Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

97 results about "Injection attacks" patented technology

Injection attacks refer to a broad class of attack vectors that allow an attacker to supply untrusted input to a program, which gets processed by an interpreter as part of a command or query which alters the course of execution of that program. Injection attacks are amongst the oldest and most dangerous web application attacks.

Model context protocol injection attack protection method and device based on dynamic semantic analysis, computer equipment and storage medium

The embodiment of the invention relates to the field of artificial intelligence, and provides a model context protocol injection attack protection method and device based on dynamic semantic analysis, computer equipment and a storage medium, and the method comprises the steps: obtaining request data corresponding to a call request initiated by a user through a model context protocol, carrying out the preprocessing of the request data, obtaining the preprocessed request data; performing semantic vectorization on request text and context historical information in the request data through a lightweight bidirectional encoder representation model to output an initial risk score; correcting the initial risk score according to context historical information carried in a model context protocol to obtain a corrected final risk score; and performing hierarchical defense decision according to the final risk score, and determining risk grading information corresponding to each piece of request data so as to execute a protection action corresponding to each piece of risk grading information. By adopting the method, the accuracy of identifying the protocol injection attack can be improved.
Owner:E SURFING VISION TECHNOLOGY CO LTD

Multi-modal attack identification method fusing BMama and difference to guide trans-attention

PendingCN121333666ABiological modelsSecuring communicationAddress Resolution ProtocolDomain name
The invention discloses a multi-modal attack identification method fusing BMama and difference to guide trans-attention, which comprises the following steps: simulating a false data injection attack, a denial of service attack, an address resolution protocol spoofing attack and a domain name system spoofing attack, collecting physical layer sensor data and network layer flow data, and preprocessing multi-modal data; bMama is constructed to perform dynamic time modeling on multi-modal data, a graph neural network is combined to adversariate a variational auto-encoder, features of a power grid system topology and a communication topology structure are fused, and robustness of potential representation is enhanced through adversarial training; the method comprises the following steps of: guiding feature complementary fusion by using modal difference through a difference guide iteration cross-attention fusion mechanism, improving the capability of distinguishing complex attacks, finally carrying out attack detection and classification on fused modals, and executing end-to-end optimization according to a weighted combination of loss of each part. The method can effectively detect and classify the multi-modal attack in the smart power grid, and enhances the safety and reliability of a complex system.
Owner:SOUTHEAST UNIV

Prompt word injection attack detection method and device for large language model, equipment, storage medium and program product

The invention relates to the technical field of artificial intelligence and information security, provides a cue word injection attack detection method and device of a large language model, equipment, a storage medium and a program product, and has a better cue word injection attack detection effect. The method comprises the following steps: generating cue words from preset test corpora, and inputting the cue words into a first large language model; the test corpus generation cue word is used for indicating the first large language model to generate a cue word injection test corpus in combination with multiple cue word injection modes for each cue word injection attack type; the cue word injection test corpus is input into the to-be-tested large language model, and an input and output data pair is obtained according to response content output by the to-be-tested large language model; and calling the second large language model to detect whether the to-be-detected large language model is successfully attacked according to the input and output data to obtain a target detection result aiming at the cue word injection attack.
Owner:GUANGZHOU QUWAN NETWORK TECH CO LTD

Scene-adaptive white-box prompt injection attack system

The invention relates to a scene self-adaptive white-box prompt injection attack system. The system comprises a self-adaptive context prompt generation module, an enhanced GCG algorithm-based confrontation suffix generation module and a simulator-based intelligent agent test module with a body. The adaptive context prompt generation module constructs specific prompt templates for different scenes, and automatically identifies and encodes unique semantic features of different application scenes. And the adversarial suffix generation module based on the enhanced GCG algorithm calculates the coordinate gradient of each token position, provides direction guidance for subsequent token replacement based on a double-component loss function, and adopts a weighted combination loss function to realize system optimization. The simulator-based intelligent agent test module carries out semantic understanding and intention recognition through a target large language model, converts a natural language into a control instruction, recognizes different types of commands, and maps the analyzed commands to a specific API for calling.
Owner:GUOXIN HIGHLAND BUSINESS CREDIT DATA CO LTD BEIJING BRANCH

Elastic control method of high-order nonlinear system under pulse false information injection attack

The invention relates to an elastic control method of a high-order nonlinear system under pulse false information injection attack. The method comprises the following steps: acquiring a system output signal and a control input signal of a current control period, and a state estimation value vector and a fuzzy weight vector estimation value of a previous control period; inputting a system output signal and a control input signal of a current control period, and a state estimation value vector and a fuzzy weight vector estimation value of a previous control period into a nonlinear state observer based on a fuzzy logic system to obtain a state estimation value vector of the current control period; the controller based on the fuzzy logic system carries out backstepping recursion through the state estimation value vector of the current control period and the fuzzy weight vector estimation value of the previous control period to obtain an elastic control input signal; and obtaining a fuzzy weight vector estimator of the current control period through an adaptive law based on the state estimation value vector of the current control period. By adopting the method, state jump and performance damage of attacks can be resisted.
Owner:SHENGSHI CONTAINER MANAGEMENT SHANGHAI

Active defense security control method for hidden false data injection attack

The invention discloses an active defense security control method for a hidden false data injection attack, and relates to the field of information physical system security control, in particular to an active defense security control method. The invention aims to solve the problem that the existing detection method can encrypt a transmitted signal, but is limited to detection of a specific type of attack, or dynamic coupling changing the configuration of a control system can increase the burden of a state estimator, and even causes the performance reduction of the system. The method comprises the following steps of: 1, acquiring output feedback gains of the information physical system under different switching signals; and 2, based on the output feedback control gain obtained in the step 1, performing active attack detection and positioning on the FDI attack, and when the attack is detected and positioned, performing active switching by a controller of the information physical system so as to construct an active security controller aiming at the FDI attack.
Owner:HARBIN INST OF TECH

Content security protection method and device based on semantic consistency

The invention belongs to the technical field of computer information security, particularly discloses a content security protection method and device based on semantic consistency, and aims to solve the problem that high-level cue word injection attacks are difficult to effectively recognize in the prior art. Carrying out real-time interception on dominant illegal texts through a content filtering module; quantizing generation rationality differences of prompt words between attack and normal language models by using a word vector confusion degree calculation module; evaluating the logic coherence of the sentence structure of the prompt word through a statement semantic consistency judgment module; integrating the multi-dimensional feature data and carrying out risk classification by adopting a machine learning algorithm; and routing the suspected attack request to a value fine tuning model for processing according to a judgment result. According to the technical scheme, high-precision recognition and response to complex cue word injection attacks are achieved, and the content safety protection capacity and compliance guarantee level of a large model in an interaction scene are remarkably improved.
Owner:ASPIRE TECH (SHENZHEN) LTD

Node injection attack method based on adaptive target selection

The invention relates to a node injection attack method based on adaptive target selection, and the method comprises the following steps: S1, target node selection: calculating a comprehensive score of a node based on uncertainty and topology centrality, and dynamically selecting a target node set of a current attack round; s2, feature generation: using an adaptive feature generator to generate node features which are similar to target node distribution and have strong aggressiveness; and S3, disturbance edge construction: selecting an optimal disturbance edge connection mode for the injection node according to strategy network output in reinforcement learning. According to the method, the attack flexibility can be improved through dynamic target selection, the attack performance can be remarkably enhanced through combination of disturbance characteristics and structures, and the method has good concealment, expandability and generalization ability. The method is widely applied to security evaluation and defense research fields related to graph neural networks, such as social network analysis, recommendation systems, knowledge graphs and the like.
Owner:BEIJING JIAOTONG UNIV

Modeling of adversarial artificial intelligence in blind false data injection against AC state estimation in smart grid security, safety and reliability

Computer-implemented methods and systems for training an adversarial neural network to simulate a stealthy blind false data injection attack on a cyber physical system are provided. Supervised learning is used to generate an initial attack vector, by an adversarial attack generation model, based on inferred grid topology and historical measurements. A final attack vector is generated, by an adversarial verification model, based on a filtered subset of the initial attack vector utilizing a substitute bad data detection threshold, wherein the final attack vector enables creation of a counter measure.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Vulnerability analysis method of multi-time scale micro-grid under FDI attack

The invention discloses a vulnerability analysis method of a multi-time-scale micro-grid under FDI attack, which comprises the following steps: decomposing system dynamics of a direct current micro-grid into a fast boundary layer subsystem and a slow order reduction subsystem by using a singular perturbation theory, respectively deducing stability conditions of each subsystem under a false data injection attack condition, and analyzing the vulnerability of the multi-time-scale micro-grid under the false data injection attack condition; and the input state stability of the low-speed subsystem under the FDI attack is proved. The worst deviation of the system state under the attack condition is calculated by constructing a zootope reachable set analysis framework, and the maximum allowable attack amplitude capable of ensuring safe operation of the system is quantified. According to the method, through numerical simulation and hardware experiment verification, a novel attack surface introduced by multi-time scale characteristics can be effectively revealed, and theoretical support and guidance are provided for safe and stable control of the DC micro-grid.
Owner:ZHEJIANG UNIV

Large language model method and system for preventing false information injection

PendingCN122310531ALinguistic modelUser input
This invention discloses a method and system for preventing false information injection using a large language model. The method involves: dynamically evaluating the credibility of user input to obtain an input credibility score; calculating a user reputation score based on historical user behavior data and mapping it to a generation permission level; retrieving authoritative knowledge fragments from a closed-loop trusted knowledge graph for the input and constructing generation constraint instructions based on the permission level; calling the large language model to generate response content according to the permission level and constraint instructions; performing consistency verification on the response content and then outputting it; finally, generating a lineage log containing end-to-end interaction data and storing it on the blockchain. This invention, by integrating input credibility assessment, user reputation coupling, knowledge tracing constraints, and end-to-end auditing, achieves pre-emptive identification, process blocking, and post-event traceability of false information, effectively solving the problem of the lack of systematic defense against false information injection attacks in existing technologies, and significantly improving the content security and compliance of generative artificial intelligence applications in key areas.
Owner:FUJIAN MEIYA GUOYUN INTELLIGENT EQUIP CO LTD

Low-overhead moving target defense method and device for false data injection attack

The invention relates to a low-overhead moving target defense method and device for false data injection attacks, and the method comprises the steps: constructing a topological structure of a power grid bus and branches based on actual intelligent power grid data, and associating the branches with an initial admittance value; establishing an initial measurement matrix based on the initial admittance value and the topological structure of the power grid bus and the branches, and constructing a moving target defense strategy based on the initial measurement matrix; based on an invalid branch identification criterion and a topological structure of a power grid bus and a branch, determining an invalid branch in the power grid; based on invalid branches and a greedy selection mechanism, traversing the bus to screen valid branches, and obtaining a modified branch set; and changing admittance values of branches in the branch set based on a moving target defense strategy, changing a measurement matrix, and realizing low-overhead moving target defense. Compared with the prior art, on the premise that the high detection probability is maintained, the number of branches needing to modify admittance and the calculation time are remarkably reduced, and therefore the system defense cost is reduced.
Owner:SHANGHAI UNIV

Black box graph injection attack method and device based on thermonuclear

The invention relates to a black box graph injection attack method and device based on a thermonuclear, and aims to solve the problems that the existing graph injection attack (GIA) is insufficient in imperceptibility, limited in application scene and high in calculation cost, and improve the effectiveness and concealment of a graph neural network (GNNs) attack. The method comprises the following steps: firstly, screening candidate nodes based on classification margins and node degrees, and grouping according to most likely misclassification labels; secondly, sampling high-frequency feature dimensions of similar original nodes to generate injection node features consistent with original image feature distribution; then, adopting a two-stage topology construction strategy: constructing a temporary perturbation graph in the first stage, and screening out an injection edge conforming to the topological characteristics of the original graph through node-level thermonuclear signature (HKS) camouflage constraint and graph-level thermonuclear matrix guidance in the second stage; and finally, generating an imperceptible perturbation graph, and reducing the classification performance of the target GNN model on the premise of not exposing attack behaviors. According to the method, the structure or parameters of the target model do not need to be obtained, the method only depends on the black box query and proxy model, the practicability, imperceptibility and calculation efficiency of attacks are remarkably improved, and the method is suitable for GNNs attack testing in safety key scenes such as the Internet of Things.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Novel power system false data injection attack detection method based on CPO-CNN-SE

The invention discloses a novel power system false data injection attack detection method based on CPO-CNN-SE. The method comprises the following steps: preprocessing a measurement test of a novel power system; performing hyper-parameter optimization by using a crown porcupine optimization algorithm (CPO) to improve the precision of the CNN detection model; meanwhile, in consideration of synchronous increase of the FDIA detection speed, a compression excitation (SE) attention mechanism is introduced, a CNN-SE mixed learning model is formed, and the characterization efficiency of the CNN on FDIA spatial features is enhanced; and finally, carrying out binary classification on the FDIA feature data through a full connection layer, a sigmoid classifier and a binary cross entropy loss function. According to the invention, the FDIA detection precision is improved, and the synchronous improvement of the detection speed is realized.
Owner:HUNAN UNIV OF TECH

A multi-agv event-triggered security path tracking method against false data injection attack

ActiveCN120578205BPathPingAttack
The present application relates to a kind of multi autonomous guide vehicle (AGV) cluster security path tracking control method of resisting false data injection attack, belong to control engineering technical field.For the problem that system stability and safety are threatened by false data injection attack in unreliable network, the present application introduces dynamic event triggering mechanism, only updates control input when necessary, reduces communication burden and energy consumption;Design adaptive state estimator, recover normal system signal from tampered sensor and actuator signal;Adaptive attack compensation mechanism is built, to inhibit the negative influence of attack on system performance.The present application fully considers the application requirement of multi-AGV cluster system in unreliable network environment, by introducing dynamic event triggered control, designing adaptive state estimator and building adaptive attack compensation mechanism, false data injection attack can be effectively resisted, and strong guarantee is provided for multi-AGV cluster system security path tracking control.
Owner:TIANJIN POLYTECHNIC UNIV

Multi-agent system encircling control method triggered by intermittent dynamic event under hybrid attack

A multi-agent system encirclement control method triggered by intermittent dynamic events under hybrid attacks comprises the following steps: S1, constructing a directed communication topology and a Laplacian matrix of a multi-agent system according to an actual task; s2, constructing a multi-agent system model including uncertain disturbance, nonlinear dynamics and false data injection attacks; s3, designing a sliding-mode observer and a double-layer attack detection mechanism for denial of service attack and false data injection attack; s4, designing a fixed time encircling controller of the intermittent dynamic event triggered multi-agent system; s5, the controller designed in the step S4 is used for achieving encircling control within fixed time, and the upper bound of convergence time is obtained; and S6, continuously operating until the encircling control of the multi-agent system is completed. The invention aims to solve the problem of safe, efficient and rapid encircling control when a multi-agent system is subjected to DoS attack, FDI attack and external disturbance at the same time.
Owner:SOUTHEAST UNIV

False data injection attack identification method based on adaptive residual weighted PINN

The invention provides a false data injection attack identification method based on an adaptive residual weighted PINN. The method comprises the following steps: constructing a physical equation describing a system operation state; a self-adaptive residual weighting network is constructed, and the self-adaptive residual weighting network takes sensor measurement data with noise or attack as input and takes the reconstructed system state as output; training the adaptive residual weighting network by using a gradient descent algorithm; mapping sensor data into a system state meeting physical consistency in real time by using an adaptive residual weighting network; and according to a weight coefficient and physical residual information which are calculated in real time by the self-adaptive residual weighting network, identifying a false data injection attack through a dual-criterion mechanism.
Owner:NANJING UNIV OF SCI & TECH

Method for discovering SQL (Structured Query Language) injection attack behavior based on chaotic parting dimension

PendingCN121333647AChaos modelsNon-linear system modelsData packSQL injection
The invention discloses a method for discovering SQL injection attack behaviors based on chaotic parting dimensions, and the method specifically comprises the steps: S1, data collection and feature extraction: obtaining HTTP request data, including SQL query data; extracting the characteristics of the SQL injection attack, wherein the characteristics comprise special characters, SQL keywords and potential malicious structures; s2, calculating a parting dimension; s3, setting a classification dimension threshold value, and if the classification dimension of the selected SQL statement is higher than the threshold value, judging that the SQL statement is an SQL injection attack; and S4, performing anomaly detection and response. The invention mainly relates to the technical field of network security, chaos theory and typing analysis. According to the method, the data is analyzed by using the typing dimension in the chaos theory, the accuracy and efficiency of attack detection are further improved, and nonlinear characteristics and complexity in an attack mode can be revealed, so that the method has advantages in coping with complex attacks.
Owner:XIAMEN ANSCEN NETWORK TECH CO LTD

Systems and methods for safeguarding user-facing artificial intelligence models

PendingUS20260195449A1User deviceComputer compatibility
Aspects of this disclosure relate to systems and methods for preventing injection attacks to large language models (LLMs). Techniques implemented by these systems and methods can include obtaining a query from a user device that is configured to cause an LLM to generate an output outside of a predetermined scope. In response to obtaining the query, systems can execute one or more evaluation models that are configured to identify one or more compatibility issues that can arise if the queries are executed by an LLM. Where a query is identified as having one compatibility issue(s), the systems described herein can either update the query to address the issue. Additionally, or alternatively, the systems described herein can prevent the processing of the query (and processing in furtherance of the injection attack) by an LLM.
Owner:CAPITAL ONE SERVICES LLC

A multimodal integrated security control method for industrial cyber-physical systems

ActiveCN121956582BAttackControl data
This invention discloses a multimodal integrated security control method for industrial cyber-physical systems (ICPS), comprising: constructing an adaptive discrete memory event-triggered communication mechanism to process the output data of the sensing side of the ICPS to obtain system transmission values; after the values ​​are subjected to a false data injection attack, they form downstream data on the sensing side; using a trained attack reconstruction model to repair the downstream data on the sensing side; designing a robust observer based on the repaired downstream data on the sensing side; and generating initial control quantities through a multimodal integrated security controller based on the state estimates and fault estimates obtained by the observer; processing the initial control quantities using the aforementioned trigger communication mechanism to obtain control data; after the data is subjected to a false data injection attack, it forms downstream data on the execution side; and using the trained attack reconstruction model to reconstruct and compensate the downstream data on the execution side before applying it to the controlled object, thereby achieving integrated security control of the ICPS.
Owner:LANZHOU UNIVERSITY OF TECHNOLOGY

CM and CUSUM-based false data injection attack detection method for power system

The invention discloses a power system false data injection attack detection method based on CM and CUSUM, and provides a new method for power system FDIA detection by fusing CM and CUSUM algorithms, and the detection speed is greatly improved while high detection accuracy is ensured. In the aspect of improving the detection speed, the method utilizes the basic principle of CM to perform compression processing on the compressible power difference data, so that the subsequent data volume for detection and calculation is reduced. In the aspect of keeping precision, a detector is constructed based on a CUSUM algorithm, abnormal data are accumulated for multiple times in a data continuation mode, and the detection precision of the weak FDIA is remarkably improved.
Owner:HUNAN UNIV OF TECH

Ship deep reinforcement learning security control method against false data injection attack

The application discloses a kind of ship deep reinforcement learning safety control methods of resisting false data injection attack, the method includes establishing the second-order state space equation under considering false data injection attack;According to the adaptive updating law of sensor attack compensator design reconstruction error variable;The estimation value of auxiliary adaptive network model is obtained by constructing the adaptive law of auxiliary neural network weight;According to the estimation value of auxiliary adaptive network model, the adaptive updating law of sensor attack compensator and reconstruction error variable, construct feedforward flexible controller;According to the estimation of optimal feedback controller, course feedback adaptive law and feedforward flexible controller, construct ship deep reinforcement learning course controller.The application solves the problem that existing USV control technology cannot give consideration to the cooperative safety control of high-precision tracking and low-power optimal control when facing the model uncertainty under complex environment and the security threat of sensor network suffering from false data injection attack.
Owner:DALIAN MARITIME UNIVERSITY

An agent identity authentication method based on a trust mechanism

PendingCN122640187AAttackEngineering
The application provides an agent identity verification method based on a trust mechanism, belongs to the technical field of artificial intelligence and network security, and is used for solving the problems that in related technologies, external credentials cannot distinguish real agents from fake requests and are vulnerable to prompt injection attacks. In the application, a natural language semantic task is issued by a verification direction request party as a verification task, the request party generates a high-cost natural language response meeting a preset quality constraint, the verification party performs lightweight verification with a lower computing resource than the generation cost, and if the verification is passed, the request party is determined to be an agent with a legal semantic generation capability. The application realizes identity verification based on the endogenous semantic capability of the agent as the trust basis, naturally resists fake and flooding attacks through a cost asymmetry mechanism, and is immune to prompt injection at the protocol level through an output locking mechanism, and can be widely applied to trusted communication scenarios of an agent network.
Owner:LONGTEL INC

A method and apparatus for detecting injection attacks

This invention discloses a method and apparatus for detecting injection attacks, comprising: acquiring a network address to be detected; inputting the network address to be detected into a detection model to obtain the detection result of the network address to be detected output by the detection model; wherein, the detection model is trained based on the fusion of the semantic encoding and word vector features of the network address, and the detection result characterizes whether the network address to be detected is malicious; if the detection result indicates that the network address to be detected is malicious, an alarm is triggered. This method combines the semantic information and word vector features of the network address before threat detection, improving the detection model's understanding of network addresses and thus improving the accuracy of injection attack detection.
Owner:CHINA TELECOM NETWORK SECURITY TECH CO LTD

Method and device for detecting false data injection attack

The application discloses a kind of false data injection attack detection method and device. Among them, the method includes: obtaining power grid measurement data, wherein the power grid measurement data includes multiple types of power data;The power grid measurement data is analyzed by integrated classification detection model, and the output vector value is obtained, wherein the integrated classification detection model is obtained by machine learning training from multiple groups of data, each group of data in the multiple groups of data includes historical power grid measurement data and the label whether historical power grid measurement data is false data injection attack data;Whether the power grid measurement data is attacked is determined according to the size of output vector value, and the attacked data is processed.The application solves the technical problem that the false data injection attack detection method for power system state estimation in the prior art has insufficient fitting ability and cannot accurately identify the contaminated power grid state quantity.
Owner:SHENZHEN POWER SUPPLY BUREAU

False data injection attack method for multi-elastic-joint robot system

The invention provides a false data injection attack method for a multi-elastic-joint robot system, and belongs to the technical field of multi-agent network attacks based on computer data processing. Firstly, a multi-elastic joint robot nonlinear dynamic mathematical model is constructed and converted into a high-order all-drive quasi-linear multi-robot system dynamic model based on an all-drive system theory; and then designing a distributed consistency controller containing a linearization item and a neighbor error related item, establishing closed-loop global dynamics and deducing a state analytical solution in combination with equivalent conversion of the model. Designing a false data injection attack strategy, and constructing an attacked system dynamic model; a closed-loop terminal state error in the presence or absence of attacks is taken as a target function, an attack optimization problem is converted into a combinatorial optimization problem, a greedy algorithm is designed by applying a sub-module optimization theory, and a suboptimal solution in polynomial time is obtained and is taken as an optimal scheme of false data injection attacks of the system. According to the method, the applicability of the complex nonlinear multi-agent system is improved, and the calculation complexity is reduced.
Owner:OCEAN UNIV OF CHINA

Smart power grid false data injection attack detection method, terminal and storage medium

PendingCN121887528ABiological modelsSecuring communicationData packComputational probability
The invention provides a smart grid false data injection attack detection method, a terminal and a storage medium, and relates to the technical field of power system information security. The method comprises the steps that heterogeneous measurement data of a target smart grid are collected, a three-dimensional space-time tensor is constructed based on the heterogeneous measurement data, and the heterogeneous measurement data comprise node measurement data, branch measurement data and network topology data; inputting the three-dimensional space-time tensor into a constructed attack feature extraction model, and outputting a target feature corresponding to the three-dimensional space-time tensor; based on the target features, calculating an attack prediction probability, and based on the attack prediction probability, determining whether the target smart grid is subjected to a false data injection attack; and when the target smart power grid is subjected to the false data injection attack, calculating a probability distribution vector by using the target features, and determining an attack type of the false data injection attack on the target smart power grid according to the probability distribution vector. According to the invention, the accuracy and reliability of detection can be improved.
Owner:YANSHAN UNIV

Injection attack identification method and device, equipment, medium and program product

The invention discloses an injection attack identification method and device, equipment, a medium and a program product, and belongs to the technical field of computers. The method comprises the steps of obtaining first visual content and second visual content in the process of executing object verification; based on the first visual content and the second visual content, determining value change degrees of the first visual content and the second visual content in the target camera parameters to obtain a first change degree; and under the condition that the first change degree is inconsistent with a second change degree, at least one of the first visual content and the second visual content is determined as the visual content used for executing the injection attack, and the second change degree is the change degree between the first value and the second value. According to the method, the injection attack can be identified, and the accuracy of the identification result is relatively high.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

Black box graph neural network injection attack method based on reinforcement learning

The invention belongs to the technical field of artificial intelligence and information security, and particularly relates to a black-box graph neural network injection attack method based on reinforcement learning, which comprises the following steps: firstly, constructing a black-box multilateral graph injection attack framework guided by reinforcement learning, and the framework comprises a double-track feature generator and a multilateral connection selector; and then modeling the whole injection process as a Markov decision process, and optimizing an attack strategy under a limited query budget through an actuator-evaluator algorithm and a composite reward mechanism, thereby realizing maximum misleading of target node classification on the premise of not performing any modification on an original graph, and improving the classification accuracy of the target node. According to the method, a reinforcement learning modeling injection process is a Markov decision process, an attack strategy is directly optimized based on query feedback, dependence on a gradient or proxy model of a target model is not needed, and the problem of unreliable attack guidance under black box setting is effectively solved.
Owner:DONGHUA UNIV

Defense method and device for context injection attack of large language model

The invention discloses a defense method and device for a context injection attack of a large language model, and relates to the technical field of artificial intelligence network security protection. The method comprises the following steps of: performing non-uniform sampling on an input context, and extracting a head system instruction area, a tail user query area and a plurality of representative text fragments in the middle; by calculating a text compression ratio feature value and an N-gram repetition rate feature value of the middle fragment, capturing structural anomaly in a non-semantic understanding mode; calculating a semantic similarity characteristic value of the tail query and the middle segment, and carrying out intention corresponding detection; a total risk score is calculated, and hierarchical non-intrusive intervention from adding a security instruction at the end of the context to applying a dynamic Logit bias in a model decoding phase is performed according to different risk levels. According to the method, the safety detection and defense of the millisecond-level delay of the ultra-long context are realized, the internal weight of the model does not need to be modified, the universality is high, and the false alarm rate is low.
Owner:GUOTAI JUNAN SECURITIES CO LTD