system

The cybersecurity ecosystem addresses the challenge of cyberattack sophistication by using a generation unit, Blue and Red teams to fine-tune and retrain a proprietary model, ensuring robust defense strategies.

JP2026072698APending Publication Date: 2026-05-01SOFTBANK GROUP CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
SOFTBANK GROUP CORP
Filing Date
2024-10-18
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

Existing systems face challenges in quickly providing effective defense strategies against the sophistication and diversification of cyberattacks.

Method used

A cybersecurity ecosystem utilizing a generation unit, Blue team, Red team, and Murasaki team to fine-tune an OSS LLM, diagnose vulnerabilities, perform hacking attempts, and integrate feedback for retraining, creating a proprietary model specialized for security within a secure environment.

Benefits of technology

Enables rapid and effective defense against cyberattacks by integrating offensive and defensive capabilities, enhancing system security through continuous learning and adaptation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026072698000001_ABST
    Figure 2026072698000001_ABST
Patent Text Reader

Abstract

The system according to this embodiment aims to provide a rapid and effective defense against cyberattacks. [Solution] The system according to the embodiment comprises a generation unit, a Blue team generation unit, a Red team generation unit, and a Murasaki team generation unit. The generation unit performs fine tuning based on OSS LLM trained in the company's secure environment to create a proprietary model specialized for security. The Blue team generation unit diagnoses vulnerabilities from the system configuration and source code, and proposes countermeasures if vulnerabilities are found. The Red team generation unit attempts hacking using all available security knowledge and vulnerability information. The Murasaki team generation unit integrates feedback from the Red team and the Blue team and performs retraining.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The technology of the present disclosure relates to a system.

Background Art

[0002] Patent Document 1 discloses a persona chatbot control method performed by at least one processor, including steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to an explanation of a chatbot character, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] In the prior art, there was a problem that it was difficult to quickly provide an effective defense strategy against the sophistication and diversification of cyberattacks.

[0005] The system according to the embodiment aims to quickly and effectively provide a defense strategy against cyberattacks.

Means for Solving the Problems

[0006] The system according to this embodiment comprises a generation unit, a Blue team generation unit, a Red team generation unit, and a Murasaki team generation unit. The generation unit fine-tunes the OSS LLM, which has been trained in the company's secure environment, to create a proprietary model specialized for security. The Blue team generation unit diagnoses vulnerabilities from the system configuration and source code, and proposes countermeasures if vulnerabilities are found. The Red team generation unit attempts hacking using all available security knowledge and vulnerability information. The Murasaki team generation unit integrates feedback from the Red team and the Blue team and performs retraining. [Effects of the Invention]

[0007] The system according to this embodiment can provide a rapid and effective defense against cyberattacks. [Brief explanation of the drawing]

[0008] [Figure 1] This is a conceptual diagram showing an example of the configuration of a data processing system according to the first embodiment. [Figure 2] This is a conceptual diagram showing an example of the essential functions of a data processing device and a smart device according to the first embodiment. [Figure 3] This is a conceptual diagram showing an example of the configuration of a data processing system according to the second embodiment. [Figure 4] This is a conceptual diagram showing an example of the main functions of a data processing device and smart glasses according to the second embodiment. [Figure 5] This is a conceptual diagram showing an example of the configuration of a data processing system according to the third embodiment. [Figure 6] This is a conceptual diagram showing an example of the main functions of a data processing device and a headset-type terminal according to the third embodiment. [Figure 7] This is a conceptual diagram showing an example of the configuration of a data processing system according to the fourth embodiment. [Figure 8] This is a conceptual diagram showing an example of the main functions of a data processing device and a robot according to the fourth embodiment. [Figure 9] This shows an emotion map where multiple emotions are mapped. [Figure 10] This shows an emotion map where multiple emotions are mapped. [Modes for carrying out the invention]

[0009] Hereinafter, an example of an embodiment of the system relating to the technology of this disclosure will be described with reference to the attached drawings.

[0010] First, let's explain the terminology used in the following explanation.

[0011] In the following embodiments, the signed processor (hereinafter simply referred to as "processor") may be a single arithmetic unit or a combination of multiple arithmetic units. Furthermore, the processor may be a single type of arithmetic unit or a combination of multiple types of arithmetic units. Examples of arithmetic units include CPU (Central Processing Unit), GPU (Graphics Processing Unit), GPGPU (General-Purpose computing on Graphics Processing Units), APU (Accelerated Processing Unit), or TPU (Tensor Processing Unit).

[0012] In the following embodiments, signed RAM (Random Access Memory) is a memory that temporarily stores information and is used as work memory by the processor.

[0013] In the following embodiments, the signed storage is one or more non-volatile storage devices that store various programs and various parameters. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), or magnetic tapes.

[0014] In the following embodiments, the signed communication I / F (Interface) is an interface including a communication processor, an antenna, and the like. The communication I / F manages communication between a plurality of computers. Examples of communication standards applied to the communication I / F include wireless communication standards including 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), or Bluetooth (registered trademark).

[0015] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B". That is, "A and / or B" means that it may be only A, only B, or a combination of A and B. Also, in this specification, when expressing three or more matters connected by "and / or", the same concept as "A and / or B" is applied.

[0016] [First Embodiment] FIG. 1 shows an example of the configuration of a data processing system 10 according to the first embodiment.

[0017] As shown in FIG. 1, the data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server. [[ID=*17]]

[0018] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. Also, the database 24 and the communication I / F 26 are connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0019] It seems there is a redundant `

[0018] ` tag in the original text which I've left as is in the translation. If this is an error, please correct the original text for a more accurate translation. The smart device 14 comprises a computer 36, a receiving device 38, an output device 40, a camera 42, and a communication interface 44. The computer 36 comprises a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The receiving device 38, output device 40, and camera 42 are also connected to the bus 52.

[0020] The reception device 38 is equipped with a touch panel 38A and a microphone 38B, and accepts user input. The touch panel 38A accepts user input via touch by detecting contact with an object (e.g., a pen or finger). The microphone 38B accepts user input via voice by detecting the user's voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and microphone 38B to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 (see Figure 2) acquires the data indicating the user input.

[0021] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user by outputting the data in a form perceptible to the user (e.g., audio and / or text). The display 40A displays visible information such as text and images according to instructions from the processor 46. The speaker 40B outputs audio according to instructions from the processor 46. The camera 42 is a small digital camera equipped with an optical system such as a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.

[0022] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various types of information between processor 46 and processor 28 via network 54.

[0023] Figure 2 shows an example of the main functions of the data processing device 12 and the smart device 14.

[0024] As shown in Figure 2, in the data processing device 12, a specific processing is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" related to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.

[0025] Storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotions using the emotion identification model 59 and perform identification processing using the user's emotions. The emotion estimation function (emotion identification function) using the emotion identification model 59 performs various estimations and predictions regarding the user's emotions, including but not limited to these examples. Furthermore, emotion estimation and prediction also include, for example, emotion analysis.

[0026] In the smart device 14, specific processing is performed by the processor 46. The storage 50 stores a specific processing program 60. The specific processing program 60 is used in conjunction with the specific processing program 56 by the data processing system 10. The processor 46 reads the specific processing program 60 from the storage 50 and executes the read specific processing program 60 on the RAM 48. The specific processing is realized by the processor 46 operating as a control unit 46A according to the specific processing program 60 executed on the RAM 48. The smart device 14 also has a data generation model 58 and an emotion identification model 59, similar to the data generation model and emotion identification model 59, and can perform processing similar to that of the specific processing unit 290 using these models.

[0027] Furthermore, other devices besides the data processing device 12 may also have the data generation model 58. For example, a server device (e.g., a generation server) may have the data generation model 58. In this case, the data processing device 12 obtains processing results (such as prediction results) using the data generation model 58 by communicating with the server device having the data generation model 58. The data processing device 12 may also be a server device or a terminal device owned by a user (e.g., a mobile phone, robot, home appliance, etc.). Next, an example of processing by the data processing system 10 according to the first embodiment will be described.

[0028] (Example of form 1) The cybersecurity ecosystem according to an embodiment of the present invention is a system for strengthening cybersecurity measures using generative AI. This system creates a local LLM (proprietary generative AI) in the company's internal environment and generates a Red team that performs attacks and a Blue team that strengthens defenses. This realizes an ecosystem in which the obtained feedback is incorporated into the local LLM for retraining. First, fine tuning is performed on an OSS LLM that has been trained in the company's secure environment to create a proprietary model specialized for security. This local LLM can safely learn confidential information without transmitting data externally. Next, the Blue team is generated. The Blue team, acting as white hat hackers, diagnoses vulnerabilities from the system configuration and source code, and proposes countermeasures if vulnerabilities are found. For information not present in the local LLM, it refers to an external database such as CVE and generates answers from the latest information. This result is reused as training data for the local LLM as a vulnerability assessment result. Furthermore, the Red team is generated. The Red team, acting as black hat hackers, attempts hacking using all available security knowledge and vulnerability information. The generative AI verifies even creative attack methods that have never been used before. This result is also reused as training data for the local LLM as a vulnerability assessment result. Finally, by integrating feedback from the Red and Blue teams and retraining, we will build a Murasaki team that combines offensive and defensive capabilities. This ecosystem will enable the creation of robust internal systems. In this way, the cybersecurity ecosystem can provide an ecosystem for strengthening cybersecurity measures using generative AI.

[0029] The cybersecurity ecosystem according to this embodiment comprises a generation unit, a Blue team generation unit, a Red team generation unit, and a Murasaki team generation unit. The generation unit performs fine tuning based on OSS LLM that has been trained in the company's secure environment to create a proprietary model specialized for security. For example, the generation unit uses the trained OSS LLM to add security-related datasets and perform fine tuning. Furthermore, the generation unit can securely learn confidential information without transmitting data externally. For example, the generation unit operates only in the company's secure environment and restricts access to external networks. The Blue team generation unit diagnoses vulnerabilities from system configurations and source code and proposes countermeasures if vulnerabilities are found. For example, the Blue team generation unit performs static analysis of the system to detect vulnerabilities. The Blue team generation unit can also perform dynamic analysis to detect runtime vulnerabilities. In addition, the Blue team generation unit refers to external databases, such as CVE, and generates answers from the latest information. For example, the Blue team generation unit queries the CVE database to obtain the latest vulnerability information. The Red team generation unit attempts hacking using all available security knowledge and vulnerability information. The Red Team generation unit, for example, conducts penetration testing and attacks system vulnerabilities. The Red Team generation unit can also verify creative attack methods using generative AI. For example, the Red Team generation unit prompts the generative AI with "Please propose a new attack method" and tries out the attack method proposed by the generative AI. The Murasaki Team generation unit integrates feedback from the Red Team and Blue Team and performs retraining. For example, the Murasaki Team generation unit aggregates the diagnostic results from the Red Team and Blue Team to create a retraining dataset. Furthermore, the Murasaki Team generation unit can improve the accuracy of the model by retraining using the generative AI. Thus, the cybersecurity ecosystem according to this embodiment can provide an ecosystem for strengthening cybersecurity measures using generative AI.

[0030] The generation unit creates a proprietary security-focused model by fine-tuning an OSS LLM (Open Source Large-Scale Language Model) that has been trained in a secure internal environment. Specifically, the generation unit first selects an OSS LLM and adds security-related datasets to it. These datasets include reports on past security incidents, vulnerability information, and security best practices. Next, the generation unit performs fine-tuning using these datasets. During the fine-tuning process, the model is adjusted to be highly accurate in making predictions and suggestions specifically for security-related tasks. Furthermore, the generation unit can securely train on confidential information without transmitting data externally. Specifically, the generation unit operates only in a secure internal environment and restricts access to external networks, eliminating the risk of confidential information leaking externally. This secure environment is equipped with security measures such as firewalls and access control lists (ACLs) to prevent unauthorized access from outside. The generation unit also regularly applies security patches to address the latest security threats. As a result, the generation unit can generate highly accurate security models while securely handling security-related data.

[0031] The Blue Team Generation Unit performs vulnerability assessments based on system configuration and source code, and proposes countermeasures if vulnerabilities are found. Specifically, the Blue Team Generation Unit first performs a static analysis of the system, analyzing source code and configuration files to detect potential vulnerabilities. Static analysis analyzes the structure and patterns of the code to identify known vulnerabilities and security holes. The Blue Team Generation Unit can also perform dynamic analysis to detect runtime vulnerabilities. Dynamic analysis detects abnormal behavior and unauthorized access while the system is actually running. Furthermore, the Blue Team Generation Unit refers to external databases such as CVE (Common Vulnerabilities and Exposures) and generates answers from the latest information. Specifically, the Blue Team Generation Unit queries the CVE database to obtain the latest vulnerability information. This allows the Blue Team Generation Unit to quickly identify system vulnerabilities based on the latest vulnerability information and propose appropriate countermeasures. For example, if a specific vulnerability is detected, it will propose how to apply a patch for that vulnerability and the procedure for changing the configuration. The Blue Team Generation Unit also performs an impact assessment and risk assessment of the detected vulnerabilities and can propose high-priority countermeasures. This allows the Blue Team generation department to strengthen system security and support early detection and rapid countermeasures against vulnerabilities.

[0032] The Red Team Generation Unit attempts hacking using all available security knowledge and vulnerability information. Specifically, the Red Team Generation Unit first conducts penetration testing to attack system vulnerabilities. In penetration testing, they attempt to bypass system defenses by mimicking the techniques used by actual attackers. This allows them to verify system vulnerabilities and security holes in real attack scenarios. The Red Team Generation Unit can also test creative attack methods using generative AI. Specifically, the Red Team Generation Unit prompts the generative AI with "Please propose a new attack method" and tries out the attack methods proposed by the generative AI. The generative AI can generate new attack methods based on past attack data and the results of security research. For example, the generative AI proposes new attack methods by combining or modifying existing attack methods. The Red Team Generation Unit also actually tries out the attack methods proposed by the generative AI and verifies their effectiveness. This allows the Red Team Generation Unit to always respond to the latest attack methods and strengthen system security. Furthermore, the Red team generation unit can provide feedback on the results of its attack method verification to the Blue team generation unit and the Murasaki team generation unit, thereby improving the overall security measures of the system.

[0033] The Murasaki Team Generation Unit integrates feedback from the Red and Blue teams and performs retraining. Specifically, the Murasaki Team Generation Unit first aggregates the diagnostic results from the Red and Blue teams to create a retraining dataset. This dataset includes detected vulnerability information, verification results of attack methods, and countermeasures. Next, the Murasaki Team Generation Unit uses a generative AI to retrain the model and improve its accuracy. During the retraining process, the generative AI updates the model based on the new dataset and is adjusted to enable more accurate predictions and suggestions. Furthermore, the Murasaki Team Generation Unit evaluates the results of the retraining and adjusts the model parameters as needed. This allows the Murasaki Team Generation Unit to always provide a highly accurate security model based on the latest information. In addition, the Murasaki Team Generation Unit shares the insights gained during the retraining process with other teams to strengthen security measures across the entire system. For example, it provides feedback on the retraining results to the Blue Team Generation Unit to improve the accuracy of vulnerability assessments. It can also propose new attack methods and countermeasures to the Red Team Generation Unit. This will allow the Murasaki team generation department to strengthen collaboration between the Red team and the Blue team, and improve overall system security measures.

[0034] The Blue Team generation unit can refer to external databases, such as CVE, and generate answers from the latest information. For example, the Blue Team generation unit queries the CVE database to obtain the latest vulnerability information. It can also refer to the NVD database to obtain vulnerability information. Furthermore, the Blue Team generation unit can refer to Exploit-DB to obtain known exploit information. This allows vulnerability assessments to be performed based on the latest information. Some or all of the above processes in the Blue Team generation unit may be performed using AI, for example, or without AI. For example, the Blue Team generation unit can input vulnerability information obtained from the CVE database into a generation AI, and the generation AI can generate vulnerability assessment results.

[0035] The Red Team Generation Unit can verify creative attack methods using a generative AI. For example, the Red Team Generation Unit can input a prompt to the generative AI such as "Please propose a new attack method," and then test the attack method proposed by the generative AI. The Red Team Generation Unit can also simulate zero-day attacks using the generative AI. For example, the Red Team Generation Unit can input a prompt to the generative AI such as "Please generate a zero-day attack scenario," and then test an attack based on the scenario generated by the generative AI. Furthermore, the Red Team Generation Unit can also simulate social engineering attacks using the generative AI. For example, the Red Team Generation Unit can input a prompt to the generative AI such as "Please generate a social engineering attack scenario," and then test an attack based on the scenario generated by the generative AI. This allows for the verification of new attack methods. Some or all of the above processes in the Red Team Generation Unit may be performed using AI, or not. For example, the Red Team Generation Unit can manually test an attack based on an attack scenario generated by the generative AI.

[0036] The generation unit can learn confidential information without transmitting data externally. For example, the generation unit operates only within a secure internal environment and restricts access to external networks. The generation unit can also encrypt data to protect confidential information. For example, it can encrypt training data to prevent unauthorized external access. Furthermore, the generation unit can implement access control, ensuring that only specific users can access the data. For example, it can perform user authentication, allowing only authenticated users to access the data. This enables the secure learning of confidential information. Some or all of the above processes in the generation unit may be performed using AI, or not. For example, the generation unit can have the generation AI perform the encryption and decryption of confidential information.

[0037] The Murasaki team generation unit can integrate feedback from the Red team and the Blue team and perform retraining. For example, the Murasaki team generation unit aggregates the diagnostic results from the Red team and the Blue team to create a retraining dataset. The Murasaki team generation unit can also improve the accuracy of the model by performing retraining using generative AI. For example, the Murasaki team generation unit can input a prompt to the generative AI, "Integrate the feedback from the Red team and the Blue team," and the generative AI will integrate the feedback. Furthermore, the Murasaki team generation unit can evaluate the results of retraining and identify areas for improvement in the model. For example, the Murasaki team generation unit can input a prompt to the generative AI, "Evaluate the results of retraining," and the generative AI will output the evaluation results. This enables the realization of an ecosystem that combines offense and defense. Some or all of the above processes in the Murasaki team generation unit may be performed using AI, for example, or without AI. For example, the Murasaki team generation unit can have the generative AI perform the integration of feedback and retraining.

[0038] The generation unit can introduce evaluation criteria to assess the quality of training data and select the optimal dataset. For example, the generation unit can assess data consistency and select a high-quality dataset. It can also assess data diversity and select a balanced dataset. Furthermore, it can assess data recency and select a dataset containing the latest information. For example, the generation unit can evaluate datasets based on criteria such as data accuracy, consistency, diversity, and recency, and select the optimal dataset. This allows for the selection of a high-quality dataset. Some or all of the above processing in the generation unit may be performed using AI, for example, or without AI. For example, the generation unit can have a generative AI perform the evaluation and selection of datasets.

[0039] The generation unit can generate multiple models based on different security scenarios during fine-tuning and select the optimal model. For example, the generation unit can generate models based on different attack scenarios and select the optimal defense model. It can also generate models based on different defense scenarios and select the optimal attack model. Furthermore, the generation unit can generate models based on different operational scenarios and select the optimal operational model. For example, the generation unit can generate models based on scenarios such as DDoS attacks, phishing attacks, and malware attacks, and select the optimal model for each scenario. This allows for the selection of the optimal model based on different security scenarios. Some or all of the above-described processes in the generation unit may be performed using AI, for example, or without AI. For example, the generation unit can have a generation AI perform model generation and selection based on different scenarios.

[0040] The generation unit can customize the model based on the security requirements of different industries during fine-tuning. For example, the generation unit can customize the model based on the security requirements of the financial industry. It can also customize the model based on the security requirements of the healthcare industry. Furthermore, it can customize the model based on the security requirements of the manufacturing industry. For example, the generation unit can add specific functions and adjust parameters based on the security requirements of the financial industry. This allows the model to be customized based on the security requirements of different industries. Some or all of the above processing in the generation unit may be performed using AI, for example, or not using AI. For example, the generation unit can have the generation AI perform model customization based on industry-specific security requirements.

[0041] The generation unit can adjust the model based on security regulations of different regions during fine-tuning. For example, the generation unit can adjust the model based on security regulations in North America. It can also adjust the model based on security regulations in Europe. Furthermore, it can adjust the model based on security regulations in Asia. For example, the generation unit can change parameters and modify the algorithm based on regulations such as GDPR and CCPA. This allows the model to be adjusted based on security regulations of different regions. Some or all of the above processing in the generation unit may be performed using AI, for example, or without AI. For example, the generation unit can have the generation AI perform model adjustments based on regional security regulations.

[0042] The Blue Team Generation Unit can monitor the system's operational status in real time during vulnerability assessments and select the optimal timing for the assessment. For example, the Blue Team Generation Unit can select a time period with low system load to conduct the vulnerability assessment. It can also consider system maintenance times when conducting the vulnerability assessment. Furthermore, the Blue Team Generation Unit can monitor the system's operational status in real time and select the optimal timing for the assessment. For example, it can monitor CPU usage and memory usage and conduct the vulnerability assessment during low load periods. This allows for the selection of the optimal assessment timing based on the system's operational status. Some or all of the above processes in the Blue Team Generation Unit may be performed using AI, or not. For example, the Blue Team Generation Unit can input system operational status data into a generation AI and have the generation AI select the optimal assessment timing.

[0043] The Blue Team Generation Unit can customize its vulnerability assessment methods based on different system configurations. For example, it can apply a specialized assessment method to cloud-based systems. It can also apply a specialized assessment method to on-premises systems. Furthermore, it can apply a specialized assessment method to hybrid systems. For example, the Blue Team Generation Unit adjusts the scope of the assessment using specific tools based on system configurations such as cloud environments, on-premises environments, and hybrid environments. This allows for the customization of assessment methods based on different system configurations. Some or all of the above processes in the Blue Team Generation Unit may be performed using AI, for example, or not. For example, the Blue Team Generation Unit can input system configuration data into a generation AI and have the generation AI perform the customization of the assessment method.

[0044] The Blue Team Generation Unit can integrate vulnerability information from different platforms during vulnerability assessments. For example, the Blue Team Generation Unit can integrate vulnerability information from the Windows platform for assessment. It can also integrate vulnerability information from the Linux platform for assessment. Furthermore, it can integrate vulnerability information from the MacOS platform for assessment. For example, the Blue Team Generation Unit integrates vulnerability information from different platforms into a database and performs assessments using an information aggregation method. This enables assessments by integrating vulnerability information from different platforms. Some or all of the above processing in the Blue Team Generation Unit may be performed using AI, for example, or without AI. For example, the Blue Team Generation Unit can input platform-specific vulnerability information into a generation AI and have the generation AI perform the assessment.

[0045] The Blue Team Generation Unit can improve the accuracy of vulnerability assessments by combining different security tools. For example, the Blue Team Generation Unit can perform assessments by combining static analysis tools and dynamic analysis tools. It can also perform assessments by combining network scanners and application scanners. Furthermore, it can perform assessments by combining vulnerability scanners and penetration testing tools. For example, the Blue Team Generation Unit can perform assessments by combining security tools such as antivirus software, firewalls, and IDS / IPS. This allows for improved assessment accuracy by combining different security tools. Some or all of the above processes in the Blue Team Generation Unit may be performed using AI, for example, or without AI. For example, the Blue Team Generation Unit can input combinations of security tools into a generation AI and have the generation AI perform the task of improving the accuracy of the assessment.

[0046] The Red Team generation unit can improve attack diversity by combining different attack methods during hacking attempts. For example, the Red Team generation unit may combine phishing attacks and malware attacks. It can also combine DDoS attacks and SQL injection. Furthermore, it can combine cross-site scripting and brute-force attacks. For example, the Red Team generation unit may combine methods such as phishing, malware, and DDoS attacks to attempt an attack. This improves attack diversity by combining different attack methods. Some or all of the above processing in the Red Team generation unit may be performed using AI, for example, or not. For example, the Red Team generation unit can input combinations of attack methods into a generation AI and have the generation AI perform the task of improving attack diversity.

[0047] The Red Team generation unit can customize attack methods based on different security environments during hacking attempts. For example, the Red Team generation unit can apply attack methods specifically tailored to cloud environments. It can also apply attack methods specifically tailored to on-premises environments. Furthermore, it can apply attack methods specifically tailored to hybrid environments. For example, the Red Team generation unit uses specific tools and adjusts methods based on security environments such as cloud, on-premises, and hybrid environments. This allows for the customization of attack methods based on different security environments. Some or all of the above processing in the Red Team generation unit may be performed using AI, for example, or not. For example, the Red Team generation unit can input security environment data into a generation AI and have the generation AI perform the customization of attack methods.

[0048] The Red Team generation unit can optimize attack methods by integrating different vulnerability information during hacking attempts. For example, the Red Team generation unit can optimize attack methods by integrating vulnerability information from a CVE database. It can also optimize attack methods by integrating vulnerability information from an NVD database. Furthermore, it can optimize attack methods by integrating vulnerability information from Exploit-DB. For example, the Red Team generation unit integrates different vulnerability information into a database and optimizes attack methods using an information aggregation method. This allows for the optimization of attack methods by integrating different vulnerability information. Some or all of the above processing in the Red Team generation unit may be performed using AI, for example, or without AI. For example, the Red Team generation unit can input vulnerability information into a generation AI and have the generation AI perform the optimization of attack methods.

[0049] The Red Team Generator can improve the accuracy of an attack by combining different security tools during a hacking attempt. For example, the Red Team Generator can combine Metasploit and Nikito to attempt an attack. It can also combine BARF Suite and OWASP ZAP to attempt an attack. Furthermore, it can combine Kalilinax and Enmap to attempt an attack. For example, the Red Team Generator can improve the accuracy of an attack by combining different security tools. This allows for improved attack accuracy by combining different security tools. Some or all of the above processing in the Red Team Generator may be performed using AI, for example, or not using AI. For example, the Red Team Generator can input a combination of security tools into a generating AI and have the generating AI perform the attack accuracy improvement.

[0050] The Murasaki team generation unit can improve the accuracy of learning by integrating different feedback data during retraining. For example, the Murasaki team generation unit can integrate feedback data from the Red team and the Blue team for retraining. It can also integrate feedback data from different security scenarios for retraining. Furthermore, the Murasaki team generation unit can integrate feedback data from different industries for retraining. For example, the Murasaki team generation unit can integrate different feedback data into a database and perform retraining using an information aggregation method. This allows for improved learning accuracy by integrating different feedback data. Some or all of the above processes in the Murasaki team generation unit may be performed using AI, for example, or without AI. For example, the Murasaki team generation unit can input feedback data into a generation AI and have the generation AI perform retraining.

[0051] The Murasaki team generation unit can customize its learning method based on different security scenarios during retraining. For example, the Murasaki team generation unit can customize its learning method based on attack scenarios. It can also customize its learning method based on defense scenarios. Furthermore, it can customize its learning method based on operational scenarios. For example, the Murasaki team generation unit can use a specific learning algorithm and adjust its parameters based on different security scenarios. This allows for the customization of the learning method based on different security scenarios. Some or all of the above processes in the Murasaki team generation unit may be performed using AI, for example, or without AI. For example, the Murasaki team generation unit can input security scenario data into a generation AI and have the generation AI perform the customization of the learning method.

[0052] The Murasaki team generation unit can select training data based on the security requirements of different industries during retraining. For example, the Murasaki team generation unit can select training data based on the security requirements of the financial industry. It can also select training data based on the security requirements of the medical industry. Furthermore, it can select training data based on the security requirements of the manufacturing industry. For example, the Murasaki team generation unit can use a specific dataset to select training data based on the security requirements of different industries. This allows for the selection of training data based on the security requirements of different industries. Some or all of the above processing in the Murasaki team generation unit may be performed using AI, for example, or not using AI. For example, the Murasaki team generation unit can have the generation AI perform the selection of training data based on industry-specific security requirements.

[0053] The Murasaki team generation unit can adjust its learning method based on security regulations in different regions during retraining. For example, the Murasaki team generation unit can adjust its learning method based on security regulations in North America. It can also adjust its learning method based on security regulations in Europe. Furthermore, it can adjust its learning method based on security regulations in Asia. For example, the Murasaki team generation unit can use a specific learning algorithm and adjust its parameters based on regulations such as GDPR and CCPA. This allows the learning method to be adjusted based on security regulations in different regions. Some or all of the above processing in the Murasaki team generation unit may be performed using AI, for example, or not using AI. For example, the Murasaki team generation unit can have the generation AI perform the adjustment of the learning method based on regional security regulations.

[0054] The system according to the embodiment is not limited to the example described above, and various modifications are possible, for example, as follows.

[0055] The Blue Team Generation Unit can monitor the system's operational status in real time during vulnerability assessments and select the optimal timing for the assessment. For example, the Blue Team Generation Unit can select a time period with low system load to conduct the vulnerability assessment. It can also consider system maintenance times when conducting the vulnerability assessment. Furthermore, the Blue Team Generation Unit can monitor the system's operational status in real time and select the optimal timing for the assessment. For example, it can monitor CPU usage and memory usage and conduct the vulnerability assessment during low load periods. This allows for the selection of the optimal assessment timing based on the system's operational status. Some or all of the above processes in the Blue Team Generation Unit may be performed using AI, or not. For example, the Blue Team Generation Unit can input system operational status data into a generation AI and have the generation AI select the optimal assessment timing.

[0056] The Red Team generation unit can improve attack diversity by combining different attack methods during hacking attempts. For example, the Red Team generation unit may combine phishing attacks and malware attacks. It can also combine DDoS attacks and SQL injection. Furthermore, it can combine cross-site scripting and brute-force attacks. For example, the Red Team generation unit may combine methods such as phishing, malware, and DDoS attacks to attempt an attack. This improves attack diversity by combining different attack methods. Some or all of the above processing in the Red Team generation unit may be performed using AI, for example, or not. For example, the Red Team generation unit can input combinations of attack methods into a generation AI and have the generation AI perform the task of improving attack diversity.

[0057] The Murasaki team generation unit can improve the accuracy of learning by integrating different feedback data during retraining. For example, the Murasaki team generation unit can integrate feedback data from the Red team and the Blue team for retraining. It can also integrate feedback data from different security scenarios for retraining. Furthermore, the Murasaki team generation unit can integrate feedback data from different industries for retraining. For example, the Murasaki team generation unit can integrate different feedback data into a database and perform retraining using an information aggregation method. This allows for improved learning accuracy by integrating different feedback data. Some or all of the above processes in the Murasaki team generation unit may be performed using AI, for example, or without AI. For example, the Murasaki team generation unit can input feedback data into a generation AI and have the generation AI perform retraining.

[0058] The Blue Team Generation Unit can customize its vulnerability assessment methods based on different system configurations. For example, it can apply a specialized assessment method to cloud-based systems. It can also apply a specialized assessment method to on-premises systems. Furthermore, it can apply a specialized assessment method to hybrid systems. For example, the Blue Team Generation Unit adjusts the scope of the assessment using specific tools based on system configurations such as cloud environments, on-premises environments, and hybrid environments. This allows for the customization of assessment methods based on different system configurations. Some or all of the above processes in the Blue Team Generation Unit may be performed using AI, for example, or not. For example, the Blue Team Generation Unit can input system configuration data into a generation AI and have the generation AI perform the customization of the assessment method.

[0059] The Red Team generation unit can customize attack methods based on different security environments during hacking attempts. For example, the Red Team generation unit can apply attack methods specifically tailored to cloud environments. It can also apply attack methods specifically tailored to on-premises environments. Furthermore, it can apply attack methods specifically tailored to hybrid environments. For example, the Red Team generation unit uses specific tools and adjusts methods based on security environments such as cloud, on-premises, and hybrid environments. This allows for the customization of attack methods based on different security environments. Some or all of the above processing in the Red Team generation unit may be performed using AI, for example, or not. For example, the Red Team generation unit can input security environment data into a generation AI and have the generation AI perform the customization of attack methods.

[0060] The Murasaki team generation unit can customize its learning method based on different security scenarios during retraining. For example, the Murasaki team generation unit can customize its learning method based on attack scenarios. It can also customize its learning method based on defense scenarios. Furthermore, it can customize its learning method based on operational scenarios. For example, the Murasaki team generation unit can use a specific learning algorithm and adjust its parameters based on different security scenarios. This allows for the customization of the learning method based on different security scenarios. Some or all of the above processes in the Murasaki team generation unit may be performed using AI, for example, or without AI. For example, the Murasaki team generation unit can input security scenario data into a generation AI and have the generation AI perform the customization of the learning method.

[0061] The following briefly describes the processing flow for example form 1.

[0062] Step 1: The generation unit fine-tunes a pre-trained OSS LLM in the company's secure environment to create a proprietary model specialized for security. The generation unit adds security-related datasets to the pre-trained OSS LLM and performs fine-tuning. Furthermore, the generation unit can securely learn confidential information without transmitting data externally. The generation unit operates only in the company's secure environment and restricts access to external networks. Step 2: The Blue Team generation unit diagnoses vulnerabilities from the system configuration and source code, and proposes countermeasures if vulnerabilities are found. The Blue Team generation unit performs static analysis of the system to detect vulnerabilities. It can also perform dynamic analysis to detect runtime vulnerabilities. Furthermore, the Blue Team generation unit refers to external databases such as CVE and generates answers from the latest information. For example, it queries the CVE database to obtain the latest vulnerability information. Step 3: The Red Team Generation Unit attempts hacking using all available security knowledge and vulnerability information. The Red Team Generation Unit conducts penetration testing and attacks system vulnerabilities. They can also use generational AI to test creative attack methods. For example, they can input a prompt to the generational AI such as "Please suggest a new attack method," and then try out the attack methods suggested by the generational AI. Step 4: The Murasaki team generation unit integrates feedback from the Red and Blue teams and performs retraining. The Murasaki team generation unit aggregates the diagnostic results from the Red and Blue teams and creates a retraining dataset. It can also use the generated AI to perform retraining and improve the accuracy of the model.

[0063] (Example of form 2) The cybersecurity ecosystem according to an embodiment of the present invention is a system for strengthening cybersecurity measures using generative AI. This system creates a local LLM (proprietary generative AI) in the company's internal environment and generates a Red team that performs attacks and a Blue team that strengthens defenses. This realizes an ecosystem in which the obtained feedback is incorporated into the local LLM for retraining. First, fine tuning is performed on an OSS LLM that has been trained in the company's secure environment to create a proprietary model specialized for security. This local LLM can safely learn confidential information without transmitting data externally. Next, the Blue team is generated. The Blue team, acting as white hat hackers, diagnoses vulnerabilities from the system configuration and source code, and proposes countermeasures if vulnerabilities are found. For information not present in the local LLM, it refers to an external database such as CVE and generates answers from the latest information. This result is reused as training data for the local LLM as a vulnerability assessment result. Furthermore, the Red team is generated. The Red team, acting as black hat hackers, attempts hacking using all available security knowledge and vulnerability information. The generative AI verifies even creative attack methods that have never been used before. This result is also reused as training data for the local LLM as a vulnerability assessment result. Finally, by integrating feedback from the Red and Blue teams and retraining, we will build a Murasaki team that combines offensive and defensive capabilities. This ecosystem will enable the creation of robust internal systems. In this way, the cybersecurity ecosystem can provide an ecosystem for strengthening cybersecurity measures using generative AI.

[0064] The cybersecurity ecosystem according to this embodiment comprises a generation unit, a Blue team generation unit, a Red team generation unit, and a Murasaki team generation unit. The generation unit performs fine tuning based on OSS LLM that has been trained in the company's secure environment to create a proprietary model specialized for security. For example, the generation unit uses the trained OSS LLM to add security-related datasets and perform fine tuning. Furthermore, the generation unit can securely learn confidential information without transmitting data externally. For example, the generation unit operates only in the company's secure environment and restricts access to external networks. The Blue team generation unit diagnoses vulnerabilities from system configurations and source code and proposes countermeasures if vulnerabilities are found. For example, the Blue team generation unit performs static analysis of the system to detect vulnerabilities. The Blue team generation unit can also perform dynamic analysis to detect runtime vulnerabilities. In addition, the Blue team generation unit refers to external databases, such as CVE, and generates answers from the latest information. For example, the Blue team generation unit queries the CVE database to obtain the latest vulnerability information. The Red team generation unit attempts hacking using all available security knowledge and vulnerability information. The Red Team generation unit, for example, conducts penetration testing and attacks system vulnerabilities. The Red Team generation unit can also verify creative attack methods using generative AI. For example, the Red Team generation unit prompts the generative AI with "Please propose a new attack method" and tries out the attack method proposed by the generative AI. The Murasaki Team generation unit integrates feedback from the Red Team and Blue Team and performs retraining. For example, the Murasaki Team generation unit aggregates the diagnostic results from the Red Team and Blue Team to create a retraining dataset. Furthermore, the Murasaki Team generation unit can improve the accuracy of the model by retraining using the generative AI. Thus, the cybersecurity ecosystem according to this embodiment can provide an ecosystem for strengthening cybersecurity measures using generative AI.

[0065] The generation unit creates a proprietary security-focused model by fine-tuning an OSS LLM (Open Source Large-Scale Language Model) that has been trained in a secure internal environment. Specifically, the generation unit first selects an OSS LLM and adds security-related datasets to it. These datasets include reports on past security incidents, vulnerability information, and security best practices. Next, the generation unit performs fine-tuning using these datasets. During the fine-tuning process, the model is adjusted to be highly accurate in making predictions and suggestions specifically for security-related tasks. Furthermore, the generation unit can securely train on confidential information without transmitting data externally. Specifically, the generation unit operates only in a secure internal environment and restricts access to external networks, eliminating the risk of confidential information leaking externally. This secure environment is equipped with security measures such as firewalls and access control lists (ACLs) to prevent unauthorized access from outside. The generation unit also regularly applies security patches to address the latest security threats. As a result, the generation unit can generate highly accurate security models while securely handling security-related data.

[0066] The Blue Team Generation Unit performs vulnerability assessments based on system configuration and source code, and proposes countermeasures if vulnerabilities are found. Specifically, the Blue Team Generation Unit first performs a static analysis of the system, analyzing source code and configuration files to detect potential vulnerabilities. Static analysis analyzes the structure and patterns of the code to identify known vulnerabilities and security holes. The Blue Team Generation Unit can also perform dynamic analysis to detect runtime vulnerabilities. Dynamic analysis detects abnormal behavior and unauthorized access while the system is actually running. Furthermore, the Blue Team Generation Unit refers to external databases such as CVE (Common Vulnerabilities and Exposures) and generates answers from the latest information. Specifically, the Blue Team Generation Unit queries the CVE database to obtain the latest vulnerability information. This allows the Blue Team Generation Unit to quickly identify system vulnerabilities based on the latest vulnerability information and propose appropriate countermeasures. For example, if a specific vulnerability is detected, it will propose how to apply a patch for that vulnerability and the procedure for changing the configuration. The Blue Team Generation Unit also performs an impact assessment and risk assessment of the detected vulnerabilities and can propose high-priority countermeasures. This allows the Blue Team generation department to strengthen system security and support early detection and rapid countermeasures against vulnerabilities.

[0067] The Red Team Generation Unit attempts hacking using all available security knowledge and vulnerability information. Specifically, the Red Team Generation Unit first conducts penetration testing to attack system vulnerabilities. In penetration testing, they attempt to bypass system defenses by mimicking the techniques used by actual attackers. This allows them to verify system vulnerabilities and security holes in real attack scenarios. The Red Team Generation Unit can also test creative attack methods using generative AI. Specifically, the Red Team Generation Unit prompts the generative AI with "Please propose a new attack method" and tries out the attack methods proposed by the generative AI. The generative AI can generate new attack methods based on past attack data and the results of security research. For example, the generative AI proposes new attack methods by combining or modifying existing attack methods. The Red Team Generation Unit also actually tries out the attack methods proposed by the generative AI and verifies their effectiveness. This allows the Red Team Generation Unit to always respond to the latest attack methods and strengthen system security. Furthermore, the Red team generation unit can provide feedback on the results of its attack method verification to the Blue team generation unit and the Murasaki team generation unit, thereby improving the overall security measures of the system.

[0068] The Murasaki Team Generation Unit integrates feedback from the Red and Blue teams and performs retraining. Specifically, the Murasaki Team Generation Unit first aggregates the diagnostic results from the Red and Blue teams to create a retraining dataset. This dataset includes detected vulnerability information, verification results of attack methods, and countermeasures. Next, the Murasaki Team Generation Unit uses a generative AI to retrain the model and improve its accuracy. During the retraining process, the generative AI updates the model based on the new dataset and is adjusted to enable more accurate predictions and suggestions. Furthermore, the Murasaki Team Generation Unit evaluates the results of the retraining and adjusts the model parameters as needed. This allows the Murasaki Team Generation Unit to always provide a highly accurate security model based on the latest information. In addition, the Murasaki Team Generation Unit shares the insights gained during the retraining process with other teams to strengthen security measures across the entire system. For example, it provides feedback on the retraining results to the Blue Team Generation Unit to improve the accuracy of vulnerability assessments. It can also propose new attack methods and countermeasures to the Red Team Generation Unit. This will allow the Murasaki team generation department to strengthen collaboration between the Red team and the Blue team, and improve overall system security measures.

[0069] The Blue Team generation unit can refer to external databases, such as CVE, and generate answers from the latest information. For example, the Blue Team generation unit queries the CVE database to obtain the latest vulnerability information. It can also refer to the NVD database to obtain vulnerability information. Furthermore, the Blue Team generation unit can refer to Exploit-DB to obtain known exploit information. This allows vulnerability assessments to be performed based on the latest information. Some or all of the above processes in the Blue Team generation unit may be performed using AI, for example, or without AI. For example, the Blue Team generation unit can input vulnerability information obtained from the CVE database into a generation AI, and the generation AI can generate vulnerability assessment results.

[0070] The Red Team Generation Unit can verify creative attack methods using a generative AI. For example, the Red Team Generation Unit can input a prompt to the generative AI such as "Please propose a new attack method," and then test the attack method proposed by the generative AI. The Red Team Generation Unit can also simulate zero-day attacks using the generative AI. For example, the Red Team Generation Unit can input a prompt to the generative AI such as "Please generate a zero-day attack scenario," and then test an attack based on the scenario generated by the generative AI. Furthermore, the Red Team Generation Unit can also simulate social engineering attacks using the generative AI. For example, the Red Team Generation Unit can input a prompt to the generative AI such as "Please generate a social engineering attack scenario," and then test an attack based on the scenario generated by the generative AI. This allows for the verification of new attack methods. Some or all of the above processes in the Red Team Generation Unit may be performed using AI, or not. For example, the Red Team Generation Unit can manually test an attack based on an attack scenario generated by the generative AI.

[0071] The generation unit can learn confidential information without transmitting data externally. For example, the generation unit operates only within a secure internal environment and restricts access to external networks. The generation unit can also encrypt data to protect confidential information. For example, it can encrypt training data to prevent unauthorized external access. Furthermore, the generation unit can implement access control, ensuring that only specific users can access the data. For example, it can perform user authentication, allowing only authenticated users to access the data. This enables the secure learning of confidential information. Some or all of the above processes in the generation unit may be performed using AI, or not. For example, the generation unit can have the generation AI perform the encryption and decryption of confidential information.

[0072] The Murasaki team generation unit can integrate feedback from the Red team and the Blue team and perform retraining. For example, the Murasaki team generation unit aggregates the diagnostic results from the Red team and the Blue team to create a retraining dataset. The Murasaki team generation unit can also improve the accuracy of the model by performing retraining using generative AI. For example, the Murasaki team generation unit can input a prompt to the generative AI, "Integrate the feedback from the Red team and the Blue team," and the generative AI will integrate the feedback. Furthermore, the Murasaki team generation unit can evaluate the results of retraining and identify areas for improvement in the model. For example, the Murasaki team generation unit can input a prompt to the generative AI, "Evaluate the results of retraining," and the generative AI will output the evaluation results. This enables the realization of an ecosystem that combines offense and defense. Some or all of the above processes in the Murasaki team generation unit may be performed using AI, for example, or without AI. For example, the Murasaki team generation unit can have the generative AI perform the integration of feedback and retraining.

[0073] The generation unit can estimate the user's emotions and adjust the fine-tuning parameters based on the estimated user emotions. For example, the generation unit can capture the user's facial expressions with a camera and estimate the emotions using an emotion estimation algorithm. For example, the generation unit can calculate an emotion score based on changes in facial expressions. The generation unit can also record the user's voice and estimate emotions using voice analysis technology. For example, the generation unit can analyze the tone and speed of the voice and calculate an emotion score. Furthermore, the generation unit can collect the user's biometric data (heart rate and skin electrical activity) with sensors and estimate emotions using an emotion estimation algorithm. For example, the generation unit can calculate an emotion score based on fluctuations in heart rate. This allows the fine-tuning parameters to be adjusted according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, for example, using an emotion engine or a generation AI. The generation AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above-described processes in the generation unit may be performed using AI, for example, or without AI. For example, the generation unit can input user emotion data into the generation AI and have the generation AI perform fine-tuning parameter adjustments.

[0074] The generation unit can introduce evaluation criteria to assess the quality of training data and select the optimal dataset. For example, the generation unit can assess data consistency and select a high-quality dataset. It can also assess data diversity and select a balanced dataset. Furthermore, it can assess data recency and select a dataset containing the latest information. For example, the generation unit can evaluate datasets based on criteria such as data accuracy, consistency, diversity, and recency, and select the optimal dataset. This allows for the selection of a high-quality dataset. Some or all of the above processing in the generation unit may be performed using AI, for example, or without AI. For example, the generation unit can have a generative AI perform the evaluation and selection of datasets.

[0075] The generation unit can generate multiple models based on different security scenarios during fine-tuning and select the optimal model. For example, the generation unit can generate models based on different attack scenarios and select the optimal defense model. It can also generate models based on different defense scenarios and select the optimal attack model. Furthermore, the generation unit can generate models based on different operational scenarios and select the optimal operational model. For example, the generation unit can generate models based on scenarios such as DDoS attacks, phishing attacks, and malware attacks, and select the optimal model for each scenario. This allows for the selection of the optimal model based on different security scenarios. Some or all of the above-described processes in the generation unit may be performed using AI, for example, or without AI. For example, the generation unit can have a generation AI perform model generation and selection based on different scenarios.

[0076] The generation unit can estimate the user's emotions and determine the priority of the models to generate based on the estimated user emotions. For example, the generation unit can capture the user's facial expressions with a camera and estimate the emotions using an emotion estimation algorithm. For example, the generation unit can calculate an emotion score based on changes in facial expressions. The generation unit can also record the user's voice and estimate the emotions using voice analysis technology. For example, the generation unit can analyze the tone and speed of the voice and calculate an emotion score. Furthermore, the generation unit can collect the user's biometric data (heart rate and skin electrical activity) with sensors and estimate the emotions using an emotion estimation algorithm. For example, the generation unit can calculate an emotion score based on fluctuations in heart rate. This allows the generation unit to determine the priority of the models to generate according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, for example, an emotion engine or a generation AI. The generation AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above-described processes in the generation unit may be performed using AI, for example, or without AI. For example, the generation unit can input user emotion data into the generation AI and have the generation AI perform the task of prioritizing models.

[0077] The generation unit can customize the model based on the security requirements of different industries during fine-tuning. For example, the generation unit can customize the model based on the security requirements of the financial industry. It can also customize the model based on the security requirements of the healthcare industry. Furthermore, it can customize the model based on the security requirements of the manufacturing industry. For example, the generation unit can add specific functions and adjust parameters based on the security requirements of the financial industry. This allows the model to be customized based on the security requirements of different industries. Some or all of the above processing in the generation unit may be performed using AI, for example, or not using AI. For example, the generation unit can have the generation AI perform model customization based on industry-specific security requirements.

[0078] The generation unit can adjust the model based on security regulations of different regions during fine-tuning. For example, the generation unit can adjust the model based on security regulations in North America. It can also adjust the model based on security regulations in Europe. Furthermore, it can adjust the model based on security regulations in Asia. For example, the generation unit can change parameters and modify the algorithm based on regulations such as GDPR and CCPA. This allows the model to be adjusted based on security regulations of different regions. Some or all of the above processing in the generation unit may be performed using AI, for example, or without AI. For example, the generation unit can have the generation AI perform model adjustments based on regional security regulations.

[0079] The Blue Team generation unit can estimate a user's emotions and determine the priority of vulnerability assessments based on the estimated emotions. For example, the Blue Team generation unit can capture a user's facial expression with a camera and estimate their emotions using an emotion estimation algorithm. For example, the Blue Team generation unit can calculate an emotion score based on changes in facial expression. The Blue Team generation unit can also record a user's voice and estimate their emotions using voice analysis technology. For example, the Blue Team generation unit can analyze the tone and speed of the voice and calculate an emotion score. Furthermore, the Blue Team generation unit can collect the user's biometric data (heart rate and skin electrical activity) with sensors and estimate their emotions using an emotion estimation algorithm. For example, the Blue Team generation unit can calculate an emotion score based on fluctuations in heart rate. This allows the priority of vulnerability assessments to be determined according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, for example, with an emotion engine or generative AI. Generative AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above-described processes in the Blue Team generation unit may be performed using AI, for example, or without AI. For example, the Blue Team generation unit can input user sentiment data into a generation AI and have the generation AI perform vulnerability assessment prioritization.

[0080] The Blue Team Generation Unit can monitor the system's operational status in real time during vulnerability assessments and select the optimal timing for the assessment. For example, the Blue Team Generation Unit can select a time period with low system load to conduct the vulnerability assessment. It can also consider system maintenance times when conducting the vulnerability assessment. Furthermore, the Blue Team Generation Unit can monitor the system's operational status in real time and select the optimal timing for the assessment. For example, it can monitor CPU usage and memory usage and conduct the vulnerability assessment during low load periods. This allows for the selection of the optimal assessment timing based on the system's operational status. Some or all of the above processes in the Blue Team Generation Unit may be performed using AI, or not. For example, the Blue Team Generation Unit can input system operational status data into a generation AI and have the generation AI select the optimal assessment timing.

[0081] The Blue Team Generation Unit can customize its vulnerability assessment methods based on different system configurations. For example, it can apply a specialized assessment method to cloud-based systems. It can also apply a specialized assessment method to on-premises systems. Furthermore, it can apply a specialized assessment method to hybrid systems. For example, the Blue Team Generation Unit adjusts the scope of the assessment using specific tools based on system configurations such as cloud environments, on-premises environments, and hybrid environments. This allows for the customization of assessment methods based on different system configurations. Some or all of the above processes in the Blue Team Generation Unit may be performed using AI, for example, or not. For example, the Blue Team Generation Unit can input system configuration data into a generation AI and have the generation AI perform the customization of the assessment method.

[0082] The Blue Team generation unit can estimate the user's emotions and adjust suggested coping strategies based on those emotions. For example, the Blue Team generation unit can capture the user's facial expressions with a camera and estimate their emotions using an emotion estimation algorithm. For instance, the Blue Team generation unit calculates an emotion score based on changes in facial expressions. The Blue Team generation unit can also record the user's voice and estimate their emotions using voice analysis technology. For example, the Blue Team generation unit analyzes the tone and speed of the voice and calculates an emotion score. Furthermore, the Blue Team generation unit can collect the user's biometric data (heart rate and skin electrical activity) with sensors and estimate their emotions using an emotion estimation algorithm. For example, the Blue Team generation unit calculates an emotion score based on fluctuations in heart rate. This allows the system to adjust suggested coping strategies according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, such as an emotion engine or generative AI. Generative AI includes, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above-described processes in the Blue Team Generation Unit may be performed using AI, for example, or without AI. For example, the Blue Team Generation Unit can input user emotion data into a generating AI and have the generating AI perform adjustments to suggest coping methods.

[0083] The Blue Team Generation Unit can integrate vulnerability information from different platforms during vulnerability assessments. For example, the Blue Team Generation Unit can integrate vulnerability information from the Windows platform for assessment. It can also integrate vulnerability information from the Linux platform for assessment. Furthermore, it can integrate vulnerability information from the MacOS platform for assessment. For example, the Blue Team Generation Unit integrates vulnerability information from different platforms into a database and performs assessments using an information aggregation method. This enables assessments by integrating vulnerability information from different platforms. Some or all of the above processing in the Blue Team Generation Unit may be performed using AI, for example, or without AI. For example, the Blue Team Generation Unit can input platform-specific vulnerability information into a generation AI and have the generation AI perform the assessment.

[0084] The Blue Team Generation Unit can improve the accuracy of vulnerability assessments by combining different security tools. For example, the Blue Team Generation Unit can perform assessments by combining static analysis tools and dynamic analysis tools. It can also perform assessments by combining network scanners and application scanners. Furthermore, it can perform assessments by combining vulnerability scanners and penetration testing tools. For example, the Blue Team Generation Unit can perform assessments by combining security tools such as antivirus software, firewalls, and IDS / IPS. This allows for improved assessment accuracy by combining different security tools. Some or all of the above processes in the Blue Team Generation Unit may be performed using AI, for example, or without AI. For example, the Blue Team Generation Unit can input combinations of security tools into a generation AI and have the generation AI perform the task of improving the accuracy of the assessment.

[0085] The Red Team generation unit can estimate a user's emotions and determine the priority of attack scenarios based on those estimated emotions. For example, the Red Team generation unit can capture a user's facial expression with a camera and estimate their emotions using an emotion estimation algorithm. For example, the Red Team generation unit can calculate an emotion score based on changes in facial expression. The Red Team generation unit can also record a user's voice and estimate their emotions using voice analysis technology. For example, the Red Team generation unit can analyze the tone and speed of the voice and calculate an emotion score. Furthermore, the Red Team generation unit can collect the user's biometric data (heart rate and skin electrical activity) with sensors and estimate their emotions using an emotion estimation algorithm. For example, the Red Team generation unit can calculate an emotion score based on fluctuations in heart rate. This allows the priority of attack scenarios to be determined according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, for example, with an emotion engine or generative AI. Generative AI includes, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above-described processes in the Red Team generation unit may be performed using AI, for example, or without AI. For example, the Red Team generation unit can input user emotion data into a generation AI and have the generation AI perform the priority determination of attack scenarios.

[0086] The Red Team generation unit can improve attack diversity by combining different attack methods during hacking attempts. For example, the Red Team generation unit may combine phishing attacks and malware attacks. It can also combine DDoS attacks and SQL injection. Furthermore, it can combine cross-site scripting and brute-force attacks. For example, the Red Team generation unit may combine methods such as phishing, malware, and DDoS attacks to attempt an attack. This improves attack diversity by combining different attack methods. Some or all of the above processing in the Red Team generation unit may be performed using AI, for example, or not. For example, the Red Team generation unit can input combinations of attack methods into a generation AI and have the generation AI perform the task of improving attack diversity.

[0087] The Red Team generation unit can customize attack methods based on different security environments during hacking attempts. For example, the Red Team generation unit can apply attack methods specifically tailored to cloud environments. It can also apply attack methods specifically tailored to on-premises environments. Furthermore, it can apply attack methods specifically tailored to hybrid environments. For example, the Red Team generation unit uses specific tools and adjusts methods based on security environments such as cloud, on-premises, and hybrid environments. This allows for the customization of attack methods based on different security environments. Some or all of the above processing in the Red Team generation unit may be performed using AI, for example, or not. For example, the Red Team generation unit can input security environment data into a generation AI and have the generation AI perform the customization of attack methods.

[0088] The Red Team generation unit can estimate the user's emotions and adjust the selection of attack methods based on the estimated emotions. For example, the Red Team generation unit can capture the user's facial expressions with a camera and estimate emotions using an emotion estimation algorithm. For example, the Red Team generation unit can calculate an emotion score based on changes in facial expressions. The Red Team generation unit can also record the user's voice and estimate emotions using voice analysis technology. For example, the Red Team generation unit can analyze the tone and speed of the voice and calculate an emotion score. Furthermore, the Red Team generation unit can collect the user's biometric data (heart rate and skin electrical activity) with sensors and estimate emotions using an emotion estimation algorithm. For example, the Red Team generation unit can calculate an emotion score based on fluctuations in heart rate. This allows the selection of attack methods to be adjusted according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, for example, using an emotion engine or generative AI. Generative AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above-described processes in the Red Team generation unit may be performed using AI, for example, or without AI. For example, the Red Team generation unit can input user sentiment data into a generation AI and have the generation AI select and adjust attack methods.

[0089] The Red Team generation unit can optimize attack methods by integrating different vulnerability information during hacking attempts. For example, the Red Team generation unit can optimize attack methods by integrating vulnerability information from a CVE database. It can also optimize attack methods by integrating vulnerability information from an NVD database. Furthermore, it can optimize attack methods by integrating vulnerability information from Exploit-DB. For example, the Red Team generation unit integrates different vulnerability information into a database and optimizes attack methods using an information aggregation method. This allows for the optimization of attack methods by integrating different vulnerability information. Some or all of the above processing in the Red Team generation unit may be performed using AI, for example, or without AI. For example, the Red Team generation unit can input vulnerability information into a generation AI and have the generation AI perform the optimization of attack methods.

[0090] The Red Team Generator can improve the accuracy of an attack by combining different security tools during a hacking attempt. For example, the Red Team Generator can combine Metasploit and Nikito to attempt an attack. It can also combine BARF Suite and OWASP ZAP to attempt an attack. Furthermore, it can combine Kalilinax and Enmap to attempt an attack. For example, the Red Team Generator can improve the accuracy of an attack by combining different security tools. This allows for improved attack accuracy by combining different security tools. Some or all of the above processing in the Red Team Generator may be performed using AI, for example, or not using AI. For example, the Red Team Generator can input a combination of security tools into a generating AI and have the generating AI perform the attack accuracy improvement.

[0091] The Murasaki Team Generator can estimate a user's emotions and determine the priority of retraining based on the estimated emotions. For example, the Murasaki Team Generator can capture a user's facial expression with a camera and estimate their emotions using an emotion estimation algorithm. For example, the Murasaki Team Generator can calculate an emotion score based on changes in facial expression. The Murasaki Team Generator can also record a user's voice and estimate their emotions using voice analysis technology. For example, the Murasaki Team Generator can analyze the tone and speed of the voice and calculate an emotion score. Furthermore, the Murasaki Team Generator can collect the user's biometric data (heart rate and skin electrical activity) with sensors and estimate their emotions using an emotion estimation algorithm. For example, the Murasaki Team Generator can calculate an emotion score based on fluctuations in heart rate. This allows the Murasaki Team Generator to determine the priority of retraining according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, for example, with an emotion engine or generative AI. Generative AIs include, but are not limited to, text generation AIs (e.g., LLMs) and multimodal generation AIs. Some or all of the above-described processes in the Murasaki team generation unit may be performed using AI, for example, or without AI. For example, the Murasaki team generation unit can input user emotion data into a generation AI and have the generation AI perform the task of determining the priority of retraining.

[0092] The Murasaki team generation unit can improve the accuracy of learning by integrating different feedback data during retraining. For example, the Murasaki team generation unit can integrate feedback data from the Red team and the Blue team for retraining. It can also integrate feedback data from different security scenarios for retraining. Furthermore, the Murasaki team generation unit can integrate feedback data from different industries for retraining. For example, the Murasaki team generation unit can integrate different feedback data into a database and perform retraining using an information aggregation method. This allows for improved learning accuracy by integrating different feedback data. Some or all of the above processes in the Murasaki team generation unit may be performed using AI, for example, or without AI. For example, the Murasaki team generation unit can input feedback data into a generation AI and have the generation AI perform retraining.

[0093] The Murasaki team generation unit can customize its learning method based on different security scenarios during retraining. For example, the Murasaki team generation unit can customize its learning method based on attack scenarios. It can also customize its learning method based on defense scenarios. Furthermore, it can customize its learning method based on operational scenarios. For example, the Murasaki team generation unit can use a specific learning algorithm and adjust its parameters based on different security scenarios. This allows for the customization of the learning method based on different security scenarios. Some or all of the above processes in the Murasaki team generation unit may be performed using AI, for example, or without AI. For example, the Murasaki team generation unit can input security scenario data into a generation AI and have the generation AI perform the customization of the learning method.

[0094] The Murasaki team's generation unit can estimate a user's emotions and adjust the method of integrating feedback based on the estimated emotions. For example, the Murasaki team's generation unit can capture a user's facial expression with a camera and estimate emotions using an emotion estimation algorithm. For example, the Murasaki team's generation unit calculates an emotion score based on changes in facial expression. The Murasaki team's generation unit can also record a user's voice and estimate emotions using voice analysis technology. For example, the Murasaki team's generation unit analyzes the tone and speed of the voice and calculates an emotion score. Furthermore, the Murasaki team's generation unit can collect the user's biometric data (heart rate and skin electrical activity) with sensors and estimate emotions using an emotion estimation algorithm. For example, the Murasaki team's generation unit calculates an emotion score based on fluctuations in heart rate. This allows the method of integrating feedback to be adjusted according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, for example, with an emotion engine or generative AI. Generative AI includes, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above-described processes in the Murasaki team generation unit may be performed using AI, for example, or without AI. For example, the Murasaki team generation unit can input user emotion data into a generation AI and have the generation AI adjust the method of integrating feedback.

[0095] The Murasaki team generation unit can select training data based on the security requirements of different industries during retraining. For example, the Murasaki team generation unit can select training data based on the security requirements of the financial industry. It can also select training data based on the security requirements of the medical industry. Furthermore, it can select training data based on the security requirements of the manufacturing industry. For example, the Murasaki team generation unit can use a specific dataset to select training data based on the security requirements of different industries. This allows for the selection of training data based on the security requirements of different industries. Some or all of the above processing in the Murasaki team generation unit may be performed using AI, for example, or not using AI. For example, the Murasaki team generation unit can have the generation AI perform the selection of training data based on industry-specific security requirements.

[0096] The Murasaki team generation unit can adjust its learning method based on security regulations in different regions during retraining. For example, the Murasaki team generation unit can adjust its learning method based on security regulations in North America. It can also adjust its learning method based on security regulations in Europe. Furthermore, it can adjust its learning method based on security regulations in Asia. For example, the Murasaki team generation unit can use a specific learning algorithm and adjust its parameters based on regulations such as GDPR and CCPA. This allows the learning method to be adjusted based on security regulations in different regions. Some or all of the above processing in the Murasaki team generation unit may be performed using AI, for example, or not using AI. For example, the Murasaki team generation unit can have the generation AI perform the adjustment of the learning method based on regional security regulations.

[0097] The system according to the embodiment is not limited to the example described above, and various modifications are possible, for example, as follows.

[0098] The Blue Team generation unit can estimate a user's emotions and determine the priority of vulnerability assessments based on the estimated emotions. For example, the Blue Team generation unit can capture a user's facial expression with a camera and estimate their emotions using an emotion estimation algorithm. For example, the Blue Team generation unit can calculate an emotion score based on changes in facial expression. The Blue Team generation unit can also record a user's voice and estimate their emotions using voice analysis technology. For example, the Blue Team generation unit can analyze the tone and speed of the voice and calculate an emotion score. Furthermore, the Blue Team generation unit can collect the user's biometric data (heart rate and skin electrical activity) with sensors and estimate their emotions using an emotion estimation algorithm. For example, the Blue Team generation unit can calculate an emotion score based on fluctuations in heart rate. This allows the priority of vulnerability assessments to be determined according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, for example, with an emotion engine or generative AI. Generative AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above-described processes in the Blue Team generation unit may be performed using AI, for example, or without AI. For example, the Blue Team generation unit can input user sentiment data into a generation AI and have the generation AI perform vulnerability assessment prioritization.

[0099] The Red Team generation unit can estimate a user's emotions and determine the priority of attack scenarios based on those estimated emotions. For example, the Red Team generation unit can capture a user's facial expression with a camera and estimate their emotions using an emotion estimation algorithm. For example, the Red Team generation unit can calculate an emotion score based on changes in facial expression. The Red Team generation unit can also record a user's voice and estimate their emotions using voice analysis technology. For example, the Red Team generation unit can analyze the tone and speed of the voice and calculate an emotion score. Furthermore, the Red Team generation unit can collect the user's biometric data (heart rate and skin electrical activity) with sensors and estimate their emotions using an emotion estimation algorithm. For example, the Red Team generation unit can calculate an emotion score based on fluctuations in heart rate. This allows the priority of attack scenarios to be determined according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, for example, with an emotion engine or generative AI. Generative AI includes, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above-described processes in the Red Team generation unit may be performed using AI, for example, or without AI. For example, the Red Team generation unit can input user emotion data into a generation AI and have the generation AI perform the priority determination of attack scenarios.

[0100] The Murasaki Team Generator can estimate a user's emotions and determine the priority of retraining based on the estimated emotions. For example, the Murasaki Team Generator can capture a user's facial expression with a camera and estimate their emotions using an emotion estimation algorithm. For example, the Murasaki Team Generator can calculate an emotion score based on changes in facial expression. The Murasaki Team Generator can also record a user's voice and estimate their emotions using voice analysis technology. For example, the Murasaki Team Generator can analyze the tone and speed of the voice and calculate an emotion score. Furthermore, the Murasaki Team Generator can collect the user's biometric data (heart rate and skin electrical activity) with sensors and estimate their emotions using an emotion estimation algorithm. For example, the Murasaki Team Generator can calculate an emotion score based on fluctuations in heart rate. This allows the Murasaki Team Generator to determine the priority of retraining according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, for example, with an emotion engine or generative AI. Generative AIs include, but are not limited to, text generation AIs (e.g., LLMs) and multimodal generation AIs. Some or all of the above-described processes in the Murasaki team generation unit may be performed using AI, for example, or without AI. For example, the Murasaki team generation unit can input user emotion data into a generation AI and have the generation AI perform the task of determining the priority of retraining.

[0101] The Blue Team Generation Unit can monitor the system's operational status in real time during vulnerability assessments and select the optimal timing for the assessment. For example, the Blue Team Generation Unit can select a time period with low system load to conduct the vulnerability assessment. It can also consider system maintenance times when conducting the vulnerability assessment. Furthermore, the Blue Team Generation Unit can monitor the system's operational status in real time and select the optimal timing for the assessment. For example, it can monitor CPU usage and memory usage and conduct the vulnerability assessment during low load periods. This allows for the selection of the optimal assessment timing based on the system's operational status. Some or all of the above processes in the Blue Team Generation Unit may be performed using AI, or not. For example, the Blue Team Generation Unit can input system operational status data into a generation AI and have the generation AI select the optimal assessment timing.

[0102] The Red Team generation unit can improve attack diversity by combining different attack methods during hacking attempts. For example, the Red Team generation unit may combine phishing attacks and malware attacks. It can also combine DDoS attacks and SQL injection. Furthermore, it can combine cross-site scripting and brute-force attacks. For example, the Red Team generation unit may combine methods such as phishing, malware, and DDoS attacks to attempt an attack. This improves attack diversity by combining different attack methods. Some or all of the above processing in the Red Team generation unit may be performed using AI, for example, or not. For example, the Red Team generation unit can input combinations of attack methods into a generation AI and have the generation AI perform the task of improving attack diversity.

[0103] The Murasaki team generation unit can improve the accuracy of learning by integrating different feedback data during retraining. For example, the Murasaki team generation unit can integrate feedback data from the Red team and the Blue team for retraining. It can also integrate feedback data from different security scenarios for retraining. Furthermore, the Murasaki team generation unit can integrate feedback data from different industries for retraining. For example, the Murasaki team generation unit can integrate different feedback data into a database and perform retraining using an information aggregation method. This allows for improved learning accuracy by integrating different feedback data. Some or all of the above processes in the Murasaki team generation unit may be performed using AI, for example, or without AI. For example, the Murasaki team generation unit can input feedback data into a generation AI and have the generation AI perform retraining.

[0104] The Blue Team Generation Unit can customize its vulnerability assessment methods based on different system configurations. For example, it can apply a specialized assessment method to cloud-based systems. It can also apply a specialized assessment method to on-premises systems. Furthermore, it can apply a specialized assessment method to hybrid systems. For example, the Blue Team Generation Unit adjusts the scope of the assessment using specific tools based on system configurations such as cloud environments, on-premises environments, and hybrid environments. This allows for the customization of assessment methods based on different system configurations. Some or all of the above processes in the Blue Team Generation Unit may be performed using AI, for example, or not. For example, the Blue Team Generation Unit can input system configuration data into a generation AI and have the generation AI perform the customization of the assessment method.

[0105] The Red Team generation unit can customize attack methods based on different security environments during hacking attempts. For example, the Red Team generation unit can apply attack methods specifically tailored to cloud environments. It can also apply attack methods specifically tailored to on-premises environments. Furthermore, it can apply attack methods specifically tailored to hybrid environments. For example, the Red Team generation unit uses specific tools and adjusts methods based on security environments such as cloud, on-premises, and hybrid environments. This allows for the customization of attack methods based on different security environments. Some or all of the above processing in the Red Team generation unit may be performed using AI, for example, or not. For example, the Red Team generation unit can input security environment data into a generation AI and have the generation AI perform the customization of attack methods.

[0106] The Murasaki team generation unit can customize its learning method based on different security scenarios during retraining. For example, the Murasaki team generation unit can customize its learning method based on attack scenarios. It can also customize its learning method based on defense scenarios. Furthermore, it can customize its learning method based on operational scenarios. For example, the Murasaki team generation unit can use a specific learning algorithm and adjust its parameters based on different security scenarios. This allows for the customization of the learning method based on different security scenarios. Some or all of the above processes in the Murasaki team generation unit may be performed using AI, for example, or without AI. For example, the Murasaki team generation unit can input security scenario data into a generation AI and have the generation AI perform the customization of the learning method.

[0107] The Blue Team generation unit can estimate the user's emotions and adjust suggested coping strategies based on those emotions. For example, the Blue Team generation unit can capture the user's facial expressions with a camera and estimate their emotions using an emotion estimation algorithm. For instance, the Blue Team generation unit calculates an emotion score based on changes in facial expressions. The Blue Team generation unit can also record the user's voice and estimate their emotions using voice analysis technology. For example, the Blue Team generation unit analyzes the tone and speed of the voice and calculates an emotion score. Furthermore, the Blue Team generation unit can collect the user's biometric data (heart rate and skin electrical activity) with sensors and estimate their emotions using an emotion estimation algorithm. For example, the Blue Team generation unit calculates an emotion score based on fluctuations in heart rate. This allows the system to adjust suggested coping strategies according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, such as an emotion engine or generative AI. Generative AI includes, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above-described processes in the Blue Team Generation Unit may be performed using AI, for example, or without AI. For example, the Blue Team Generation Unit can input user emotion data into a generating AI and have the generating AI perform adjustments to suggest coping methods.

[0108] The following briefly describes the processing flow for example form 2.

[0109] Step 1: The generation unit fine-tunes a pre-trained OSS LLM in the company's secure environment to create a proprietary model specialized for security. The generation unit adds security-related datasets to the pre-trained OSS LLM and performs fine-tuning. Furthermore, the generation unit can securely learn confidential information without transmitting data externally. The generation unit operates only in the company's secure environment and restricts access to external networks. Step 2: The Blue Team generation unit diagnoses vulnerabilities from the system configuration and source code, and proposes countermeasures if vulnerabilities are found. The Blue Team generation unit performs static analysis of the system to detect vulnerabilities. It can also perform dynamic analysis to detect runtime vulnerabilities. Furthermore, the Blue Team generation unit refers to external databases such as CVE and generates answers from the latest information. For example, it queries the CVE database to obtain the latest vulnerability information. Step 3: The Red Team Generation Unit attempts hacking using all available security knowledge and vulnerability information. The Red Team Generation Unit conducts penetration testing and attacks system vulnerabilities. They can also use generational AI to test creative attack methods. For example, they can input a prompt to the generational AI such as "Please suggest a new attack method," and then try out the attack methods suggested by the generational AI. Step 4: The Murasaki team generation unit integrates feedback from the Red and Blue teams and performs retraining. The Murasaki team generation unit aggregates the diagnostic results from the Red and Blue teams and creates a retraining dataset. It can also use the generated AI to perform retraining and improve the accuracy of the model.

[0110] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[0111] Data generation model 58 is a form of so-called generative AI (Artificial Intelligence). An example of data generation model 58 is ChatGPT (registered trademark) (Internet search).<URL: https: / / openai.com / blog / chatgpt> Examples of generative AI include text generation AI, image generation AI, and multimodal generation AI. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images (e.g., still image data or video data). The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference result in one or more data formats from audio data, text data, and image data. The data generation model 58 includes, for example, text generation AI, image generation AI, and multimodal generation AI. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specific processing unit 290 performs the specific processing described above using the data generation model 58. The data generation model 58 may be a fine-tuned model that outputs inference results from prompts that do not contain instructions, in which case the data generation model 58 can output inference results from prompts that do not contain instructions. In the data processing device 12, etc., there are multiple types of data generation models 58, and the data generation model 58 includes AI other than generative AI. AI other than generative AI includes, for example, linear regression, logistic regression, decision trees, random forests, support vector machines (SVMs), k-means clustering, convolutional neural networks (CNNs), recurrent neural networks (RNNs), generative adversarial networks (GANs), or naive Bayes, and can perform various processes, but is not limited to these examples. Also, the AI ​​may be an AI agent. Furthermore, when the processing of each of the above parts is performed by the AI, the processing may be performed by the AI ​​in part or in whole, but is not limited to this example.Furthermore, processing performed by AI, including generative AI, may be replaced with rule-based processing, and rule-based processing may be replaced with processing performed by AI, including generative AI.

[0112] Furthermore, the processing performed by the data processing system 10 described above is carried out by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the smart device 14, but it may also be carried out by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the smart device 14. In addition, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the smart device 14 or an external device, and the smart device 14 acquires or collects information necessary for processing from the data processing device 12 or an external device.

[0113] Each of the multiple elements, including the generation unit, Blue team generation unit, Red team generation unit, and Murasaki team generation unit described above, is implemented in at least one of the smart device 14 and the data processing unit 12. For example, the generation unit is implemented by the specific processing unit 290 of the data processing unit 12 and performs fine tuning based on OSS LLM learned in the company's secure environment. The Blue team generation unit is implemented by the control unit 46A of the smart device 14 and diagnoses vulnerabilities from the system configuration and source code. The Red team generation unit is implemented by the specific processing unit 290 of the data processing unit 12 and attempts hacking using all available security knowledge and vulnerability information. The Murasaki team generation unit is implemented by the control unit 46A of the smart device 14 and integrates feedback from the Red team and Blue team and performs retraining. The correspondence between each unit and the device or control unit is not limited to the example described above and can be changed in various ways.

[0114] [Second Embodiment] Figure 3 shows an example of the configuration of the data processing system 210 according to the second embodiment.

[0115] As shown in Figure 3, the data processing system 210 includes a data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.

[0116] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN and / or LAN.

[0117] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication interface 44. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, and camera 42 are also connected to the bus 52.

[0118] The microphone 238 receives voice signals from the user and accepts instructions from the user. The microphone 238 captures the voice signals from the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.

[0119] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, which captures images of the area around the user (for example, an imaging range defined by a field of view equivalent to the field of vision of a typical healthy person).

[0120] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.

[0121] Figure 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Figure 4, the data processing device 12 performs specific processing by the processor 28. The storage 32 stores the specific processing program 56.

[0122] The processor 28 reads a specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 acting as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.

[0123] Storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotions using the emotion identification model 59 and perform identification processing using the user's emotions. The emotion estimation function (emotion identification function) using the emotion identification model 59 performs various estimations and predictions regarding the user's emotions, including but not limited to these examples. Furthermore, emotion estimation and prediction also include, for example, emotion analysis.

[0124] In the smart glasses 214, specific processing is performed by the processor 46. The storage 50 stores a specific processing program 60. The processor 46 reads the specific processing program 60 from the storage 50 and executes the read specific processing program 60 on the RAM 48. The specific processing is realized by the processor 46 acting as a control unit 46A according to the specific processing program 60 executed on the RAM 48. The smart glasses 214 also have a data generation model 58 and an emotion identification model 59, similar to the data generation model and emotion identification model 59, and can perform processing similar to that of the specific processing unit 290 using these models.

[0125] Furthermore, other devices besides the data processing device 12 may also have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 obtains processing results (such as prediction results) using the data generation model 58 by communicating with the server device that has the data generation model 58. Also, the data processing device 12 may be a server device or a terminal device owned by the user (for example, a mobile phone, robot, home appliance, etc.).

[0126] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.

[0127] The data generation model 58 is a so-called generative AI. An example of a data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and inference data such as audio data representing speech, text data representing text, and image data representing images (e.g., still image data or video data). The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference result in one or more data formats such as audio data, text data, and image data. The data generation model 58 includes, for example, text generation AI, image generation AI, and multimodal generation AI. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specific processing unit 290 performs the specific processing described above using the data generation model 58. The data generation model 58 may be a fine-tuned model that outputs inference results from prompts that do not contain instructions, in which case the data generation model 58 can output inference results from prompts that do not contain instructions. In the data processing device 12, etc., there are multiple types of data generation models 58, and the data generation model 58 includes AI other than generative AI. AI other than generative AI includes, for example, linear regression, logistic regression, decision trees, random forests, support vector machines (SVM), k-means clustering, convolutional neural networks (CNN), recurrent neural networks (RNN), generative adversarial networks (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. Also, the AI ​​may be an AI agent. Furthermore, when the processing of each part described above is performed by the AI, the processing may be performed by the AI ​​in part or in whole, but is not limited to this example. Also, processing performed by an AI including a generative AI may be replaced by rule-based processing, and rule-based processing may be replaced by processing performed by an AI including a generative AI.

[0128] The data processing system 210 according to the second embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 210 is performed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the smart glasses 214, but it may also be performed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the smart glasses 214. In addition, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the smart glasses 214 or an external device, and the smart glasses 214 acquires or collects information necessary for processing from the data processing device 12 or an external device.

[0129] Each of the multiple elements described above, including the generation unit, Blue team generation unit, Red team generation unit, and Murasaki team generation unit, is implemented in at least one of the smart glasses 214 and the data processing unit 12. For example, the generation unit is implemented by the specific processing unit 290 of the data processing unit 12 and performs fine tuning based on OSS LLM learned in the company's secure environment. The Blue team generation unit is implemented by the control unit 46A of the smart glasses 214 and diagnoses vulnerabilities from the system configuration and source code. The Red team generation unit is implemented by the specific processing unit 290 of the data processing unit 12 and attempts hacking using all available security knowledge and vulnerability information. The Murasaki team generation unit is implemented by the control unit 46A of the smart glasses 214 and integrates feedback from the Red team and Blue team and performs retraining. The correspondence between each unit and the device or control unit is not limited to the examples described above and can be changed in various ways.

[0130] [Third Embodiment] Figure 5 shows an example of the configuration of the data processing system 310 according to the third embodiment.

[0131] As shown in Figure 5, the data processing system 310 includes a data processing device 12 and a headset terminal 314. An example of the data processing device 12 is a server.

[0132] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN and / or LAN.

[0133] The headset terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a display 343. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and display 343 are also connected to the bus 52.

[0134] The microphone 238 receives voice signals from the user and accepts instructions from the user. The microphone 238 captures the voice signals from the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.

[0135] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, which captures images of the area around the user (for example, an imaging range defined by a field of view equivalent to the field of vision of a typical healthy person).

[0136] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.

[0137] Figure 6 shows an example of the main functions of the data processing device 12 and the headset terminal 314. As shown in Figure 6, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.

[0138] The processor 28 reads a specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 acting as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.

[0139] Storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotions using the emotion identification model 59 and perform identification processing using the user's emotions. The emotion estimation function (emotion identification function) using the emotion identification model 59 performs various estimations and predictions regarding the user's emotions, including but not limited to these examples. Furthermore, emotion estimation and prediction also include, for example, emotion analysis.

[0140] In the headset terminal 314, specific processing is performed by the processor 46. The storage 50 stores a specific program 60. The processor 46 reads the specific program 60 from the storage 50 and executes the read specific program 60 on the RAM 48. The specific processing is realized by the processor 46 acting as a control unit 46A according to the specific program 60 executed on the RAM 48. The headset terminal 314 also has a data generation model 58 and an emotion identification model 59, similar to the data generation model and emotion identification model 59, and can perform processing similar to that of the specific processing unit 290 using these models.

[0141] Furthermore, other devices besides the data processing device 12 may also have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 obtains processing results (such as prediction results) using the data generation model 58 by communicating with the server device that has the data generation model 58. Also, the data processing device 12 may be a server device or a terminal device owned by the user (for example, a mobile phone, robot, home appliance, etc.).

[0142] The specific processing unit 290 transmits the result of the specific processing to the headset terminal 314. In the headset terminal 314, the control unit 46A causes the speaker 240 and display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.

[0143] The data generation model 58 is a so-called generative AI. An example of a data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and inference data such as audio data representing speech, text data representing text, and image data representing images (e.g., still image data or video data). The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference result in one or more data formats such as audio data, text data, and image data. The data generation model 58 includes, for example, text generation AI, image generation AI, and multimodal generation AI. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specific processing unit 290 performs the specific processing described above using the data generation model 58. The data generation model 58 may be a fine-tuned model that outputs inference results from prompts that do not contain instructions, in which case the data generation model 58 can output inference results from prompts that do not contain instructions. In the data processing device 12, etc., there are multiple types of data generation models 58, and the data generation model 58 includes AI other than generative AI. AI other than generative AI includes, for example, linear regression, logistic regression, decision trees, random forests, support vector machines (SVM), k-means clustering, convolutional neural networks (CNN), recurrent neural networks (RNN), generative adversarial networks (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. Also, the AI ​​may be an AI agent. Furthermore, when the processing of each part described above is performed by the AI, the processing may be performed by the AI ​​in part or in whole, but is not limited to this example. Also, processing performed by an AI including a generative AI may be replaced by rule-based processing, and rule-based processing may be replaced by processing performed by an AI including a generative AI.

[0144] The data processing system 310 according to the third embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 310 is performed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the headset terminal 314, but may also be performed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the headset terminal 314. In addition, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the headset terminal 314 or an external device, and the headset terminal 314 acquires or collects information necessary for processing from the data processing device 12 or an external device.

[0145] Each of the multiple elements described above, including the generation unit, Blue team generation unit, Red team generation unit, and Murasaki team generation unit, is implemented in at least one of the headset terminal 314 and the data processing unit 12. For example, the generation unit is implemented by the specific processing unit 290 of the data processing unit 12 and performs fine tuning based on OSS LLM learned in the company's secure environment. The Blue team generation unit is implemented by the control unit 46A of the headset terminal 314 and diagnoses vulnerabilities from the system configuration and source code. The Red team generation unit is implemented by the specific processing unit 290 of the data processing unit 12 and attempts hacking using all available security knowledge and vulnerability information. The Murasaki team generation unit is implemented by the control unit 46A of the headset terminal 314 and integrates feedback from the Red team and Blue team and performs retraining. The correspondence between each unit and the device or control unit is not limited to the example described above and can be changed in various ways.

[0146] [Fourth Embodiment] Figure 7 shows an example of the configuration of the data processing system 410 according to the fourth embodiment.

[0147] As shown in Figure 7, the data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.

[0148] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN and / or LAN.

[0149] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a controlled object 443. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and controlled object 443 are also connected to the bus 52.

[0150] The microphone 238 receives voice signals from the user and accepts instructions from the user. The microphone 238 captures the voice signals from the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.

[0151] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS image sensor or CCD image sensor, which captures images of the area around the user (for example, an imaging range defined by a field of view equivalent to the field of vision of a typical healthy person).

[0152] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.

[0153] The controlled object 443 includes a display device, LEDs in the eyes, and motors that drive the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the robot 414's emotions can be expressed by controlling these motors. The robot 414's facial expressions can also be expressed by controlling the illumination state of the LEDs in its eyes.

[0154] Figure 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Figure 8, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.

[0155] The processor 28 reads a specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 acting as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.

[0156] Storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotions using the emotion identification model 59 and perform identification processing using the user's emotions. The emotion estimation function (emotion identification function) using the emotion identification model 59 performs various estimations and predictions regarding the user's emotions, including but not limited to these examples. Furthermore, emotion estimation and prediction also include, for example, emotion analysis.

[0157] In robot 414, specific processing is performed by processor 46. A specific program 60 is stored in storage 50. Processor 46 reads the specific program 60 from storage 50 and executes it on RAM 48. The specific processing is achieved by processor 46 acting as a control unit 46A according to the specific program 60 executed on RAM 48. Robot 414 also has data generation model 58 and emotion identification model 59, similar to those of the robot, and can perform processing similar to that of the specific processing unit 290 using these models.

[0158] Furthermore, other devices besides the data processing device 12 may also have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 obtains processing results (such as prediction results) using the data generation model 58 by communicating with the server device that has the data generation model 58. Also, the data processing device 12 may be a server device or a terminal device owned by the user (for example, a mobile phone, robot, home appliance, etc.).

[0159] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the controlled object 443 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.

[0160] The data generation model 58 is a so-called generative AI. An example of a data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and inference data such as audio data representing speech, text data representing text, and image data representing images (e.g., still image data or video data). The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference result in one or more data formats such as audio data, text data, and image data. The data generation model 58 includes, for example, text generation AI, image generation AI, and multimodal generation AI. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specific processing unit 290 performs the specific processing described above using the data generation model 58. The data generation model 58 may be a fine-tuned model that outputs inference results from prompts that do not contain instructions, in which case the data generation model 58 can output inference results from prompts that do not contain instructions. In the data processing device 12, etc., there are multiple types of data generation models 58, and the data generation model 58 includes AI other than generative AI. AI other than generative AI includes, for example, linear regression, logistic regression, decision trees, random forests, support vector machines (SVM), k-means clustering, convolutional neural networks (CNN), recurrent neural networks (RNN), generative adversarial networks (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. Also, the AI ​​may be an AI agent. Furthermore, when the processing of each part described above is performed by the AI, the processing may be performed by the AI ​​in part or in whole, but is not limited to this example. Also, processing performed by an AI including a generative AI may be replaced by rule-based processing, and rule-based processing may be replaced by processing performed by an AI including a generative AI.

[0161] The data processing system 410 according to the fourth embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 410 is performed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the robot 414, but it may also be performed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the robot 414. In addition, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the robot 414 or an external device, and the robot 414 acquires or collects information necessary for processing from the data processing device 12 or an external device.

[0162] Each of the multiple elements described above, including the generation unit, Blue team generation unit, Red team generation unit, and Murasaki team generation unit, is implemented in at least one of the following: the robot 414 and the data processing unit 12. For example, the generation unit is implemented by the specific processing unit 290 of the data processing unit 12 and performs fine tuning based on OSS LLM learned in the company's secure environment. The Blue team generation unit is implemented by the control unit 46A of the robot 414 and diagnoses vulnerabilities from the system configuration and source code. The Red team generation unit is implemented by the specific processing unit 290 of the data processing unit 12 and attempts hacking using all available security knowledge and vulnerability information. The Murasaki team generation unit is implemented by the control unit 46A of the robot 414 and integrates feedback from the Red team and Blue team to perform retraining. The correspondence between each unit and the device or control unit is not limited to the examples described above and can be modified in various ways.

[0163] Furthermore, the emotion identification model 59, acting as an emotion engine, may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to a specific mapping, which is an emotion map (see Figure 9). Similarly, the emotion identification model 59 may also determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.

[0164] Figure 9 shows the emotion map 400, in which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. The closer to the center of the concentric circles, the more primitive the emotions are located. Further out of the concentric circles, emotions representing states and actions arising from mental states are located. Emotion is a concept that includes feelings and mental states. On the left side of the concentric circles, emotions that are generally generated from reactions occurring in the brain are located. On the right side of the concentric circles, emotions that are generally induced by situational judgment are located. Above and below the concentric circles, emotions that are generally generated from reactions occurring in the brain and induced by situational judgment are located. In addition, the emotion of "pleasure" is located on the upper side of the concentric circles, and the emotion of "displeasure" is located on the lower side. Thus, in the emotion map 400, multiple emotions are mapped based on the structure in which emotions arise, and emotions that are likely to occur simultaneously are mapped close together.

[0165] These emotions are distributed at the 3 o'clock position on the Emotion Map 400, and usually fluctuate between feelings of security and anxiety. In the right half of the Emotion Map 400, situational awareness takes precedence over internal feelings, resulting in a calm impression.

[0166] The inside of the Emotion Map 400 represents inner thoughts, while the outside represents actions. Therefore, the further you go from the outside of the Emotion Map 400, the more visible (expressed in actions) your emotions become.

[0167] Here, human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. Similarly, in robots, cars, and motorcycles, emotions can be created based on various balances, such as posture and battery level. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. The emotion map can be generated based, for example, on Dr. Mitsuyoshi's emotion map (Research on a system for analyzing brain physiological signals of speech emotion recognition and emotion, Tokushima University, doctoral dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map contains emotions belonging to a region called "response," where sensation is dominant. The right half of the emotion map contains emotions belonging to a region called "situation," where situational awareness is dominant.

[0168] The emotion map defines two emotions that promote learning. One is the emotion around the middle of the negative "repentance" and "reflection" on the situation side. In other words, it is when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is the emotion around the positive "desire" on the reaction side. In other words, it is when the robot has positive feelings such as "I want more" or "I want to know more."

[0169] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values ​​representing each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple training data sets, which are combinations of user input and emotion values ​​representing each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions located close together have similar values, as shown in the emotion map 900 in Figure 10. Figure 10 shows an example where multiple emotions such as "reassured," "calm," and "confident" have similar emotion values.

[0170] In the above embodiment, an example was given in which a specific process is performed by a single computer 22. However, the technology of this disclosure is not limited thereto, and a distributed processing method for the specific process may be used, which includes computer 22 and multiple other computers.

[0171] In the above embodiment, an example was given in which the specific processing program 56 is stored in the storage 32, but the technology of this disclosure is not limited thereto. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-temporary storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-temporary storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes specific processing according to the specific processing program 56.

[0172] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.

[0173] Furthermore, it is not necessary to store the entirety of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store the entirety of the specific processing program 56 in the storage 32; it is acceptable to store only a portion of the specific processing program 56.

[0174] The following types of processors can be used as hardware resources to perform specific processing. Examples of processors include a CPU, a general-purpose processor that functions as a hardware resource to perform specific processing by executing software, i.e., a program. Other examples of processors include dedicated electrical circuits, such as FPGAs (Field-Programmable Gate Arrays), PLDs (Programmable Logic Devices), or ASICs (Application Specific Integrated Circuits), which have circuit configurations specifically designed to perform specific processing. All of these processors have built-in or connected memory, and all of them perform specific processing by using memory.

[0175] The hardware resource that performs a specific process may consist of one of these various processors, or it may consist of a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Alternatively, the hardware resource that performs a specific process may consist of a single processor.

[0176] Examples of configurations using a single processor include, firstly, a configuration in which one or more CPUs and software are combined to form a single processor, and this processor functions as a hardware resource that performs a specific process. Secondly, there is a configuration using a processor that realizes the functions of the entire system, including multiple hardware resources that perform a specific process, on a single IC chip, as exemplified by SoCs (System-on-a-chip). In this way, a specific process is realized using one or more of the above types of processors as hardware resources.

[0177] Furthermore, the hardware structure of these various processors can more specifically utilize electrical circuits that combine circuit elements such as semiconductor devices. Also, the specific processing described above is merely an example. Therefore, it goes without saying that unnecessary steps can be deleted, new steps added, or the processing order rearranged, as long as it does not deviate from the main purpose.

[0178] Furthermore, although the above-described examples were divided into four embodiments, some or all of these embodiments may be combined. Also, the smart device 14, smart glasses 214, headset terminal 314, and robot 414 are just examples, and they may be combined, or other devices may be used. Also, although the above-described examples were divided into two embodiments, Embodiment 1 and Embodiment 2, these may be combined.

[0179] The descriptions and illustrations presented above are detailed explanations of the technical aspects of this disclosure and are merely examples of the technical aspects. For example, the above descriptions of the structure, function, operation, and effect are examples of the structure, function, operation, and effect of the technical aspects of this disclosure. Therefore, it goes without saying that you may delete unnecessary parts, add new elements, or replace elements in the descriptions and illustrations presented above, as long as you do not deviate from the essence of the technical aspects of this disclosure. Furthermore, in order to avoid confusion and facilitate understanding of the technical aspects of this disclosure, explanations of common technical knowledge and other things that do not require special explanation to enable the implementation of the technical aspects of this disclosure have been omitted from the descriptions and illustrations presented above.

[0180] All documents, patent applications, and technical standards described herein are incorporated by reference to the same extent as if each individual document, patent application, and technical standard were specifically and individually noted to be incorporated by reference.

[0181] (Note 1) The generation unit creates a proprietary model specifically for security-related issues by performing fine-tuning based on OSS LLM that has been trained in the company's secure environment. The Blue Team Generation Unit diagnoses vulnerabilities from the system configuration and source code, and proposes countermeasures if vulnerabilities are found. The Red Team Generation Department attempts hacking using all available security knowledge and vulnerability information, It includes a Murasaki team generation unit that integrates feedback from the Red team and the Blue team and performs retraining. A system characterized by the following features. (Note 2) The aforementioned Blue team generation unit is It references external databases, such as CVE, and generates answers from the latest information. The system described in Appendix 1, characterized by the features described herein. (Note 3) The aforementioned Grid team generation unit, Generative AI is used to test creative attack methods. The system described in Appendix 1, characterized by the features described herein. (Note 4) The generating unit is Learn confidential information without sending data externally. The system described in Appendix 1, characterized by the features described herein. (Note 5) The aforementioned Murasaki team generation unit is, We will integrate feedback from the Red and Blue teams and retrain them. The system described in Appendix 1, characterized by the features described herein. (Note 6) The generating unit is It estimates the user's emotions and adjusts the fine-tuning parameters based on the estimated user emotions. The system described in Appendix 1, characterized by the features described herein. (Note 7) The generating unit is We will introduce evaluation criteria to assess the quality of training data and select the optimal dataset. The system described in Appendix 1, characterized by the features described herein. (Note 8) The generating unit is During fine-tuning, multiple models are generated based on different security scenarios, and the optimal model is selected. The system described in Appendix 1, characterized by the features described herein. (Note 9) The generating unit is It estimates the user's emotions and determines the priority of models to generate based on the estimated user emotions. The system described in Appendix 1, characterized by the features described herein. (Note 10) The generating unit is During fine-tuning, the model is customized based on the security requirements of different industries. The system described in Appendix 1, characterized by the features described herein. (Note 11) The generating unit is During fine-tuning, the model is adjusted based on security regulations in different regions. The system described in Appendix 1, characterized by the features described herein. (Note 12) The aforementioned Blue team generation unit is It estimates user sentiment and determines the priority of vulnerability assessments based on the estimated user sentiment. The system described in Appendix 1, characterized by the features described herein. (Note 13) The aforementioned Blue team generation unit is During vulnerability assessments, the system's operational status is monitored in real time to select the optimal timing for the assessment. The system described in Appendix 1, characterized by the features described herein. (Note 14) The aforementioned Blue team generation unit is During vulnerability assessments, customize the assessment methodology based on different system configurations. The system described in Appendix 1, characterized by the features described herein. (Note 15) The aforementioned Blue team generation unit is It estimates the user's emotions and adjusts suggested solutions based on those emotions. The system described in Appendix 1, characterized by the features described herein. (Note 16) The aforementioned Blue team generation unit is During vulnerability assessments, vulnerability information from different platforms is integrated and used for the assessment. The system described in Appendix 1, characterized by the features described herein. (Note 17) The aforementioned Blue team generation unit is Combining different security tools during vulnerability assessment improves the accuracy of the assessment. The system described in Appendix 1, characterized by the features described herein. (Note 18) The aforementioned Grid team generation unit, It estimates user sentiment and prioritizes attack scenarios based on the estimated user sentiment. The system described in Appendix 1, characterized by the features described herein. (Note 19) The aforementioned Grid team generation unit, When attempting to hack, combine different attack methods to improve attack diversity. The system described in Appendix 1, characterized by the features described herein. (Note 20) The aforementioned Grid team generation unit, During hacking attempts, customize attack methods based on different security environments. The system described in Appendix 1, characterized by the features described herein. (Note 21) The aforementioned Grid team generation unit, It estimates the user's emotions and adjusts the selection of attack methods based on the estimated user emotions. The system described in Appendix 1, characterized by the features described herein. (Note 22) The aforementioned Grid team generation unit, During hacking attempts, integrate different vulnerability information to optimize the attack method. The system described in Appendix 1, characterized by the features described herein. (Note 23) The aforementioned Grid team generation unit, When attempting a hack, combine different security tools to improve the accuracy of the attack. The system described in Appendix 1, characterized by the features described herein. (Note 24) The aforementioned Murasaki team generation unit is, The system estimates the user's emotions and determines the priority of retraining based on the estimated user emotions. The system described in Appendix 1, characterized by the features described herein. (Note 25) The aforementioned Murasaki team generation unit is, During retraining, different feedback data is integrated to improve the accuracy of the learning process. The system described in Appendix 1, characterized by the features described herein. (Note 26) The aforementioned Murasaki team generation unit is, During retraining, customize the learning method based on different security scenarios. The system described in Appendix 1, characterized by the features described herein. (Note 27) The aforementioned Murasaki team generation unit is, It estimates the user's emotions and adjusts how feedback is integrated based on those estimated emotions. The system described in Appendix 1, characterized by the features described herein. (Note 28) The aforementioned Murasaki team generation unit is, During retraining, select training data based on security requirements from different industries. The system described in Appendix 1, characterized by the features described herein. (Note 29) The aforementioned Murasaki team generation unit is, During retraining, the learning method is adjusted based on security regulations in different regions. The system described in Appendix 1, characterized by the features described herein. [Explanation of symbols]

[0182] 10, 210, 310, 410 Data Processing Systems 12 Data Processing Devices 14 Smart Devices 214 Smart Glasses 314 Headset-type terminal 414 Robots

Claims

1. The generation unit creates a proprietary model specifically for security-related issues by performing fine-tuning based on OSS LLM that has been trained in the company's secure environment. The Blue Team Generation Unit diagnoses vulnerabilities from the system configuration and source code, and proposes countermeasures if vulnerabilities are found. The Red Team Generation Department attempts hacking using all available security knowledge and vulnerability information, It includes a Murasaki team generation unit that integrates feedback from the Red team and the Blue team and performs retraining. A system characterized by the following features.

2. The aforementioned Blue team generation unit is It references external databases, such as CVE, and generates answers from the latest information. The system according to feature 1.

3. The aforementioned Grid team generation unit, Generative AI will be used to test creative attack methods. The system according to feature 1.

4. The generating unit is Learn confidential information without sending data externally. The system according to feature 1.

5. The aforementioned Murasaki team generation unit is, We will integrate feedback from the Red and Blue teams and retrain them. The system according to feature 1.

6. The generating unit is It estimates the user's emotions and adjusts the fine-tuning parameters based on the estimated user emotions. The system according to feature 1.

7. The generating unit is We will introduce evaluation criteria to assess the quality of training data and select the optimal dataset. The system according to feature 1.

8. The generating unit is During fine-tuning, multiple models are generated based on different security scenarios, and the optimal model is selected. The system according to feature 1.

Citation Information

Patent Citations

  • Persona chatbot control method and system

    JP2022180282A