AI Threat Detection Using User Intent in Sparse-Data Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The detection of cyber incidents is hindered by the lack of ample and high-quality training data required for artificial intelligence models, which is particularly challenging due to user-specific behaviors and the need for immediate responses, making conventional approaches ineffective.

Innovation Solution

A novel architecture for an artificial intelligence model that bifurcates training into two portions: one for sentiment analysis and user intent determination based on user groups, and another for user engagement metrics, using neural networks and machine learning to generate quantitative metrics for cyber threat detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If artificial intelligence models are used for cyber incident detection, then detection accuracy and real-time response capability are improved, but the requirement for large amounts of high-quality training data increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidtraining data volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent segments the training data requirement into two distinct portions: (1) user group level training data that captures general behavioral patterns and sentiment analysis capabilities, and (2) user specific training data that captures individual engagement metrics and intent patterns. This segmentation allows the system to train effective AI models with significantly less total data than would be required to train on individual user data alone.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary training of the AI model on aggregated user group data before deploying it for specific user detection. This preliminary action establishes baseline patterns and sentiment analysis capabilities that can then be fine-tuned with minimal user-specific data, reducing the overall training data requirement while maintaining detection accuracy.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If artificial intelligence models are trained on user-specific data, then detection precision for individual users is improved, but the complexity of data collection and processing increases

Engineering Contradiction:
Improveuser-specific detection precisionVSAvoiddata collection and processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent separates data collection into two streams: aggregated user group data that captures general patterns and sentiments, and individual user interaction data that captures engagement metrics. This segmentation simplifies data collection by allowing parallel processing of group-level and user-level data through different pipelines, reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces user group level patterns as an intermediary layer between raw user data and final detection outcomes. This intermediary aggregation layer simplifies processing by pre-processing and summarizing user behaviors at the group level before individual user analysis, reducing the computational complexity of handling raw user-specific data.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If immediate response to cyber incidents is implemented, then security protection is improved, but the time for data verification and analysis is reduced

Engineering Contradiction:
Improvesecurity protectionVSAvoiddata verification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary training of AI models on aggregated user group data and establishes baseline patterns before actual cyber incident detection is needed. This preliminary preparation allows the system to make immediate responses to incidents without requiring time-consuming verification at the moment of detection, as the model is already calibrated with pre-processed patterns.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the AI model continuously learns from detected incidents and adjusts its predictions in real-time. This feedback loop allows the system to maintain high reliability for immediate responses by continuously refining its detection accuracy based on actual incident outcomes, reducing the need for extensive pre-verification.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12603903B2Methods and systems for cyber threat detection using artificial intelligence models in data-sparse environments
Publication Date: 2026.04.14 CAPITAL ONE SERVICES LLC
  • US12603903B2 patent drawing
  • US12603903B2 patent drawing
  • US12603903B2 patent drawing

AI summary

Methods and systems comprising a first portion of a model that includes a model component that is trained to perform sentiment analysis based on training data for a plurality of users (e.g., what language, phrases, and/or responses the population at large uses). The first portion of the model also includes a model component that is trained to identify user intent based on the sentiment analysis that is specific to user groups. For example, the system first determines the likely context and/or meaning of communications of the user. The system then determines a likely intent of the user based on the likely context and/or meaning of communications (e.g., based on a correlation of the meaning of communications of the user and the intents of users corresponding to a user group of the user).