Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

19 results about "Attack strategy" patented technology

Failure analysis method and related device, electronic device and storage medium

The application discloses a failure analysis method and related device, electronic equipment and storage medium, wherein the failure analysis method comprises: detecting based on the description document of the target agent to obtain the design elements of the target agent; analyzing based on the failure mode knowledge base and each design element to determine the first element suspected of existing failure risk and the first risk degree of the first element in each design element; selecting the first element as the second element based on the first risk degree of each first element; generating the test session and the adjudication rule of the second element based on the attack strategy knowledge base and the second element; determining the test reply of the second element based on the adjudication rule of the second element to obtain the second risk degree of the second element. The above scheme can identify the failure risk of the agent in advance before the agent goes online, and quantize the failure risk.
Owner:IFLYTEK CO LTD

Network game strategy generation method based on node average path constraint

The application discloses a network game strategy generation method based on node average path constraint, and the method comprises the following steps: acquiring the topological structure of a network, determining the strategy set of an attack party and a defense party, and constructing a basic model of the network game; calculating the shortest path between nodes in each attack strategy and each defense strategy, taking the average value, and obtaining the average path corresponding to each attack strategy and each defense strategy; setting a constraint function based on the average path, so that the selection probability of each attack strategy and each defense strategy is less than the corresponding function value, and obtaining the strategy constraint set of the attack party and the strategy constraint set of the defense party; representing the network performance by a maximum connected piece scale index, calculating the income of the attack party and the defense party under each strategy profile, and obtaining the income matrix of the network game model; and replacing the basic model of the network game with a linear programming problem for solving, and obtaining the mixed strategy Nash equilibrium solution of the attack party and the defense party.
Owner:NAT UNIV OF DEFENSE TECH

Large language model self-adaptive security protection method and system, and storage medium

PendingCN122457379ALinguistic modelAlgorithm
The application provides a large language model adaptive security protection method and system, and a storage medium, the method breaks the hysteresis of the traditional defense strategy by constructing a three-agent collaborative architecture of an attack strategy generator, a dynamic defense device and a defense and attack environment evaluator, combining a double-layer optimization and a dynamic evolution mechanism, driving a two-way iteration relying on attack and defense utility quantitative scores, and synchronously evolving the defense capability and the attack evolution; the method constructs a double-layer defense capability for coping with the current situation and predicting the future by real-time adaptation of the defense parameters to the current attack and pre-judgment of the new attack by the defense parameter, improves the generalization to unknown attacks; the method strengthens the learning and identification of high uncertainty attacks by combining meta-learning attack evolution and threat entropy weighted loss, reduces the bypass probability of new attacks; the method balances the security and usability of the large language model by using a dynamic threshold judgment, realizes adaptive and highly reliable security protection in an open scene, and has better generalization.
Owner:SHENZHEN SHENNONG INFORMATION TECHNOLOGY CO LTD

A network intrusion detection model end-to-end adversarial training defense method and device

This invention relates to the field of network security technology, and more particularly to a method and apparatus for adversarial training and defense of a network intrusion detection model. The method includes: dynamically outputting attack strategies based on traffic feature vectors and current strategy parameters using an adversarial strategy generator; imposing restrictions on perturbations in the problem space through adversarial domain constraints to ensure that the generated adversarial samples conform to network protocol specifications and feature logic consistency requirements; and forming a dynamic game mechanism by alternately executing adversarial training and strategy parameter optimization between the intrusion detection model and the adversarial strategy generator. This allows the model to gradually improve its defense capabilities against mixed threats in the feature space and problem space as it continuously adapts to increasingly complex attack patterns, ultimately achieving a synergistic improvement in the robustness and generalization of the intrusion detection model.
Owner:CHINA STATE SHIPBUILDING CORP LTD RESEARCH INSTITUTE 719

Network security target field-based virtual simulation and security evaluation method and system

The application discloses a network security target-based virtual simulation and security evaluation method and system. First, a network asset knowledge graph describing a virtual target environment is constructed through information collection. Second, intelligent attack simulation is performed on the knowledge graph based on an attack strategy syntax rule library using a Monte Carlo tree search (MCTS) algorithm to discover nonlinear and multi-stage attack paths. Third, a Bayesian attack graph (BAG) is constructed based on the knowledge graph to probabilistically and systematically quantitatively evaluate the security risks of asset nodes in the network through Bayesian inference. Finally, the attack paths and quantitative risk values are integrated to generate a comprehensive evaluation report containing visualized paths, risk rankings and reinforcement suggestions. The application solves the problems of insufficient realism of existing target simulation, one-sided security evaluation and lack of predictability by combining strategic simulation of MCTS and global quantitative analysis of BAG.
Owner:BEIJING BO YI WANG XUN SCI & TECH CO LTD

Computer Network Intrusion Detection and Prevention Methods Based on Anomaly Data Analysis

This application discloses a computer network intrusion detection and defense method based on anomaly data analysis, relating to the field of computer network technology. The method includes: collecting a multi-dimensional dataset; extracting the correlations between anomaly data to form an anomaly correlation rule set; fusing multi-source features to form an anomaly feature set; establishing an intelligent agent model; the intelligent agent executing an attack task; inputting the anomaly data set into the intrusion detection model to obtain the first-stage detection result; comparing and analyzing the first-stage detection result with the first-stage simulated attack result to obtain feedback information; optimizing the second-stage attack strategy and executing the optimized second-stage attack strategy to obtain the second-stage detection result; extracting anomaly features to form a final anomaly feature set; generating repair instructions based on the final anomaly feature set and executing the repair instructions to repair the computer network. This application's method overcomes the limitations of single attack simulation and deepens the two-stage attack optimization, improving detection accuracy.
Owner:XIANYANG VOCATIONAL TECHN COLLEGE

An automated safety test scheme generation method and system for intelligent networked vehicles and a medium

PendingCN122284579ATest scriptAttack
This invention relates to a method, system, and medium for generating automated security testing schemes for intelligent connected vehicles. The method includes: constructing an attack tactics knowledge graph; collecting and parsing asset configuration information and network topology information of the target vehicle system; generating attack strategies based on a multi-agent collaborative mechanism; establishing a semantic mapping library between attack techniques and attack tools, and generating tool execution parameter configurations according to the configuration parameters of the target vehicle system; generating a structured attack test scheme document and converting it into an executable attack test script sequence; executing the attack test script sequence, capturing test result data during execution, and updating the confidence scores of attack technique nodes and the effectiveness scores of attack tool nodes in the attack tactics knowledge graph based on the test result data. This invention improves the automation, intelligence, and executability of generating attack test schemes for intelligent connected vehicles.
Owner:HARBIN INSTITUTE OF TECHNOLOGY (SHENZHEN) (INSTITUTE OF SCIENCE AND TECHNOLOGY INNOVATION HARBIN INSTITUTE OF TECHNOLOGY SHENZHEN)

A Method for Generating Optimal Attack Strategies for Wind Farms Considering DoS and FDIA

This application relates to a method for generating optimal attack strategies for wind farms considering DoS and FDIA attacks. The method includes: first, establishing an optimized control model and an optimal scheduling model for normal operation of the wind turbine; then, constructing an FDIA control command tampering attack model, a DoS attack model, and an FDIA wind speed measurement tampering attack model, respectively; and finally, combining wind turbine operation constraints and attack resource constraints to solve for the attack strategy that maximizes the total power output loss of the wind farm and complete a quantitative assessment of the attack impact. This invention integrates DoS and FDIA attacks into the physical operation constraint framework of the wind turbine, generating an implementable optimal attack strategy with the goal of maximizing power output loss, achieving unified quantitative assessment of multiple attack scenarios, and providing support for the network security risk analysis and protection of wind farms.
Owner:STATE GRID ANHUI ELECTRIC POWER CO LTD ELECTRIC POWER SCI RES INST

Big language model-based bas system attack load automatic generation method and system

PendingCN122419839ALinguistic modelSafety knowledge
The application discloses a BAS system attack load automatic generation method and system based on a large language model, and belongs to the technical field of network security. In order to solve the problems that attack load generation depends on manual work, has poor compliance and is difficult to break through dynamic defense, the BAS attack instruction or environment fingerprint is received and modeled as a decision process; search enhancement technology is used to fuse safety knowledge to form prompt information; an initial load is generated by a strategy network under the constraint of a predefined syntax rule; a reward model is trained based on target environment feedback to evaluate bypassing capability; and the strategy network is updated by using a reinforcement learning mechanism and knowledge dynamic backfilling is realized. The application can significantly improve the simulation degree and bypass success rate of the BAS system, realize automatic iteration of attack strategies and mining of new vulnerability variants.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

A method for poisoning attack on a local differential privacy protocol of a graph neural network

PendingCN122457377AFeature DimensionAttack
The application discloses a kind of methods of poisoning attack to local differential privacy protocol of graph neural network, comprising: calculating node influence based on degree centrality, identify high-influence node as attack target;Malicious edge injection strategy is used to establish the connection between false node and target node or its neighbor;Based on local differential privacy protocol constraint and statistical prior, identify the vulnerable feature dimension with the maximum statistical deviation potential, generate malicious features deviating from the real distribution, and associate false node to the highest frequency category label in the graph;The constructed false node feature, label and malicious edge are injected into the original graph.The application also introduces defense countermeasures based on node homogeneity detection, Jaccard similarity detection and high-influence node protection, by verifying the evasion ability of the attack strategy to the above defense measures, the security of graph learning protocol under local differential privacy is evaluated from all directions, which provides technical basis for designing high-robustness privacy protection graph learning protocol.
Owner:ZHEJIANG UNIV

Method and system for modeling genetic attacks on power systems based on autonomous evolutionary game

The application discloses a power system gene attack modeling method and system based on autonomous evolution game, relates to the technical field of power system attack and defense simulation, and comprises the following steps: performing evolution processing on a plurality of first power attack genes by using a power attack gene regulation coding model, obtaining second power attack genes corresponding to each first power attack gene and performing genetic evolution, simulating a dynamic confrontation process between an attack behavior and a defense mechanism based on an immune response model by using all third-generation power attack genes; constructing an attack and defense game optimization objective function, taking the attack and defense game optimization objective function as an optimization criterion, and making attack strategies and defense strategies interactively evolve through autonomous evolution game until the attack and defense game converges to Nash equilibrium. The first power attack genes are subjected to evolution processing by using the power attack gene regulation coding model, so that the attack logic can be self-organized and cooperatively evolved like biological genes.
Owner:NORTHEAST DIANLI UNIVERSITY

Image processing method and device based on attack test, equipment and storage medium

The application provides an image processing method and device based on attack testing, equipment and a storage medium. The method comprises: obtaining an image to be identified to be attacked; according to an attack intention, selecting a first object list of objects expected to be hidden in the image to be identified and a second object list of new objects expected to be generated in the image to be identified; and according to a target detector, the first object list and the second object list, iteratively processing the image to be identified through a preset attention attack strategy to obtain an attack image used to replace the image to be identified. In this way, the first object list can be used to hide the corresponding objects in the image to be identified, the second object list can be used to generate new objects in the image to be identified, various targeted objects can be flexibly simulated to generate attack pictures, and the flexibility and efficiency of attack testing can be improved.
Owner:CHONGQING CHANGAN TECH CO LTD

A dynamic network architecture maintenance system and method under adversarial conditions

A dynamic network architecture maintenance system and method under adversarial conditions includes an attack prediction module, a decision update module, and a pre-deployment decision module. The attack prediction module predicts the sequence of important nodes that the adversary will attack in the next moment. The decision update module updates the adversary's attack strategy and feeds the results back to the attack prediction module. The pre-deployment decision module makes deployment decisions based on the prediction results of the network architecture maintainer. This invention uses a decision architecture that predicts the nodes of the SoS (Socially Targeted Systems) to be attacked based on the changes in the system's topology between time i-1 and time i, and makes advance judgments. According to the attack strategy, it outputs the importance sequence of communication nodes participating in the SoS in the next moment. The communication nodes in this sequence are highly likely to become the targets of the attack in the next moment. Based on this sequence, the SoS can make pre-deployment decisions, enabling the communication nodes in this sequence to maneuver in advance or deploy redundant silent communication nodes nearby.
Owner:XIDIAN UNIV +1

An adaptive adversarial attack method for cross-modal pedestrian search in an open environment

PendingCN122290170AAlgorithmEngineering
This invention specifically relates to an adaptive adversarial attack method for cross-modal pedestrian search in open environments, belonging to the technical fields of computer vision and cross-modal retrieval. It employs a white-box adversarial attack strategy, adding only minor perturbations to the image. The method first designs a multi-granularity gradient collaboration module to construct attack targets at the sample and data distribution levels, targeting both semantic and modal attacks. Backpropagation is used to obtain gradient maps and collaboratively guide perturbation calculation. Next, a quality-aware adaptive pixel-level improvement module is designed to perform quality-aware adaptive fusion of the gradient maps, calculating a pixel-level step matrix to concentrate the perturbation in key image regions. Finally, the perturbation is calculated based on the fused gradient map and step matrix, iteratively updating the adversarial image. This invention is the first to conduct adversarial attacks on cross-modal pedestrian search in natural language, achieving significant performance improvements compared to traditional single-modal pedestrian search and cross-modal retrieval attack methods.
Owner:NORTHWESTERN POLYTECHNICAL UNIV

A model vulnerability detection system and method for aerospace field

PendingCN122286788AData setLinguistic model
This invention relates to the field of model vulnerability detection technology, and specifically to a model vulnerability detection system and method for the aerospace field. The system includes: a large model decision layer configured to: parse the aerospace model under test and its dataset to obtain features; generate structured input prompts based on the features; input the prompts into an external large language model to obtain an attack strategy; execution steps: a scheduling algorithm support layer executes the attack strategy and collects results; based on the results and vulnerability location information, combined with historical strategy generation criteria, generates new prompts and calls the external large language model again to generate an optimized attack strategy; based on the optimized attack strategy, returns to the execution steps for iteration until the optimization termination condition is met; a vulnerability detection layer configured to generate and output vulnerability location information to the large model decision layer; and a bottom support layer configured to generate and output a vulnerability detection report, thereby meeting the high-coverage, adaptive, and low-dependency automated testing requirements of the aerospace field.
Owner:BEIHANG UNIV

A method and system for reverse cryptanalysis attacks

This invention belongs to the field of cryptanalysis technology and provides a cryptanalysis reverse attack method and system. It determines the classification of activation functions in a neural network model, including piecewise linear activation functions and piecewise nonlinear activation functions. For piecewise linear activation functions, it performs reverse attacks by achieving signature recovery with polynomial time complexity and symbol recovery with a certain time complexity on the original output and hard label settings, respectively. It also performs reverse attacks by achieving symbol recovery with polynomial time complexity on the original output of a contracted network. For piecewise nonlinear activation functions, it performs reverse attacks by achieving signature recovery with polynomial time complexity and symbol recovery with polynomial time complexity on the original output settings. This invention can recover an equivalent neural network with the same output characteristics as the original neural network through attack strategies.
Owner:SHANDONG UNIV

A false data injection attack method for a multi-elastic-joint robot system

The application provides a false data injection attack method for a multi-elastic joint robot system, and belongs to the technical field of multi-agent network attacks based on computer data processing; firstly, a nonlinear dynamic mathematical model of the multi-elastic joint robot is constructed, and the model is converted into a high-order full-drive pseudo-linear multi-robot system dynamic model based on a full-drive system theory; then, a distributed consistency controller containing a linearization term and a neighbor error related term is designed, a closed-loop global dynamics is established in combination with model equivalent conversion, and a state analytical solution is derived. An attack strategy of false data injection is designed, a system dynamic model after being attacked is constructed, a closed-loop terminal state error with or without attack is taken as an objective function, an attack optimization problem is converted into a combination optimization problem, a greedy algorithm is designed by using a submodular optimization theory, a suboptimal solution in a polynomial time is obtained, and the suboptimal solution is used as an optimal scheme of the false data injection attack of the system. The application improves the applicability of a complex nonlinear multi-agent system and reduces the calculation complexity.
Owner:OCEAN UNIV OF CHINA

A method, apparatus, device, and medium for information processing in games.

This application discloses a method, apparatus, device, and medium for information processing in games, applied in the field of game technology. Specifically, it involves responding to a second virtual character entering the attack range of a first virtual character, obtaining the first attack move currently to be executed by the first virtual character, determining the attack trajectory and attack direction of the first attack move, and displaying at least the attack trajectory and attack direction prompts on the graphical user interface. This allows players to know the attack move information of the first virtual character before attacking the second virtual character. This not only assists players in getting started and lowers the learning threshold, but also allows players to better understand the attack characteristics of the first attack move, enabling them to adjust their attack strategy in a timely manner according to the actual game situation, thereby improving the player's gaming experience.
Owner:NETEASE (HANGZHOU) NETWORK CO LTD

A dual-source driven self-evolution red team confrontation test method based on a large model agent

PendingCN122286771ALinguistic modelAttack
This application provides a dual-source driven self-evolving red team adversarial testing method based on a large-model intelligent agent. The method comprises: the agent periodically generating an initial attack strategy set using an external knowledge base and an internal historical strategy base; the agent performing intelligent decision-making and strategy filtering on the initial attack strategy set based on persistent memory to obtain a queue of strategies to be executed; the agent dynamically generating an executable attack script with complex attack logic based on the queue of strategies to be executed by calling a large language model; the agent running the executable attack script in an isolated sandbox environment, the executable attack script receiving an original set of harmful questions as input and outputting the target model's response content and metadata; and the agent performing security assessment and quantitative scoring on the target model's response content and metadata using an evaluation large model with semantic understanding and security judgment capabilities to obtain multiple indicators of the attack strategy.
Owner:GUANGZHOU UNIVERSITY