AI Decision Engine for Endpoint Behavior Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional defensive measures fail to adequately protect user devices from sophisticated AI-based attacks in network environments, which are highly efficient, personalized, frequent, and damaging, with AI-based actors often evading multifactor authentication and compromising privacy.

Innovation Solution

A computer-implemented method using an AI-based decision making engine to analyze endpoint data from user devices, determining whether actions constitute AI attack events by comparing them to normal behavior baselines, and generating alerts or remedial actions when abnormal activity is detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional defensive measures are used to protect user devices, then basic security is maintained, but they fail to detect sophisticated AI-based attacks

Engineering Contradiction:
Improvesecurity protection effectivenessVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an AI-based decision making engine as an intermediary component between endpoint data collection and attack detection. This engine acts as a mediator that processes endpoint data, compares it against normal behavior baselines, and generates alerts for abnormal activities. The intermediary engine enables sophisticated attack detection without requiring complete restructuring of the existing security architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary action by establishing normal behavior baselines before attacks occur. The AI engine continuously learns and stores what constitutes normal endpoint behavior patterns, enabling it to quickly identify deviations when AI-based attacks occur. This preliminary baseline establishment allows the system to be ready for detection without requiring complex real-time analysis of every anomaly.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If AI-based decision making engine is deployed to detect attacks, then detection accuracy improves, but processing operations increase

Engineering Contradiction:
Improveattack detection accuracyVSAvoidprocessing operation efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent extracts only the essential features and characteristics needed for attack detection from the full endpoint data. The AI-based decision making engine focuses on comparing specific behavioral patterns against established baselines rather than processing all raw endpoint data. This extraction approach maintains high detection accuracy while reducing the overall processing burden on the system.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system applies partial action by generating alerts only when abnormal patterns are detected that exceed the normal behavior baseline, rather than continuously processing and responding to all endpoint activities. The AI engine performs selective analysis, focusing computational resources on suspicious activities that deviate from established norms, thereby improving efficiency without sacrificing detection capability.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If multifactor authentication is implemented, then basic authentication security is improved, but AI-based actors can still evade it

Engineering Contradiction:
Improveauthentication securityVSAvoidresistance to AI-based attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements feedback mechanisms where the AI-based decision making engine continuously monitors endpoint behavior and adjusts detection thresholds based on learned patterns. The system receives feedback from ongoing operations, refines its understanding of normal behavior, and adapts its detection criteria accordingly. This feedback loop enables the system to evolve against sophisticated AI-based attacks that may attempt to evade static authentication measures.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Instead of relying solely on traditional authentication verification, the system inverts the approach by monitoring what the endpoint should be doing (normal behavior patterns) rather than just verifying credentials. The AI engine detects attacks by identifying deviations from expected behavior rather than attempting to verify every authentication attempt, thereby detecting AI-based actors that have successfully evaded traditional authentication.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS20250240307A1Using an artificial intelligence (AI)-based decision making engine to identify ai attack events
Publication Date: 2025.07.24 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US20250240307A1 patent drawing
  • US20250240307A1 patent drawing
  • US20250240307A1 patent drawing

AI summary

A computer-implemented method (CIM) according to one embodiment includes obtaining first endpoint data associated with first actions performed by one or more first user devices of a network environment. The CIM further includes inputting the first endpoint data into a predetermined artificial intelligence (AI)-based decision making engine, where the predetermined AI-based decision making engine is configured to determine, based on endpoint data, whether actions constitute an AI attack event. In response to a determination that an output of the predetermined AI-based decision making engine indicates that at least some of the first actions constitute an AI attack event, an alert that indicates that the at least some of the first actions likely constitute an AI attack event is output.