Base Machine Learning Model With LoRA Attachments for Cyber Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cyber security systems face challenges in efficiently detecting cyber threats due to the computational and memory overhead required by large, fully-tuned machine learning models, which are cumbersome to deploy and resource-intensive.
Innovation Solution
A cyber security system utilizing a base machine learning model paired with low-rank adaptation (LoRA) attachments, where each LoRA attachment is trained on specific cyber threat indications, working in tandem to analyze input data, and an ensemble model combines their embedding understandings to make a final decision.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If large fully-tuned machine learning models are used for cyber threat detection, then detection accuracy is improved, but computational overhead and memory requirements increase
Solution Approach 1:
The patent segments the machine learning model into a base model and multiple LoRA attachments. Each attachment is a small, specialized module trained on specific threat types (phishing, malware, ransomware) that can be selectively applied to the base model. This segmentation allows the system to use only the necessary specialized knowledge for each detection task rather than deploying a fully-tuned large model for all scenarios, reducing computational overhead while maintaining detection accuracy.
Solution Approach 2:
The patent changes the parameter configuration by using Low-Rank Adaptation (LoRA) attachments that modify only specific parameters of the base model rather than retraining all parameters. This parameter change approach allows the system to adapt the model to different threat types with minimal computational resources, achieving high detection accuracy without the heavy computational cost of fully-tuned large models.
2Measurement precision
If large fully-tuned machine learning models are used for cyber threat detection, then detection accuracy is improved, but memory requirements increase
Solution Approach 1:
The patent segments the machine learning model into a base model and multiple LoRA attachments. Each attachment is a small, specialized module trained on specific threat types (phishing, malware, ransomware) that can be selectively applied to the base model. This segmentation allows the system to use only the necessary specialized knowledge for each detection task rather than deploying a fully-tuned large model for all scenarios, reducing computational overhead while maintaining detection accuracy.
Solution Approach 2:
The patent changes the parameter configuration by using Low-Rank Adaptation (LoRA) attachments that modify only specific parameters of the base model rather than retraining all parameters. This parameter change approach allows the system to adapt the model to different threat types with minimal computational resources, achieving high detection accuracy without the heavy computational cost of fully-tuned large models.
3Measurement precision
If multiple specialized models are used for different threat types, then detection accuracy is improved, but device complexity increases
Solution Approach 1:
The patent merges multiple specialized detection capabilities into a single base model through LoRA attachments. Instead of managing separate models for phishing, malware, and ransomware detection, the system combines them all as attachments to one base model. This merging reduces device complexity by centralizing model management while maintaining the specialized detection accuracy of individual threat-type models through the modular attachment structure.
Data Source
AI summary
A cyber security appliance can detect a cyber threat with a set of LoRA attachments, a base machine learning model, and an ensemble machine learning model. Each LoRa attachment in the set is specifically trained on identifying and confirming a particular indication of the cyber threat and/or another property being analyzed for cyber security purposes. The base machine learning model and one or more of the LoRa attachments in the set of attachments are paired to work in tandem with each other to analyze input data to look for the particular indication of the cyber threat and/or other property being analyzed for cyber security purposes. An ensemble machine learning model can analyze a compilation of produced embedding understandings of each particular indication of the cyber threat and/or other property being analyzed for cyber security purposes from two or more pairings of different LoRa attachments with the base machine learning model to form a final output decision of whether the cyber threat and/or other property being analyzed for cyber security purposes is present or not in a system being monitored.


