AI Security Platform for Anomaly Detection and Threat Tracing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Artificial intelligence systems are vulnerable to various threats and vulnerabilities, including adversarial attacks, data pollution, and infiltration, which are often undetected until significant damage has occurred, and existing malware detection methods are inadequate for AI systems.

Innovation Solution

A multi-layered security platform and services that include discovery, tracking, risk analysis, detection, and anomaly monitoring to identify and mitigate threats in AI systems, utilizing components such as injectors, discoverers, detectors, and tracking services to provide real-time alerts and trace the origin of attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If multi-layered security platform with discovery, tracking, and detection components is implemented, then detection capability and response time are improved, but device complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The security platform is divided into distinct functional modules including discovery service, tracking service, detector components, and analysis services. Each module performs a specific function (discovering AI resources, tracking data flow, detecting anomalies, analyzing threats) and can be independently deployed and managed, reducing overall system complexity while maintaining comprehensive detection capability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components such as the tracking service that acts as a mediator between AI resources and detection mechanisms. The tracking service collects and consolidates information from multiple AI components, providing a unified view that simplifies the detection process and reduces the complexity of direct monitoring between numerous individual components

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive tracking and lineage analysis are performed to trace malware origin, then detection accuracy is improved, but loss of time increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The tracking service continuously collects and stores lineage information, data flow patterns, and component relationships in advance before any threat occurs. This pre-established baseline data enables rapid comparison and anomaly detection when threats arise, eliminating the need for time-consuming retrospective analysis while maintaining high detection accuracy

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where detection results and threat intelligence are fed back into the tracking and discovery services. This feedback mechanism refines the baseline data and improves detection algorithms over time, enabling faster and more accurate threat origin tracing with each iteration

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250365302A1System and method for security platform and services for protecting an artificial intelligence system and its components against threats, risks and vulnerabilities
Publication Date: 2025.11.27 TAG SECURITY NETWORKS INC
  • US20250365302A1 patent drawing
  • US20250365302A1 patent drawing
  • US20250365302A1 patent drawing

AI summary

A system for a security platform and services for protecting an artificial intelligence system, comprising: wherein the security platform detects all events and creates a log of anomalous events; wherein a detector detects malware based on the anomalous events; wherein the security platform analyzes the malware by creating a risk analysis based on each detected malware; wherein based on the risk analysis, the security platform engages in adversarial threat mapping; wherein adversarial threat mapping includes input filtering, output filtering and masking; wherein the security platform also tracks the malware utilizing a variety of tracking services; wherein, if malware is detected, then the security platform informs a user of the system that the user has been hacked; wherein if the malware is contained, the security platform attempts to identify where the malware came from; wherein 1 form of finding an origin of the malware is engaging in incident correlation.