LLM Suspicious Activity Report Generation via Composite Data Preprocessing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for generating suspicious activity reports (SARs) face challenges such as the need for high-quality training datasets, frequent model updates, and resource-intensive retraining, especially for large language models.

Innovation Solution

The system addresses these challenges by performing an initial preprocessing step that combines detected cybersecurity events with historical data of similar events, generating composite data that is then fed into a large language model to produce SARs. This approach increases the data input for the model, reducing the training burden and allowing for more efficient detection of nuances and patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a large language model is trained from scratch with extensive high-quality datasets, then the model can detect nuances and patterns accurately, but the training process becomes resource-intensive and technically challenging

Engineering Contradiction:
Improvedetection accuracyVSAvoidtraining resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent applies preliminary action by pre-processing and combining detected cybersecurity events with historical similar events to create composite data before feeding it to the large language model. This preliminary data preparation reduces the training burden by pre-aggregating relevant information, allowing the model to focus on pattern recognition rather than learning from raw, unprocessed data.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses an intermediary approach by introducing a data processing layer that combines current cybersecurity events with historical data to create composite input data. This intermediary composite data structure serves as a bridge between raw data and the large language model, reducing the model's training requirements while maintaining detection accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the model is frequently updated and retrained to keep up with new patterns of suspicious activity, then the model remains accurate, but the process becomes resource-intensive and technically challenging

Engineering Contradiction:
Improvemodel updatednessVSAvoidretraining resource consumption
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The patent applies preliminary action by pre-processing and combining detected cybersecurity events with historical similar events to create composite data before feeding it to the large language model. This preliminary data preparation reduces the training burden by pre-aggregating relevant information, allowing the model to focus on pattern recognition rather than learning from raw, unprocessed data.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies dynamics by making the data input dynamic through the combination of current detected events with historical similar events. This dynamic data composition allows the model to adapt to new patterns without requiring full retraining, as the composite data structure naturally incorporates historical context alongside current information.

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If human individuals manually prepare and submit SARs, then the process can be adapted to complex cases, but it is time-consuming and prone to human error

Engineering Contradiction:
Improveoperational flexibilityVSAvoidSAR preparation speed
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent applies self-service by enabling the system to automatically generate SARs using the large language model processed through composite data. The system performs self-processing of cybersecurity events, historical data combination, and SAR generation without requiring manual human intervention for routine cases, thereby increasing productivity while maintaining operational flexibility through the model's adaptive capabilities.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250184340A1System and method for improving cybersecurity by generating activity reports using machine-learning models
Publication Date: 2025.06.05 CITIBANK N A
  • US20250184340A1 patent drawing
  • US20250184340A1 patent drawing
  • US20250184340A1 patent drawing

AI summary

Presented herein are systems and methods for generating suspicious activity reports using large language models. A system may include one or more processors that obtain event data associated with an event from a client device and from one or more databases, apply a prompt generator on the event data to generate a large language model (LLM) prompt, and generate a machine-readable suspicious activity (SAR) report in accordance with an LLM prompt. The one or more processors may also apply the prompt generator on the event data based on determining that a fraud risk score associated with the event satisfies a reporting threshold score. Computer program products are also presented.