Adversarial Activity Detection via Worldview Graph Fusion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for modeling adversarial activities are sensitive to noisy inputs and fail to effectively align user identities across different communication networks, lacking support for finding sub-networks matching a specified threat template and handling dynamic, heterogeneous data.

Innovation Solution

A computational framework that integrates multiple dynamic and heterogeneous networks through optimization-based alignment, using topological features and attribute information to merge networks and detect suspicious subgraph regions, generating alerts and rankings of adversarial activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If Named Entity Recognition (NER) is used for identity correspondence estimation, then the system can process natural language data, but the system becomes sensitive to noise in real-world data

Engineering Contradiction:
Improvenatural language processing capabilityVSAvoidnoise sensitivity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent merges multiple heterogeneous networks (communication networks, transaction networks, social networks) into a unified worldview graph. This integration allows the system to cross-validate entity identities across different data sources, reducing sensitivity to noise in any single network while maintaining versatility in processing various data types including natural language.

Inventive Principle:
Principle #5Merging (Combining)

2Measurement precision

If the system integrates multiple dynamic and heterogeneous networks, then the system can align user identities across different networks, but the device complexity increases

Engineering Contradiction:
Improveidentity alignment accuracyVSAvoidnetwork integration complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces an optimization-based alignment framework that acts as an intermediary mechanism to match entities across heterogeneous networks. This framework uses topological features and attribute information as mediators to align identities without requiring direct complex integration of all network structures, thereby improving identity alignment accuracy while managing system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system transforms heterogeneous network data into a unified worldview graph representation by changing parameters such as node attributes, edge weights, and topological features. This parameter transformation allows diverse networks to be integrated into a common framework, improving measurement precision for identity alignment while abstracting away the underlying complexity of individual networks.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If the system performs optimization-based alignment using topological features and attribute information, then the alignment accuracy improves, but the computation time increases

Engineering Contradiction:
Improvealignment accuracyVSAvoidcomputation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the alignment process into distinct stages: constructing individual network graphs, extracting topological features and attributes, performing optimization-based alignment, and generating the worldview graph. This segmentation allows computation to be distributed and optimized at each stage, improving alignment accuracy through systematic processing while reducing overall computation time by avoiding monolithic processing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by pre-processing network data to extract topological features and attribute information before the main alignment computation. This preliminary extraction organizes data in a structured format that accelerates the subsequent optimization-based alignment process, thereby improving alignment accuracy without proportionally increasing total computation time.

Inventive Principle:
Principle #10Preliminary action

4Difficulty of detecting and measuring

If the system uses unsupervised threat detection, then the system can detect anomalies, but the system cannot find sub-networks matching a specified threat template

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoidthreat template matching capability
Core Design Contradiction:
Difficulty of detecting and measuringVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal worldview graph framework that supports multiple detection modes. The same integrated graph structure can be queried using both unsupervised anomaly detection methods and supervised threat template matching queries. This multi-functionality allows the system to detect anomalies without prior knowledge while also searching for specific threat patterns, combining the strengths of both approaches without requiring separate systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11671436B1Computational framework for modeling adversarial activities
Publication Date: 2023.06.06 HRL LAB
  • US11671436B1 patent drawing
  • US11671436B1 patent drawing
  • US11671436B1 patent drawing

AI summary

Described is a system for producing indicators and warnings of adversarial activities. The system receives multiple networks of transactional data from different sources. Each node of a network of transactional data represents an entity, and each edge represents a relation between entities. A worldview graph is generated by merging the multiple networks of transactional data. Suspicious subgraph regions related to an adversarial activity are identified in the worldview graph through activity detection. The suspicious subgraph regions are used to generate and transmit an alert of the adversarial activity.