AI Detection Explainability for Cybersecurity False Positives

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cybersecurity systems often generate false positive detections, leading to inefficient use of computational, network, and storage resources, as well as requiring manual intervention by administrators lacking expertise in both machine learning and cybersecurity, which complicates the resolution of such false positives.

Innovation Solution

An AI model-based pipeline is employed to generate explanations for false positive detections, automating the handling of these issues by providing clear reasons for false positives and facilitating the improvement of detection mechanisms through corpus growth and model retraining.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual intervention by administrators is used to handle false positive detections, then detailed analysis and resolution of false positives can be performed, but computational resources are wasted and resolution time increases

Engineering Contradiction:
Improvefalse positive resolution accuracyVSAvoidfalse positive resolution speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables self-service by having the AI model automatically analyze false positive detections, generate explanations, and resolve issues without requiring human administrator intervention. The model processes detections autonomously, reducing both resource consumption and resolution time while maintaining accuracy through its trained capabilities.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical manual analysis process with an AI-based automated system. The AI model substitutes human administrators in analyzing false positives, generating explanations, and resolving detections, thereby eliminating the waste of computational resources and time associated with manual intervention.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If AI models are used to detect malicious behavior, then detection accuracy improves, but false positive detections increase requiring manual intervention

Engineering Contradiction:
Improvedetection accuracyVSAvoidfalse positive rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system implements feedback mechanisms where the AI model analyzes false positive detections, generates explanations, and uses this information to refine its future detections. The feedback loop includes monitoring false positive rates and adjusting model parameters accordingly, thereby reducing false positives while maintaining high detection accuracy.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies parameter changes by adjusting AI model parameters and thresholds based on analyzed false positive detections. The model modifies its detection criteria and parameter weights to reduce false positive rates while preserving detection accuracy, adapting its behavior through continuous learning from resolved false positive cases.

Inventive Principle:
Principle #35Parameter changes

3Manufacturing precision

If detailed analysis of false positives is performed manually, then resolution quality improves, but computational and network resources are consumed

Engineering Contradiction:
Improveresolution qualityVSAvoidcomputational resource consumption
Core Design Contradiction:
Manufacturing precisionVSUse of energy by moving object

Solution Approach 1:

The patent replaces manual analysis with an AI-based automated system that performs detailed analysis of false positives. The AI model processes detection data, generates comprehensive explanations, and resolves issues without consuming computational or network resources in the same way manual analysis would, as it operates through efficient algorithmic processing rather than human cognitive resources.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250371138A1Automated ai model-based pipeline for detection explainability
Publication Date: 2025.12.04 CROWDSTRIKE
  • US20250371138A1 patent drawing
  • US20250371138A1 patent drawing
  • US20250371138A1 patent drawing

AI summary

The present disclosure provides techniques for AI model-based detection explainability. A processing device obtains computer-readable text and an indication of a false positive detection of malicious behavior with respect to the computer-readable text by a cybersecurity system, The processing device obtains, via an artificial intelligence (AI) model trained to generate language, a reason for the false positive detection of the malicious behavior. The processing device provides an indication of the reason for the false positive detection to a destination device.