Base Machine Learning Model With LoRA Attachments for Cyber Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyber security systems face challenges in efficiently detecting cyber threats due to the computational and memory overhead required by large, fully-tuned machine learning models, which are cumbersome to deploy and resource-intensive.

Innovation Solution

A cyber security system utilizing a base machine learning model paired with low-rank adaptation (LoRA) attachments, where each LoRA attachment is trained on specific cyber threat indications, working in tandem to analyze input data, and an ensemble model combines their embedding understandings to make a final decision.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If large fully-tuned machine learning models are used for cyber threat detection, then detection accuracy is improved, but computational overhead and memory requirements increase

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidcomputational overhead
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent segments the machine learning model into a base model and multiple LoRA attachments. Each attachment is a small, specialized module trained on specific threat types (phishing, malware, ransomware) that can be selectively applied to the base model. This segmentation allows the system to use only the necessary specialized knowledge for each detection task rather than deploying a fully-tuned large model for all scenarios, reducing computational overhead while maintaining detection accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter configuration by using Low-Rank Adaptation (LoRA) attachments that modify only specific parameters of the base model rather than retraining all parameters. This parameter change approach allows the system to adapt the model to different threat types with minimal computational resources, achieving high detection accuracy without the heavy computational cost of fully-tuned large models.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If large fully-tuned machine learning models are used for cyber threat detection, then detection accuracy is improved, but memory requirements increase

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidmemory requirements
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent segments the machine learning model into a base model and multiple LoRA attachments. Each attachment is a small, specialized module trained on specific threat types (phishing, malware, ransomware) that can be selectively applied to the base model. This segmentation allows the system to use only the necessary specialized knowledge for each detection task rather than deploying a fully-tuned large model for all scenarios, reducing computational overhead while maintaining detection accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter configuration by using Low-Rank Adaptation (LoRA) attachments that modify only specific parameters of the base model rather than retraining all parameters. This parameter change approach allows the system to adapt the model to different threat types with minimal computational resources, achieving high detection accuracy without the heavy computational cost of fully-tuned large models.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If multiple specialized models are used for different threat types, then detection accuracy is improved, but device complexity increases

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidmodel management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges multiple specialized detection capabilities into a single base model through LoRA attachments. Instead of managing separate models for phishing, malware, and ransomware detection, the system combines them all as attachments to one base model. This merging reduces device complexity by centralizing model management while maintaining the specialized detection accuracy of individual threat-type models through the modular attachment structure.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20250267155A1Base machine learning model paired with multiple low ranking adaption attachments for cyber security purposes
Publication Date: 2025.08.21 DARKTRACE HLDG LTD
  • US20250267155A1 patent drawing
  • US20250267155A1 patent drawing
  • US20250267155A1 patent drawing

AI summary

A cyber security appliance can detect a cyber threat with a set of LoRA attachments, a base machine learning model, and an ensemble machine learning model. Each LoRa attachment in the set is specifically trained on identifying and confirming a particular indication of the cyber threat and/or another property being analyzed for cyber security purposes. The base machine learning model and one or more of the LoRa attachments in the set of attachments are paired to work in tandem with each other to analyze input data to look for the particular indication of the cyber threat and/or other property being analyzed for cyber security purposes. An ensemble machine learning model can analyze a compilation of produced embedding understandings of each particular indication of the cyber threat and/or other property being analyzed for cyber security purposes from two or more pairings of different LoRa attachments with the base machine learning model to form a final output decision of whether the cyber threat and/or other property being analyzed for cyber security purposes is present or not in a system being monitored.