system
A computer system using a generative AI model to analyze and filter emails automatically, addressing the limitations of conventional methods by adapting to new threats and improving accuracy through user feedback.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- SOFTBANK GROUP CORP
- Filing Date
- 2024-12-12
- Publication Date
- 2026-06-24
Smart Images

Figure 2026103588000001_ABST
Abstract
Description
Technical Field
[0001] The technology of the present disclosure relates to a system.
Background Art
[0002] Patent Document 1 discloses a method for controlling a persona chatbot, which is performed by at least one processor, the method including steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to an explanation of a character of the chatbot, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] In recent years, the damage caused by phishing and fraud via email remains at a high level, posing a great risk especially to the elderly and users with poor security awareness. Although conventional spam filters and individual warnings are effective, these approaches relying on them have limitations and cannot cope with the sophisticated methods that are becoming more and more sophisticated with technological progress. Therefore, it is required to effectively discriminate suspicious emails without the user's awareness and respond promptly.
Means for Solving the Problems
[0005] This invention provides a means for analyzing emails using a computer system, enabling a mechanism to automatically analyze the content and characteristics of emails upon receipt and determine if they are suspicious. Furthermore, it automatically quarantines or deletes suspicious emails based on this determination and notifies the user of the result. In addition, it incorporates a learning function to continuously improve the determination algorithm based on received feedback, thereby improving the accuracy of the system. As a result, users can maintain a high level of security without having to identify suspicious emails themselves.
[0006] A "computer system" refers to a combination of hardware and software used for processing tasks such as email analysis and filtering.
[0007] "Methods for analyzing emails" refer to the process of extracting and evaluating information such as the email body, sender, and title.
[0008] "Methods for automatically identifying suspicious emails" refer to algorithms or rules that mechanically determine whether an email is suspicious based on the analysis results.
[0009] "Quarantine or delete measures" refers to processes used to remove emails deemed suspicious from a user's inbox.
[0010] "Means of notifying the user" refers to interfaces or methods for informing the user of the email's judgment results and processing status.
[0011] A "means of learning from feedback" is a mechanism for incorporating evaluations and results from users to improve the system's algorithms.
[0012] A "generative AI model" refers to a model that uses artificial intelligence technology to recognize patterns from large amounts of data and make predictions.
[0013] "Assigning a score" refers to the process of quantifying and evaluating the level of suspiciousness based on the analysis results of an email.
[0014] The "specified threshold" refers to the score value used as a criterion for determining whether an email is suspicious. [Brief explanation of the drawing]
[0015] [Figure 1] This is a conceptual diagram showing an example of the configuration of a data processing system according to the first embodiment. [Figure 2] This is a conceptual diagram showing an example of the essential functions of a data processing device and a smart device according to the first embodiment. [Figure 3] This is a conceptual diagram showing an example of the configuration of a data processing system according to the second embodiment. [Figure 4] This is a conceptual diagram showing an example of the main functions of a data processing device and smart glasses according to the second embodiment. [Figure 5] This is a conceptual diagram showing an example of the configuration of a data processing system according to the third embodiment. [Figure 6] This is a conceptual diagram showing an example of the main functions of a data processing device and a headset-type terminal according to the third embodiment. [Figure 7] This is a conceptual diagram showing an example of the configuration of a data processing system according to the fourth embodiment. [Figure 8] This is a conceptual diagram showing an example of the main functions of a data processing device and a robot according to the fourth embodiment. [Figure 9] This shows an emotion map where multiple emotions are mapped. [Figure 10] This shows an emotion map where multiple emotions are mapped. [Figure 11] This is a sequence diagram showing the processing flow of the data processing system in Example 1. [Figure 12] This is a sequence diagram showing the processing flow of the data processing system in Application Example 1. [Figure 13] This is a sequence diagram showing the processing flow of the data processing system in Example 2, which incorporates an emotion engine. [Figure 14]It is a sequence diagram showing the processing flow of a data processing system in Application Example 2 when a sentiment engine is combined.
Embodiments for Carrying Out the Invention
[0016] Hereinafter, an example of an embodiment of a system according to the technology of the present disclosure will be described with reference to the accompanying drawings.
[0017] First, the terms used in the following description will be explained.
[0018] In the following embodiments, a processor with a reference number (hereinafter simply referred to as "processor") may be a single arithmetic unit or a combination of a plurality of arithmetic units. Also, the processor may be a single type of arithmetic unit or a combination of a plurality of types of arithmetic units. Examples of arithmetic units include a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a GPGPU (General-Purpose computing on Graphics Processing Units), an APU (Accelerated Processing Unit), and the like.
[0019] In the following embodiments, a RAM (Random Access Memory) with a reference number is a memory in which information is temporarily stored and is used as a work memory by the processor.
[0020] In the following embodiments, a storage with a reference number is one or more non-volatile storage devices that store various programs and various parameters, etc. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), or magnetic tapes, and the like.
[0021] In the following embodiments, the signed communication interface (I / F) is an interface that includes a communication processor and an antenna, etc. The communication interface manages communication between multiple computers. Examples of communication standards applicable to the communication interface include wireless communication standards such as 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), or Bluetooth (registered trademark).
[0022] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B." That is, "A and / or B" means that it may be A alone, or B alone, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" applies when expressing three or more things linked by "and / or."
[0023] [First Embodiment]
[0024] Figure 1 shows an example of the configuration of the data processing system 10 according to the first embodiment.
[0025] As shown in Figure 1, the data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.
[0026] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0027] The smart device 14 comprises a computer 36, a reception device 38, an output device 40, a camera 42, and a communication interface 44. The computer 36 comprises a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The reception device 38, output device 40, and camera 42 are also connected to the bus 52.
[0028] The reception device 38 is equipped with a touch panel 38A and a microphone 38B, etc., and receives user input. The touch panel 38A receives user input by detecting contact with an object (e.g., a pen or finger). The microphone 38B receives user input by detecting the user's voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the data indicating the user input.
[0029] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user 20 by outputting the data in a form perceptible to the user 20 (e.g., audio and / or text). The display 40A displays visible information such as text and images according to instructions from the processor 46. The speaker 40B outputs audio according to instructions from the processor 46. The camera 42 is a small digital camera equipped with an optical system such as a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.
[0030] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various types of information between processor 46 and processor 28 via network 54.
[0031] Figure 2 shows an example of the main functions of the data processing device 12 and the smart device 14.
[0032] As shown in Figure 2, in the data processing device 12, a specific processing is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" related to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.
[0033] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0034] In the smart device 14, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The reception output program 60 is used in conjunction with a specific processing program 56 by the data processing system 10. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0035] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the smart device 14 as the "terminal".
[0036] This invention is a system for effectively filtering out suspicious emails, and includes a program that runs on a computer system. Specific embodiments thereof are described below.
[0037] First, when a user launches their email client, an agent within the system begins operating in the background. The agent queries the email server and retrieves all new emails to the device. The received emails are sequentially passed to a generative AI model built by the server, where their content and characteristics are analyzed. The AI model has learned from past data and has the ability to calculate a suspicion score for each email.
[0038] Based on the analysis, emails identified as suspicious are automatically moved to the trash or saved to a quarantine folder on the device. The user is notified of the processing result, and a feedback function is provided in case of false positives.
[0039] The feedback data is sent back to the server and used for the continuous learning of the AI model. This allows the system to constantly improve its accuracy and adapt flexibly to new methods of fraudulent emails.
[0040] For example, if a fraudulent email is received, the AI model detects the sender information and link patterns within the email, assigning it a high suspicion score. This email is immediately deleted, and the user receives a notification stating that "one of six emails was deemed suspicious and deleted."
[0041] Thus, because this system automatically analyzes and processes emails every time it is received, users can engage in email-related tasks with peace of mind.
[0042] The following describes the processing flow.
[0043] Step 1:
[0044] The user launches their email client. This starts the agent in the background. The agent connects to the mail server and prepares to retrieve all new mail.
[0045] Step 2:
[0046] The server sends received emails to an AI model for analysis. The analysis calculates a suspiciousness score based on various elements such as the email body, sender, title, and links. The AI model recognizes patterns based on past data and assigns scores accordingly.
[0047] Step 3:
[0048] The device receives a suspiciousness score for each email and determines whether that score exceeds a predetermined threshold. If an email is deemed suspicious, it is automatically moved to the trash or saved to a quarantine folder.
[0049] Step 4:
[0050] The device notifies the user of the results of processing suspicious emails. Specifically, it provides a brief report of the number of emails processed and their contents. This allows the user to understand the status of their mailbox.
[0051] Step 5:
[0052] Users can review notification results and provide feedback as needed. For example, they can report false positives to the system.
[0053] Step 6:
[0054] The server receives user feedback, incorporates it into the learning process of the generating AI model, and improves the algorithm. This improves the accuracy of subsequent predictions.
[0055] Step 7:
[0056] The system continues to operate in the background even after completing the overall process, repeating the same process each time a new email is received. This ensures that users always have access to email in a secure environment with the latest security measures in place.
[0057] (Example 1)
[0058] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."
[0059] With the increasing use of email on the internet, fraudulent and malicious emails are rampant. There is a need to quickly and automatically identify such suspicious emails and provide an environment where users can use email with peace of mind. However, conventional email filtering technologies rely on fixed rules and struggle to adapt to new methods and changes.
[0060] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0061] In this invention, the server operates on a terminal and includes means for acquiring new emails from a mail server, means for analyzing the content of the acquired emails using a generation AI model on the server, and means for assigning a suspiciousness score to each email based on the analysis results. This makes it possible to dynamically analyze the content and characteristics of emails and flexibly respond to changing patterns of suspicious emails.
[0062] A "terminal" refers to a computer or electronic device used by a user to send, receive, and process emails.
[0063] A "server" refers to a computer system that provides services to terminals via a network and uses a generative AI model to analyze emails and determine their suspiciousness score.
[0064] A "generative AI model" refers to an artificial intelligence model that analyzes the content and characteristics of emails and evaluates their level of suspiciousness by learning from past data based on machine learning algorithms.
[0065] The "suspiciousness score" refers to a numerical value assigned by a generative AI model to quantitatively evaluate the security of an email based on the results of email analysis.
[0066] "Quarantine" refers to the process of separating emails deemed suspicious from the regular inbox and moving them to a separate, dedicated folder, thereby preventing users from opening them directly.
[0067] "Feedback" refers to user reactions and opinions, which serve as the basis for the generation AI model to learn and continuously improve its accuracy.
[0068] This invention provides an information processing system that offers technology for automatically detecting and processing suspicious emails in an email system. This system consists of an email client and background agent running on the user's terminal, and a generation AI model on a server. Specific embodiments are described below.
[0069] When a user launches an email client on their device, the device starts an agent program in the background and communicates with the server. The device communicates with the email server via the internet connection and downloads new emails for the user. The downloaded email data includes email header information (sender, subject, etc.) and the email body.
[0070] The server sequentially analyzes received emails using a generative AI model. This generative AI model is trained using machine learning algorithms and calculates a suspiciousness score from the content and structural features of the emails. The generative AI model analyzes the email text using natural language processing and compares it to suspicious email patterns it has learned in the past. This process includes text analysis, information extraction, and scoring algorithms.
[0071] If the AI model determines an email is suspicious, the device will automatically move the email to a quarantine folder or delete it. Information about quarantined or deleted emails is stored on the device as a log, and feedback is provided to the user in the form of a notification.
[0072] For example, when a user opens an email, the server can indicate that a large number of new phishing emails have been detected for that time. If a phishing email is received, the sender's domain information and the link patterns in the email body will be identified as suspicious. This email will have a high suspicion score and will be immediately quarantined. The user will be notified that "1 out of 10 emails has been quarantined because it is suspicious."
[0073] An example of a prompt is, "Please describe a system that uses an AI model trained on the characteristics of phishing emails to calculate a suspiciousness score for new emails and process them automatically." This prompt can be used to explain in detail the technology for automatically detecting suspicious emails.
[0074] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0075] Step 1:
[0076] The user launches the email client on their device. This automatically starts the agent program running in the background. The input is the user's actions, and the output is the agent's startup status. Specifically, the email client connects to the email server and prepares to send and receive data.
[0077] Step 2:
[0078] The terminal queries the mail server and receives new emails in a list format. The input is email data from the server, and the output is saved email data. Specifically, information such as the sender, subject, and body of each received email is stored on the terminal. This information is used for subsequent suspiciousness analysis.
[0079] Step 3:
[0080] The server uses a generative AI model to analyze email data transferred from the terminal. The input is email data, and the output is a suspiciousness score. Specifically, the AI model analyzes the text information of the email and calculates the score by comparing it with patterns of suspicious emails that it has learned in the past. Natural language processing techniques are used in this process to extract and evaluate context and keywords.
[0081] Step 4:
[0082] The device automatically moves suspicious emails to a quarantine folder or deletes them based on the suspicion score obtained from the server. The input is a suspicion score, and the output is the status of the email folder after processing. Specifically, emails with scores exceeding a set threshold are quarantined or deleted, thereby protecting the user from suspicious emails.
[0083] Step 5:
[0084] Users are notified of the email processing results on their device. The feedback function allows for the provision of information as feedback data in case of false positives or missed detections. Inputs include processing results and user feedback, while output is feedback data sent to the server. Specifically, the feedback information is sent to the server and used for the continuous learning of the generated AI model.
[0085] (Application Example 1)
[0086] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."
[0087] In recent years, there has been an increase in cases of malicious information and fraud being transmitted through email and communication data. There is a need for technology that can effectively detect such suspicious communications and protect user safety. However, conventional technologies have been unable to adequately remove suspicious emails and communications, resulting in false positives and delayed notifications. Furthermore, there is a need for a system that enables real-time scanning and immediate response while reducing the burden on users.
[0088] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0089] In this invention, the server includes means for analyzing communication data using an information processing device, means for automatically determining suspicious communications based on the analysis results of the communication data, means for notifying the user of the determination and the results of isolation or deletion, and means for providing a real-time scanning function in cooperation with a mobile terminal. This makes it possible to quickly and efficiently detect and manage suspicious communication data.
[0090] An "information processing device" is a computer system that has the function of analyzing and processing communication data.
[0091] "Communication data" refers to a collection of electrical or electronic information transmitted and received through a network.
[0092] A "generative AI model" is an algorithm that learns patterns and features from past data using machine learning, and then makes predictions and classifications for unknown data.
[0093] A "mobile terminal" refers to an electronic device that is portable and can connect to a network using wireless communication.
[0094] This invention is implemented by constructing a system that analyzes communication data using an information processing device and identifies and isolates suspicious communications. The aim of this system is to cooperate between a server and a mobile terminal, scan communication data in real time, and immediately notify the user of the results.
[0095] The server first receives communication data and passes it to a generative AI model for analysis. The generative AI model is implemented using Python and the TENSORFLOW® library and learns suspicious patterns from past data. This model analyzes the characteristics of the communication data and scores whether the communication is suspicious or not.
[0096] If a communication is deemed suspicious, the server will automatically initiate a process to isolate or delete the communication data. Simultaneously, a notification message will be sent to the user's mobile device, and the result will be reported immediately. This allows users to check suspicious communications in real time and ensure their safety.
[0097] As a concrete example, consider a case where a user receives a short email saying "Hello." The server analyzes this email using a generation AI model and calculates a suspicion score based on the sender information and content. If the score is low, it is deemed safe, and the user is notified that there is no problem.
[0098] User feedback is sent back to the server, and this data is used for the continuous training of the generating AI model, allowing the system to flexibly adapt to new techniques and improve accuracy.
[0099] The following is an example of a prompt asking how a generative AI model should be described: "Please describe the latest spam filtering technologies, especially how generative AI models are used to detect suspicious emails."
[0100] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0101] Step 1:
[0102] The server initially receives communication data via the network. At this stage, the data has not yet been analyzed; the raw communication data is the input. The output is a dataset awaiting analysis.
[0103] Step 2:
[0104] The server begins analyzing the communication data using a generative AI model. Specifically, the generative AI model (using Python and the TensorFlow library) converts the text of the communication data into numerical data and evaluates its suspiciousness. The input is the dataset from Step 1, and the output is the suspiciousness score corresponding to each communication data.
[0105] Step 3:
[0106] The server checks whether the suspicion score exceeds a pre-set threshold. The input for this step is the generated score, and the output is a judgment flag (whether it is suspicious or not). Specifically, if the score exceeds the threshold, the communication data is marked as suspicious.
[0107] Step 4:
[0108] The server automatically moves or deletes any communication data deemed suspicious. The input is the result of the determination in step 3, and the output is the datastore status after the suspicious communication data has been quarantined or deleted.
[0109] Step 5:
[0110] The server notifies the user of the judgment result. This notification includes which communications were deemed suspicious. The input is the judgment flag from step 3, and the output is the notification message displayed on the user's terminal. Specifically, a pop-up message is sent to the user's smartphone or computer.
[0111] Step 6:
[0112] Users submit feedback if they encounter a misjudgment. The input is the user's feedback, and the output is the transmission of that data to the server. This updates the training dataset for the generative AI model.
[0113] Step 7:
[0114] The server updates the parameters of the generated AI model using the received feedback and retrains the model. The input is user feedback information, and the output is the tuned AI model. Specifically, the model's accuracy is improved.
[0115] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0116] This invention provides a system that combines a system for analyzing emails and automatically identifying and processing suspicious emails with an emotion engine that recognizes user emotions and optimizes countermeasures. In this embodiment, both email analysis and emotion recognition functions are combined to improve the user experience.
[0117] When a user launches their email client, an agent starts in the background. This agent sends the received email to the server and analyzes it using a generative AI model. This analysis calculates a suspicion score based on the content and characteristics of the email. Simultaneously, an emotion engine running on the device analyzes the user's emotions from the camera, microphone, and text input. The emotion engine evaluates the user's current emotions based on their facial expressions, voice tone, and the speed and style of text input.
[0118] If an email's suspiciousness score exceeds a predetermined threshold, the results of this sentiment engine's analysis are taken into account when making a final decision. If anxiety or caution is indicated, the email is quarantined or deleted, and a detailed notification is provided to the user. Furthermore, special notification messages and measures are taken depending on the user's mental state, allowing users to conduct email work more securely.
[0119] For example, if a user opens a newly received email and it contains an email with a high suspicion score, the emotion engine will detect the user's facial expression at this point and recognize tension or surprise. As a result, the system will issue a special warning about the email and take safety measures such as providing further information about the sender or disabling links.
[0120] Thus, in this embodiment of the present invention, by integrating a suspicious email prevention function with emotion recognition technology, it is possible to provide an environment in which users can use email with peace of mind.
[0121] The following describes the processing flow.
[0122] Step 1:
[0123] The user launches their email client. This action causes the suspicious email identification system to start running in the background.
[0124] Step 2:
[0125] The device checks for new emails and forwards them to the server. The server then prepares the emails for distribution to the AI model that generates them.
[0126] Step 3:
[0127] The server uses an AI model to analyze the body, sender information, subject, etc., of each email and calculates a suspiciousness score. This score is used to assess the risk by comparing it to known email patterns.
[0128] Step 4:
[0129] The device activates an emotion engine to check the user's emotional state. Through the device's camera and microphone, it analyzes the user's facial expressions and voice tone in real time to determine what emotions are being expressed.
[0130] Step 5:
[0131] The device integrates the suspicion score and the sentiment engine's evaluation to make a final decision on whether an email is suspicious. If the user indicates anxiety or caution, it will be treated as suspicious even if the score is somewhat low.
[0132] Step 6:
[0133] The device immediately quarantines emails it deems suspicious and notifies the user of this fact and the reason. In addition, a special warning message is displayed to encourage safe actions. The notification to the user includes concise language and reassuring content.
[0134] Step 7:
[0135] Users can review notifications and provide feedback if they find the detection to be incorrect. This feedback is used to improve the system.
[0136] Step 8:
[0137] The server receives user feedback and incorporates it into the AI model's training. Based on this information, continuous improvements are made to enhance the accuracy of future email filtering processes.
[0138] (Example 2)
[0139] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the smart device 14 as the "terminal".
[0140] Traditional email management systems have features to identify and automatically quarantine / delete suspicious messages such as spam and phishing messages, but they often do not take into account the emotional reactions of users. Therefore, users may experience confusion or anxiety when receiving suspicious messages, which can disrupt their work. Consequently, there is a need for a system that can process and notify users more appropriately based on their emotional state.
[0141] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0142] In this invention, the server includes means for analyzing messages using a computer system, means for automatically determining suspicious messages based on the message analysis results, and means including an analysis device on the terminal for analyzing the user's emotional state. This enables integrated analysis of message content and the user's emotions, and allows for message processing and notifications to reduce anxiety.
[0143] A "computer system" is a system that uses electronic devices to process data and automatically perform various tasks.
[0144] "Message" refers to information or communication content that is transferred as email or text data.
[0145] "Means of analysis" refers to a process or device that has the function of analyzing information in detail and understanding its characteristics and patterns based on that analysis.
[0146] A "suspicious message" is any communication that includes spam or phishing and is deemed to have the potential to harm the recipient.
[0147] "Means of determination" refers to a device or program that has the function of evaluating the results based on the input information and determining whether or not specific conditions are met.
[0148] "Means of isolation or deletion" refers to a process or system that has the capability to move a identified suspicious message to a secure location or to delete it completely to prevent access.
[0149] "User" refers to an individual or legal entity that operates electronic devices or software.
[0150] "Means of notification" refers to a communication function or device used to inform a user of a specific situation or result.
[0151] "Means of learning from feedback" refer to processes and devices that analyze responses and opinions obtained from users and utilize them to improve the accuracy and functionality of a system.
[0152] A "generative AI model" is a model that uses artificial intelligence algorithms to learn from large amounts of data and recognize patterns and features.
[0153] A "terminal analysis device for analyzing emotional state" refers to a device or software that has the function of interpreting the user's facial expressions, voice, text input, etc., and evaluating their emotional state.
[0154] This invention is a system that enables users to use email comfortably and securely. This system consists of multiple components to perform message analysis and suspicious message processing that takes into account the user's emotions.
[0155] When a user launches an email client on their device, an analysis agent starts in the background. Message data is sent to a server, where its content is analyzed using a generative AI model. This generative AI model calculates a suspiciousness score for the message based on patterns and features derived from a large amount of data. The server also determines that a message is suspicious if its score exceeds a certain threshold and takes appropriate isolation or deletion measures.
[0156] Meanwhile, the device is equipped with an emotion analysis engine that analyzes the user's emotional state in real time through the camera, microphone, and keyboard input. This engine identifies emotions from the user's facial expressions, voice tone, and input speed, and reports them to the server as feedback.
[0157] By utilizing this sentiment information, the server can take appropriate action when processing suspicious messages, taking into account the user's state. For example, users who indicate anxiety will receive special notifications tailored to the content of their anxiety, and safety measures such as providing additional information or disabling links will be automatically applied.
[0158] For example, suppose a user opens a newly received message and receives a high suspicion score, and the sentiment analysis engine detects the user's surprise. In this case, the server will issue a further warning to the user and disable the link in the message.
[0159] Examples of prompt messages include the following:
[0160] "Please analyze the following email and calculate a suspicion score. Check the subject and content, and identify any risky elements."
[0161] "Generate recommended actions for when users express surprise or anxiety. For example, provide secure email handling methods and guidelines."
[0162] In this way, users can enjoy an environment where they can use email more safely and securely through the system.
[0163] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0164] Step 1:
[0165] When a user launches their email client, the system automatically starts an agent in the background. The agent detects new messages in the user's inbox. This process is provided with data from newly received messages as input. The output is message data that is sent to the server for analysis.
[0166] Step 2:
[0167] The server inputs the received message data into a generating AI model and begins analyzing its content. This analysis process thoroughly examines the email sender, subject, body, links, attachments, and other elements. For data processing, each of these elements is pattern-recognized by the AI model to extract risk factors. As an output, a suspiciousness score is calculated for each message.
[0168] Step 3:
[0169] The server evaluates the suspiciousness score and classifies messages as suspicious if they exceed a pre-set threshold. This determination also takes into account the sender's trustworthiness and the results of spam filters. The output is a list of messages that have been determined to be suspicious.
[0170] Step 4:
[0171] The device's emotion analysis engine monitors the user's facial expressions, voice, and keyboard input. Camera video, microphone audio, and keyboard input are used as inputs. From these, emotional patterns are analyzed to evaluate the user's current emotional state. The output is data indicating the user's emotional state, which is reported to the server.
[0172] Step 5:
[0173] The server comprehensively considers the suspicion score and the user's emotional state to determine the final handling of the message. For example, if the user's emotional state indicates anxiety, it may choose to isolate the message or disable the link. The output of this process is a notification provided to the user, which includes information about specific safety measures.
[0174] Step 6:
[0175] The user is also provided with notifications from the system, and if necessary, can directly review the message content and take the instructions. The input is notification information from the server, and the output is the specific action the user should take. The notification includes recommended actions based on prompts and other information.
[0176] (Application Example 2)
[0177] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."
[0178] In modern times, the amount of suspicious information flowing in via information media such as email is steadily increasing, and the burden on users to deal with this suspicious information is growing. While there is a need to strengthen the automated response capabilities of systems to such suspicious information, conventional systems fail to consider the user's emotions and psychological state, resulting in a risk of damaging the user experience. Therefore, the challenge is to provide a system that not only accurately and efficiently identifies and isolates suspicious information, but also allows for flexible responses that take user emotions into consideration.
[0179] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0180] In this invention, the server includes means for analyzing information using a computer system, means for automatically determining suspicious information based on the results of the information analysis, and means for automatically isolating or deleting information determined to be suspicious. This enables automatic determination and isolation of suspicious information. Furthermore, by adding means for analyzing the user's psychological state using an emotion analysis engine and considering this in the final decision, flexible responses based on the user's psychological state become possible.
[0181] A "computer system" refers to a collection of electronic computers and their programs used for analyzing information.
[0182] "Information analysis" is the process of analyzing received data and extracting its content and characteristics.
[0183] "Suspicious information" refers to information that deviates from normal standards and patterns and is judged to be fraudulent or dangerous.
[0184] "Automatic judgment" refers to a function where the system makes a decision based on analysis results without human intervention.
[0185] "Isolation or deletion" refers to the process of removing and invalidating suspicious information from the system when it is detected.
[0186] "Notification means" refers to a method or function for communicating the judgment result to the user.
[0187] "Feedback learning" is the process by which a system learns from past results and user responses to improve its future processing capabilities.
[0188] A "generative AI model" refers to a model that generates and analyzes new patterns and data based on artificial intelligence technology.
[0189] The "emotion analysis engine" is part of a system designed to analyze a user's psychological state, processing data such as facial expressions and voice.
[0190] To implement this application, the server first uses a computer system to intensively analyze the received information. Here, a generative AI model is utilized to extract the content and characteristics of the information. The generative AI model learns data patterns using Python libraries such as NLTK and Scikit-learn to accurately and efficiently identify suspicious information. It also calculates a suspiciousness score and automatically initiates a quarantine or deletion process if it exceeds a predetermined threshold.
[0191] Meanwhile, an emotion analysis engine runs on the device to analyze the user's psychological state. Using the smartphone's camera and microphone, it analyzes facial expressions in real time with OpenCV and DeepFace, and voice tone with PyDub and Librosa. This visualizes the user's emotions, and the analysis results are sent to the server.
[0192] The server also has the ability to adjust its judgment algorithm in response to changes in emotions, optimizing the processing of suspicious information. This makes it possible to enhance security while minimizing the impact on the user.
[0193] One concrete example is a scenario where a user asks questions. For instance, if a user prompts the system with a message like, "Please provide information about the latest phishing scams. Please tell me the specific characteristics of the emails," the system would generate a report on the latest threats, list specific characteristics, and issue a warning.
[0194] Thus, the present invention can combine information analysis and emotion recognition to provide a safer and more interactive user experience.
[0195] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0196] Step 1:
[0197] The server analyzes received information using a computer system. Emails and digital messages are provided as input, and a generative AI model is used to extract content and features. Here, libraries such as NLTK and Scikit-learn are used for pattern learning and suspiciousness scoring. The output includes a suspiciousness score and the features of the analyzed information.
[0198] Step 2:
[0199] The sentiment analysis engine on the device is activated to analyze the user's psychological state. Specifically, it collects the user's facial expressions and vocalizations in real time through the smartphone's camera and microphone. Video and audio are handled as input data, and image analysis is performed using OpenCV and DeepFace, while audio analysis is performed using PyDub and Librosa. As a result, an evaluation of the user's emotional state is output.
[0200] Step 3:
[0201] The server integrates the suspicion score obtained in Step 1 with the emotional state obtained in Step 2 to make a final decision. The input consists of the suspicion score and the emotional analysis results, and based on this data, the server makes a final determination of the reliability and safety of the information. If appropriate, the information is isolated or deleted, and the result is output to the user as a notification.
[0202] Step 4:
[0203] The user takes appropriate action based on notifications received from the system. This involves the user confirming and executing specific actions provided by the system (e.g., risk warnings, reporting suspicious information). This process includes the user requesting information from the system by entering an example "prompt message," such as "Please provide information about the latest phishing scam. Please describe the specific characteristics of the email."
[0204] In this way, a concrete process is implemented in which the server and terminal work together to improve user security.
[0205] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.
[0206] Data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of data generation model 58 is ChatGPT (registered trademark) (Internet search).<URL: https: / / openai.com / blog / chatgpt> ), Gemini (registered trademark) (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0207] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the smart device 14.
[0208] [Second Embodiment]
[0209] Figure 3 shows an example of the configuration of the data processing system 210 according to the second embodiment.
[0210] As shown in Figure 3, the data processing system 210 includes a data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.
[0211] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0212] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication interface 44. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, and camera 42 are also connected to the bus 52.
[0213] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0214] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).
[0215] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0216] Figure 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Figure 4, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0217] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0218] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0219] In the smart glasses 214, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0220] Next, the identification processing performed by the identification processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".
[0221] This invention is a system for effectively filtering out suspicious emails, and includes a program that runs on a computer system. Specific embodiments thereof are described below.
[0222] First, when a user launches their email client, an agent within the system begins operating in the background. The agent queries the email server and retrieves all new emails to the device. The received emails are sequentially passed to a generative AI model built by the server, where their content and characteristics are analyzed. The AI model has learned from past data and has the ability to calculate a suspicion score for each email.
[0223] Based on the analysis, emails identified as suspicious are automatically moved to the trash or saved to a quarantine folder on the device. The user is notified of the processing result, and a feedback function is provided in case of false positives.
[0224] The feedback data is sent back to the server and used for the continuous learning of the AI model. This allows the system to constantly improve its accuracy and adapt flexibly to new methods of fraudulent emails.
[0225] For example, if a fraudulent email is received, the AI model detects the sender information and link patterns within the email, assigning it a high suspicion score. This email is immediately deleted, and the user receives a notification stating that "one of six emails was deemed suspicious and deleted."
[0226] Thus, because this system automatically analyzes and processes emails every time it is received, users can engage in email-related tasks with peace of mind.
[0227] The following describes the processing flow.
[0228] Step 1:
[0229] The user launches their email client. This starts the agent in the background. The agent connects to the mail server and prepares to retrieve all new mail.
[0230] Step 2:
[0231] The server sends received emails to an AI model for analysis. The analysis calculates a suspiciousness score based on various elements such as the email body, sender, title, and links. The AI model recognizes patterns based on past data and assigns scores accordingly.
[0232] Step 3:
[0233] The device receives a suspiciousness score for each email and determines whether that score exceeds a predetermined threshold. If an email is deemed suspicious, it is automatically moved to the trash or saved to a quarantine folder.
[0234] Step 4:
[0235] The device notifies the user of the results of processing suspicious emails. Specifically, it provides a brief report of the number of emails processed and their contents. This allows the user to understand the status of their mailbox.
[0236] Step 5:
[0237] Users can review notification results and provide feedback as needed. For example, they can report false positives to the system.
[0238] Step 6:
[0239] The server receives user feedback, incorporates it into the learning process of the generating AI model, and improves the algorithm. This improves the accuracy of subsequent predictions.
[0240] Step 7:
[0241] The system continues to operate in the background even after completing the overall process, repeating the same process each time a new email is received. This ensures that users always have access to email in a secure environment with the latest security measures in place.
[0242] (Example 1)
[0243] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."
[0244] With the increasing use of email on the internet, fraudulent and malicious emails are rampant. There is a need to quickly and automatically identify such suspicious emails and provide an environment where users can use email with peace of mind. However, conventional email filtering technologies rely on fixed rules and struggle to adapt to new methods and changes.
[0245] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0246] In this invention, the server operates on a terminal and includes means for acquiring new emails from a mail server, means for analyzing the content of the acquired emails using a generation AI model on the server, and means for assigning a suspiciousness score to each email based on the analysis results. This makes it possible to dynamically analyze the content and characteristics of emails and flexibly respond to changing patterns of suspicious emails.
[0247] A "terminal" refers to a computer or electronic device used by a user to send, receive, and process emails.
[0248] A "server" refers to a computer system that provides services to terminals via a network and uses a generative AI model to analyze emails and determine their suspiciousness score.
[0249] A "generative AI model" refers to an artificial intelligence model that analyzes the content and characteristics of emails and evaluates their level of suspiciousness by learning from past data based on machine learning algorithms.
[0250] The "suspiciousness score" refers to a numerical value assigned by a generative AI model to quantitatively evaluate the security of an email based on the results of email analysis.
[0251] "Quarantine" refers to the process of separating emails deemed suspicious from the regular inbox and moving them to a separate, dedicated folder, thereby preventing users from opening them directly.
[0252] "Feedback" refers to user reactions and opinions, which serve as the basis for the generation AI model to learn and continuously improve its accuracy.
[0253] This invention provides an information processing system that offers technology for automatically detecting and processing suspicious emails in an email system. This system consists of an email client and background agent running on the user's terminal, and a generation AI model on a server. Specific embodiments are described below.
[0254] When a user launches an email client on their device, the device starts an agent program in the background and communicates with the server. The device communicates with the email server via the internet connection and downloads new emails for the user. The downloaded email data includes email header information (sender, subject, etc.) and the email body.
[0255] The server sequentially analyzes received emails using a generative AI model. This generative AI model is trained using machine learning algorithms and calculates a suspiciousness score from the content and structural features of the emails. The generative AI model analyzes the email text using natural language processing and compares it to suspicious email patterns it has learned in the past. This process includes text analysis, information extraction, and scoring algorithms.
[0256] If the AI model determines an email is suspicious, the device will automatically move the email to a quarantine folder or delete it. Information about quarantined or deleted emails is stored on the device as a log, and feedback is provided to the user in the form of a notification.
[0257] For example, when a user opens an email, the server can indicate that a large number of new phishing emails have been detected for that time. If a phishing email is received, the sender's domain information and the link patterns in the email body will be identified as suspicious. This email will have a high suspicion score and will be immediately quarantined. The user will be notified that "1 out of 10 emails has been quarantined because it is suspicious."
[0258] An example of a prompt is, "Please describe a system that uses an AI model trained on the characteristics of phishing emails to calculate a suspiciousness score for new emails and process them automatically." This prompt can be used to explain in detail the technology for automatically detecting suspicious emails.
[0259] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0260] Step 1:
[0261] The user launches the email client on their device. This automatically starts the agent program running in the background. The input is the user's actions, and the output is the agent's startup status. Specifically, the email client connects to the email server and prepares to send and receive data.
[0262] Step 2:
[0263] The terminal queries the mail server and receives new emails in a list format. The input is email data from the server, and the output is saved email data. Specifically, information such as the sender, subject, and body of each received email is stored on the terminal. This information is used for subsequent suspiciousness analysis.
[0264] Step 3:
[0265] The server uses a generative AI model to analyze email data transferred from the terminal. The input is email data, and the output is a suspiciousness score. Specifically, the AI model analyzes the text information of the email and calculates the score by comparing it with patterns of suspicious emails that it has learned in the past. Natural language processing techniques are used in this process to extract and evaluate context and keywords.
[0266] Step 4:
[0267] The device automatically moves suspicious emails to a quarantine folder or deletes them based on the suspicion score obtained from the server. The input is a suspicion score, and the output is the status of the email folder after processing. Specifically, emails with scores exceeding a set threshold are quarantined or deleted, thereby protecting the user from suspicious emails.
[0268] Step 5:
[0269] Users are notified of the email processing results on their device. The feedback function allows for the provision of information as feedback data in case of false positives or missed detections. Inputs include processing results and user feedback, while output is feedback data sent to the server. Specifically, the feedback information is sent to the server and used for the continuous learning of the generated AI model.
[0270] (Application Example 1)
[0271] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."
[0272] In recent years, there has been an increase in cases of malicious information and fraud being transmitted through email and communication data. There is a need for technology that can effectively detect such suspicious communications and protect user safety. However, conventional technologies have been unable to adequately remove suspicious emails and communications, resulting in false positives and delayed notifications. Furthermore, there is a need for a system that enables real-time scanning and immediate response while reducing the burden on users.
[0273] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0274] In this invention, the server includes means for analyzing communication data using an information processing device, means for automatically determining suspicious communications based on the analysis results of the communication data, means for notifying the user of the determination and the results of isolation or deletion, and means for providing a real-time scanning function in cooperation with a mobile terminal. This makes it possible to quickly and efficiently detect and manage suspicious communication data.
[0275] An "information processing device" is a computer system that has the function of analyzing and processing communication data.
[0276] "Communication data" refers to a collection of electrical or electronic information transmitted and received through a network.
[0277] A "generative AI model" is an algorithm that learns patterns and features from past data using machine learning, and then makes predictions and classifications for unknown data.
[0278] A "mobile terminal" refers to an electronic device that is portable and can connect to a network using wireless communication.
[0279] This invention is implemented by constructing a system that analyzes communication data using an information processing device and identifies and isolates suspicious communications. The aim of this system is to cooperate between a server and a mobile terminal, scan communication data in real time, and immediately notify the user of the results.
[0280] The server first receives the communication data and passes it to the generative AI model for analysis. The generative AI model is implemented using Python and the TensorFlow library and learns suspicious patterns from past data. This model analyzes the characteristics of the communication data and scores whether the communication is suspicious.
[0281] If the communication is determined to be suspicious, the server enters a procedure to automatically isolate or delete the communication data. At the same time, a notification message is sent to the mobile terminal used by the user, and the result is reported immediately. This enables the user to check for suspicious communications in real time and ensure security.
[0282] As a specific example, consider the case where a user receives a short email saying "Hello". The server analyzes this email with the generative AI model and calculates a suspicion score from the sender information and content. If the score is low, it is judged as safe and the user is notified that there is no problem.
[0283] The user's feedback is sent back to the server again, and this data is used for the continuous learning of the generative AI model, enabling the system to adapt flexibly to new modus operandi and improve accuracy.
[0284] The following is an example of a prompt sentence regarding how the generative AI model is described. "Please explain the latest spam email filtering technology. In particular, please explain in detail the method for detecting suspicious emails using the generative AI model."
[0285] The flow of the specific process in Application Example 1 will be described using FIG. 12.
[0286] Step 1:
[0287] The server initially receives communication data via the network. At this stage, the data has not yet been analyzed; the raw communication data is the input. The output is a dataset awaiting analysis.
[0288] Step 2:
[0289] The server begins analyzing the communication data using a generative AI model. Specifically, the generative AI model (using Python and the TensorFlow library) converts the text of the communication data into numerical data and evaluates its suspiciousness. The input is the dataset from Step 1, and the output is the suspiciousness score corresponding to each communication data.
[0290] Step 3:
[0291] The server checks whether the suspicion score exceeds a pre-set threshold. The input for this step is the generated score, and the output is a judgment flag (whether it is suspicious or not). Specifically, if the score exceeds the threshold, the communication data is marked as suspicious.
[0292] Step 4:
[0293] The server automatically moves or deletes any communication data deemed suspicious. The input is the result of the determination in step 3, and the output is the datastore status after the suspicious communication data has been quarantined or deleted.
[0294] Step 5:
[0295] The server notifies the user of the judgment result. This notification includes which communications were deemed suspicious. The input is the judgment flag from step 3, and the output is the notification message displayed on the user's terminal. Specifically, a pop-up message is sent to the user's smartphone or computer.
[0296] Step 6:
[0297] Users submit feedback if they encounter a misjudgment. The input is the user's feedback, and the output is the transmission of that data to the server. This updates the training dataset for the generative AI model.
[0298] Step 7:
[0299] The server updates the parameters of the generated AI model using the received feedback and retrains the model. The input is user feedback information, and the output is the tuned AI model. Specifically, the model's accuracy is improved.
[0300] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0301] This invention provides a system that combines a system for analyzing emails and automatically identifying and processing suspicious emails with an emotion engine that recognizes user emotions and optimizes countermeasures. In this embodiment, both email analysis and emotion recognition functions are combined to improve the user experience.
[0302] When a user launches their email client, an agent starts in the background. This agent sends the received email to the server and analyzes it using a generative AI model. This analysis calculates a suspicion score based on the content and characteristics of the email. Simultaneously, an emotion engine running on the device analyzes the user's emotions from the camera, microphone, and text input. The emotion engine evaluates the user's current emotions based on their facial expressions, voice tone, and the speed and style of text input.
[0303] When the suspicious score of an email exceeds a predetermined threshold, a final determination is made considering the analysis results of this emotion engine. If signs of uneasiness or vigilance are shown, the email is isolated or deleted, and a detailed notice regarding this is provided to the user. Also, due to special notice messages and countermeasures being taken according to the user's mental state, the user can conduct email operations more securely.
[0304] As a specific example, when a user opens a newly received email and there is an email with a high suspicious score, at this point, the emotion engine detects the user's expression, and tension or surprise is recognized. As a result, the system issues a special alert regarding this email and implements security measures such as obtaining further information about the sender and invalidating links.
[0305] In this way, in the embodiment of the present invention, by integrating the function of preventing suspicious emails and emotion recognition technology, an environment where users can use emails with confidence can be provided.
[0306] The following describes the processing flow.
[0307] Step 1:
[0308] The user launches the email client. By this action, the suspicious email identification system starts operating in the background.
[0309] Step 2:
[0310] The terminal checks for new emails and forwards them to the server. The server prepares to distribute the emails to the generation AI model.
[0311] Step 3:
[0312] The server uses the AI model to analyze the body text, sender information, subject, etc. of each email and calculates the suspicious score. This score is used to evaluate the risk by comparing it with known patterns of emails.
[0313] Step 4:
[0314] The device activates an emotion engine to check the user's emotional state. Through the device's camera and microphone, it analyzes the user's facial expressions and voice tone in real time to determine what emotions are being expressed.
[0315] Step 5:
[0316] The device integrates the suspicion score and the sentiment engine's evaluation to make a final decision on whether an email is suspicious. If the user indicates anxiety or caution, it will be treated as suspicious even if the score is somewhat low.
[0317] Step 6:
[0318] The device immediately quarantines emails it deems suspicious and notifies the user of this fact and the reason. In addition, a special warning message is displayed to encourage safe actions. The notification to the user includes concise language and reassuring content.
[0319] Step 7:
[0320] Users can review notifications and provide feedback if they find the detection to be incorrect. This feedback is used to improve the system.
[0321] Step 8:
[0322] The server receives user feedback and incorporates it into the AI model's training. Based on this information, continuous improvements are made to enhance the accuracy of future email filtering processes.
[0323] (Example 2)
[0324] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".
[0325] Traditional email management systems have features to identify and automatically quarantine / delete suspicious messages such as spam and phishing messages, but they often do not take into account the emotional reactions of users. Therefore, users may experience confusion or anxiety when receiving suspicious messages, which can disrupt their work. Consequently, there is a need for a system that can process and notify users more appropriately based on their emotional state.
[0326] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0327] In this invention, the server includes means for analyzing messages using a computer system, means for automatically determining suspicious messages based on the message analysis results, and means including an analysis device on the terminal for analyzing the user's emotional state. This enables integrated analysis of message content and the user's emotions, and allows for message processing and notifications to reduce anxiety.
[0328] A "computer system" is a system that uses electronic devices to process data and automatically perform various tasks.
[0329] "Message" refers to information or communication content that is transferred as email or text data.
[0330] "Means of analysis" refers to a process or device that has the function of analyzing information in detail and understanding its characteristics and patterns based on that analysis.
[0331] A "suspicious message" is any communication that includes spam or phishing and is deemed to have the potential to harm the recipient.
[0332] "Means of determination" refers to a device or program that has the function of evaluating the results based on the input information and determining whether or not specific conditions are met.
[0333] "Means of isolation or deletion" refers to a process or system that has the capability to move a identified suspicious message to a secure location or to delete it completely to prevent access.
[0334] "User" refers to an individual or legal entity that operates electronic devices or software.
[0335] "Means of notification" refers to a communication function or device used to inform a user of a specific situation or result.
[0336] "Means of learning from feedback" refer to processes and devices that analyze responses and opinions obtained from users and utilize them to improve the accuracy and functionality of a system.
[0337] A "generative AI model" is a model that uses artificial intelligence algorithms to learn from large amounts of data and recognize patterns and features.
[0338] A "terminal analysis device for analyzing emotional state" refers to a device or software that has the function of interpreting the user's facial expressions, voice, text input, etc., and evaluating their emotional state.
[0339] This invention is a system that enables users to use email comfortably and securely. This system consists of multiple components to perform message analysis and suspicious message processing that takes into account the user's emotions.
[0340] When a user launches an email client on their device, an analysis agent starts in the background. Message data is sent to a server, where its content is analyzed using a generative AI model. This generative AI model calculates a suspiciousness score for the message based on patterns and features derived from a large amount of data. The server also determines that a message is suspicious if its score exceeds a certain threshold and takes appropriate isolation or deletion measures.
[0341] Meanwhile, the device is equipped with an emotion analysis engine that analyzes the user's emotional state in real time through the camera, microphone, and keyboard input. This engine identifies emotions from the user's facial expressions, voice tone, and input speed, and reports them to the server as feedback.
[0342] By utilizing this sentiment information, the server can take appropriate action when processing suspicious messages, taking into account the user's state. For example, users who indicate anxiety will receive special notifications tailored to the content of their anxiety, and safety measures such as providing additional information or disabling links will be automatically applied.
[0343] For example, suppose a user opens a newly received message and receives a high suspicion score, and the sentiment analysis engine detects the user's surprise. In this case, the server will issue a further warning to the user and disable the link in the message.
[0344] Examples of prompt messages include the following:
[0345] "Please analyze the following email and calculate a suspicion score. Check the subject and content, and identify any risky elements."
[0346] "Generate recommended actions for when users express surprise or anxiety. For example, provide secure email handling methods and guidelines."
[0347] In this way, users can enjoy an environment where they can use email more safely and securely through the system.
[0348] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0349] Step 1:
[0350] When a user launches their email client, the system automatically starts an agent in the background. The agent detects new messages in the user's inbox. This process is provided with data from newly received messages as input. The output is message data that is sent to the server for analysis.
[0351] Step 2:
[0352] The server inputs the received message data into a generating AI model and begins analyzing its content. This analysis process thoroughly examines the email sender, subject, body, links, attachments, and other elements. For data processing, each of these elements is pattern-recognized by the AI model to extract risk factors. As an output, a suspiciousness score is calculated for each message.
[0353] Step 3:
[0354] The server evaluates the suspiciousness score and classifies messages as suspicious if they exceed a pre-set threshold. This determination also takes into account the sender's trustworthiness and the results of spam filters. The output is a list of messages that have been determined to be suspicious.
[0355] Step 4:
[0356] The device's emotion analysis engine monitors the user's facial expressions, voice, and keyboard input. Camera video, microphone audio, and keyboard input are used as inputs. From these, emotional patterns are analyzed to evaluate the user's current emotional state. The output is data indicating the user's emotional state, which is reported to the server.
[0357] Step 5:
[0358] The server comprehensively considers the suspicion score and the user's emotional state to determine the final handling of the message. For example, if the user's emotional state indicates anxiety, it may choose to isolate the message or disable the link. The output of this process is a notification provided to the user, which includes information about specific safety measures.
[0359] Step 6:
[0360] The user is also provided with notifications from the system, and if necessary, can directly review the message content and take the instructions. The input is notification information from the server, and the output is the specific action the user should take. The notification includes recommended actions based on prompts and other information.
[0361] (Application Example 2)
[0362] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."
[0363] In modern times, the amount of suspicious information flowing in via information media such as email is steadily increasing, and the burden on users to deal with this suspicious information is growing. While there is a need to strengthen the automated response capabilities of systems to such suspicious information, conventional systems fail to consider the user's emotions and psychological state, resulting in a risk of damaging the user experience. Therefore, the challenge is to provide a system that not only accurately and efficiently identifies and isolates suspicious information, but also allows for flexible responses that take user emotions into consideration.
[0364] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0365] In this invention, the server includes means for analyzing information using a computer system, means for automatically determining suspicious information based on the results of the information analysis, and means for automatically isolating or deleting information determined to be suspicious. This enables automatic determination and isolation of suspicious information. Furthermore, by adding means for analyzing the user's psychological state using an emotion analysis engine and considering this in the final decision, flexible responses based on the user's psychological state become possible.
[0366] A "computer system" refers to a collection of electronic computers and their programs used for analyzing information.
[0367] "Information analysis" is the process of analyzing received data and extracting its content and characteristics.
[0368] "Suspicious information" refers to information that deviates from normal standards and patterns and is judged to be fraudulent or dangerous.
[0369] "Automatic judgment" refers to a function where the system makes a decision based on analysis results without human intervention.
[0370] "Isolation or deletion" refers to the process of removing and invalidating suspicious information from the system when it is detected.
[0371] "Notification means" refers to a method or function for communicating the judgment result to the user.
[0372] "Feedback learning" is the process by which a system learns from past results and user responses to improve its future processing capabilities.
[0373] A "generative AI model" refers to a model that generates and analyzes new patterns and data based on artificial intelligence technology.
[0374] The "emotion analysis engine" is part of a system designed to analyze a user's psychological state, processing data such as facial expressions and voice.
[0375] To implement this application, the server first uses a computer system to intensively analyze the received information. Here, a generative AI model is utilized to extract the content and characteristics of the information. The generative AI model learns data patterns using Python libraries such as NLTK and Scikit-learn to accurately and efficiently identify suspicious information. It also calculates a suspiciousness score and automatically initiates a quarantine or deletion process if it exceeds a predetermined threshold.
[0376] Meanwhile, an emotion analysis engine runs on the device to analyze the user's psychological state. Using the smartphone's camera and microphone, it analyzes facial expressions in real time with OpenCV and DeepFace, and voice tone with PyDub and Librosa. This visualizes the user's emotions, and the analysis results are sent to the server.
[0377] The server also has the ability to adjust its judgment algorithm in response to changes in emotions, optimizing the processing of suspicious information. This makes it possible to enhance security while minimizing the impact on the user.
[0378] One concrete example is a scenario where a user asks questions. For instance, if a user prompts the system with a message like, "Please provide information about the latest phishing scams. Please tell me the specific characteristics of the emails," the system would generate a report on the latest threats, list specific characteristics, and issue a warning.
[0379] Thus, the present invention can combine information analysis and emotion recognition to provide a safer and more interactive user experience.
[0380] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0381] Step 1:
[0382] The server analyzes received information using a computer system. Emails and digital messages are provided as input, and a generative AI model is used to extract content and features. Here, libraries such as NLTK and Scikit-learn are used for pattern learning and suspiciousness scoring. The output includes a suspiciousness score and the features of the analyzed information.
[0383] Step 2:
[0384] The sentiment analysis engine on the device is activated to analyze the user's psychological state. Specifically, it collects the user's facial expressions and vocalizations in real time through the smartphone's camera and microphone. Video and audio are handled as input data, and image analysis is performed using OpenCV and DeepFace, while audio analysis is performed using PyDub and Librosa. As a result, an evaluation of the user's emotional state is output.
[0385] Step 3:
[0386] The server integrates the suspicion score obtained in Step 1 with the emotional state obtained in Step 2 to make a final decision. The input consists of the suspicion score and the emotional analysis results, and based on this data, the server makes a final determination of the reliability and safety of the information. If appropriate, the information is isolated or deleted, and the result is output to the user as a notification.
[0387] Step 4:
[0388] The user takes appropriate action based on notifications received from the system. This involves the user confirming and executing specific actions provided by the system (e.g., risk warnings, reporting suspicious information). This process includes the user requesting information from the system by entering an example "prompt message," such as "Please provide information about the latest phishing scam. Please describe the specific characteristics of the email."
[0389] In this way, a concrete process is implemented in which the server and terminal work together to improve user security.
[0390] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0391] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0392] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the smart glasses 214.
[0393] [Third Embodiment]
[0394] Figure 5 shows an example of the configuration of the data processing system 310 according to the third embodiment.
[0395] As shown in Figure 5, the data processing system 310 includes a data processing device 12 and a headset terminal 314. An example of the data processing device 12 is a server.
[0396] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0397] The headset terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a display 343. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and display 343 are also connected to the bus 52.
[0398] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0399] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).
[0400] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0401] Figure 6 shows an example of the main functions of the data processing device 12 and the headset terminal 314. As shown in Figure 6, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0402] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0403] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0404] In the headset terminal 314, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0405] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the headset terminal 314 will be referred to as the "terminal".
[0406] This invention is a system for effectively filtering out suspicious emails, and includes a program that runs on a computer system. Specific embodiments thereof are described below.
[0407] First, when a user launches their email client, an agent within the system begins operating in the background. The agent queries the email server and retrieves all new emails to the device. The received emails are sequentially passed to a generative AI model built by the server, where their content and characteristics are analyzed. The AI model has learned from past data and has the ability to calculate a suspicion score for each email.
[0408] Based on the analysis, emails identified as suspicious are automatically moved to the trash or saved to a quarantine folder on the device. The user is notified of the processing result, and a feedback function is provided in case of false positives.
[0409] The feedback data is sent back to the server and used for the continuous learning of the AI model. This allows the system to constantly improve its accuracy and adapt flexibly to new methods of fraudulent emails.
[0410] For example, if a fraudulent email is received, the AI model detects the sender information and link patterns within the email, assigning it a high suspicion score. This email is immediately deleted, and the user receives a notification stating that "one of six emails was deemed suspicious and deleted."
[0411] Thus, because this system automatically analyzes and processes emails every time it is received, users can engage in email-related tasks with peace of mind.
[0412] The following describes the processing flow.
[0413] Step 1:
[0414] The user launches their email client. This starts the agent in the background. The agent connects to the mail server and prepares to retrieve all new mail.
[0415] Step 2:
[0416] The server sends received emails to an AI model for analysis. The analysis calculates a suspiciousness score based on various elements such as the email body, sender, title, and links. The AI model recognizes patterns based on past data and assigns scores accordingly.
[0417] Step 3:
[0418] The device receives a suspiciousness score for each email and determines whether that score exceeds a predetermined threshold. If an email is deemed suspicious, it is automatically moved to the trash or saved to a quarantine folder.
[0419] Step 4:
[0420] The device notifies the user of the results of processing suspicious emails. Specifically, it provides a brief report of the number of emails processed and their contents. This allows the user to understand the status of their mailbox.
[0421] Step 5:
[0422] Users can review notification results and provide feedback as needed. For example, they can report false positives to the system.
[0423] Step 6:
[0424] The server receives user feedback, incorporates it into the learning process of the generating AI model, and improves the algorithm. This improves the accuracy of subsequent predictions.
[0425] Step 7:
[0426] The system continues to operate in the background even after completing the overall process, repeating the same process each time a new email is received. This ensures that users always have access to email in a secure environment with the latest security measures in place.
[0427] (Example 1)
[0428] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0429] With the increasing use of email on the internet, fraudulent and malicious emails are rampant. There is a need to quickly and automatically identify such suspicious emails and provide an environment where users can use email with peace of mind. However, conventional email filtering technologies rely on fixed rules and struggle to adapt to new methods and changes.
[0430] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0431] In this invention, the server operates on a terminal and includes means for acquiring new emails from a mail server, means for analyzing the content of the acquired emails using a generation AI model on the server, and means for assigning a suspiciousness score to each email based on the analysis results. This makes it possible to dynamically analyze the content and characteristics of emails and flexibly respond to changing patterns of suspicious emails.
[0432] A "terminal" refers to a computer or electronic device used by a user to send, receive, and process emails.
[0433] A "server" refers to a computer system that provides services to terminals via a network and uses a generative AI model to analyze emails and determine their suspiciousness score.
[0434] A "generative AI model" refers to an artificial intelligence model that analyzes the content and characteristics of emails and evaluates their level of suspiciousness by learning from past data based on machine learning algorithms.
[0435] The "suspiciousness score" refers to a numerical value assigned by a generative AI model to quantitatively evaluate the security of an email based on the results of email analysis.
[0436] "Quarantine" refers to the process of separating emails deemed suspicious from the regular inbox and moving them to a separate, dedicated folder, thereby preventing users from opening them directly.
[0437] "Feedback" refers to user reactions and opinions, which serve as the basis for the generation AI model to learn and continuously improve its accuracy.
[0438] This invention provides an information processing system that offers technology for automatically detecting and processing suspicious emails in an email system. This system consists of an email client and background agent running on the user's terminal, and a generation AI model on a server. Specific embodiments are described below.
[0439] When a user launches an email client on their device, the device starts an agent program in the background and communicates with the server. The device communicates with the email server via the internet connection and downloads new emails for the user. The downloaded email data includes email header information (sender, subject, etc.) and the email body.
[0440] The server sequentially analyzes received emails using a generative AI model. This generative AI model is trained using machine learning algorithms and calculates a suspiciousness score from the content and structural features of the emails. The generative AI model analyzes the email text using natural language processing and compares it to suspicious email patterns it has learned in the past. This process includes text analysis, information extraction, and scoring algorithms.
[0441] If the AI model determines an email is suspicious, the device will automatically move the email to a quarantine folder or delete it. Information about quarantined or deleted emails is stored on the device as a log, and feedback is provided to the user in the form of a notification.
[0442] For example, when a user opens an email, the server can indicate that a large number of new phishing emails have been detected for that time. If a phishing email is received, the sender's domain information and the link patterns in the email body will be identified as suspicious. This email will have a high suspicion score and will be immediately quarantined. The user will be notified that "1 out of 10 emails has been quarantined because it is suspicious."
[0443] An example of a prompt is, "Please describe a system that uses an AI model trained on the characteristics of phishing emails to calculate a suspiciousness score for new emails and process them automatically." This prompt can be used to explain in detail the technology for automatically detecting suspicious emails.
[0444] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0445] Step 1:
[0446] The user launches the email client on their device. This automatically starts the agent program running in the background. The input is the user's actions, and the output is the agent's startup status. Specifically, the email client connects to the email server and prepares to send and receive data.
[0447] Step 2:
[0448] The terminal queries the mail server and receives new emails in a list format. The input is email data from the server, and the output is saved email data. Specifically, information such as the sender, subject, and body of each received email is stored on the terminal. This information is used for subsequent suspiciousness analysis.
[0449] Step 3:
[0450] The server uses a generative AI model to analyze email data transferred from the terminal. The input is email data, and the output is a suspiciousness score. Specifically, the AI model analyzes the text information of the email and calculates the score by comparing it with patterns of suspicious emails that it has learned in the past. Natural language processing techniques are used in this process to extract and evaluate context and keywords.
[0451] Step 4:
[0452] The device automatically moves suspicious emails to a quarantine folder or deletes them based on the suspicion score obtained from the server. The input is a suspicion score, and the output is the status of the email folder after processing. Specifically, emails with scores exceeding a set threshold are quarantined or deleted, thereby protecting the user from suspicious emails.
[0453] Step 5:
[0454] Users are notified of the email processing results on their device. The feedback function allows for the provision of information as feedback data in case of false positives or missed detections. Inputs include processing results and user feedback, while output is feedback data sent to the server. Specifically, the feedback information is sent to the server and used for the continuous learning of the generated AI model.
[0455] (Application Example 1)
[0456] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0457] In recent years, there has been an increase in cases of malicious information and fraud being transmitted through email and communication data. There is a need for technology that can effectively detect such suspicious communications and protect user safety. However, conventional technologies have been unable to adequately remove suspicious emails and communications, resulting in false positives and delayed notifications. Furthermore, there is a need for a system that enables real-time scanning and immediate response while reducing the burden on users.
[0458] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0459] In this invention, the server includes means for analyzing communication data using an information processing device, means for automatically determining suspicious communications based on the analysis results of the communication data, means for notifying the user of the determination and the results of isolation or deletion, and means for providing a real-time scanning function in cooperation with a mobile terminal. This makes it possible to quickly and efficiently detect and manage suspicious communication data.
[0460] An "information processing device" is a computer system that has the function of analyzing and processing communication data.
[0461] "Communication data" refers to a collection of electrical or electronic information transmitted and received through a network.
[0462] A "generative AI model" is an algorithm that learns patterns and features from past data using machine learning, and then makes predictions and classifications for unknown data.
[0463] A "mobile terminal" refers to an electronic device that is portable and can connect to a network using wireless communication.
[0464] This invention is implemented by constructing a system that analyzes communication data using an information processing device and identifies and isolates suspicious communications. The aim of this system is to cooperate between a server and a mobile terminal, scan communication data in real time, and immediately notify the user of the results.
[0465] The server first receives communication data and passes it to a generative AI model for analysis. The generative AI model is implemented using Python and TensorFlow libraries and learns suspicious patterns from past data. This model analyzes the characteristics of the communication data and scores whether the communication is suspicious or not.
[0466] If a communication is deemed suspicious, the server will automatically initiate a process to isolate or delete the communication data. Simultaneously, a notification message will be sent to the user's mobile device, and the result will be reported immediately. This allows users to check suspicious communications in real time and ensure their safety.
[0467] As a concrete example, consider a case where a user receives a short email saying "Hello." The server analyzes this email using a generation AI model and calculates a suspicion score based on the sender information and content. If the score is low, it is deemed safe, and the user is notified that there is no problem.
[0468] User feedback is sent back to the server, and this data is used for the continuous training of the generating AI model, allowing the system to flexibly adapt to new techniques and improve accuracy.
[0469] The following is an example of a prompt asking how a generative AI model should be described: "Please describe the latest spam filtering technologies, especially how generative AI models are used to detect suspicious emails."
[0470] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0471] Step 1:
[0472] The server initially receives communication data via the network. At this stage, the data has not yet been analyzed; the raw communication data is the input. The output is a dataset awaiting analysis.
[0473] Step 2:
[0474] The server begins analyzing the communication data using a generative AI model. Specifically, the generative AI model (using Python and the TensorFlow library) converts the text of the communication data into numerical data and evaluates its suspiciousness. The input is the dataset from Step 1, and the output is the suspiciousness score corresponding to each communication data.
[0475] Step 3:
[0476] The server checks whether the suspicion score exceeds a pre-set threshold. The input for this step is the generated score, and the output is a judgment flag (whether it is suspicious or not). Specifically, if the score exceeds the threshold, the communication data is marked as suspicious.
[0477] Step 4:
[0478] The server automatically moves or deletes any communication data deemed suspicious. The input is the result of the determination in step 3, and the output is the datastore status after the suspicious communication data has been quarantined or deleted.
[0479] Step 5:
[0480] The server notifies the user of the judgment result. This notification includes which communications were deemed suspicious. The input is the judgment flag from step 3, and the output is the notification message displayed on the user's terminal. Specifically, a pop-up message is sent to the user's smartphone or computer.
[0481] Step 6:
[0482] Users submit feedback if they encounter a misjudgment. The input is the user's feedback, and the output is the transmission of that data to the server. This updates the training dataset for the generative AI model.
[0483] Step 7:
[0484] The server updates the parameters of the generated AI model using the received feedback and retrains the model. The input is user feedback information, and the output is the tuned AI model. Specifically, the model's accuracy is improved.
[0485] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0486] This invention provides a system that combines a system for analyzing emails and automatically identifying and processing suspicious emails with an emotion engine that recognizes user emotions and optimizes countermeasures. In this embodiment, both email analysis and emotion recognition functions are combined to improve the user experience.
[0487] When a user launches their email client, an agent starts in the background. This agent sends the received email to the server and analyzes it using a generative AI model. This analysis calculates a suspicion score based on the content and characteristics of the email. Simultaneously, an emotion engine running on the device analyzes the user's emotions from the camera, microphone, and text input. The emotion engine evaluates the user's current emotions based on their facial expressions, voice tone, and the speed and style of text input.
[0488] If an email's suspiciousness score exceeds a predetermined threshold, the results of this sentiment engine's analysis are taken into account when making a final decision. If anxiety or caution is indicated, the email is quarantined or deleted, and a detailed notification is provided to the user. Furthermore, special notification messages and measures are taken depending on the user's mental state, allowing users to conduct email work more securely.
[0489] For example, if a user opens a newly received email and it contains an email with a high suspicion score, the emotion engine will detect the user's facial expression at this point and recognize tension or surprise. As a result, the system will issue a special warning about the email and take safety measures such as providing further information about the sender or disabling links.
[0490] Thus, in this embodiment of the present invention, by integrating a suspicious email prevention function with emotion recognition technology, it is possible to provide an environment in which users can use email with peace of mind.
[0491] The following describes the processing flow.
[0492] Step 1:
[0493] The user launches their email client. This action causes the suspicious email identification system to start running in the background.
[0494] Step 2:
[0495] The device checks for new emails and forwards them to the server. The server then prepares the emails for distribution to the AI model that generates them.
[0496] Step 3:
[0497] The server uses an AI model to analyze the body, sender information, subject, etc., of each email and calculates a suspiciousness score. This score is used to assess the risk by comparing it to known email patterns.
[0498] Step 4:
[0499] The device activates an emotion engine to check the user's emotional state. Through the device's camera and microphone, it analyzes the user's facial expressions and voice tone in real time to determine what emotions are being expressed.
[0500] Step 5:
[0501] The device integrates the suspicion score and the sentiment engine's evaluation to make a final decision on whether an email is suspicious. If the user indicates anxiety or caution, it will be treated as suspicious even if the score is somewhat low.
[0502] Step 6:
[0503] The device immediately quarantines emails it deems suspicious and notifies the user of this fact and the reason. In addition, a special warning message is displayed to encourage safe actions. The notification to the user includes concise language and reassuring content.
[0504] Step 7:
[0505] Users can review notifications and provide feedback if they find the detection to be incorrect. This feedback is used to improve the system.
[0506] Step 8:
[0507] The server receives user feedback and incorporates it into the AI model's training. Based on this information, continuous improvements are made to enhance the accuracy of future email filtering processes.
[0508] (Example 2)
[0509] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0510] Traditional email management systems have features to identify and automatically quarantine / delete suspicious messages such as spam and phishing messages, but they often do not take into account the emotional reactions of users. Therefore, users may experience confusion or anxiety when receiving suspicious messages, which can disrupt their work. Consequently, there is a need for a system that can process and notify users more appropriately based on their emotional state.
[0511] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0512] In this invention, the server includes means for analyzing messages using a computer system, means for automatically determining suspicious messages based on the message analysis results, and means including an analysis device on the terminal for analyzing the user's emotional state. This enables integrated analysis of message content and the user's emotions, and allows for message processing and notifications to reduce anxiety.
[0513] A "computer system" is a system that uses electronic devices to process data and automatically perform various tasks.
[0514] "Message" refers to information or communication content that is transferred as email or text data.
[0515] "Means of analysis" refers to a process or device that has the function of analyzing information in detail and understanding its characteristics and patterns based on that analysis.
[0516] A "suspicious message" is any communication that includes spam or phishing and is deemed to have the potential to harm the recipient.
[0517] "Means of determination" refers to a device or program that has the function of evaluating the results based on the input information and determining whether or not specific conditions are met.
[0518] "Means of isolation or deletion" refers to a process or system that has the capability to move a identified suspicious message to a secure location or to delete it completely to prevent access.
[0519] "User" refers to an individual or legal entity that operates electronic devices or software.
[0520] "Means of notification" refers to a communication function or device used to inform a user of a specific situation or result.
[0521] "Means of learning from feedback" refer to processes and devices that analyze responses and opinions obtained from users and utilize them to improve the accuracy and functionality of a system.
[0522] A "generative AI model" is a model that uses artificial intelligence algorithms to learn from large amounts of data and recognize patterns and features.
[0523] A "terminal analysis device for analyzing emotional state" refers to a device or software that has the function of interpreting the user's facial expressions, voice, text input, etc., and evaluating their emotional state.
[0524] This invention is a system that enables users to use email comfortably and securely. This system consists of multiple components to perform message analysis and suspicious message processing that takes into account the user's emotions.
[0525] When a user launches an email client on their device, an analysis agent starts in the background. Message data is sent to a server, where its content is analyzed using a generative AI model. This generative AI model calculates a suspiciousness score for the message based on patterns and features derived from a large amount of data. The server also determines that a message is suspicious if its score exceeds a certain threshold and takes appropriate isolation or deletion measures.
[0526] Meanwhile, the device is equipped with an emotion analysis engine that analyzes the user's emotional state in real time through the camera, microphone, and keyboard input. This engine identifies emotions from the user's facial expressions, voice tone, and input speed, and reports them to the server as feedback.
[0527] By utilizing this sentiment information, the server can take appropriate action when processing suspicious messages, taking into account the user's state. For example, users who indicate anxiety will receive special notifications tailored to the content of their anxiety, and safety measures such as providing additional information or disabling links will be automatically applied.
[0528] For example, suppose a user opens a newly received message and receives a high suspicion score, and the sentiment analysis engine detects the user's surprise. In this case, the server will issue a further warning to the user and disable the link in the message.
[0529] Examples of prompt messages include the following:
[0530] "Please analyze the following email and calculate a suspicion score. Check the subject and content, and identify any risky elements."
[0531] "Generate recommended actions for when users express surprise or anxiety. For example, provide secure email handling methods and guidelines."
[0532] In this way, users can enjoy an environment where they can use email more safely and securely through the system.
[0533] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0534] Step 1:
[0535] When a user launches their email client, the system automatically starts an agent in the background. The agent detects new messages in the user's inbox. This process is provided with data from newly received messages as input. The output is message data that is sent to the server for analysis.
[0536] Step 2:
[0537] The server inputs the received message data into a generating AI model and begins analyzing its content. This analysis process thoroughly examines the email sender, subject, body, links, attachments, and other elements. For data processing, each of these elements is pattern-recognized by the AI model to extract risk factors. As an output, a suspiciousness score is calculated for each message.
[0538] Step 3:
[0539] The server evaluates the suspiciousness score and classifies messages as suspicious if they exceed a pre-set threshold. This determination also takes into account the sender's trustworthiness and the results of spam filters. The output is a list of messages that have been determined to be suspicious.
[0540] Step 4:
[0541] The device's emotion analysis engine monitors the user's facial expressions, voice, and keyboard input. Camera video, microphone audio, and keyboard input are used as inputs. From these, emotional patterns are analyzed to evaluate the user's current emotional state. The output is data indicating the user's emotional state, which is reported to the server.
[0542] Step 5:
[0543] The server comprehensively considers the suspicion score and the user's emotional state to determine the final handling of the message. For example, if the user's emotional state indicates anxiety, it may choose to isolate the message or disable the link. The output of this process is a notification provided to the user, which includes information about specific safety measures.
[0544] Step 6:
[0545] The user is also provided with notifications from the system, and if necessary, can directly review the message content and take the instructions. The input is notification information from the server, and the output is the specific action the user should take. The notification includes recommended actions based on prompts and other information.
[0546] (Application Example 2)
[0547] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0548] In modern times, the amount of suspicious information flowing in via information media such as email is steadily increasing, and the burden on users to deal with this suspicious information is growing. While there is a need to strengthen the automated response capabilities of systems to such suspicious information, conventional systems fail to consider the user's emotions and psychological state, resulting in a risk of damaging the user experience. Therefore, the challenge is to provide a system that not only accurately and efficiently identifies and isolates suspicious information, but also allows for flexible responses that take user emotions into consideration.
[0549] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0550] In this invention, the server includes means for analyzing information using a computer system, means for automatically determining suspicious information based on the results of the information analysis, and means for automatically isolating or deleting information determined to be suspicious. This enables automatic determination and isolation of suspicious information. Furthermore, by adding means for analyzing the user's psychological state using an emotion analysis engine and considering this in the final decision, flexible responses based on the user's psychological state become possible.
[0551] A "computer system" refers to a collection of electronic computers and their programs used for analyzing information.
[0552] "Information analysis" is the process of analyzing received data and extracting its content and characteristics.
[0553] "Suspicious information" refers to information that deviates from normal standards and patterns and is judged to be fraudulent or dangerous.
[0554] "Automatic judgment" refers to a function where the system makes a decision based on analysis results without human intervention.
[0555] "Isolation or deletion" refers to the process of removing and invalidating suspicious information from the system when it is detected.
[0556] "Notification means" refers to a method or function for communicating the judgment result to the user.
[0557] "Feedback learning" is the process by which a system learns from past results and user responses to improve its future processing capabilities.
[0558] A "generative AI model" refers to a model that generates and analyzes new patterns and data based on artificial intelligence technology.
[0559] The "emotion analysis engine" is part of a system designed to analyze a user's psychological state, processing data such as facial expressions and voice.
[0560] To implement this application, the server first uses a computer system to intensively analyze the received information. Here, a generative AI model is utilized to extract the content and characteristics of the information. The generative AI model learns data patterns using Python libraries such as NLTK and Scikit-learn to accurately and efficiently identify suspicious information. It also calculates a suspiciousness score and automatically initiates a quarantine or deletion process if it exceeds a predetermined threshold.
[0561] Meanwhile, an emotion analysis engine runs on the device to analyze the user's psychological state. Using the smartphone's camera and microphone, it analyzes facial expressions in real time with OpenCV and DeepFace, and voice tone with PyDub and Librosa. This visualizes the user's emotions, and the analysis results are sent to the server.
[0562] The server also has the ability to adjust its judgment algorithm in response to changes in emotions, optimizing the processing of suspicious information. This makes it possible to enhance security while minimizing the impact on the user.
[0563] One concrete example is a scenario where a user asks questions. For instance, if a user prompts the system with a message like, "Please provide information about the latest phishing scams. Please tell me the specific characteristics of the emails," the system would generate a report on the latest threats, list specific characteristics, and issue a warning.
[0564] Thus, the present invention can combine information analysis and emotion recognition to provide a safer and more interactive user experience.
[0565] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0566] Step 1:
[0567] The server analyzes received information using a computer system. Emails and digital messages are provided as input, and a generative AI model is used to extract content and features. Here, libraries such as NLTK and Scikit-learn are used for pattern learning and suspiciousness scoring. The output includes a suspiciousness score and the features of the analyzed information.
[0568] Step 2:
[0569] The sentiment analysis engine on the device is activated to analyze the user's psychological state. Specifically, it collects the user's facial expressions and vocalizations in real time through the smartphone's camera and microphone. Video and audio are handled as input data, and image analysis is performed using OpenCV and DeepFace, while audio analysis is performed using PyDub and Librosa. As a result, an evaluation of the user's emotional state is output.
[0570] Step 3:
[0571] The server integrates the suspicion score obtained in Step 1 with the emotional state obtained in Step 2 to make a final decision. The input consists of the suspicion score and the emotional analysis results, and based on this data, the server makes a final determination of the reliability and safety of the information. If appropriate, the information is isolated or deleted, and the result is output to the user as a notification.
[0572] Step 4:
[0573] The user takes appropriate action based on notifications received from the system. This involves the user confirming and executing specific actions provided by the system (e.g., risk warnings, reporting suspicious information). This process includes the user requesting information from the system by entering an example "prompt message," such as "Please provide information about the latest phishing scam. Please describe the specific characteristics of the email."
[0574] In this way, a concrete process is implemented in which the server and terminal work together to improve user security.
[0575] The specific processing unit 290 transmits the result of the specific processing to the headset terminal 314. In the headset terminal 314, the control unit 46A causes the speaker 240 and display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0576] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0577] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and specific processing may also be performed by the headset terminal 314.
[0578] [Fourth Embodiment]
[0579] Figure 7 shows an example of the configuration of the data processing system 410 according to the fourth embodiment.
[0580] As shown in Figure 7, the data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.
[0581] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0582] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a controlled object 443. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and controlled object 443 are also connected to the bus 52.
[0583] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0584] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).
[0585] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0586] The controlled object 443 includes a display device, LEDs in the eyes, and motors that drive the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the robot 414's emotions can be expressed by controlling these motors. Furthermore, the robot 414's facial expressions can also be expressed by controlling the illumination state of the LEDs in its eyes.
[0587] Figure 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Figure 8, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0588] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0589] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0590] In robot 414, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0591] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0592] This invention is a system for effectively filtering out suspicious emails, and includes a program that runs on a computer system. Specific embodiments thereof are described below.
[0593] First, when a user launches their email client, an agent within the system begins operating in the background. The agent queries the email server and retrieves all new emails to the device. The received emails are sequentially passed to a generative AI model built by the server, where their content and characteristics are analyzed. The AI model has learned from past data and has the ability to calculate a suspicion score for each email.
[0594] Based on the analysis, emails identified as suspicious are automatically moved to the trash or saved to a quarantine folder on the device. The user is notified of the processing result, and a feedback function is provided in case of false positives.
[0595] The feedback data is sent back to the server and used for the continuous learning of the AI model. This allows the system to constantly improve its accuracy and adapt flexibly to new methods of fraudulent emails.
[0596] For example, if a fraudulent email is received, the AI model detects the sender information and link patterns within the email, assigning it a high suspicion score. This email is immediately deleted, and the user receives a notification stating that "one of six emails was deemed suspicious and deleted."
[0597] Thus, because this system automatically analyzes and processes emails every time it is received, users can engage in email-related tasks with peace of mind.
[0598] The following describes the processing flow.
[0599] Step 1:
[0600] The user launches their email client. This starts the agent in the background. The agent connects to the mail server and prepares to retrieve all new mail.
[0601] Step 2:
[0602] The server sends received emails to an AI model for analysis. The analysis calculates a suspiciousness score based on various elements such as the email body, sender, title, and links. The AI model recognizes patterns based on past data and assigns scores accordingly.
[0603] Step 3:
[0604] The device receives a suspiciousness score for each email and determines whether that score exceeds a predetermined threshold. If an email is deemed suspicious, it is automatically moved to the trash or saved to a quarantine folder.
[0605] Step 4:
[0606] The device notifies the user of the results of processing suspicious emails. Specifically, it provides a brief report of the number of emails processed and their contents. This allows the user to understand the status of their mailbox.
[0607] Step 5:
[0608] Users can review notification results and provide feedback as needed. For example, they can report false positives to the system.
[0609] Step 6:
[0610] The server receives user feedback, incorporates it into the learning process of the generating AI model, and improves the algorithm. This improves the accuracy of subsequent predictions.
[0611] Step 7:
[0612] The system continues to operate in the background even after completing the overall process, repeating the same process each time a new email is received. This ensures that users always have access to email in a secure environment with the latest security measures in place.
[0613] (Example 1)
[0614] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0615] With the increasing use of email on the internet, fraudulent and malicious emails are rampant. There is a need to quickly and automatically identify such suspicious emails and provide an environment where users can use email with peace of mind. However, conventional email filtering technologies rely on fixed rules and struggle to adapt to new methods and changes.
[0616] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0617] In this invention, the server operates on a terminal and includes means for acquiring new emails from a mail server, means for analyzing the content of the acquired emails using a generation AI model on the server, and means for assigning a suspiciousness score to each email based on the analysis results. This makes it possible to dynamically analyze the content and characteristics of emails and flexibly respond to changing patterns of suspicious emails.
[0618] A "terminal" refers to a computer or electronic device used by a user to send, receive, and process emails.
[0619] A "server" refers to a computer system that provides services to terminals via a network and uses a generative AI model to analyze emails and determine their suspiciousness score.
[0620] A "generative AI model" refers to an artificial intelligence model that analyzes the content and characteristics of emails and evaluates their level of suspiciousness by learning from past data based on machine learning algorithms.
[0621] The "suspiciousness score" refers to a numerical value assigned by a generative AI model to quantitatively evaluate the security of an email based on the results of email analysis.
[0622] "Quarantine" refers to the process of separating emails deemed suspicious from the regular inbox and moving them to a separate, dedicated folder, thereby preventing users from opening them directly.
[0623] "Feedback" refers to user reactions and opinions, which serve as the basis for the generation AI model to learn and continuously improve its accuracy.
[0624] This invention provides an information processing system that offers technology for automatically detecting and processing suspicious emails in an email system. This system consists of an email client and background agent running on the user's terminal, and a generation AI model on a server. Specific embodiments are described below.
[0625] When a user launches an email client on their device, the device starts an agent program in the background and communicates with the server. The device communicates with the email server via the internet connection and downloads new emails for the user. The downloaded email data includes email header information (sender, subject, etc.) and the email body.
[0626] The server sequentially analyzes received emails using a generative AI model. This generative AI model is trained using machine learning algorithms and calculates a suspiciousness score from the content and structural features of the emails. The generative AI model analyzes the email text using natural language processing and compares it to suspicious email patterns it has learned in the past. This process includes text analysis, information extraction, and scoring algorithms.
[0627] If the AI model determines an email is suspicious, the device will automatically move the email to a quarantine folder or delete it. Information about quarantined or deleted emails is stored on the device as a log, and feedback is provided to the user in the form of a notification.
[0628] For example, when a user opens an email, the server can indicate that a large number of new phishing emails have been detected for that time. If a phishing email is received, the sender's domain information and the link patterns in the email body will be identified as suspicious. This email will have a high suspicion score and will be immediately quarantined. The user will be notified that "1 out of 10 emails has been quarantined because it is suspicious."
[0629] An example of a prompt is, "Please describe a system that uses an AI model trained on the characteristics of phishing emails to calculate a suspiciousness score for new emails and process them automatically." This prompt can be used to explain in detail the technology for automatically detecting suspicious emails.
[0630] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0631] Step 1:
[0632] The user launches the email client on their device. This automatically starts the agent program running in the background. The input is the user's actions, and the output is the agent's startup status. Specifically, the email client connects to the email server and prepares to send and receive data.
[0633] Step 2:
[0634] The terminal queries the mail server and receives new emails in a list format. The input is email data from the server, and the output is saved email data. Specifically, information such as the sender, subject, and body of each received email is stored on the terminal. This information is used for subsequent suspiciousness analysis.
[0635] Step 3:
[0636] The server uses a generative AI model to analyze email data transferred from the terminal. The input is email data, and the output is a suspiciousness score. Specifically, the AI model analyzes the text information of the email and calculates the score by comparing it with patterns of suspicious emails that it has learned in the past. Natural language processing techniques are used in this process to extract and evaluate context and keywords.
[0637] Step 4:
[0638] The device automatically moves suspicious emails to a quarantine folder or deletes them based on the suspicion score obtained from the server. The input is a suspicion score, and the output is the status of the email folder after processing. Specifically, emails with scores exceeding a set threshold are quarantined or deleted, thereby protecting the user from suspicious emails.
[0639] Step 5:
[0640] Users are notified of the email processing results on their device. The feedback function allows for the provision of information as feedback data in case of false positives or missed detections. Inputs include processing results and user feedback, while output is feedback data sent to the server. Specifically, the feedback information is sent to the server and used for the continuous learning of the generated AI model.
[0641] (Application Example 1)
[0642] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0643] In recent years, there has been an increase in cases of malicious information and fraud being transmitted through email and communication data. There is a need for technology that can effectively detect such suspicious communications and protect user safety. However, conventional technologies have been unable to adequately remove suspicious emails and communications, resulting in false positives and delayed notifications. Furthermore, there is a need for a system that enables real-time scanning and immediate response while reducing the burden on users.
[0644] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0645] In this invention, the server includes means for analyzing communication data using an information processing device, means for automatically determining suspicious communications based on the analysis results of the communication data, means for notifying the user of the determination and the results of isolation or deletion, and means for providing a real-time scanning function in cooperation with a mobile terminal. This makes it possible to quickly and efficiently detect and manage suspicious communication data.
[0646] An "information processing device" is a computer system that has the function of analyzing and processing communication data.
[0647] "Communication data" refers to a collection of electrical or electronic information transmitted and received through a network.
[0648] A "generative AI model" is an algorithm that learns patterns and features from past data using machine learning, and then makes predictions and classifications for unknown data.
[0649] A "mobile terminal" refers to an electronic device that is portable and can connect to a network using wireless communication.
[0650] This invention is implemented by constructing a system that analyzes communication data using an information processing device and identifies and isolates suspicious communications. The aim of this system is to cooperate between a server and a mobile terminal, scan communication data in real time, and immediately notify the user of the results.
[0651] The server first receives communication data and passes it to a generative AI model for analysis. The generative AI model is implemented using Python and TensorFlow libraries and learns suspicious patterns from past data. This model analyzes the characteristics of the communication data and scores whether the communication is suspicious or not.
[0652] If a communication is deemed suspicious, the server will automatically initiate a process to isolate or delete the communication data. Simultaneously, a notification message will be sent to the user's mobile device, and the result will be reported immediately. This allows users to check suspicious communications in real time and ensure their safety.
[0653] As a concrete example, consider a case where a user receives a short email saying "Hello." The server analyzes this email using a generation AI model and calculates a suspicion score based on the sender information and content. If the score is low, it is deemed safe, and the user is notified that there is no problem.
[0654] User feedback is sent back to the server, and this data is used for the continuous training of the generating AI model, allowing the system to flexibly adapt to new techniques and improve accuracy.
[0655] The following is an example of a prompt asking how a generative AI model should be described: "Please describe the latest spam filtering technologies, especially how generative AI models are used to detect suspicious emails."
[0656] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0657] Step 1:
[0658] The server initially receives communication data via the network. At this stage, the data has not yet been analyzed; the raw communication data is the input. The output is a dataset awaiting analysis.
[0659] Step 2:
[0660] The server begins analyzing the communication data using a generative AI model. Specifically, the generative AI model (using Python and the TensorFlow library) converts the text of the communication data into numerical data and evaluates its suspiciousness. The input is the dataset from Step 1, and the output is the suspiciousness score corresponding to each communication data.
[0661] Step 3:
[0662] The server checks whether the suspicion score exceeds a pre-set threshold. The input for this step is the generated score, and the output is a judgment flag (whether it is suspicious or not). Specifically, if the score exceeds the threshold, the communication data is marked as suspicious.
[0663] Step 4:
[0664] The server automatically moves or deletes any communication data deemed suspicious. The input is the result of the determination in step 3, and the output is the datastore status after the suspicious communication data has been quarantined or deleted.
[0665] Step 5:
[0666] The server notifies the user of the judgment result. This notification includes which communications were deemed suspicious. The input is the judgment flag from step 3, and the output is the notification message displayed on the user's terminal. Specifically, a pop-up message is sent to the user's smartphone or computer.
[0667] Step 6:
[0668] Users submit feedback if they encounter a misjudgment. The input is the user's feedback, and the output is the transmission of that data to the server. This updates the training dataset for the generative AI model.
[0669] Step 7:
[0670] The server updates the parameters of the generated AI model using the received feedback and retrains the model. The input is user feedback information, and the output is the tuned AI model. Specifically, the model's accuracy is improved.
[0671] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0672] This invention provides a system that combines a system for analyzing emails and automatically identifying and processing suspicious emails with an emotion engine that recognizes user emotions and optimizes countermeasures. In this embodiment, both email analysis and emotion recognition functions are combined to improve the user experience.
[0673] When a user launches their email client, an agent starts in the background. This agent sends the received email to the server and analyzes it using a generative AI model. This analysis calculates a suspicion score based on the content and characteristics of the email. Simultaneously, an emotion engine running on the device analyzes the user's emotions from the camera, microphone, and text input. The emotion engine evaluates the user's current emotions based on their facial expressions, voice tone, and the speed and style of text input.
[0674] If an email's suspiciousness score exceeds a predetermined threshold, the results of this sentiment engine's analysis are taken into account when making a final decision. If anxiety or caution is indicated, the email is quarantined or deleted, and a detailed notification is provided to the user. Furthermore, special notification messages and measures are taken depending on the user's mental state, allowing users to conduct email work more securely.
[0675] For example, if a user opens a newly received email and it contains an email with a high suspicion score, the emotion engine will detect the user's facial expression at this point and recognize tension or surprise. As a result, the system will issue a special warning about the email and take safety measures such as providing further information about the sender or disabling links.
[0676] Thus, in this embodiment of the present invention, by integrating a suspicious email prevention function with emotion recognition technology, it is possible to provide an environment in which users can use email with peace of mind.
[0677] The following describes the processing flow.
[0678] Step 1:
[0679] The user launches their email client. This action causes the suspicious email identification system to start running in the background.
[0680] Step 2:
[0681] The device checks for new emails and forwards them to the server. The server then prepares the emails for distribution to the AI model that generates them.
[0682] Step 3:
[0683] The server uses an AI model to analyze the body, sender information, subject, etc., of each email and calculates a suspiciousness score. This score is used to assess the risk by comparing it to known email patterns.
[0684] Step 4:
[0685] The device activates an emotion engine to check the user's emotional state. Through the device's camera and microphone, it analyzes the user's facial expressions and voice tone in real time to determine what emotions are being expressed.
[0686] Step 5:
[0687] The device integrates the suspicion score and the sentiment engine's evaluation to make a final decision on whether an email is suspicious. If the user indicates anxiety or caution, it will be treated as suspicious even if the score is somewhat low.
[0688] Step 6:
[0689] The device immediately quarantines emails it deems suspicious and notifies the user of this fact and the reason. In addition, a special warning message is displayed to encourage safe actions. The notification to the user includes concise language and reassuring content.
[0690] Step 7:
[0691] Users can review notifications and provide feedback if they find the detection to be incorrect. This feedback is used to improve the system.
[0692] Step 8:
[0693] The server receives user feedback and incorporates it into the AI model's training. Based on this information, continuous improvements are made to enhance the accuracy of future email filtering processes.
[0694] (Example 2)
[0695] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0696] Traditional email management systems have features to identify and automatically quarantine / delete suspicious messages such as spam and phishing messages, but they often do not take into account the emotional reactions of users. Therefore, users may experience confusion or anxiety when receiving suspicious messages, which can disrupt their work. Consequently, there is a need for a system that can process and notify users more appropriately based on their emotional state.
[0697] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0698] In this invention, the server includes means for analyzing messages using a computer system, means for automatically determining suspicious messages based on the message analysis results, and means including an analysis device on the terminal for analyzing the user's emotional state. This enables integrated analysis of message content and the user's emotions, and allows for message processing and notifications to reduce anxiety.
[0699] A "computer system" is a system that uses electronic devices to process data and automatically perform various tasks.
[0700] "Message" refers to information or communication content that is transferred as email or text data.
[0701] "Means of analysis" refers to a process or device that has the function of analyzing information in detail and understanding its characteristics and patterns based on that analysis.
[0702] A "suspicious message" is any communication that includes spam or phishing and is deemed to have the potential to harm the recipient.
[0703] "Means of determination" refers to a device or program that has the function of evaluating the results based on the input information and determining whether or not specific conditions are met.
[0704] "Means of isolation or deletion" refers to a process or system that has the capability to move a identified suspicious message to a secure location or to delete it completely to prevent access.
[0705] "User" refers to an individual or legal entity that operates electronic devices or software.
[0706] "Means of notification" refers to a communication function or device used to inform a user of a specific situation or result.
[0707] "Means of learning from feedback" refer to processes and devices that analyze responses and opinions obtained from users and utilize them to improve the accuracy and functionality of a system.
[0708] A "generative AI model" is a model that uses artificial intelligence algorithms to learn from large amounts of data and recognize patterns and features.
[0709] A "terminal analysis device for analyzing emotional state" refers to a device or software that has the function of interpreting the user's facial expressions, voice, text input, etc., and evaluating their emotional state.
[0710] This invention is a system that enables users to use email comfortably and securely. This system consists of multiple components to perform message analysis and suspicious message processing that takes into account the user's emotions.
[0711] When a user launches an email client on their device, an analysis agent starts in the background. Message data is sent to a server, where its content is analyzed using a generative AI model. This generative AI model calculates a suspiciousness score for the message based on patterns and features derived from a large amount of data. The server also determines that a message is suspicious if its score exceeds a certain threshold and takes appropriate isolation or deletion measures.
[0712] Meanwhile, the device is equipped with an emotion analysis engine that analyzes the user's emotional state in real time through the camera, microphone, and keyboard input. This engine identifies emotions from the user's facial expressions, voice tone, and input speed, and reports them to the server as feedback.
[0713] By utilizing this sentiment information, the server can take appropriate action when processing suspicious messages, taking into account the user's state. For example, users who indicate anxiety will receive special notifications tailored to the content of their anxiety, and safety measures such as providing additional information or disabling links will be automatically applied.
[0714] For example, suppose a user opens a newly received message and receives a high suspicion score, and the sentiment analysis engine detects the user's surprise. In this case, the server will issue a further warning to the user and disable the link in the message.
[0715] Examples of prompt messages include the following:
[0716] "Please analyze the following email and calculate a suspicion score. Check the subject and content, and identify any risky elements."
[0717] "Generate recommended actions for when users express surprise or anxiety. For example, provide secure email handling methods and guidelines."
[0718] In this way, users can enjoy an environment where they can use email more safely and securely through the system.
[0719] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0720] Step 1:
[0721] When a user launches their email client, the system automatically starts an agent in the background. The agent detects new messages in the user's inbox. This process is provided with data from newly received messages as input. The output is message data that is sent to the server for analysis.
[0722] Step 2:
[0723] The server inputs the received message data into a generating AI model and begins analyzing its content. This analysis process thoroughly examines the email sender, subject, body, links, attachments, and other elements. For data processing, each of these elements is pattern-recognized by the AI model to extract risk factors. As an output, a suspiciousness score is calculated for each message.
[0724] Step 3:
[0725] The server evaluates the suspiciousness score and classifies messages as suspicious if they exceed a pre-set threshold. This determination also takes into account the sender's trustworthiness and the results of spam filters. The output is a list of messages that have been determined to be suspicious.
[0726] Step 4:
[0727] The device's emotion analysis engine monitors the user's facial expressions, voice, and keyboard input. Camera video, microphone audio, and keyboard input are used as inputs. From these, emotional patterns are analyzed to evaluate the user's current emotional state. The output is data indicating the user's emotional state, which is reported to the server.
[0728] Step 5:
[0729] The server comprehensively considers the suspicion score and the user's emotional state to determine the final handling of the message. For example, if the user's emotional state indicates anxiety, it may choose to isolate the message or disable the link. The output of this process is a notification provided to the user, which includes information about specific safety measures.
[0730] Step 6:
[0731] The user is also provided with notifications from the system, and if necessary, can directly review the message content and take the instructions. The input is notification information from the server, and the output is the specific action the user should take. The notification includes recommended actions based on prompts and other information.
[0732] (Application Example 2)
[0733] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0734] In modern times, the amount of suspicious information flowing in via information media such as email is steadily increasing, and the burden on users to deal with this suspicious information is growing. While there is a need to strengthen the automated response capabilities of systems to such suspicious information, conventional systems fail to consider the user's emotions and psychological state, resulting in a risk of damaging the user experience. Therefore, the challenge is to provide a system that not only accurately and efficiently identifies and isolates suspicious information, but also allows for flexible responses that take user emotions into consideration.
[0735] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0736] In this invention, the server includes means for analyzing information using a computer system, means for automatically determining suspicious information based on the results of the information analysis, and means for automatically isolating or deleting information determined to be suspicious. This enables automatic determination and isolation of suspicious information. Furthermore, by adding means for analyzing the user's psychological state using an emotion analysis engine and considering this in the final decision, flexible responses based on the user's psychological state become possible.
[0737] A "computer system" refers to a collection of electronic computers and their programs used for analyzing information.
[0738] "Information analysis" is the process of analyzing received data and extracting its content and characteristics.
[0739] "Suspicious information" refers to information that deviates from normal standards and patterns and is judged to be fraudulent or dangerous.
[0740] "Automatic judgment" refers to a function where the system makes a decision based on analysis results without human intervention.
[0741] "Isolation or deletion" refers to the process of removing and invalidating suspicious information from the system when it is detected.
[0742] "Notification means" refers to a method or function for communicating the judgment result to the user.
[0743] "Feedback learning" is the process by which a system learns from past results and user responses to improve its future processing capabilities.
[0744] A "generative AI model" refers to a model that generates and analyzes new patterns and data based on artificial intelligence technology.
[0745] The "emotion analysis engine" is part of a system designed to analyze a user's psychological state, processing data such as facial expressions and voice.
[0746] To implement this application, the server first uses a computer system to intensively analyze the received information. Here, a generative AI model is utilized to extract the content and characteristics of the information. The generative AI model learns data patterns using Python libraries such as NLTK and Scikit-learn to accurately and efficiently identify suspicious information. It also calculates a suspiciousness score and automatically initiates a quarantine or deletion process if it exceeds a predetermined threshold.
[0747] Meanwhile, an emotion analysis engine runs on the device to analyze the user's psychological state. Using the smartphone's camera and microphone, it analyzes facial expressions in real time with OpenCV and DeepFace, and voice tone with PyDub and Librosa. This visualizes the user's emotions, and the analysis results are sent to the server.
[0748] The server also has the ability to adjust its judgment algorithm in response to changes in emotions, optimizing the processing of suspicious information. This makes it possible to enhance security while minimizing the impact on the user.
[0749] One concrete example is a scenario where a user asks questions. For instance, if a user prompts the system with a message like, "Please provide information about the latest phishing scams. Please tell me the specific characteristics of the emails," the system would generate a report on the latest threats, list specific characteristics, and issue a warning.
[0750] Thus, the present invention can combine information analysis and emotion recognition to provide a safer and more interactive user experience.
[0751] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0752] Step 1:
[0753] The server analyzes received information using a computer system. Emails and digital messages are provided as input, and a generative AI model is used to extract content and features. Here, libraries such as NLTK and Scikit-learn are used for pattern learning and suspiciousness scoring. The output includes a suspiciousness score and the features of the analyzed information.
[0754] Step 2:
[0755] The sentiment analysis engine on the device is activated to analyze the user's psychological state. Specifically, it collects the user's facial expressions and vocalizations in real time through the smartphone's camera and microphone. Video and audio are handled as input data, and image analysis is performed using OpenCV and DeepFace, while audio analysis is performed using PyDub and Librosa. As a result, an evaluation of the user's emotional state is output.
[0756] Step 3:
[0757] The server integrates the suspicion score obtained in Step 1 with the emotional state obtained in Step 2 to make a final decision. The input consists of the suspicion score and the emotional analysis results, and based on this data, the server makes a final determination of the reliability and safety of the information. If appropriate, the information is isolated or deleted, and the result is output to the user as a notification.
[0758] Step 4:
[0759] The user takes appropriate action based on notifications received from the system. This involves the user confirming and executing specific actions provided by the system (e.g., risk warnings, reporting suspicious information). This process includes the user requesting information from the system by entering an example "prompt message," such as "Please provide information about the latest phishing scam. Please describe the specific characteristics of the email."
[0760] In this way, a concrete process is implemented in which the server and terminal work together to improve user security.
[0761] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the controlled object 443 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0762] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0763] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the robot 414.
[0764] Furthermore, the emotion identification model 59, acting as an emotion engine, may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to a specific mapping, which is an emotion map (see Figure 9). Similarly, the emotion identification model 59 may also determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.
[0765] Figure 9 shows an emotion map 400 in which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. The closer to the center of the concentric circles, the more primitive the emotions are located. Further out of the concentric circles, emotions representing states and actions arising from mental states are located. Emotion is a concept that includes feelings and mental states. On the left side of the concentric circles, emotions that are generally generated from reactions occurring in the brain are located. On the right side of the concentric circles, emotions that are generally induced by situational judgment are located. Above and below the concentric circles, emotions that are generally generated from reactions occurring in the brain and induced by situational judgment are located. In addition, the emotion of "pleasure" is located on the upper side of the concentric circles, and the emotion of "displeasure" is located on the lower side. Thus, in the emotion map 400, multiple emotions are mapped based on the structure in which emotions arise, and emotions that are likely to occur simultaneously are mapped close together.
[0766] These emotions are distributed at the 3 o'clock position on the Emotion Map 400, and usually fluctuate between feelings of security and anxiety. In the right half of the Emotion Map 400, situational awareness takes precedence over internal feelings, resulting in a calm impression.
[0767] The inside of the Emotion Map 400 represents inner thoughts, while the outside represents actions. Therefore, the further you go from the outside of the Emotion Map 400, the more visible (expressed in actions) your emotions become.
[0768] Here, human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. Similarly, in robots, cars, motorcycles, etc., emotions can be created based on various balances, such as posture and battery level. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. The emotion map can be generated, for example, based on Dr. Mitsuyoshi's emotion map (Research on a system for analyzing brain physiological signals of speech emotion recognition and emotion, Tokushima University, doctoral dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map contains emotions belonging to a region called "response," where sensation is dominant. The right half of the emotion map contains emotions belonging to a region called "situation," where situational awareness is dominant.
[0769] The emotion map defines two emotions that promote learning. One is the emotion around the middle of the negative "repentance" and "reflection" on the situation side. In other words, it is when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is the emotion around the positive "desire" on the reaction side. In other words, it is when the robot has positive feelings such as "I want more" or "I want to know more."
[0770] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values representing each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple training data sets, which are combinations of user input and emotion values representing each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions located close together have similar values, as shown in the emotion map 900 in Figure 10. Figure 10 shows an example where multiple emotions such as "reassured," "calm," and "confident" have similar emotion values.
[0771] The above description primarily focuses on the functions of the data processing device 12 in relation to this disclosure. However, the system related to this disclosure is not necessarily implemented on a server. The system related to this disclosure may be implemented as a general information processing system. This disclosure may be implemented, for example, as a software program that runs on a personal computer or as an application that runs on a smartphone. The method related to this disclosure may be provided to users in SaaS (Software as a Service) format.
[0772] In the above embodiment, an example was given in which a specific process is performed by a single computer 22. However, the technology of this disclosure is not limited thereto, and a distributed processing of the specific process may be performed by multiple computers, including computer 22. For example, a data generation model 58 may be provided in an external device of the data processing device 12, and the external device may generate data according to the input data.
[0773] In the above embodiment, an example was given in which the specific processing program 56 is stored in the storage 32, but the technology of this disclosure is not limited thereto. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-temporary storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-temporary storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes specific processing according to the specific processing program 56.
[0774] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.
[0775] Furthermore, it is not necessary to store the entirety of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store the entirety of the specific processing program 56 in the storage 32; it is acceptable to store only a portion of the specific processing program 56.
[0776] The following types of processors can be used as hardware resources to perform specific processing. Examples of processors include a CPU, a general-purpose processor that functions as a hardware resource to perform specific processing by executing software, i.e., a program. Other examples of processors include dedicated electrical circuits, such as FPGAs (Field-Programmable Gate Arrays), PLDs (Programmable Logic Devices), or ASICs (Application Specific Integrated Circuits), which have circuit configurations specifically designed to perform specific processing. All of these processors have built-in or connected memory, and all of them perform specific processing by using memory.
[0777] The hardware resource that performs a specific process may consist of one of these various processors, or it may consist of a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Alternatively, the hardware resource that performs a specific process may consist of a single processor.
[0778] Examples of configurations using a single processor include, firstly, a configuration in which one or more CPUs and software are combined to form a single processor, and this processor functions as a hardware resource that performs a specific process. Secondly, there is a configuration using a processor that realizes the functions of the entire system, including multiple hardware resources that perform a specific process, on a single IC chip, as exemplified by SoCs (System-on-a-chip). In this way, a specific process is realized using one or more of the above types of processors as hardware resources.
[0779] Furthermore, the hardware structure of these various processors can more specifically utilize electrical circuits that combine circuit elements such as semiconductor devices. Also, the specific processing described above is merely an example. Therefore, it goes without saying that unnecessary steps can be deleted, new steps added, or the processing order rearranged, as long as it does not deviate from the main purpose.
[0780] The descriptions and illustrations presented above are detailed explanations of the technical aspects of this disclosure and are merely examples of the technical aspects. For example, the above descriptions of the structure, function, operation, and effect are examples of the structure, function, operation, and effect of the technical aspects of this disclosure. Therefore, it goes without saying that you may delete unnecessary parts, add new elements, or replace elements in the descriptions and illustrations presented above, as long as you do not deviate from the essence of the technical aspects of this disclosure. Furthermore, in order to avoid confusion and facilitate understanding of the technical aspects of this disclosure, explanations of common technical knowledge and the like that do not require special explanation to enable the implementation of the technical aspects of this disclosure have been omitted from the descriptions and illustrations presented above.
[0781] All documents, patent applications, and technical standards described herein are incorporated by reference to the same extent as if each individual document, patent application, and technical standard were specifically and individually noted as being incorporated by reference.
[0782] The following is further disclosed regarding the embodiments described above.
[0783] (Claim 1)
[0784] A means of analyzing emails using a computer system,
[0785] A means for automatically identifying suspicious emails based on the results of the analysis of the aforementioned emails,
[0786] A means for automatically quarantining or deleting emails that have been identified as suspicious,
[0787] Means for notifying the user of the results of the aforementioned determination and isolation or deletion,
[0788] The system provides a means for improving the judgment algorithm by learning from the feedback it receives,
[0789] A system that includes this.
[0790] (Claim 2)
[0791] The system according to claim 1, characterized in that, in analyzing the aforementioned emails, it includes means for learning patterns of the content and characteristics of emails using a generative AI model.
[0792] (Claim 3)
[0793] The system according to claim 1, characterized in that, in the suspicious email determination, it includes means for assigning a score and determining that an email is suspicious if the score exceeds a predetermined threshold.
[0794] "Example 1"
[0795] (Claim 1)
[0796] A means of operating on a terminal and retrieving new emails from a mail server,
[0797] A means of analyzing the content of acquired emails using a generation AI model on a server,
[0798] A means of assigning a suspiciousness score to each email based on the analysis results,
[0799] A means to automatically quarantine or delete suspicious emails based on their suspicion score,
[0800] Means for notifying the user of the judgment result and the result of the isolation or deletion process,
[0801] A means of sending user feedback to a server and improving the judgment algorithm based on the generated AI model,
[0802] An information processing system that includes this.
[0803] (Claim 2)
[0804] The information processing system according to claim 1, characterized in that it includes a means for using a generative AI model to learn patterns of email characteristics when analyzing emails.
[0805] (Claim 3)
[0806] The information processing system according to claim 1, characterized by comprising means for identifying an email as suspicious based on a suspiciousness score, if the score exceeds a set threshold value.
[0807] "Application Example 1"
[0808] (Claim 1)
[0809] A means for analyzing communication data using an information processing device,
[0810] A means for automatically identifying suspicious communications based on the analysis results of the aforementioned communication data,
[0811] A means for automatically isolating or deleting data that has been determined to be suspicious communication,
[0812] Means for notifying the user of the results of the aforementioned determination and isolation or deletion,
[0813] The system provides a means for improving the judgment algorithm by learning from the feedback it receives,
[0814] A means of providing real-time scanning functionality through integration with mobile terminals,
[0815] A system that includes this.
[0816] (Claim 2)
[0817] The system according to claim 1, characterized in that, in the analysis of the aforementioned communication data, it includes means for learning the communication content and features as patterns using a generative AI model.
[0818] (Claim 3)
[0819] The system according to claim 1, characterized in that, in the suspicious communication determination, it includes means for assigning an evaluation value and determining that a communication is suspicious if the evaluation value exceeds a predetermined threshold.
[0820] "Example 2 of combining an emotion engine"
[0821] (Claim 1)
[0822] A means of analyzing messages using a computer system,
[0823] A means for automatically identifying suspicious messages based on the results of analyzing the aforementioned messages,
[0824] A means for automatically quarantining or deleting emails that have been identified as suspicious messages,
[0825] Means for notifying the user of the results of the aforementioned determination and isolation or deletion,
[0826] The system provides a means for improving the judgment algorithm by learning from the feedback it receives,
[0827] A means including an on-terminal analysis device for analyzing the emotional state of the user,
[0828] A means for determining the final processing of a message based on the analysis results of the message and the user's emotional state,
[0829] A system that includes this.
[0830] (Claim 2)
[0831] The system according to claim 1, characterized in that, in analyzing the message, it includes means for learning the content and features of the message using a generative AI model.
[0832] (Claim 3)
[0833] The system according to claim 1, characterized in that, in determining a suspicious message, it includes means for scoring the risk and determining that a message is suspicious if the score exceeds a predetermined threshold.
[0834] "Application example 2 when combining with an emotional engine"
[0835] (Claim 1)
[0836] A means of analyzing information using a computer system,
[0837] A means for automatically determining suspicious information based on the results of the analysis of the aforementioned information,
[0838] A means for automatically isolating or deleting information that has been determined to be suspicious,
[0839] Means for notifying the user of the results of the aforementioned determination and isolation or deletion,
[0840] The system provides a means for improving the judgment algorithm by learning from the feedback it receives,
[0841] A means for analyzing the user's psychological state using an emotion analysis engine and considering it in the final judgment in the suspicious information determination,
[0842] A means of implementing additional measures against the aforementioned suspicious information based on the user's psychological state,
[0843] A system that includes this.
[0844] (Claim 2)
[0845] The system according to claim 1, characterized in that, in the analysis of the aforementioned information, it includes means for learning the content and features of the information by pattern learning using a generative AI model.
[0846] (Claim 3)
[0847] The system according to claim 1, characterized in that, in the suspicious information determination, it includes means for assigning a score and determining that the information is suspicious if the score exceeds a predetermined threshold. [Explanation of Symbols]
[0848] 10, 210, 310, 410 Data Processing Systems 12 Data Processing Devices 14 Smart Devices 214 Smart Glasses 314 Headset-type terminal 414 Robots< / url:> < / url:> < / url:> < / url:>
Claims
1. A means for analyzing communication data using an information processing device, A means for automatically identifying suspicious communications based on the analysis results of the aforementioned communication data, A means for automatically isolating or deleting data that has been determined to be suspicious communication, Means for notifying the user of the results of the aforementioned determination and isolation or deletion, The system provides a means for improving the judgment algorithm by learning from the feedback it receives, A means of providing real-time scanning functionality through integration with mobile terminals, A system that includes this.
2. The system according to claim 1, characterized in that, in the analysis of the aforementioned communication data, it includes means for learning the communication content and features as patterns using a generative AI model.
3. The system according to claim 1, characterized in that, in the suspicious communication determination, it includes means for assigning an evaluation value and determining that a communication is suspicious if the evaluation value exceeds a predetermined threshold.