender, subject, and body of the received message, as well as a notice indicating the possibility of fraud. For example, the following warning information may be generated:

[0853] html

[0854]

[0855]

[0856] <h2> Caution: This may be a phishing email.< / h2>

[0857] The following email is likely a scam. Do not click on the link.

[0858] Sender: 12345

[0859] Subject: (Urgent) Unauthorized access to your account has been detected

[0860] Text: Click the following link to verify your account: http: / / example.com

[0861]

[0862]

[0863] Adjusting responses using an emotional engine

[0864] Before sending the generated alert information, the emotion engine recognizes the user's emotions. The emotion engine determines the user's emotions by analyzing the user's facial expressions, tone of voice, input patterns, etc. Based on the recognized emotions, it adjusts the content and display method of the alert information.

[0865] For example, if a user indicates stress or anxiety, the server will provide additional support information and guidance. Specifically, it might display a message such as, "This email may be a scam. Please remain calm. If you have any questions, please contact our support center."

[0866] User notifications

[0867] The server sends the generated warning HTML to the device. The device displays the received HTML to the user. This display allows the user to recognize that the received message is likely to be fraudulent and to avoid taking actions such as clicking on links.

[0868] A concrete example would be inputting the following prompt into an automated AI model:

[0869] To assess the likelihood of a scam message regarding unauthorized access to your account, search the internet for information and check for similar scam reports. Keywords to look for are "unauthorized account access" and "example.com".

[0870] Using this prompt, an automated artificial intelligence system performs an internet search and evaluates the likelihood of fraud.

[0871] As described above, this invention provides a system that automatically identifies fraudulent messages sent via carrier email and short message services, and promptly and appropriately warns users, thereby preventing damage from fraud. Furthermore, by using an emotion engine, it can respond in a way that takes the user's emotions into consideration, thereby protecting users more effectively.

[0872] The flow of the specific processing in Example 2 will be explained using Figure 13.

[0873] Step 1: Receiving emails

[0874] The device monitors and receives new messages in carrier email and short message service (SMS) in real time. This monitoring utilizes services such as the notification listener service of the Android OS. When a new message arrives, the device immediately retrieves the information.

[0875] Input: Messages sent via carrier email or SMS

[0876] Output: Received message data

[0877] Specific operation: When a new message is sent, the terminal immediately captures its metadata and text content.

[0878] Step 2: Message Extraction

[0879] The terminal analyzes and extracts the body and header information (sender, subject, etc.) of the received message. This includes, for example, using regular expressions to analyze the email sender and subject according to a specific format.

[0880] Input: Received message data

[0881] Output: Header information of the extracted message (sender, subject), body.

[0882] Specific operation: The terminal uses regular expressions to extract the sender's address, subject, and body. For example, it identifies fields such as "From:" and "Subject:" and retrieves their values.

[0883] Step 3: Send message information

[0884] The terminal sends the extracted message information (sender, subject, and body) to the server. This transmission uses an HTTP POST request. The server receives this information and proceeds to the next processing step.

[0885] Input: Header information and body of the extracted message

[0886] Output: Sending message information to the server

[0887] Specific operation: The terminal generates an HTTP POST request and sends message information to the server. The request is constructed including the destination URL and authentication information.

[0888] Step 4: Analyze message information

[0889] The server forwards the received message information to an automated artificial intelligence system (e.g., a BERT or GPT model). This system extracts keywords from the message information to assess the likelihood of fraud and performs a web search based on these keywords.

[0890] Input: Message information sent to the server

[0891] Output: Search results and related information to assess the likelihood of fraud.

[0892] Specific operation: The automated artificial intelligence system extracts specific keywords from the body and header information of received messages. This is done using natural language processing techniques. Next, it uses these keywords to perform a web search on the internet and collect relevant information.

[0893] Step 5: Determining the possibility of fraud

[0894] The server scores the likelihood of fraud based on search results and related information from an automatically generated artificial intelligence system. This scoring uses a continuous scale, for example, ranging from 0 to 1, with a score of 0.7 or higher indicating a high probability of fraud.

[0895] Input: Search results and related information from an automatically generated artificial intelligence system.

[0896] Output: Fraud Probability Score

[0897] Specific operation: The server scores the search results based on factors such as frequency of results, the degree of matching with past fraud databases, and warning information, and assesses the likelihood of fraud.

[0898] Step 6: Generating a warning message

[0899] If a message is determined to be highly likely to be a scam, the server generates a warning in HTML format. This information includes the sender, subject, and body of the received message, as well as a notification indicating the possibility of fraud.

[0900] Input: Message information and score that are likely to be fraudulent.

[0901] Output: HTML document containing a warning message.

[0902] Specific operation: The server uses a template engine to generate a warning message in HTML format. For example, it might insert text such as, "This may be a scam. Do not click the link."

[0903] Step 7: Adjusting responses using the emotional engine

[0904] Before sending the generated alert information, the emotion engine recognizes the user's emotions. The emotion engine analyzes the user's facial expressions, tone of voice, input patterns, etc., to determine the user's emotions. Based on the recognized emotions, the content and display method of the alert information are adjusted.

[0905] Input: User emotional data (facial expressions, voice tone, input patterns)

[0906] Output: Adjusted warning information

[0907] Specific operation: The emotion engine uses the camera and microphone to analyze the user's emotional state in real time, and if the user shows signs of anxiety, it provides additional supportive information.

[0908] Step 8: User Notifications

[0909] The server sends the generated warning HTML to the device. The device receives this HTML and displays it to the user. This display allows the user to recognize the risk of fraud and avoid actions such as clicking on links.

[0910] Input: Warning HTML from the server

[0911] Output: Warning information displayed to the user

[0912] Specific operation: The device displays the received HTML to the user using WebView or browser components, visually conveying the warning content.

[0913] This allows users to take appropriate action against fraudulent messages and prevent becoming a victim. For example, users can avoid becoming a victim of fraud by not clicking on links such as "http: / / example.com".

[0914] (Application Example 2)

[0915] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."

[0916] In recent years, fraudulent activities using carrier email and short message services have become rampant, and effective countermeasures are needed. Furthermore, in autonomous vehicles, it is difficult to take appropriate measures when passengers receive fraudulent messages. In addition, there is a need for responses that take into account the emotional state of passengers in response to fraudulent messages, but such systems do not yet exist. To solve these problems, a system is needed that evaluates messages and takes appropriate responses based on the emotions involved.

[0917] In Application Example 2, the identification processing by the identification processing unit 290 of the data processing device 12 is realized by the following means. In this invention, the server includes means for receiving the body and header information of messages received via carrier mail or short message service, means for extracting the received message information, means for transmitting the extracted message information to a central processing device, means for transmitting the message information to an automatically generated artificial intelligence system for the central processing device to evaluate the message information, means for the automatically generated artificial intelligence system to perform a web search based on the message information and evaluate the possibility of fraud, means for receiving the evaluation results, means for generating warning information if there is a high possibility of fraud, means for transmitting the generated warning information to a terminal, means for displaying the transmitted warning information to the user, means for recognizing the user's emotions and adjusting the response, and means for coordinating with the in-vehicle information system of an autonomous vehicle to evaluate the fraudulent nature of messages received by passengers in the vehicle and notify them. This makes it possible to efficiently evaluate the fraudulent nature of messages received by passengers and provide appropriate warnings. Furthermore, by adjusting the response based on the passenger's emotional state, it becomes possible to effectively prevent fraud damage.

[0918] "Carrier email" refers to email services provided by telecommunications carriers, and is typically sent and received using mobile phones or smartphones.

[0919] Short Message Service (SMS) is a communication service that allows users to send and receive short messages via mobile phones and smartphones.

[0920] "Message body" refers to the actual content written in carrier emails and short message services.

[0921] "Message header information" refers to the part of the message that contains information related to its management, such as the sender, recipient, subject, date and time, etc.

[0922] A "central processing unit" is the central part of a computer system that performs data processing. It receives data from other systems and devices, and then analyzes and makes decisions based on that data.

[0923] An "automatic generation artificial intelligence system" is a system that uses artificial intelligence technology to automatically generate and analyze data.

[0924] "Web search" refers to the act of finding information on the internet using a search engine.

[0925] "Potential fraud" refers to the possibility that a message could be used for malicious purposes, such as fraudulent activities.

[0926] "Warning information" is information intended to alert users and is presented when there is a possibility of fraud.

[0927] A "terminal" refers to an information device that the user directly operates, and includes personal computers, smartphones, tablets, and other similar devices.

[0928] A "user" refers to a person who uses this system.

[0929] "Means of recognizing emotions" refer to methods and technologies for analyzing a user's facial expressions, tone of voice, etc., to understand their emotional state.

[0930] An "autonomous vehicle" is a vehicle that has the function to drive itself without a human driver.

[0931] An "in-vehicle information system" refers to an information processing system installed in a vehicle, providing functions such as navigation, entertainment, and communication.

[0932] This invention is a system that automatically evaluates the fraudulent nature of messages received via carrier email or short message service and alerts the user as needed. In particular, it works in conjunction with the in-vehicle information system of autonomous vehicles to evaluate the likelihood of fraud in messages received by passengers in the vehicle and provide a response that takes the user's feelings into consideration.

[0933] Receiving and extracting emails

[0934] The device receives new messages via carrier email or short message service. For example, consider the following message:

[0935] From: 12345

[0936] Subject: (Urgent) Unauthorized access to your account has been detected

[0937] Body: Click the following link to verify your account: http: / / example.com

[0938] The terminal extracts the message body and header information (sender, subject, etc.). This allows the message content and its associated metadata to be separated and extracted.

[0939] Analysis and evaluation of message information

[0940] The extracted message information is sent from the terminal to the central processing unit. The central processing unit receives this information and forwards it to the automated artificial intelligence system. The automated artificial intelligence system performs a web search to evaluate the likelihood of fraud based on the message information.

[0941] The automated artificial intelligence system extracts keywords from the message body and header information, and then searches the internet for related information based on those keywords. For example, it might extract keywords such as "unauthorized account access" and "example.com". In this way, the search results confirm that there are numerous reports and warnings of similar phishing emails.

[0942] Determination and notification of potential fraud

[0943] The central processing unit receives results from the automatically generated artificial intelligence system and scores the likelihood of fraud. Based on this scoring, it determines whether the likelihood of fraud is high.

[0944] If a message is determined to be highly likely to be fraudulent, the central processing unit generates a warning. This information, in HTML format, includes the sender, subject, and body of the received message, as well as a notification indicating the possibility of fraud. For example, the following warning information may be generated:

[0945] html

[0946]

[0947]

[0948] <h2> Caution: This may be a phishing email.< / h2>

[0949] The following email is likely a scam. Do not click on the link.

[0950] Sender: 12345

[0951] Subject: (Urgent) Unauthorized access to your account has been detected

[0952] Text: Click the following link to verify your account: http: / / example.com

[0953]

[0954]

[0955] Adjusting responses using an emotional engine

[0956] Before sending the generated alert information, the emotion engine recognizes the user's emotions. The emotion engine determines the user's emotions by analyzing the user's facial expressions, tone of voice, input patterns, etc. Based on the recognized emotions, the content and display method of the alert information are adjusted. For example, if the user is showing signs of stress or anxiety, the central processing unit provides additional support information and guidance. Specifically, it might display a message such as, "This email may be a scam. Please remain calm. If you have any questions, please contact our support center."

[0957] User notifications

[0958] The central processing unit sends the generated warning HTML to the terminal. The terminal displays the received HTML to the user. This display allows the user to recognize that the received message is likely to be fraudulent and to avoid actions such as clicking on links. For example, the risk of a user unknowingly clicking on a link such as "http: / / example.com" is reduced. In this way, the user is protected from becoming a victim of fraud.

[0959] Specific example

[0960] If a passenger receives a fraudulent email while in an autonomous vehicle, the system analyzes the message and determines that it is likely to be a scam. At the same time, if the emotion engine detects that the passenger is feeling stressed, it will display a reassuring message such as "Please stay calm and deal with this calmly" as a warning.

[0961] Example of a prompt

[0962] Please evaluate the fraudulent nature of the following message:

[0963] Email sender: 12345

[0964] Subject: (Urgent) Unauthorized access to your account has been detected

[0965] Text: Click the following link to verify your account: http: / / example.com

[0966] Additionally, if the system determines that the user is emotionally unstable, please generate a gentle and reassuring message.

[0967] The flow of a specific process in Application Example 2 will be explained using Figure 14.

[0968] Program processing flow

[0969] Step 1:

[0970] The device receives new messages from carrier email or short message service. The input includes the message body and header information (sender, subject, etc.). Data processing involves extracting the message body and header information. The output is the extracted message information.

[0971] Step 2:

[0972] The terminal transmits the extracted message information to the central processing unit. The extracted message information is required as input. The data processing involves transmitting the information. The output is the message information received by the central processing unit.

[0973] Step 3:

[0974] The central processing unit transmits message information to the automated artificial intelligence system. Its input includes message information received from the terminal. As a data calculation, it reprocesses the message information and transmits it. The output is the message information received by the automated artificial intelligence system.

[0975] Step 4:

[0976] The automated artificial intelligence system performs a web search based on message information and evaluates the likelihood of fraud. The input includes keywords extracted from the message body and header information. Data processing involves keyword extraction and web search. The output is an evaluation of the likelihood of fraud.

[0977] Step 5:

[0978] The central processing unit receives evaluation results from an automatically generated artificial intelligence system and scores the likelihood of fraud. The input includes the evaluation results. The data calculation is performed as a scoring process. The output is a score regarding the likelihood of fraud.

[0979] Step 6:

[0980] If a fraudulent activity is determined to be highly likely, the central processing unit generates a warning. The input includes a score indicating the likelihood of fraud. The data processing generates a warning in HTML format. The output is the generated warning.

[0981] Step 7:

[0982] Before sending the generated alert information, the emotion engine recognizes the user's emotions. Inputs include the user's facial expressions and tone of voice. The data calculation involves emotion recognition. The output is the recognized emotional state of the user.

[0983] Step 8:

[0984] The system adjusts the content and display method of alert information based on the user's emotions recognized by the emotion engine. Input includes the recognized emotional state and alert information. Data processing involves adjusting the information. Output is the adjusted alert information.

[0985] Step 9:

[0986] The central processing unit transmits the adjusted alert information to the terminal. The input includes the adjusted alert information. The data processing involves transmitting the information. The output is the adjusted alert information received by the terminal.

[0987] Step 10:

[0988] The device displays the received, adjusted alert information to the user. The input includes the adjusted alert information. The data calculation process displays the information. The output is the alert information displayed to the user. This allows the user to recognize that the received message is likely fraudulent and take appropriate action.

[0989] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.

[0990] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[0991] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the smart glasses 214.

[0992] [Third Embodiment]

[0993] Figure 5 shows an example of the configuration of the data processing system 310 according to the third embodiment.

[0994] As shown in Figure 5, the data processing system 310 includes a data processing device 12 and a headset terminal 314. An example of the data processing device 12 is a server.

[0995] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0996] The headset terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a display 343. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and display 343 are also connected to the bus 52.

[0997] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.

[0998] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).

[0999] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.

[1000] Figure 6 shows an example of the main functions of the data processing device 12 and the headset terminal 314. As shown in Figure 6, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.

[1001] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[1002] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[1003] In the headset terminal 314, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.

[1004] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the headset terminal 314 will be referred to as the "terminal".

[1005] This invention is a system for automatically evaluating the fraudulent nature of messages received via carrier email or short message service and, if necessary, alerting the user. The system of this invention mainly consists of three elements: a terminal, a server, and a user.

[1006] Receiving and extracting emails

[1007] The device receives messages sent to carrier email or short message service. For example, suppose the following message is received:

[1008] From: 12345

[1009] Subject: (Urgent) Unauthorized access to your account has been detected

[1010] Body: Please click the following link to verify your account: http: / / example.com

[1011] The terminal extracts the message body and header information (sender, subject, etc.). This allows the message content and its associated metadata to be separated and extracted.

[1012] Message analysis

[1013] The extracted message information is sent from the terminal to the server. The server receives this information and forwards it to an automated artificial intelligence system. This system performs a web search to assess the likelihood of fraud based on the message information.

[1014] The automated artificial intelligence system extracts keywords from the message body and header information, and then searches the internet for related information based on those keywords. For example, it might extract keywords such as "unauthorized account access" and "example.com". In this way, the search results confirm that there are numerous reports and warnings of similar phishing emails.

[1015] Determination and notification of potential fraud

[1016] The server receives results from an automated artificial intelligence system and scores the likelihood of fraud. Based on this scoring, it determines whether the information is likely to be fraudulent.

[1017] If the server determines that there is a high probability of fraud, it will generate an HTML-formatted warning message to alert the user. The generated warning message will contain the following information:

[1018] html

[1019]

[1020]

[1021] <h2> Caution: This may be a phishing email.< / h2>

[1022] The following email is likely a scam. Do not click on the link.

[1023] Sender: 12345

[1024] Subject: (Urgent) Unauthorized access to your account has been detected

[1025] Text: Click the following link to verify your account: http: / / example.com

[1026]

[1027]

[1028] User notifications

[1029] The server sends the generated warning HTML to the device. The device displays the received HTML to the user. This display allows the user to recognize that the received message is likely to be fraudulent and to avoid taking actions such as clicking on links.

[1030] For example, the risk of a user unknowingly clicking on a link like "http: / / example.com" is reduced. In this way, users are protected from becoming victims of fraud.

[1031] As described above, this invention provides a system that automatically identifies fraudulent messages sent via carrier email and short message services, and promptly and appropriately warns users, thereby preventing damage from fraud.

[1032] The following describes the processing flow.

[1033] Step 1:

[1034] The device receives new messages that have arrived via carrier email or short message service. For example, consider a message with the following content.

[1035] From: 12345

[1036] Subject: (Urgent) Unauthorized access to your account has been detected

[1037] Body: Please click the following link to verify your account: http: / / example.com

[1038] Step 2:

[1039] The device extracts the message body and header information (sender, subject, etc.) from the received message. Specifically, it retrieves information such as "From: 12345", "Subject: (Urgent) Unauthorized access to your account has been detected", and "Body: Click the link below to verify your account: http: / / example.com".

[1040] Step 3:

[1041] The terminal sends the extracted message information to the server. It uses communication methods such as HTTP POST requests to send the message information to the server.

[1042] Step 4:

[1043] The server forwards the received message information to the automated artificial intelligence system. The system converts the message information into a format that it can process and then makes an API call.

[1044] Step 5:

[1045] The automated artificial intelligence system extracts keywords from the message body and header information. For example, it extracts keywords such as "unauthorized access to account" and "example.com".

[1046] Step 6:

[1047] The automated artificial intelligence system performs a web search based on extracted keywords. This search is conducted on the internet, gathering information on similar messages.

[1048] Step 7:

[1049] The automated artificial intelligence system evaluates web search results and scores their likelihood of being a scam. This includes similar scam reports and risk assessments.

[1050] Step 8:

[1051] The server receives results from an automatically generated artificial intelligence system and determines whether there is a high probability of fraud based on a scoring system. For example, if the score exceeds a certain level, it is determined to be "highly likely to be a phishing email."

[1052] Step 9:

[1053] If a message is determined to be highly likely to be a scam, the server generates a warning. This information is in HTML format and includes the sender, subject, and body of the received message, as well as a notice indicating the possibility of fraud.

[1054] Step 10:

[1055] The server sends the generated warning HTML to the device.

[1056] Step 11:

[1057] The device displays the received alert HTML to the user. This display is done through the user interface, warning the user of the danger of the message.

[1058] Step 12:

[1059] Users can check the warning HTML displayed on their device and recognize that the received message is likely to be fraudulent. This allows users to avoid actions such as clicking on links.

[1060] (Example 1)

[1061] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."

[1062] In modern society, fraudulent activities targeting users of carrier email and short message services are on the rise. Consequently, there is a growing need for systems that can reliably detect fraudulent emails and issue prompt and appropriate warnings to users. However, traditional manual methods for detecting fraudulent emails are often ineffective in preventing timely responses and failing to prevent damage. Therefore, there is a demand for automated systems that can quickly detect fraudulent emails and provide appropriate warnings to users.

[1063] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.

[1064] In this invention, the server includes means for receiving the body and header information of messages received via carrier email or short message service, means for extracting the received message information, means for transmitting the extracted message information to a central processing unit, and means for an automatically generated artificial intelligence system to perform a web search based on the message information and evaluate the likelihood of fraud. This enables automatic detection of fraudulent emails and rapid warning.

[1065] "Carrier email" refers to email services provided by telecommunications carriers.

[1066] Short Message Service (SSS) is a communication service for sending and receiving short text messages between mobile devices.

[1067] "Message information" refers to data that includes the body and header information of an email or short message.

[1068] The "main text" refers to the part of the message that describes its main content.

[1069] "Header information" refers to information that includes metadata such as the sender of the message, the subject, and the date and time it was sent.

[1070] "Terminal" refers to an electronic device used by a user, and includes, for example, smartphones and tablets.

[1071] A "server" is a computer system that performs central processing.

[1072] An "automatic generation artificial intelligence system" is a system that uses artificial intelligence technology to analyze the content of messages and assess the likelihood of fraud.

[1073] "Web search" refers to the act of searching for information on the internet using a search engine.

[1074] "Assessing the likelihood of fraud" refers to performing a series of analytical processes to determine whether a message is fraudulent.

[1075] "Warning information" refers to information that warns users about the possibility of receiving a fraudulent email.

[1076] "HTML format" refers to a format that uses HTML, a markup language for describing web pages.

[1077] "User" refers to the general consumer who uses the system.

[1078] This invention is a system for automatically evaluating the fraudulent nature of messages received via carrier email or short message service and, if necessary, alerting the user. The system of this invention mainly consists of three elements: a terminal, a server, and a user.

[1079] Receiving and extracting emails

[1080] The device receives messages sent to carrier email or short message service. For example, suppose the following message is received:

[1081] From: 12345

[1082] Subject: (Urgent) Unauthorized access to your account has been detected

[1083] Body: Please click the following link to verify your account: http: / / example.com

[1084] When such a message arrives, the device extracts the message body and header information (sender, subject, etc.). The extracted data will have the following structure:

[1085] Message body: Please click the following link to verify your account: http: / / example.com

[1086] Sender: 12345

[1087] Subject: (Urgent) Unauthorized access to your account has been detected

[1088] Message information transfer and analysis

[1089] The terminal sends the extracted message information to the server. The server forwards the received information to an automated artificial intelligence system. This system evaluates the likelihood of fraud based on the message information. For example, the system extracts keywords such as "unauthorized account access" and "example.com" from the message body and header information and performs a search on the internet.

[1090] For example, if keywords such as "unauthorized access to an account" and "example.com" are extracted, and numerous similar fraud reports and warnings are found on the internet, it will be determined that there is a possibility of fraud.

[1091] Determining the possibility of fraud

[1092] The server receives and analyzes search results from an automated artificial intelligence system. If the analysis reveals numerous fraud reports or warnings, the server scores the likelihood of fraud. For example, if the search results indicate that "example.com" is included in a list of malicious domains, its score will be high.

[1093] Generating warning information

[1094] If the server determines that there is a high probability of fraud, it will generate an HTML-formatted warning message to alert the user. For example, the following HTML content will be generated:

[1095] html

[1096]

[1097]

[1098] <h2> Caution: This may be a phishing email.< / h2>

[1099] The following email is likely a scam. Do not click on the link.

[1100] Sender: 12345

[1101] Subject: (Urgent) Unauthorized access to your account has been detected

[1102] Text: Click the following link to verify your account: http: / / example.com

[1103]

[1104]

[1105] User notifications

[1106] After the warning HTML is generated, the server sends this information to the device. The device displays the received HTML to the user. This display allows the user to recognize that the received message is likely fraudulent and avoid the risk of clicking the link.

[1107] For example, the risk of a user unknowingly clicking on a link like "http: / / example.com" is reduced. In this way, users are protected from becoming victims of fraud.

[1108] As an example of a prompt, the following text can be input to the generating AI model:

[1109] Please check if messages containing phrases like "unauthorized access to your account" or "example.com" are likely to be phishing emails, and generate a warning if they are.

[1110] As described above, this invention provides a system that automatically identifies fraudulent messages sent via carrier email and short message services, and promptly and appropriately warns users, thereby preventing damage from fraud.

[1111] The flow of the specific processing in Example 1 will be explained using Figure 11.

[1112] Step 1:

[1113] The device receives messages sent via carrier email or short message service. These messages include sender information, subject, and body text, which serve as input data.

[1114] Specifically, consider the following message as an example:

[1115] From: 12345

[1116] Subject: (Urgent) Unauthorized access to your account has been detected

[1117] Body: Please click the following link to verify your account: http: / / example.com

[1118] The device receives this message in its original format.

[1119] Step 2:

[1120] The terminal extracts the message body and header information (sender, subject, etc.) from the received message information. The input data is the entire message received in step 1.

[1121] As for specific data processing, the following information will be extracted and output from the message:

[1122] Message body: Please click the following link to verify your account: http: / / example.com

[1123] Sender: 12345

[1124] Subject: (Urgent) Unauthorized access to your account has been detected

[1125] Step 3:

[1126] The terminal sends the extracted message information (body and header information) to the server. The input data is the data extracted in step 2, which is packaged into a packet and sent to the server.

[1127] Specifically, the device sends the following data to the server over the network:

[1128] {

[1129] "Body text": "Click the following link to verify your account: http: / / example.com",

[1130] "Sender": "12345",

[1131] Subject: (Urgent) Unauthorized access to your account has been detected.

[1132] }

[1133] Step 4:

[1134] The server forwards the received message information to the automated artificial intelligence system. The input data is the data received in step 3.

[1135] The server analyzes the data, extracts the necessary keywords, and passes them directly to the automated generation artificial intelligence system.

[1136] For example, extract and submit the following keywords:

[1137] Keywords: ["Unauthorized access to an account", "example.com"]

[1138] Step 5:

[1139] The automated artificial intelligence system performs a web search based on the received keywords and evaluates the likelihood of fraud. The input data is the keywords submitted in step 4.

[1140] The automated artificial intelligence system collects reports and warnings about fraud from the web, scores the likelihood of fraud, and outputs the results.

[1141] For example, the following scoring results will be output:

[1142] Score: 85 (Highly likely to be a scam)

[1143] Step 6:

[1144] The server receives scoring results from an automatically generated artificial intelligence system and generates a warning if it determines that there is a high probability of fraud. The input data is the scoring results obtained in step 5.

[1145] Based on this, a warning message in HTML format is generated and output.

[1146] Specifically, the following content will be generated:

[1147] html

[1148]

[1149]

[1150] <h2> Caution: This may be a phishing email.< / h2>

[1151] The following email is likely a scam. Do not click on the link.

[1152] Sender: 12345

[1153] Subject: (Urgent) Unauthorized access to your account has been detected

[1154] Text: Click the following link to verify your account: http: / / example.com

[1155]

[1156]

[1157] Step 7:

[1158] The server sends the generated alert information to the terminal. The input data is the HTML-formatted alert information generated in step 6.

[1159] Specifically, the server sends this information to the terminal via the network.

[1160] Step 8:

[1161] The terminal displays the received alert information to the user. The input data is HTML-formatted information received from the server in step 7.

[1162] Specifically, the terminal displays the received HTML on the user interface and issues a warning to the user.

[1163] This allows users to identify potentially fraudulent messages and choose to take action, such as not clicking on links.

[1164] By coordinating the above specific actions, the system of the present invention can prevent damage from fraud.

[1165] (Application Example 1)

[1166] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."

[1167] Messages received via carrier email or short message services may contain malicious content designed to lure users into fraud, putting them at risk of becoming victims. A system is needed to quickly identify such fraudulent messages and warn users. However, conventional methods have struggled to evaluate message content in real time and provide appropriate warnings. Therefore, the challenge lies in providing a system that automatically evaluates the fraudulent nature of messages received by users and delivers necessary warnings quickly and effectively.

[1168] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.

[1169] In this invention, the server includes means for receiving the body and header information of messages received via carrier email or short message service; means for extracting the received message information; means for transmitting the extracted message information to a central processing unit; means for transmitting the message information to an artificial intelligence system automatically generated by the central processing unit for evaluating the message information; means for the automatically generated artificial intelligence system to perform a web search based on the message information and evaluate the likelihood of fraud; means for receiving the evaluation results; means for generating warning information if there is a high possibility of fraud; means for transmitting the generated warning information to a terminal; means for displaying the transmitted warning information to the user; and means implemented as a smartphone application for receiving and evaluating messages and notifying the user. This makes it possible to automatically evaluate the fraudulent nature of messages received by the user and provide necessary warnings quickly and effectively.

[1170] "Carrier email" refers to the email service provided by mobile phone carriers.

[1171] "Short Message Service" refers to a service that allows users to send and receive short messages using a mobile phone network.

[1172] "Message body" refers to the main content portion of a message that a user sends or receives.

[1173] "Header information" refers to metadata attached to a message, such as the sender and subject.

[1174] "Means of receiving" refers to functions and devices for obtaining messages via carrier email or short message service.

[1175] "Means of extraction" refers to functions or devices that extract and separate the message body and header information.

[1176] A "central processing unit" refers to a computer system used to analyze and process received message data.

[1177] An "automatically generated artificial intelligence system" refers to machine learning models or algorithms trained to analyze message information and assess the likelihood of fraud.

[1178] "Means of performing a web search" refers to functions or devices that search for keywords on the internet and obtain related information.

[1179] "Means of assessing the possibility of fraud" refers to functions or devices that determine whether a received message has an illegitimate purpose based on its content.

[1180] "Means of receiving evaluation results" refers to functions or devices that receive analysis results from artificial intelligence systems.

[1181] "Warning information" refers to information intended to alert users that a message is highly likely to be a scam.

[1182] "Means of generation" refers to functions or devices that create warning messages when a situation is deemed highly likely to be fraudulent.

[1183] "Terminal" refers to devices such as smartphones and tablets that are directly operated by the user.

[1184] A "smartphone application" refers to a dedicated software program that runs on a smartphone.

[1185] This invention is a system that automatically evaluates the fraudulent nature of messages received via carrier email or short message service and alerts the user if necessary, and is implemented as a smartphone application.

[1186] Configuration and Operation Overview

[1187] Receiving and extracting messages

[1188] The device (smartphone) receives the body and header information of messages received via carrier email or short message service. A dedicated application running on the smartphone handles this task. For example, suppose the following message is received:

[1189] From: 12345

[1190] Subject: (Urgent) Unauthorized access to your account has been detected

[1191] Body: Please click the following link to verify your account: http: / / example.com

[1192] The terminal extracts the message body and header information.

[1193] Message analysis

[1194] The extracted message information is sent from the terminal to the server. The server receives the message information and forwards it to an automatically generated artificial intelligence system. This AI system performs an evaluation to assess the likelihood of fraud based on the message information. Specifically, it extracts keywords from the message body and header information and searches the internet for related information based on those keywords. For example, keywords such as "unauthorized account access" and "example.com" may be extracted. This method allows the system to check the search results to see if there are many reports or warnings of similar fraudulent emails.

[1195] Determination and notification of potential fraud

[1196] The server receives results from an automatically generated artificial intelligence system and scores the likelihood of fraud. Based on this scoring, it determines whether the situation is likely to be fraudulent. If it is determined to be likely to be fraudulent, the server generates an HTML-formatted warning message to alert the user. The generated warning message will contain the following information:

[1197] html

[1198]

[1199]

[1200] <h2> Caution: This may be a phishing email.< / h2>

[1201] The following email is likely a scam. Do not click on the link.

[1202] Sender: 12345

[1203] Subject: (Urgent) Unauthorized access to your account has been detected

[1204] Text: Click the following link to verify your account: http: / / example.com

[1205]

[1206]

[1207] This information will be notified to the user via a smartphone application.

[1208] The technologies used

[1209] The following technologies will be used to implement this system:

[1210] Smartphone application: A dedicated software program designed to run on a smartphone. Kotlin (Android) and Swift (iOS) are commonly used.

[1211] Cloud server: A server that processes message information and returns evaluation results. Python and Flask (web framework) are used.

[1212] Artificial intelligence system: Machine learning models and algorithms for analyzing message information and assessing the likelihood of fraud. TensorFlow and BeautifulSoup are used.

[1213] Database: A database for storing message data. PostgreSQL is used.

[1214] Specific example

[1215] Consider a scenario where a user receives the following message:

[1216] Example of a prompt:

[1217] Message body: Please click the following link to verify your account: http: / / example.com

[1218] Sender: 12345

[1219] Subject: (Urgent) Unauthorized access to your account has been detected

[1220] Based on this prompt, the artificial intelligence system evaluates the message's fraudulent nature and, if it determines it is highly likely to be fraudulent, displays a warning to the user. This system reduces the risk of users clicking on suspicious links and protects them from becoming victims of fraud.

[1221] The flow of a specific process in Application Example 1 will be explained using Figure 12.

[1222] Step 1:

[1223] The device (smartphone) receives messages via carrier email or short message service. The body and header information (sender, subject, etc.) of the received message are extracted. Specifically, a dedicated application analyzes the message content and extracts the necessary information. The input is the received message data, and the output is the extracted body and header information.

[1224] Step 2:

[1225] The terminal sends the extracted message information to the server. The input is the extracted message information, and the output is the data sent to the server. A dedicated communication protocol is used to transmit the data.

[1226] Step 3:

[1227] The server sends the received message information to an automatically generated artificial intelligence system. The input is the received message information, and the output is the data passed to the AI ​​system. A Python script is used to transfer the data to the AI ​​model.

[1228] Step 4:

[1229] An automatically generated artificial intelligence system extracts keywords from message information and performs a web search. The input is message information, and the output is search results. Specifically, it uses TensorFlow for keyword extraction and BeautifulSoup to collect relevant information from the internet.

[1230] Step 5:

[1231] The server scores the likelihood of fraud based on the search results. The input is the search results, and the output is the fraud score. The AI ​​model learns patterns of fraudulent activity based on past data and calculates the score accordingly.

[1232] Step 6:

[1233] The server receives a fraud score and generates HTML-formatted information to alert users if there is a high probability of fraud. The input is the fraud score, and the output is a warning message. A Python script is used to generate the HTML document.

[1234] Step 7:

[1235] The server sends generated alert information to the terminal. The input is the alert information, and the output is the warning message sent to the terminal. A dedicated communication protocol is used to transmit the data.

[1236] Step 8:

[1237] The terminal displays received warning information to the user. The input is the received warning message, and the output is the warning information displayed to the user. A dedicated application presents the warning message to the user in HTML format.

[1238] Through these processing flows, users can evaluate suspicious messages in real time and receive appropriate warnings to prevent fraud.

[1239] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.

[1240] This invention is a system for automatically evaluating the fraudulent nature of messages received via carrier email and short message services, and for alerting users as necessary. The system of this invention mainly consists of three elements: a terminal, a server, and a user. Furthermore, by incorporating an emotion engine that recognizes the user's emotions and adjusts its response accordingly, it can more effectively prevent damage from fraudulent emails.

[1241] Receiving and extracting emails

[1242] The device receives new messages that have arrived via carrier email or short message service. For example, consider the following message:

[1243] From: 12345

[1244] Subject: (Urgent) Unauthorized access to your account has been detected

[1245] Body: Please click the following link to verify your account: http: / / example.com

[1246] The terminal extracts the message body and header information (sender, subject, etc.). This allows the message content and its associated metadata to be separated and extracted.

[1247] Message analysis

[1248] The extracted message information is sent from the terminal to the server. The server receives this information and forwards it to an automated artificial intelligence system. This system performs a web search to assess the likelihood of fraud based on the message information.

[1249] The automated artificial intelligence system extracts keywords from the message body and header information, and then searches the internet for related information based on those keywords. For example, it might extract keywords such as "unauthorized account access" and "example.com". In this way, the search results confirm that there are numerous reports and warnings of similar phishing emails.

[1250] Determination and notification of potential fraud

[1251] The server receives results from an automated artificial intelligence system and scores the likelihood of fraud. Based on this scoring, it determines whether the information is likely to be fraudulent.

[1252] If a message is determined to be highly likely to be fraudulent, the server generates a warning. This information, in HTML format, includes the sender, subject, and body of the received message, as well as a notice indicating the possibility of fraud. For example, the following warning information may be generated:

[1253] html

[1254]

[1255]

[1256] <h2> Caution: This may be a phishing email.< / h2>

[1257] The following email is likely a scam. Do not click on the link.

[1258] Sender: 12345

[1259] Subject: (Urgent) Unauthorized access to your account has been detected

[1260] Text: Click the following link to verify your account: http: / / example.com

[1261]

[1262]

[1263] Adjusting responses using an emotional engine

[1264] Before sending the generated alert information, the emotion engine recognizes the user's emotions. The emotion engine determines the user's emotions by analyzing the user's facial expressions, tone of voice, input patterns, etc. Based on the recognized emotions, it adjusts the content and display method of the alert information.

[1265] For example, if a user indicates stress or anxiety, the server will provide additional support information and guidance. Specifically, it might display a message such as, "This email may be a scam. Please remain calm. If you have any questions, please contact our support center."

[1266] User notifications

[1267] The server sends the generated warning HTML to the device. The device displays the received HTML to the user. This display allows the user to recognize that the received message is likely to be fraudulent and to avoid taking actions such as clicking on links.

[1268] For example, the risk of a user unknowingly clicking on a link like "http: / / example.com" is reduced. In this way, users are protected from becoming victims of fraud.

[1269] As described above, this invention provides a system that automatically identifies fraudulent messages sent via carrier email and short message services, and promptly and appropriately warns users, thereby preventing damage from fraud. Furthermore, by using an emotion engine, it can respond in a way that takes the user's emotions into consideration, thereby protecting users more effectively.

[1270] The following describes the processing flow.

[1271] Step 1:

[1272] The device receives new messages that have arrived via carrier email or short message service. For example, suppose a message like the following is received:

[1273] From: 12345

[1274] Subject: (Urgent) Unauthorized access to your account has been detected

[1275] Body: Please click the following link to verify your account: http: / / example.com

[1276] Step 2:

[1277] The terminal extracts the body and header information (sender, subject, etc.) of the received message. Specifically, it retrieves information such as "From: 12345", "Subject: (Urgent) Unauthorized access to your account has been detected", and "Body: Click the link below to verify your account: http: / / example.com".

[1278] Step 3:

[1279] The terminal sends the extracted message information to the server. It uses communication methods such as HTTP POST requests to send the message information to the server.

[1280] Step 4:

[1281] The server forwards the received message information to the automated artificial intelligence system. The system converts the message information into a format that it can process and then makes an API call.

[1282] Step 5:

[1283] The automated artificial intelligence system extracts keywords from the message body and header information. For example, it extracts keywords such as "unauthorized access to account" and "example.com".

[1284] Step 6:

[1285] The automated artificial intelligence system performs a web search based on extracted keywords. This search is conducted on the internet, gathering information on similar messages.

[1286] Step 7:

[1287] The automated artificial intelligence system evaluates web search results and scores their likelihood of being a scam. This includes similar scam reports and risk assessments.

[1288] Step 8:

[1289] The server receives results from an automatically generated artificial intelligence system and determines whether there is a high probability of fraud based on a scoring system. For example, if the score exceeds a certain level, it is determined to be "highly likely to be a phishing email."

[1290] Step 9:

[1291] If a message is determined to be highly likely to be a scam, the server generates a warning. This information is in HTML format and includes the sender, subject, and body of the received message, as well as a notice indicating the possibility of fraud.

[1292] Step 10:

[1293] The server sends the generated alert HTML to the device.

[1294] Step 11:

[1295] The device activates the emotion engine before displaying the received alert HTML. The emotion engine provides a means to analyze and recognize the user's emotions. The emotion engine analyzes the user's facial expressions, voice tone, input patterns, etc., and evaluates the user's emotional state.

[1296] Step 12:

[1297] If the emotion engine detects that a user is exhibiting stress or anxiety, the server adjusts the content and display of the alert information. For example, it may include more detailed explanations or additional support.

[1298] Step 13:

[1299] The device displays a customized warning HTML to the user. This display allows the user to recognize the risk of receiving a phishing email and understand how to deal with it safely.

[1300] Step 14:

[1301] Users can check the warning HTML displayed on their device and recognize that the received message is likely to be fraudulent. This allows them to avoid actions such as clicking on links.

[1302] This series of steps not only protects users from phishing emails, but also provides more user-friendly warnings and support through the workings of an emotion engine.

[1303] (Example 2)

[1304] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."

[1305] The risk of receiving fraudulent messages via email and short message services remains high. Many users fall victim to these messages, partly due to the lack of systems that accurately identify and quickly warn against fraudulent messages. Another problem is that the inability to respond appropriately to users' emotions leads to panic and an inability to take appropriate action.

[1306] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.

[1307] In this invention, the server includes means for receiving the body and header information of messages received via carrier email or short message service, means for extracting the received message information, means for transmitting the extracted message information to a central processing unit, means for transmitting the message information to an automatically generated artificial intelligence system, means for the automatically generated artificial intelligence system to perform a web search based on the message information and evaluate the possibility of fraud, means for receiving the evaluation results, means for generating warning information if there is a high possibility of fraud, means for transmitting the generated warning information to a terminal, means for displaying the transmitted warning information to the user, and an emotion engine that recognizes the user's emotions and adjusts the content and display method of the warning information. This makes it possible to automatically identify fraudulent messages and issue warnings to users quickly and accurately. Furthermore, because appropriate responses can be taken according to the user's emotional state, users can receive information with peace of mind.

[1308] "Carrier email" refers to the email service provided by mobile phone carriers.

[1309] "Short Message Service" refers to a service that allows users to send and receive short text messages using their mobile phones.

[1310] "Message body" refers to the main text content included in carrier emails and short message services.

[1311] "Header information" refers to metadata such as the sender and recipient of a message, the subject, and the date and time it was sent.

[1312] A "terminal" refers to an electronic device that receives and sends carrier emails and short message services.

[1313] A "central processing unit" refers to a computer device that controls and processes data for the entire system.

[1314] An "automatic generation artificial intelligence system" refers to a system that uses artificial intelligence technology to analyze information and make decisions.

[1315] "Web search" refers to the act of using the internet to search for information related to specific keywords or topics.

[1316] "Potential fraud" refers to the probability that the received message is fraudulent or not.

[1317] "Warning information" refers to messages intended to inform users of specific risks or warnings.

[1318] An "emotion engine" refers to a system that recognizes a user's emotional state and adjusts responses and message content based on that state.

[1319] "HTML format" refers to a document format that uses the hypertext markup language.

[1320] This invention is a system for automatically evaluating the fraudulent nature of messages received via carrier email and short message services, and for alerting users as necessary. The system of this invention mainly consists of three elements: a terminal, a server, and a user. Furthermore, by incorporating an emotion engine that recognizes the user's emotions and adjusts its response accordingly, it can more effectively prevent damage from fraudulent emails.

[1321] Receiving and extracting emails

[1322] The device receives new messages that have arrived via carrier email or short message service. For example, consider the following message:

[1323] From: 12345

[1324] Subject: (Urgent) Unauthorized access to your account has been detected

[1325] Body: Please click the following link to verify your account: http: / / example.com

[1326] The terminal extracts the message body and header information (sender, subject, etc.). This allows the message content and its associated metadata to be separated and extracted.

[1327] Message analysis

[1328] The extracted message information is sent from the terminal to the server. The server receives this information and forwards it to an automated artificial intelligence system. This system performs a web search to assess the likelihood of fraud based on the message information.

[1329] The automated artificial intelligence system extracts keywords from the message body and header information, and then searches the internet for related information based on those keywords. For example, it might extract keywords such as "unauthorized account access" and "example.com". In this way, the search results confirm that there are numerous reports and warnings of similar phishing emails.

[1330] Determination and notification of potential fraud

[1331] The server receives results from an automated artificial intelligence system and scores the likelihood of fraud. Based on this scoring, it determines whether the information is likely to be fraudulent.

[1332] If a message is determined to be highly likely to be fraudulent, the server generates a warning. This information, in HTML format, includes the sender, subject, and body of the received message, as well as a notice indicating the possibility of fraud. For example, the following warning information may be generated:

[1333] html

[1334]

[1335]

[1336] <h2> Caution: This may be a phishing email.< / h2>

[1337] The following email is likely a scam. Do not click on the link.

[1338] Sender: 12345

[1339] Subject: (Urgent) Unauthorized access to your account has been detected

[1340] Text: Click the following link to verify your account: http: / / example.com

[1341]

[1342]

[1343] Adjusting responses using an emotional engine

[1344] Before sending the generated alert information, the emotion engine recognizes the user's emotions. The emotion engine determines the user's emotions by analyzing the user's facial expressions, tone of voice, input patterns, etc. Based on the recognized emotions, it adjusts the content and display method of the alert information.

[1345] For example, if a user indicates stress or anxiety, the server will provide additional support information and guidance. Specifically, it might display a message such as, "This email may be a scam. Please remain calm. If you have any questions, please contact our support center."

[1346] User notifications

[1347] The server sends the generated warning HTML to the device. The device displays the received HTML to the user. This display allows the user to recognize that the received message is likely to be fraudulent and to avoid taking actions such as clicking on links.

[1348] A concrete example would be inputting the following prompt into an automated AI model:

[1349] To assess the likelihood of a scam message regarding unauthorized access to your account, search the internet for information and check for similar scam reports. Keywords to look for are "unauthorized account access" and "example.com".

[1350] Using this prompt, an automated artificial intelligence system performs an internet search and evaluates the likelihood of fraud.

[1351] As described above, this invention provides a system that automatically identifies fraudulent messages sent via carrier email and short message services, and promptly and appropriately warns users, thereby preventing damage from fraud. Furthermore, by using an emotion engine, it can respond in a way that takes the user's emotions into consideration, thereby protecting users more effectively.

[1352] The flow of the specific processing in Example 2 will be explained using Figure 13.

[1353] Step 1: Receiving emails

[1354] The device monitors and receives new messages in carrier email and short message service (SMS) in real time. This monitoring utilizes services such as the notification listener service of the Android OS. When a new message arrives, the device immediately retrieves the information.

[1355] Input: Messages sent via carrier email or SMS

[1356] Output: Received message data

[1357] Specific operation: When a new message is sent, the terminal immediately captures its metadata and text content.

[1358] Step 2: Message Extraction

[1359] The terminal analyzes and extracts the body and header information (sender, subject, etc.) of the received message. This includes, for example, using regular expressions to analyze the email sender and subject according to a specific format.

[1360] Input: Received message data

[1361] Output: Header information of the extracted message (sender, subject), body.

[1362] Specific operation: The terminal uses regular expressions to extract the sender's address, subject, and body. For example, it identifies fields such as "From:" and "Subject:" and retrieves their values.

[1363] Step 3: Send message information

[1364] The terminal sends the extracted message information (sender, subject, and body) to the server. This transmission uses an HTTP POST request. The server receives this information and proceeds to the next processing step.

[1365] Input: Header information and body of the extracted message

[1366] Output: Sending message information to the server

[1367] Specific operation: The terminal generates an HTTP POST request and sends message information to the server. The request is constructed including the destination URL and authentication information.

[1368] Step 4: Analyze message information

[1369] The server forwards the received message information to an automated artificial intelligence system (e.g., a BERT or GPT model). This system extracts keywords from the message information to assess the likelihood of fraud and performs a web search based on these keywords.

[1370] Input: Message information sent to the server

[1371] Output: Search results and related information to assess the likelihood of fraud.

[1372] Specific operation: The automated artificial intelligence system extracts specific keywords from the body and header information of received messages. This is done using natural language processing techniques. Next, it uses these keywords to perform a web search on the internet and collect relevant information.

[1373] Step 5: Determining the possibility of fraud

[1374] The server scores the likelihood of fraud based on search results and related information from an automatically generated artificial intelligence system. This scoring uses a continuous scale, for example, ranging from 0 to 1, with a score of 0.7 or higher indicating a high probability of fraud.

[1375] Input: Search results and related information from an automatically generated artificial intelligence system.

[1376] Output: Fraud Probability Score

[1377] Specific operation: The server scores the search results based on factors such as frequency of results, the degree of matching with past fraud databases, and warning information, and assesses the likelihood of fraud.

[1378] Step 6: Generating a warning message

[1379] If a message is determined to be highly likely to be a scam, the server generates a warning in HTML format. This information includes the sender, subject, and body of the received message, as well as a notification indicating the possibility of fraud.

[1380] Input: Message information and score that are likely to be fraudulent.

[1381] Output: HTML document containing a warning message.

[1382] Specific operation: The server uses a template engine to generate a warning message in HTML format. For example, it might insert text such as, "This may be a scam. Do not click the link."

[1383] Step 7: Adjusting responses using the emotional engine

[1384] Before sending the generated alert information, the emotion engine recognizes the user's emotions. The emotion engine analyzes the user's facial expressions, tone of voice, input patterns, etc., to determine the user's emotions. Based on the recognized emotions, the content and display method of the alert information are adjusted.

[1385] Input: User emotional data (facial expressions, voice tone, input patterns)

[1386] Output: Adjusted warning information

[1387] Specific operation: The emotion engine uses the camera and microphone to analyze the user's emotional state in real time, and if the user shows signs of anxiety, it provides additional supportive information.

[1388] Step 8: User Notifications

[1389] The server sends the generated warning HTML to the device. The device receives this HTML and displays it to the user. This display allows the user to recognize the risk of fraud and avoid actions such as clicking on links.

[1390] Input: Warning HTML from the server

[1391] Output: Warning information displayed to the user

[1392] Specific operation: The device displays the received HTML to the user using WebView or browser components, visually conveying the warning content.

[1393] This allows users to take appropriate action against fraudulent messages and prevent becoming a victim. For example, users can avoid becoming a victim of fraud by not clicking on links such as "http: / / example.com".

[1394] (Application Example 2)

[1395] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."

[1396] In recent years, fraudulent activities using carrier email and short message services have become rampant, and effective countermeasures are needed. Furthermore, in autonomous vehicles, it is difficult to take appropriate measures when passengers receive fraudulent messages. In addition, there is a need for responses that take into account the emotional state of passengers in response to fraudulent messages, but such systems do not yet exist. To solve these problems, a system is needed that evaluates messages and takes appropriate responses based on the emotions involved.

[1397] In Application Example 2, the identification processing by the identification processing unit 290 of the data processing device 12 is realized by the following means. In this invention, the server includes means for receiving the body and header information of messages received via carrier mail or short message service, means for extracting the received message information, means for transmitting the extracted message information to a central processing device, means for transmitting the message information to an automatically generated artificial intelligence system for the central processing device to evaluate the message information, means for the automatically generated artificial intelligence system to perform a web search based on the message information and evaluate the possibility of fraud, means for receiving the evaluation results, means for generating warning information if there is a high possibility of fraud, means for transmitting the generated warning information to a terminal, means for displaying the transmitted warning information to the user, means for recognizing the user's emotions and adjusting the response, and means for coordinating with the in-vehicle information system of an autonomous vehicle to evaluate the fraudulent nature of messages received by passengers in the vehicle and notify them. This makes it possible to efficiently evaluate the fraudulent nature of messages received by passengers and provide appropriate warnings. Furthermore, by adjusting the response based on the passenger's emotional state, it becomes possible to effectively prevent fraud damage.

[1398] "Carrier email" refers to email services provided by telecommunications carriers, and is typically sent and received using mobile phones or smartphones.

[1399] Short Message Service (SMS) is a communication service that allows users to send and receive short messages via mobile phones and smartphones.

[1400] "Message body" refers to the actual content written in carrier emails and short message services.

[1401] "Message header information" refers to the part of the message that contains information related to its management, such as the sender, recipient, subject, date and time, etc.

[1402] A "central processing unit" is the central part of a computer system that performs data processing. It receives data from other systems and devices, and then analyzes and makes decisions based on that data.

[1403] An "automatic generation artificial intelligence system" is a system that uses artificial intelligence technology to automatically generate and analyze data.

[1404] "Web search" refers to the act of finding information on the internet using a search engine.

[1405] "Potential fraud" refers to the possibility that a message could be used for malicious purposes, such as fraudulent activities.

[1406] "Warning information" is information intended to alert users and is presented when there is a possibility of fraud.

[1407] A "terminal" refers to an information device that the user directly operates, and includes personal computers, smartphones, tablets, and other similar devices.

[1408] A "user" refers to a person who uses this system.

[1409] "Means of recognizing emotions" refer to methods and technologies for analyzing a user's facial expressions, tone of voice, etc., to understand their emotional state.

[1410] An "autonomous vehicle" is a vehicle that has the function to drive itself without a human driver.

[1411] An "in-vehicle information system" refers to an information processing system installed in a vehicle, providing functions such as navigation, entertainment, and communication.

[1412] This invention is a system that automatically evaluates the fraudulent nature of messages received via carrier email or short message service and alerts the user as needed. In particular, it works in conjunction with the in-vehicle information system of autonomous vehicles to evaluate the likelihood of fraud in messages received by passengers in the vehicle and provide a response that takes the user's feelings into consideration.

[1413] Receiving and extracting emails

[1414] The device receives new messages via carrier email or short message service. For example, consider the following message:

[1415] From: 12345

[1416] Subject: (Urgent) Unauthorized access to your account has been detected

[1417] Body: Click the following link to verify your account: http: / / example.com

[1418] The terminal extracts the message body and header information (sender, subject, etc.). This allows the message content and its associated metadata to be separated and extracted.

[1419] Analysis and evaluation of message information

[1420] The extracted message information is sent from the terminal to the central processing unit. The central processing unit receives this information and forwards it to the automated artificial intelligence system. The automated artificial intelligence system performs a web search to evaluate the likelihood of fraud based on the message information.

[1421] The automated artificial intelligence system extracts keywords from the message body and header information, and then searches the internet for related information based on those keywords. For example, it might extract keywords such as "unauthorized account access" and "example.com". In this way, the search results confirm that there are numerous reports and warnings of similar phishing emails.

[1422] Determination and notification of potential fraud

[1423] The central processing unit receives results from the automatically generated artificial intelligence system and scores the likelihood of fraud. Based on this scoring, it determines whether the likelihood of fraud is high.

[1424] If a message is determined to be highly likely to be fraudulent, the central processing unit generates a warning. This information, in HTML format, includes the sender, subject, and body of the received message, as well as a notification indicating the possibility of fraud. For example, the following warning information may be generated:

[1425] html

[1426]

[1427]

[1428] <h2> Caution: This may be a phishing email.< / h2>

[1429] The following email is likely a scam. Do not click on the link.

[1430] Sender: 12345

[1431] Subject: (Urgent) Unauthorized access to your account has been detected

[1432] Text: Click the following link to verify your account: http: / / example.com

[1433]

[1434]

[1435] Adjusting responses using an emotional engine

[1436] Before sending the generated alert information, the emotion engine recognizes the user's emotions. The emotion engine determines the user's emotions by analyzing the user's facial expressions, tone of voice, input patterns, etc. Based on the recognized emotions, the content and display method of the alert information are adjusted. For example, if the user is showing signs of stress or anxiety, the central processing unit provides additional support information and guidance. Specifically, it might display a message such as, "This email may be a scam. Please remain calm. If you have any questions, please contact our support center."

[1437] User notifications

[1438] The central processing unit sends the generated warning HTML to the terminal. The terminal displays the received HTML to the user. This display allows the user to recognize that the received message is likely to be fraudulent and to avoid actions such as clicking on links. For example, the risk of a user unknowingly clicking on a link such as "http: / / example.com" is reduced. In this way, the user is protected from becoming a victim of fraud.

[1439] Specific example

[1440] If a passenger receives a fraudulent email while in an autonomous vehicle, the system analyzes the message and determines that it is likely to be a scam. At the same time, if the emotion engine detects that the passenger is feeling stressed, it will display a reassuring message such as "Please stay calm and deal with this calmly" as a warning.

[1441] Example of a prompt

[1442] Please evaluate the fraudulent nature of the following message:

[1443] Email sender: 12345

[1444] Subject: (Urgent) Unauthorized access to your account has been detected

[1445] Text: Click the following link to verify your account: http: / / example.com

[1446] Additionally, if the system determines that the user is emotionally unstable, please generate a gentle and reassuring message.

[1447] The flow of a specific process in Application Example 2 will be explained using Figure 14.

[1448] Program processing flow

[1449] Step 1:

[1450] The device receives new messages from carrier email or short message service. The input includes the message body and header information (sender, subject, etc.). Data processing involves extracting the message body and header information. The output is the extracted message information.

[1451] Step 2:

[1452] The terminal transmits the extracted message information to the central processing unit. The extracted message information is required as input. The data processing involves transmitting the information. The output is the message information received by the central processing unit.

[1453] Step 3:

[1454] The central processing unit transmits message information to the automated artificial intelligence system. Its input includes message information received from the terminal. As a data calculation, it reprocesses the message information and transmits it. The output is the message information received by the automated artificial intelligence system.

[1455] Step 4:

[1456] The automated artificial intelligence system performs a web search based on message information and evaluates the likelihood of fraud. The input includes keywords extracted from the message body and header information. Data processing involves keyword extraction and web search. The output is an evaluation of the likelihood of fraud.

[1457] Step 5:

[1458] The central processing unit receives evaluation results from an automatically generated artificial intelligence system and scores the likelihood of fraud. The input includes the evaluation results. The data calculation is performed as a scoring process. The output is a score regarding the likelihood of fraud.

[1459] Step 6:

[1460] If a fraudulent activity is determined to be highly likely, the central processing unit generates a warning. The input includes a score indicating the likelihood of fraud. The data processing generates a warning in HTML format. The output is the generated warning.

[1461] Step 7:

[1462] Before sending the generated alert information, the emotion engine recognizes the user's emotions. Inputs include the user's facial expressions and tone of voice. The data calculation involves emotion recognition. The output is the recognized emotional state of the user.

[1463] Step 8:

[1464] The system adjusts the content and display method of alert information based on the user's emotions recognized by the emotion engine. Input includes the recognized emotional state and alert information. Data processing involves adjusting the information. Output is the adjusted alert information.

[1465] Step 9:

[1466] The central processing unit transmits the adjusted alert information to the terminal. The input includes the adjusted alert information. The data processing involves transmitting the information. The output is the adjusted alert information received by the terminal.

[1467] Step 10:

[1468] The device displays the received, adjusted alert information to the user. The input includes the adjusted alert information. The data calculation process displays the information. The output is the alert information displayed to the user. This allows the user to recognize that the received message is likely fraudulent and take appropriate action.

[1469] The specific processing unit 290 transmits the result of the specific processing to the headset terminal 314. In the headset terminal 314, the control unit 46A causes the speaker 240 and display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.

[1470] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[1471] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and specific processing may also be performed by the headset terminal 314.

[1472] [Fourth Embodiment]

[1473] Figure 7 shows an example of the configuration of the data processing system 410 according to the fourth embodiment.

[1474] As shown in Figure 7, the data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.

[1475] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[1476] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a controlled object 443. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and controlled object 443 are also connected to the bus 52.

[1477] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.

[1478] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).

[1479] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.

[1480] The controlled object 443 includes a display device, LEDs in the eyes, and motors that drive the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the robot 414's emotions can be expressed by controlling these motors. Furthermore, the robot 414's facial expressions can also be expressed by controlling the illumination state of the LEDs in its eyes.

[1481] Figure 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Figure 8, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.

[1482] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[1483] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[1484] In robot 414, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.

[1485] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".

[1486] This invention is a system for automatically evaluating the fraudulent nature of messages received via carrier email or short message service and, if necessary, alerting the user. The system of this invention mainly consists of three elements: a terminal, a server, and a user.

[1487] Receiving and extracting emails

[1488] The device receives messages sent to carrier email or short message service. For example, suppose the following message is received:

[1489] From: 12345

[1490] Subject: (Urgent) Unauthorized access to your account has been detected

[1491] Body: Please click the following link to verify your account: http: / / example.com

[1492] The terminal extracts the message body and header information (sender, subject, etc.). This allows the message content and its associated metadata to be separated and extracted.

[1493] Message analysis

[1494] The extracted message information is sent from the terminal to the server. The server receives this information and forwards it to an automated artificial intelligence system. This system performs a web search to assess the likelihood of fraud based on the message information.

[1495] The automated artificial intelligence system extracts keywords from the message body and header information, and then searches the internet for related information based on those keywords. For example, it might extract keywords such as "unauthorized account access" and "example.com". In this way, the search results confirm that there are numerous reports and warnings of similar phishing emails.

[1496] Determination and notification of potential fraud

[1497] The server receives results from an automated artificial intelligence system and scores the likelihood of fraud. Based on this scoring, it determines whether the information is likely to be fraudulent.

[1498] If the server determines that there is a high probability of fraud, it will generate an HTML-formatted warning message to alert the user. The generated warning message will contain the following information:

[1499] html

[1500]

[1501]

[1502] <h2> Caution: This may be a phishing email.< / h2>

[1503] The following email is likely a scam. Do not click on the link.

[1504] Sender: 12345

[1505] Subject: (Urgent) Unauthorized access to your account has been detected

[1506] Text: Click the following link to verify your account: http: / / example.com

[1507]

[1508]

[1509] User notifications

[1510] The server sends the generated warning HTML to the device. The device displays the received HTML to the user. This display allows the user to recognize that the received message is likely to be fraudulent and to avoid taking actions such as clicking on links.

[1511] For example, the risk of a user unknowingly clicking on a link like "http: / / example.com" is reduced. In this way, users are protected from becoming victims of fraud.

[1512] As described above, this invention provides a system that automatically identifies fraudulent messages sent via carrier email and short message services, and promptly and appropriately warns users, thereby preventing damage from fraud.

[1513] The following describes the processing flow.

[1514] Step 1:

[1515] The device receives new messages that have arrived via carrier email or short message service. For example, consider a message with the following content.

[1516] From: 12345

[1517] Subject: (Urgent) Unauthorized access to your account has been detected

[1518] Body: Please click the following link to verify your account: http: / / example.com

[1519] Step 2:

[1520] The device extracts the message body and header information (sender, subject, etc.) from the received message. Specifically, it retrieves information such as "From: 12345", "Subject: (Urgent) Unauthorized access to your account has been detected", and "Body: Click the link below to verify your account: http: / / example.com".

[1521] Step 3:

[1522] The terminal sends the extracted message information to the server. It uses communication methods such as HTTP POST requests to send the message information to the server.

[1523] Step 4:

[1524] The server forwards the received message information to the automated artificial intelligence system. The system converts the message information into a format that it can process and then makes an API call.

[1525] Step 5:

[1526] The automated artificial intelligence system extracts keywords from the message body and header information. For example, it extracts keywords such as "unauthorized access to account" and "example.com".

[1527] Step 6:

[1528] The automated artificial intelligence system performs a web search based on extracted keywords. This search is conducted on the internet, gathering information on similar messages.

[1529] Step 7:

[1530] The automated artificial intelligence system evaluates web search results and scores their likelihood of being a scam. This includes similar scam reports and risk assessments.

[1531] Step 8:

[1532] The server receives results from an automatically generated artificial intelligence system and determines whether there is a high probability of fraud based on a scoring system. For example, if the score exceeds a certain level, it is determined to be "highly likely to be a phishing email."

[1533] Step 9:

[1534] If a message is determined to be highly likely to be a scam, the server generates a warning. This information is in HTML format and includes the sender, subject, and body of the received message, as well as a notice indicating the possibility of fraud.

[1535] Step 10:

[1536] The server sends the generated warning HTML to the device.

[1537] Step 11:

[1538] The device displays the received alert HTML to the user. This display is done through the user interface, warning the user of the danger of the message.

[1539] Step 12:

[1540] Users can check the warning HTML displayed on their device and recognize that the received message is likely to be fraudulent. This allows users to avoid actions such as clicking on links.

[1541] (Example 1)

[1542] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".

[1543] In modern society, fraudulent activities targeting users of carrier email and short message services are on the rise. Consequently, there is a growing need for systems that can reliably detect fraudulent emails and issue prompt and appropriate warnings to users. However, traditional manual methods for detecting fraudulent emails are often ineffective in preventing timely responses and failing to prevent damage. Therefore, there is a demand for automated systems that can quickly detect fraudulent emails and provide appropriate warnings to users.

[1544] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.

[1545] In this invention, the server includes means for receiving the body and header information of messages received via carrier email or short message service, means for extracting the received message information, means for transmitting the extracted message information to a central processing unit, and means for an automatically generated artificial intelligence system to perform a web search based on the message information and evaluate the likelihood of fraud. This enables automatic detection of fraudulent emails and rapid warning.

[1546] "Carrier email" refers to email services provided by telecommunications carriers.

[1547] Short Message Service (SSS) is a communication service for sending and receiving short text messages between mobile devices.

[1548] "Message information" refers to data that includes the body and header information of an email or short message.

[1549] The "main text" refers to the part of the message that describes its main content.

[1550] "Header information" refers to information that includes metadata such as the sender of the message, the subject, and the date and time it was sent.

[1551] "Terminal" refers to an electronic device used by a user, and includes, for example, smartphones and tablets.

[1552] A "server" is a computer system that performs central processing.

[1553] An "automatic generation artificial intelligence system" is a system that uses artificial intelligence technology to analyze the content of messages and assess the likelihood of fraud.

[1554] "Web search" refers to the act of searching for information on the internet using a search engine.

[1555] "Assessing the likelihood of fraud" refers to performing a series of analytical processes to determine whether a message is fraudulent.

[1556] "Warning information" refers to information that warns users about the possibility of receiving a fraudulent email.

[1557] "HTML format" refers to a format that uses HTML, a markup language for describing web pages.

[1558] "User" refers to the general consumer who uses the system.

[1559] This invention is a system for automatically evaluating the fraudulent nature of messages received via carrier email or short message service and, if necessary, alerting the user. The system of this invention mainly consists of three elements: a terminal, a server, and a user.

[1560] Receiving and extracting emails

[1561] The device receives messages sent to carrier email or short message service. For example, suppose the following message is received:

[1562] From: 12345

[1563] Subject: (Urgent) Unauthorized access to your account has been detected

[1564] Body: Please click the following link to verify your account: http: / / example.com

[1565] When such a message arrives, the device extracts the message body and header information (sender, subject, etc.). The extracted data will have the following structure:

[1566] Message body: Please click the following link to verify your account: http: / / example.com

[1567] Sender: 12345

[1568] Subject: (Urgent) Unauthorized access to your account has been detected

[1569] Message information transfer and analysis

[1570] The terminal sends the extracted message information to the server. The server forwards the received information to an automated artificial intelligence system. This system evaluates the likelihood of fraud based on the message information. For example, the system extracts keywords such as "unauthorized account access" and "example.com" from the message body and header information and performs a search on the internet.

[1571] For example, if keywords such as "unauthorized access to an account" and "example.com" are extracted, and numerous similar fraud reports and warnings are found on the internet, it will be determined that there is a possibility of fraud.

[1572] Determining the possibility of fraud

[1573] The server receives and analyzes search results from an automated artificial intelligence system. If the analysis reveals numerous fraud reports or warnings, the server scores the likelihood of fraud. For example, if the search results indicate that "example.com" is included in a list of malicious domains, its score will be high.

[1574] Generating warning information

[1575] If the server determines that there is a high probability of fraud, it will generate an HTML-formatted warning message to alert the user. For example, the following HTML content will be generated:

[1576] html

[1577]

[1578]

[1579] <h2> Caution: This may be a phishing email.< / h2>

[1580] The following email is likely a scam. Do not click on the link.

[1581] Sender: 12345

[1582] Subject: (Urgent) Unauthorized access to your account has been detected

[1583] Text: Click the following link to verify your account: http: / / example.com

[1584]

[1585]

[1586] User notifications

[1587] After the warning HTML is generated, the server sends this information to the device. The device displays the received HTML to the user. This display allows the user to recognize that the received message is likely fraudulent and avoid the risk of clicking the link.

[1588] For example, the risk of a user unknowingly clicking on a link like "http: / / example.com" is reduced. In this way, users are protected from becoming victims of fraud.

[1589] As an example of a prompt, the following text can be input to the generating AI model:

[1590] Please check if messages containing phrases like "unauthorized access to your account" or "example.com" are likely to be phishing emails, and generate a warning if they are.

[1591] As described above, this invention provides a system that automatically identifies fraudulent messages sent via carrier email and short message services, and promptly and appropriately warns users, thereby preventing damage from fraud.

[1592] The flow of the specific processing in Example 1 will be explained using Figure 11.

[1593] Step 1:

[1594] The device receives messages sent via carrier email or short message service. These messages include sender information, subject, and body text, which serve as input data.

[1595] Specifically, consider the following message as an example:

[1596] From: 12345

[1597] Subject: (Urgent) Unauthorized access to your account has been detected

[1598] Body: Please click the following link to verify your account: http: / / example.com

[1599] The device receives this message in its original format.

[1600] Step 2:

[1601] The terminal extracts the message body and header information (sender, subject, etc.) from the received message information. The input data is the entire message received in step 1.

[1602] As for specific data processing, the following information will be extracted and output from the message:

[1603] Message body: Please click the following link to verify your account: http: / / example.com

[1604] Sender: 12345

[1605] Subject: (Urgent) Unauthorized access to your account has been detected

[1606] Step 3:

[1607] The terminal sends the extracted message information (body and header information) to the server. The input data is the data extracted in step 2, which is packaged into a packet and sent to the server.

[1608] Specifically, the device sends the following data to the server over the network:

[1609] {

[1610] "Body text": "Click the following link to verify your account: http: / / example.com",

[1611] "Sender": "12345",

[1612] Subject: (Urgent) Unauthorized access to your account has been detected.

[1613] }

[1614] Step 4:

[1615] The server forwards the received message information to the automated artificial intelligence system. The input data is the data received in step 3.

[1616] The server analyzes the data, extracts the necessary keywords, and passes them directly to the automated generation artificial intelligence system.

[1617] For example, extract and submit the following keywords:

[1618] Keywords: ["Unauthorized access to an account", "example.com"]

[1619] Step 5:

[1620] The automated artificial intelligence system performs a web search based on the received keywords and evaluates the likelihood of fraud. The input data is the keywords submitted in step 4.

[1621] The automated artificial intelligence system collects reports and warnings about fraud from the web, scores the likelihood of fraud, and outputs the results.

[1622] For example, the following scoring results will be output:

[1623] Score: 85 (Highly likely to be a scam)

[1624] Step 6:

[1625] The server receives scoring results from an automatically generated artificial intelligence system and generates a warning if it determines that there is a high probability of fraud. The input data is the scoring results obtained in step 5.

[1626] Based on this, a warning message in HTML format is generated and output.

[1627] Specifically, the following content will be generated:

[1628] html

[1629]

[1630]

[1631] <h2> Caution: This may be a phishing email.< / h2>

[1632] The following email is likely a scam. Do not click on the link.

[1633] Sender: 12345

[1634] Subject: (Urgent) Unauthorized access to your account has been detected

[1635] Text: Click the following link to verify your account: http: / / example.com

[1636]

[1637]

[1638] Step 7:

[1639] The server sends the generated alert information to the terminal. The input data is the HTML-formatted alert information generated in step 6.

[1640] Specifically, the server sends this information to the terminal via the network.

[1641] Step 8:

[1642] The terminal displays the received alert information to the user. The input data is HTML-formatted information received from the server in step 7.

[1643] Specifically, the terminal displays the received HTML on the user interface and issues a warning to the user.

[1644] This allows users to identify potentially fraudulent messages and choose to take action, such as not clicking on links.

[1645] By coordinating the above specific actions, the system of the present invention can prevent damage from fraud.

[1646] (Application Example 1)

[1647] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".

[1648] Messages received via carrier email or short message services may contain malicious content designed to lure users into fraud, putting them at risk of becoming victims. A system is needed to quickly identify such fraudulent messages and warn users. However, conventional methods have struggled to evaluate message content in real time and provide appropriate warnings. Therefore, the challenge lies in providing a system that automatically evaluates the fraudulent nature of messages received by users and delivers necessary warnings quickly and effectively.

[1649] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.

[1650] In this invention, the server includes means for receiving the body and header information of messages received via carrier email or short message service; means for extracting the received message information; means for transmitting the extracted message information to a central processing unit; means for transmitting the message information to an artificial intelligence system automatically generated by the central processing unit for evaluating the message information; means for the automatically generated artificial intelligence system to perform a web search based on the message information and evaluate the likelihood of fraud; means for receiving the evaluation results; means for generating warning information if there is a high possibility of fraud; means for transmitting the generated warning information to a terminal; means for displaying the transmitted warning information to the user; and means implemented as a smartphone application for receiving and evaluating messages and notifying the user. This makes it possible to automatically evaluate the fraudulent nature of messages received by the user and provide necessary warnings quickly and effectively.

[1651] "Carrier email" refers to the email service provided by mobile phone carriers.

[1652] "Short Message Service" refers to a service that allows users to send and receive short messages using a mobile phone network.

[1653] "Message body" refers to the main content portion of a message that a user sends or receives.

[1654] "Header information" refers to metadata attached to a message, such as the sender and subject.

[1655] "Means of receiving" refers to functions and devices for obtaining messages via carrier email or short message service.

[1656] "Means of extraction" refers to functions or devices that extract and separate the message body and header information.

[1657] A "central processing unit" refers to a computer system used to analyze and process received message data.

[1658] An "automatically generated artificial intelligence system" refers to machine learning models or algorithms trained to analyze message information and assess the likelihood of fraud.

[1659] "Means of performing a web search" refers to functions or devices that search for keywords on the internet and obtain related information.

[1660] "Means of assessing the possibility of fraud" refers to functions or devices that determine whether a received message has an illegitimate purpose based on its content.

[1661] "Means of receiving evaluation results" refers to functions or devices that receive analysis results from artificial intelligence systems.

[1662] "Warning information" refers to information intended to alert users that a message is highly likely to be a scam.

[1663] "Means of generation" refers to functions or devices that create warning messages when a situation is deemed highly likely to be fraudulent.

[1664] "Terminal" refers to devices such as smartphones and tablets that are directly operated by the user.

[1665] A "smartphone application" refers to a dedicated software program that runs on a smartphone.

[1666] This invention is a system that automatically evaluates the fraudulent nature of messages received via carrier email or short message service and alerts the user if necessary, and is implemented as a smartphone application.

[1667] Configuration and Operation Overview

[1668] Receiving and extracting messages

[1669] The device (smartphone) receives the body and header information of messages received via carrier email or short message service. A dedicated application running on the smartphone handles this task. For example, suppose the following message is received:

[1670] From: 12345

[1671] Subject: (Urgent) Unauthorized access to your account has been detected

[1672] Body: Please click the following link to verify your account: http: / / example.com

[1673] The terminal extracts the message body and header information.

[1674] Message analysis

[1675] The extracted message information is sent from the terminal to the server. The server receives the message information and forwards it to an automatically generated artificial intelligence system. This AI system performs an evaluation to assess the likelihood of fraud based on the message information. Specifically, it extracts keywords from the message body and header information and searches the internet for related information based on those keywords. For example, keywords such as "unauthorized account access" and "example.com" may be extracted. This method allows the system to check the search results to see if there are many reports or warnings of similar fraudulent emails.

[1676] Determination and notification of potential fraud

[1677] The server receives results from an automatically generated artificial intelligence system and scores the likelihood of fraud. Based on this scoring, it determines whether the situation is likely to be fraudulent. If it is determined to be likely to be fraudulent, the server generates an HTML-formatted warning message to alert the user. The generated warning message will contain the following information:

[1678] html

[1679]

[1680]

[1681] <h2> Caution: This may be a phishing email.< / h2>

[1682] The following email is likely a scam. Do not click on the link.

[1683] Sender: 12345

[1684] Subject: (Urgent) Unauthorized access to your account has been detected

[1685] Text: Click the following link to verify your account: http: / / example.com

[1686]

[1687]

[1688] This information will be notified to the user via a smartphone application.

[1689] The technologies used

[1690] The following technologies will be used to implement this system:

[1691] Smartphone application: A dedicated software program designed to run on a smartphone. Kotlin (Android) and Swift (iOS) are commonly used.

[1692] Cloud server: A server that processes message information and returns evaluation results. Python and Flask (web framework) are used.

[1693] Artificial intelligence system: Machine learning models and algorithms for analyzing message information and assessing the likelihood of fraud. TensorFlow and BeautifulSoup are used.

[1694] Database: A database for storing message data. PostgreSQL is used.

[1695] Specific example

[1696] Consider a scenario where a user receives the following message:

[1697] Example of a prompt:

[1698] Message body: Please click the following link to verify your account: http: / / example.com

[1699] Sender: 12345

[1700] Subject: (Urgent) Unauthorized access to your account has been detected

[1701] Based on this prompt, the artificial intelligence system evaluates the message's fraudulent nature and, if it determines it is highly likely to be fraudulent, displays a warning to the user. This system reduces the risk of users clicking on suspicious links and protects them from becoming victims of fraud.

[1702] The flow of a specific process in Application Example 1 will be explained using Figure 12.

[1703] Step 1:

[1704] The device (smartphone) receives messages via carrier email or short message service. The body and header information (sender, subject, etc.) of the received message are extracted. Specifically, a dedicated application analyzes the message content and extracts the necessary information. The input is the received message data, and the output is the extracted body and header information.

[1705] Step 2:

[1706] The terminal sends the extracted message information to the server. The input is the extracted message information, and the output is the data sent to the server. A dedicated communication protocol is used to transmit the data.

[1707] Step 3:

[1708] The server sends the received message information to an automatically generated artificial intelligence system. The input is the received message information, and the output is the data passed to the AI ​​system. A Python script is used to transfer the data to the AI ​​model.

[1709] Step 4:

[1710] An automatically generated artificial intelligence system extracts keywords from message information and performs a web search. The input is message information, and the output is search results. Specifically, it uses TensorFlow for keyword extraction and BeautifulSoup to collect relevant information from the internet.

[1711] Step 5:

[1712] The server scores the likelihood of fraud based on the search results. The input is the search results, and the output is the fraud score. The AI ​​model learns patterns of fraudulent activity based on past data and calculates the score accordingly.

[1713] Step 6:

[1714] The server receives a fraud score and generates HTML-formatted information to alert users if there is a high probability of fraud. The input is the fraud score, and the output is a warning message. A Python script is used to generate the HTML document.

[1715] Step 7:

[1716] The server sends generated alert information to the terminal. The input is the alert information, and the output is the warning message sent to the terminal. A dedicated communication protocol is used to transmit the data.

[1717] Step 8:

[1718] The terminal displays received warning information to the user. The input is the received warning message, and the output is the warning information displayed to the user. A dedicated application presents the warning message to the user in HTML format.

[1719] Through these processing flows, users can evaluate suspicious messages in real time and receive appropriate warnings to prevent fraud.

[1720] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.

[1721] This invention is a system for automatically evaluating the fraudulent nature of messages received via carrier email and short message services, and for alerting users as necessary. The system of this invention mainly consists of three elements: a terminal, a server, and a user. Furthermore, by incorporating an emotion engine that recognizes the user's emotions and adjusts its response accordingly, it can more effectively prevent damage from fraudulent emails.

[1722] Receiving and extracting emails

[1723] The device receives new messages that have arrived via carrier email or short message service. For example, consider the following message:

[1724] From: 12345

[1725] Subject: (Urgent) Unauthorized access to your account has been detected

[1726] Body: Please click the following link to verify your account: http: / / example.com

[1727] The terminal extracts the message body and header information (sender, subject, etc.). This allows the message content and its associated metadata to be separated and extracted.

[1728] Message analysis

[1729] The extracted message information is sent from the terminal to the server. The server receives this information and forwards it to an automated artificial intelligence system. This system performs a web search to assess the likelihood of fraud based on the message information.

[1730] The automated artificial intelligence system extracts keywords from the message body and header information, and then searches the internet for related information based on those keywords. For example, it might extract keywords such as "unauthorized account access" and "example.com". In this way, the search results confirm that there are numerous reports and warnings of similar phishing emails.

[1731] Determination and notification of potential fraud

[1732] The server receives results from an automated artificial intelligence system and scores the likelihood of fraud. Based on this scoring, it determines whether the information is likely to be fraudulent.

[1733] If a message is determined to be highly likely to be fraudulent, the server generates a warning. This information, in HTML format, includes the sender, subject, and body of the received message, as well as a notice indicating the possibility of fraud. For example, the following warning information may be generated:

[1734] html

[1735]

[1736]

[1737] <h2> Caution: This may be a phishing email.< / h2>

[1738] The following email is likely a scam. Do not click on the link.

[1739] Sender: 12345

[1740] Subject: (Urgent) Unauthorized access to your account has been detected

[1741] Text: Click the following link to verify your account: http: / / example.com

[1742]

[1743]

[1744] Adjusting responses using an emotional engine

[1745] Before sending the generated alert information, the emotion engine recognizes the user's emotions. The emotion engine determines the user's emotions by analyzing the user's facial expressions, tone of voice, input patterns, etc. Based on the recognized emotions, it adjusts the content and display method of the alert information.

[1746] For example, if a user indicates stress or anxiety, the server will provide additional support information and guidance. Specifically, it might display a message such as, "This email may be a scam. Please remain calm. If you have any questions, please contact our support center."

[1747] User notifications

[1748] The server sends the generated warning HTML to the device. The device displays the received HTML to the user. This display allows the user to recognize that the received message is likely to be fraudulent and to avoid taking actions such as clicking on links.

[1749] For example, the risk of a user unknowingly clicking on a link like "http: / / example.com" is reduced. In this way, users are protected from becoming victims of fraud.

[1750] As described above, this invention provides a system that automatically identifies fraudulent messages sent via carrier email and short message services, and promptly and appropriately warns users, thereby preventing damage from fraud. Furthermore, by using an emotion engine, it can respond in a way that takes the user's emotions into consideration, thereby protecting users more effectively.

[1751] The following describes the processing flow.

[1752] Step 1:

[1753] The device receives new messages that have arrived via carrier email or short message service. For example, suppose a message like the following is received:

[1754] From: 12345

[1755] Subject: (Urgent) Unauthorized access to your account has been detected

[1756] Body: Please click the following link to verify your account: http: / / example.com

[1757] Step 2:

[1758] The terminal extracts the body and header information (sender, subject, etc.) of the received message. Specifically, it retrieves information such as "From: 12345", "Subject: (Urgent) Unauthorized access to your account has been detected", and "Body: Click the link below to verify your account: http: / / example.com".

[1759] Step 3:

[1760] The terminal sends the extracted message information to the server. It uses communication methods such as HTTP POST requests to send the message information to the server.

[1761] Step 4:

[1762] The server forwards the received message information to the automated artificial intelligence system. The system converts the message information into a format that it can process and then makes an API call.

[1763] Step 5:

[1764] The automated artificial intelligence system extracts keywords from the message body and header information. For example, it extracts keywords such as "unauthorized access to account" and "example.com".

[1765] Step 6:

[1766] The automated artificial intelligence system performs a web search based on extracted keywords. This search is conducted on the internet, gathering information on similar messages.

[1767] Step 7:

[1768] The automated artificial intelligence system evaluates web search results and scores their likelihood of being a scam. This includes similar scam reports and risk assessments.

[1769] Step 8:

[1770] The server receives results from an automatically generated artificial intelligence system and determines whether there is a high probability of fraud based on a scoring system. For example, if the score exceeds a certain level, it is determined to be "highly likely to be a phishing email."

[1771] Step 9:

[1772] If a message is determined to be highly likely to be a scam, the server generates a warning. This information is in HTML format and includes the sender, subject, and body of the received message, as well as a notice indicating the possibility of fraud.

[1773] Step 10:

[1774] The server sends the generated alert HTML to the device.

[1775] Step 11:

[1776] The device activates the emotion engine before displaying the received alert HTML. The emotion engine provides a means to analyze and recognize the user's emotions. The emotion engine analyzes the user's facial expressions, voice tone, input patterns, etc., and evaluates the user's emotional state.

[1777] Step 12:

[1778] If the emotion engine detects that a user is exhibiting stress or anxiety, the server adjusts the content and display of the alert information. For example, it may include more detailed explanations or additional support.

[1779] Step 13:

[1780] The device displays a customized warning HTML to the user. This display allows the user to recognize the risk of receiving a phishing email and understand how to deal with it safely.

[1781] Step 14:

[1782] Users can check the warning HTML displayed on their device and recognize that the received message is likely to be fraudulent. This allows them to avoid actions such as clicking on links.

[1783] This series of steps not only protects users from phishing emails, but also provides more user-friendly warnings and support through the workings of an emotion engine.

[1784] (Example 2)

[1785] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".

[1786] The risk of receiving fraudulent messages via email and short message services remains high. Many users fall victim to these messages, partly due to the lack of systems that accurately identify and quickly warn against fraudulent messages. Another problem is that the inability to respond appropriately to users' emotions leads to panic and an inability to take appropriate action.

[1787] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.

[1788] In this invention, the server includes means for receiving the body and header information of messages received via carrier email or short message service, means for extracting the received message information, means for transmitting the extracted message information to a central processing unit, means for transmitting the message information to an automatically generated artificial intelligence system, means for the automatically generated artificial intelligence system to perform a web search based on the message information and evaluate the possibility of fraud, means for receiving the evaluation results, means for generating warning information if there is a high possibility of fraud, means for transmitting the generated warning information to a terminal, means for displaying the transmitted warning information to the user, and an emotion engine that recognizes the user's emotions and adjusts the content and display method of the warning information. This makes it possible to automatically identify fraudulent messages and issue warnings to users quickly and accurately. Furthermore, because appropriate responses can be taken according to the user's emotional state, users can receive information with peace of mind.

[1789] "Carrier email" refers to the email service provided by mobile phone carriers.

[1790] "Short Message Service" refers to a service that allows users to send and receive short text messages using their mobile phones.

[1791] "Message body" refers to the main text content included in carrier emails and short message services.

[1792] "Header information" refers to metadata such as the sender and recipient of a message, the subject, and the date and time it was sent.

[1793] A "terminal" refers to an electronic device that receives and sends carrier emails and short message services.

[1794] A "central processing unit" refers to a computer device that controls and processes data for the entire system.

[1795] An "automatic generation artificial intelligence system" refers to a system that uses artificial intelligence technology to analyze information and make decisions.

[1796] "Web search" refers to the act of using the internet to search for information related to specific keywords or topics.

[1797] "Potential fraud" refers to the probability that the received message is fraudulent or not.

[1798] "Warning information" refers to messages intended to inform users of specific risks or warnings.

[1799] An "emotion engine" refers to a system that recognizes a user's emotional state and adjusts responses and message content based on that state.

[1800] "HTML format" refers to a document format that uses the hypertext markup language.

[1801] This invention is a system for automatically evaluating the fraudulent nature of messages received via carrier email and short message services, and for alerting users as necessary. The system of this invention mainly consists of three elements: a terminal, a server, and a user. Furthermore, by incorporating an emotion engine that recognizes the user's emotions and adjusts its response accordingly, it can more effectively prevent damage from fraudulent emails.

[1802] Receiving and extracting emails

[1803] The device receives new messages that have arrived via carrier email or short message service. For example, consider the following message:

[1804] From: 12345

[1805] Subject: (Urgent) Unauthorized access to your account has been detected

[1806] Body: Please click the following link to verify your account: http: / / example.com

[1807] The terminal extracts the message body and header information (sender, subject, etc.). This allows the message content and its associated metadata to be separated and extracted.

[1808] Message analysis

[1809] The extracted message information is sent from the terminal to the server. The server receives this information and forwards it to an automated artificial intelligence system. This system performs a web search to assess the likelihood of fraud based on the message information.

[1810] The automated artificial intelligence system extracts keywords from the message body and header information, and then searches the internet for related information based on those keywords. For example, it might extract keywords such as "unauthorized account access" and "example.com". In this way, the search results confirm that there are numerous reports and warnings of similar phishing emails.

[1811] Determination and notification of potential fraud

[1812] The server receives results from an automated artificial intelligence system and scores the likelihood of fraud. Based on this scoring, it determines whether the information is likely to be fraudulent.

[1813] If a message is determined to be highly likely to be fraudulent, the server generates a warning. This information, in HTML format, includes the sender, subject, and body of the received message, as well as a notice indicating the possibility of fraud. For example, the following warning information may be generated:

[1814] html

[1815]

[1816]

[1817] <h2> Caution: This may be a phishing email.< / h2>

[1818] The following email is likely a scam. Do not click on the link.

[1819] Sender: 12345

[1820] Subject: (Urgent) Unauthorized access to your account has been detected

[1821] Text: Click the following link to verify your account: http: / / example.com

[1822]

[1823]

[1824] Adjusting responses using an emotional engine

[1825] Before sending the generated alert information, the emotion engine recognizes the user's emotions. The emotion engine determines the user's emotions by analyzing the user's facial expressions, tone of voice, input patterns, etc. Based on the recognized emotions, it adjusts the content and display method of the alert information.

[1826] For example, if a user indicates stress or anxiety, the server will provide additional support information and guidance. Specifically, it might display a message such as, "This email may be a scam. Please remain calm. If you have any questions, please contact our support center."

[1827] User notifications

[1828] The server sends the generated warning HTML to the device. The device displays the received HTML to the user. This display allows the user to recognize that the received message is likely to be fraudulent and to avoid taking actions such as clicking on links.

[1829] A concrete example would be inputting the following prompt into an automated AI model:

[1830] To assess the likelihood of a scam message regarding unauthorized access to your account, search the internet for information and check for similar scam reports. Keywords to look for are "unauthorized account access" and "example.com".

[1831] Using this prompt, an automated artificial intelligence system performs an internet search and evaluates the likelihood of fraud.

[1832] As described above, this invention provides a system that automatically identifies fraudulent messages sent via carrier email and short message services, and promptly and appropriately warns users, thereby preventing damage from fraud. Furthermore, by using an emotion engine, it can respond in a way that takes the user's emotions into consideration, thereby protecting users more effectively.

[1833] The flow of the specific processing in Example 2 will be explained using Figure 13.

[1834] Step 1: Receiving emails

[1835] The device monitors and receives new messages in carrier email and short message service (SMS) in real time. This monitoring utilizes services such as the notification listener service of the Android OS. When a new message arrives, the device immediately retrieves the information.

[1836] Input: Messages sent via carrier email or SMS

[1837] Output: Received message data

[1838] Specific operation: When a new message is sent, the terminal immediately captures its metadata and text content.

[1839] Step 2: Message Extraction

[1840] The terminal analyzes and extracts the body and header information (sender, subject, etc.) of the received message. This includes, for example, using regular expressions to analyze the email sender and subject according to a specific format.

[1841] Input: Received message data

[1842] Output: Header information of the extracted message (sender, subject), body.

[1843] Specific operation: The terminal uses regular expressions to extract the sender's address, subject, and body. For example, it identifies fields such as "From:" and "Subject:" and retrieves their values.

[1844] Step 3: Send message information

[1845] The terminal sends the extracted message information (sender, subject, and body) to the server. This transmission uses an HTTP POST request. The server receives this information and proceeds to the next processing step.

[1846] Input: Header information and body of the extracted message

[1847] Output: Sending message information to the server

[1848] Specific operation: The terminal generates an HTTP POST request and sends message information to the server. The request is constructed including the destination URL and authentication information.

[1849] Step 4: Analyze message information

[1850] The server forwards the received message information to an automated artificial intelligence system (e.g., a BERT or GPT model). This system extracts keywords from the message information to assess the likelihood of fraud and performs a web search based on these keywords.

[1851] Input: Message information sent to the server

[1852] Output: Search results and related information to assess the likelihood of fraud.

[1853] Specific operation: The automated artificial intelligence system extracts specific keywords from the body and header information of received messages. This is done using natural language processing techniques. Next, it uses these keywords to perform a web search on the internet and collect relevant information.

[1854] Step 5: Determining the possibility of fraud

[1855] The server scores the likelihood of fraud based on search results and related information from an automatically generated artificial intelligence system. This scoring uses a continuous scale, for example, ranging from 0 to 1, with a score of 0.7 or higher indicating a high probability of fraud.

[1856] Input: Search results and related information from an automatically generated artificial intelligence system.

[1857] Output: Fraud Probability Score

[1858] Specific operation: The server scores the search results based on factors such as frequency of results, the degree of matching with past fraud databases, and warning information, and assesses the likelihood of fraud.

[1859] Step 6: Generating a warning message

[1860] If a message is determined to be highly likely to be a scam, the server generates a warning in HTML format. This information includes the sender, subject, and body of the received message, as well as a notification indicating the possibility of fraud.

[1861] Input: Message information and score that are likely to be fraudulent.

[1862] Output: HTML document containing a warning message.

[1863] Specific operation: The server uses a template engine to generate a warning message in HTML format. For example, it might insert text such as, "This may be a scam. Do not click the link."

[1864] Step 7: Adjusting responses using the emotional engine

[1865] Before sending the generated alert information, the emotion engine recognizes the user's emotions. The emotion engine analyzes the user's facial expressions, tone of voice, input patterns, etc., to determine the user's emotions. Based on the recognized emotions, the content and display method of the alert information are adjusted.

[1866] Input: User emotional data (facial expressions, voice tone, input patterns)

[1867] Output: Adjusted warning information

[1868] Specific operation: The emotion engine uses the camera and microphone to analyze the user's emotional state in real time, and if the user shows signs of anxiety, it provides additional supportive information.

[1869] Step 8: User Notifications

[1870] The server sends the generated warning HTML to the device. The device receives this HTML and displays it to the user. This display allows the user to recognize the risk of fraud and avoid actions such as clicking on links.

[1871] Input: Warning HTML from the server

[1872] Output: Warning information displayed to the user

[1873] Specific operation: The device displays the received HTML to the user using WebView or browser components, visually conveying the warning content.

[1874] This allows users to take appropriate action against fraudulent messages and prevent becoming a victim. For example, users can avoid becoming a victim of fraud by not clicking on links such as "http: / / example.com".

[1875] (Application Example 2)

[1876] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".

[1877] In recent years, fraudulent activities using carrier email and short message services have become rampant, and effective countermeasures are needed. Furthermore, in autonomous vehicles, it is difficult to take appropriate measures when passengers receive fraudulent messages. In addition, there is a need for responses that take into account the emotional state of passengers in response to fraudulent messages, but such systems do not yet exist. To solve these problems, a system is needed that evaluates messages and takes appropriate responses based on the emotions involved.

[1878] In Application Example 2, the identification processing by the identification processing unit 290 of the data processing device 12 is realized by the following means. In this invention, the server includes means for receiving the body and header information of messages received via carrier mail or short message service, means for extracting the received message information, means for transmitting the extracted message information to a central processing device, means for transmitting the message information to an automatically generated artificial intelligence system for the central processing device to evaluate the message information, means for the automatically generated artificial intelligence system to perform a web search based on the message information and evaluate the possibility of fraud, means for receiving the evaluation results, means for generating warning information if there is a high possibility of fraud, means for transmitting the generated warning information to a terminal, means for displaying the transmitted warning information to the user, means for recognizing the user's emotions and adjusting the response, and means for coordinating with the in-vehicle information system of an autonomous vehicle to evaluate the fraudulent nature of messages received by passengers in the vehicle and notify them. This makes it possible to efficiently evaluate the fraudulent nature of messages received by passengers and provide appropriate warnings. Furthermore, by adjusting the response based on the passenger's emotional state, it becomes possible to effectively prevent fraud damage.

[1879] "Carrier email" refers to email services provided by telecommunications carriers, and is typically sent and received using mobile phones or smartphones.

[1880] Short Message Service (SMS) is a communication service that allows users to send and receive short messages via mobile phones and smartphones.

[1881] "Message body" refers to the actual content written in carrier emails and short message services.

[1882] "Message header information" refers to the part of the message that contains information related to its management, such as the sender, recipient, subject, date and time, etc.

[1883] A "central processing unit" is the central part of a computer system that performs data processing. It receives data from other systems and devices, and then analyzes and makes decisions based on that data.

[1884] An "automatic generation artificial intelligence system" is a system that uses artificial intelligence technology to automatically generate and analyze data.

[1885] "Web search" refers to the act of finding information on the internet using a search engine.

[1886] "Potential fraud" refers to the possibility that a message could be used for malicious purposes, such as fraudulent activities.

[1887] "Warning information" is information intended to alert users and is presented when there is a possibility of fraud.

[1888] A "terminal" refers to an information device that the user directly operates, and includes personal computers, smartphones, tablets, and other similar devices.

[1889] A "user" refers to a person who uses this system.

[1890] "Means of recognizing emotions" refer to methods and technologies for analyzing a user's facial expressions, tone of voice, etc., to understand their emotional state.

[1891] An "autonomous vehicle" is a vehicle that has the function to drive itself without a human driver.

[1892] An "in-vehicle information system" refers to an information processing system installed in a vehicle, providing functions such as navigation, entertainment, and communication.

[1893] This invention is a system that automatically evaluates the fraudulent nature of messages received via carrier email or short message service and alerts the user as needed. In particular, it works in conjunction with the in-vehicle information system of autonomous vehicles to evaluate the likelihood of fraud in messages received by passengers in the vehicle and provide a response that takes the user's feelings into consideration.

[1894] Receiving and extracting emails

[1895] The device receives new messages via carrier email or short message service. For example, consider the following message:

[1896] From: 12345

[1897] Subject: (Urgent) Unauthorized access to your account has been detected

[1898] Body: Click the following link to verify your account: http: / / example.com

[1899] The terminal extracts the message body and header information (sender, subject, etc.). This allows the message content and its associated metadata to be separated and extracted.

[1900] Analysis and evaluation of message information

[1901] The extracted message information is sent from the terminal to the central processing unit. The central processing unit receives this information and forwards it to the automated artificial intelligence system. The automated artificial intelligence system performs a web search to evaluate the likelihood of fraud based on the message information.

[1902] The automated artificial intelligence system extracts keywords from the message body and header information, and then searches the internet for related information based on those keywords. For example, it might extract keywords such as "unauthorized account access" and "example.com". In this way, the search results confirm that there are numerous reports and warnings of similar phishing emails.

[1903] Determination and notification of potential fraud

[1904] The central processing unit receives results from the automatically generated artificial intelligence system and scores the likelihood of fraud. Based on this scoring, it determines whether the likelihood of fraud is high.

[1905] If a message is determined to be highly likely to be fraudulent, the central processing unit generates a warning. This information, in HTML format, includes the sender, subject, and body of the received message, as well as a notification indicating the possibility of fraud. For example, the following warning information may be generated:

[1906] html

[1907]

[1908]

[1909] <h2>Caution: This may be a phishing email.< / h2>

[1910] The following email is likely a scam. Do not click on the link.

[1911] Sender: 12345

[1912] Subject: (Urgent) Unauthorized access to your account has been detected

[1913] Text: Click the following link to verify your account: http: / / example.com

[1914]

[1915]

[1916] Adjusting responses using an emotional engine

[1917] Before sending the generated alert information, the emotion engine recognizes the user's emotions. The emotion engine determines the user's emotions by analyzing the user's facial expressions, tone of voice, input patterns, etc. Based on the recognized emotions, the content and display method of the alert information are adjusted. For example, if the user is showing signs of stress or anxiety, the central processing unit provides additional support information and guidance. Specifically, it might display a message such as, "This email may be a scam. Please remain calm. If you have any questions, please contact our support center."

[1918] User notifications

[1919] The central processing unit sends the generated warning HTML to the terminal. The terminal displays the received HTML to the user. This display allows the user to recognize that the received message is likely to be fraudulent and to avoid actions such as clicking on links. For example, the risk of a user unknowingly clicking on a link such as "http: / / example.com" is reduced. In this way, the user is protected from becoming a victim of fraud.

[1920] Specific example

[1921] If a passenger receives a fraudulent email while in an autonomous vehicle, the system analyzes the message and determines that it is likely to be a scam. At the same time, if the emotion engine detects that the passenger is feeling stressed, it will display a reassuring message such as "Please stay calm and deal with this calmly" as a warning.

[1922] Example of a prompt

[1923] Please evaluate the fraudulent nature of the following message:

[1924] Email sender: 12345

[1925] Subject: (Urgent) Unauthorized access to your account has been detected

[1926] Text: Click the following link to verify your account: http: / / example.com

[1927] Additionally, if the system determines that the user is emotionally unstable, please generate a gentle and reassuring message.

[1928] The flow of a specific process in Application Example 2 will be explained using Figure 14.

[1929] Program processing flow

[1930] Step 1:

[1931] The device receives new messages from carrier email or short message service. The input includes the message body and header information (sender, subject, etc.). Data processing involves extracting the message body and header information. The output is the extracted message information.

[1932] Step 2:

[1933] The terminal transmits the extracted message information to the central processing unit. The extracted message information is required as input. The data processing involves transmitting the information. The output is the message information received by the central processing unit.

[1934] Step 3:

[1935] The central processing unit transmits message information to the automated artificial intelligence system. Its input includes message information received from the terminal. As a data calculation, it reprocesses the message information and transmits it. The output is the message information received by the automated artificial intelligence system.

[1936] Step 4:

[1937] The automated artificial intelligence system performs a web search based on message information and evaluates the likelihood of fraud. The input includes keywords extracted from the message body and header information. Data processing involves keyword extraction and web search. The output is an evaluation of the likelihood of fraud.

[1938] Step 5:

[1939] The central processing unit receives evaluation results from an automatically generated artificial intelligence system and scores the likelihood of fraud. The input includes the evaluation results. The data calculation is performed as a scoring process. The output is a score regarding the likelihood of fraud.

[1940] Step 6:

[1941] If a fraudulent activity is determined to be highly likely, the central processing unit generates a warning. The input includes a score indicating the likelihood of fraud. The data processing generates a warning in HTML format. The output is the generated warning.

[1942] Step 7:

[1943] Before sending the generated alert information, the emotion engine recognizes the user's emotions. Inputs include the user's facial expressions and tone of voice. The data calculation involves emotion recognition. The output is the recognized emotional state of the user.

[1944] Step 8:

[1945] The system adjusts the content and display method of alert information based on the user's emotions recognized by the emotion engine. Input includes the recognized emotional state and alert information. Data processing involves adjusting the information. Output is the adjusted alert information.

[1946] Step 9:

[1947] The central processing unit transmits the adjusted alert information to the terminal. The input includes the adjusted alert information. The data processing involves transmitting the information. The output is the adjusted alert information received by the terminal.

[1948] Step 10:

[1949] The device displays the received, adjusted alert information to the user. The input includes the adjusted alert information. The data calculation process displays the information. The output is the alert information displayed to the user. This allows the user to recognize that the received message is likely fraudulent and take appropriate action.

[1950] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the controlled object 443 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.

[1951] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[1952] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the robot 414.

[1953] Furthermore, the emotion identification model 59, acting as an emotion engine, may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to a specific mapping, which is an emotion map (see Figure 9). Similarly, the emotion identification model 59 may also determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.

[1954] Figure 9 shows an emotion map 400 in which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. The closer to the center of the concentric circles, the more primitive the emotions are located. Further out of the concentric circles, emotions representing states and actions arising from mental states are located. Emotion is a concept that includes feelings and mental states. On the left side of the concentric circles, emotions that are generally generated from reactions occurring in the brain are located. On the right side of the concentric circles, emotions that are generally induced by situational judgment are located. Above and below the concentric circles, emotions that are generally generated from reactions occurring in the brain and induced by situational judgment are located. In addition, the emotion of "pleasure" is located on the upper side of the concentric circles, and the emotion of "displeasure" is located on the lower side. Thus, in the emotion map 400, multiple emotions are mapped based on the structure in which emotions arise, and emotions that are likely to occur simultaneously are mapped close together.

[1955] These emotions are distributed at the 3 o'clock position on the Emotion Map 400, and usually fluctuate between feelings of security and anxiety. In the right half of the Emotion Map 400, situational awareness takes precedence over internal feelings, resulting in a calm impression.

[1956] The inside of the Emotion Map 400 represents inner thoughts, while the outside represents actions. Therefore, the further you go from the outside of the Emotion Map 400, the more visible (expressed in actions) your emotions become.

[1957] Here, human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. Similarly, in robots, cars, motorcycles, etc., emotions can be created based on various balances, such as posture and battery level. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. The emotion map can be generated, for example, based on Dr. Mitsuyoshi's emotion map (Research on a system for analyzing brain physiological signals of speech emotion recognition and emotion, Tokushima University, doctoral dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map contains emotions belonging to a region called "response," where sensation is dominant. The right half of the emotion map contains emotions belonging to a region called "situation," where situational awareness is dominant.

[1958] The emotion map defines two emotions that promote learning. One is the emotion around the middle of the negative "repentance" and "reflection" on the situation side. In other words, it is when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is the emotion around the positive "desire" on the reaction side. In other words, it is when the robot has positive feelings such as "I want more" or "I want to know more."

[1959] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values ​​representing each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple training data sets, which are combinations of user input and emotion values ​​representing each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions located close together have similar values, as shown in the emotion map 900 in Figure 10. Figure 10 shows an example where multiple emotions such as "reassured," "calm," and "confident" have similar emotion values.

[1960] The above description primarily focuses on the functions of the data processing device 12 in relation to this disclosure. However, the system related to this disclosure is not necessarily implemented on a server. The system related to this disclosure may be implemented as a general information processing system. This disclosure may be implemented, for example, as a software program that runs on a personal computer or as an application that runs on a smartphone. The method related to this disclosure may be provided to users in SaaS (Software as a Service) format.

[1961] In the above embodiment, an example was given in which a specific process is performed by a single computer 22. However, the technology of this disclosure is not limited thereto, and a distributed processing of the specific process may be performed by multiple computers, including computer 22. For example, a data generation model 58 may be provided in an external device of the data processing device 12, and the external device may generate data according to the input data.

[1962] In the above embodiment, an example was given in which the specific processing program 56 is stored in the storage 32, but the technology of this disclosure is not limited thereto. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-te...

Claims

1. A means of receiving the body and header information of messages received via carrier email or short message service, A means for extracting received message information, Means for transmitting extracted message information to a central processing unit, A means by which a central processing unit transmits message information to an automated artificial intelligence system for evaluation of the message information, An automated artificial intelligence system performs a web search based on message information to evaluate the likelihood of fraud, Means of receiving evaluation results, A means of generating warning information when there is a high possibility of fraud, A means for transmitting the generated warning information to a terminal, A means of displaying the transmitted warning information to the user, A system that includes this.

2. The system according to claim 1, further comprising means for an automatically generating artificial intelligence system to extract keywords from message information and perform a web search based on the extracted keywords in order to assess the possibility of fraud.

3. The system according to claim 1, further comprising means for generating warning information in HTML format, including the sender of the message, subject, body, and a notice indicating the possibility of fraud.

Citation Information

Patent Citations

  • Persona chatbot control method and system

    JP2022180282A