IP Library Granted Patent US 11,710,078
Granted Patent B2
US 11,710,078 · App. 17/669,554 · Granted Jul 25, 2023

System and method for incremental training of machine learning models in artificial intelligence systems, including incremental training using analysis of network identity graphs

Inventors: Mohamed M. Badawy (Round Rock, TX); Rajat Kabra (Austin, TX); Jostine Fei Ho (Austin, TX)
Assignee: SAILPOINT TECHNOLOGIES, INC.
G06N20/00G06F16/245
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,710,078
App. No.
17/669,554
Granted
Jul 25, 2023
Kind
B2
Abstract

Systems and methods for embodiments of incremental training of machine learning model in artificial intelligence systems are disclosed. Specifically, embodiments of incremental training of machine learning models using drift detection models are disclosed, including embodiments that utilize drift detection models to determine drift based on identity graphs in artificial intelligence identity management systems.

Claims (57)

1. A method, comprising:

generating an identity graph by:

obtaining identity management data from one or more identity management systems in a distributed enterprise computing environment, the identity management data comprising data associated with a set of entitlements and a set of identities utilized with identity management in the distributed enterprise computing environment, wherein each entitlement of the set of entitlements relates to an access right within the distributed enterprise computing environment;

generating the identity graph from the identity management data by creating a node in the identity graph for each identity and for each entitlement; and

for each identity that is associated with an entitlement of the set of entitlements, creating an edge in the identity graph representing a relationship between the nodes representing the respective identity and respective entitlement;

deriving a first dataset from the identity graph at a first time;

training a first machine learning model used by a machine learning system based on the first dataset;

deriving a second dataset from the identity graph at a second time;

applying a drift detection model to the second dataset to determine a drift measure between the second dataset and the first dataset;

comparing the drift measure to a first threshold;

comparing the drift measure to a second threshold;

when the drift measure is greater than the first threshold, incrementally training the first machine learning model using a third dataset comprised of data including data from the second dataset; and

when the drift measure is greater than the second threshold, training a second machine learning model for use in the machine learning system and replacing the first machine learning model with the second machine learning model.

2. The method of claim 1 , wherein the drift prediction model is trained based on the first dataset.

3. The method of claim 1 , wherein the first dataset comprises data generated from performing graph embedding on at least a portion of the identity graph at the first time and the second dataset comprises data generated from performing graph embedding on at least a portion of the identity graph at the second time.

4. The method of claim 3 , wherein the graph embedding is performed using a graph embedding model.

5. The method of claim 1 , further comprising comparing the drift measure to a third threshold.

6. The method of claim 5 , further comprising when the drift measure is greater than the third threshold and less than the second threshold, generating an alert to a user indicating that data drift is occurring.

7. A non-transitory computer readable medium, comprising instructions for:

generating an identity graph by:

obtaining identity management data from one or more identity management systems in a distributed enterprise computing environment, the identity management data comprising data associated with a set of entitlements and a set of identities utilized with identity management in the distributed enterprise computing environment, wherein each entitlement of the set of entitlements relates to an access right within the distributed enterprise computing environment;

generating the identity graph from the identity management data by creating a node in the identity graph for each identity and for each entitlement; and

for each identity that is associated with an entitlement of the set of entitlements, creating an edge in the identity graph representing a relationship between the nodes representing the respective identity and respective entitlement;

deriving a first dataset from the identity graph at a first time;

training a first machine learning model used by a machine learning system based on the first dataset;

deriving a second dataset from the identity graph at a second time;

applying a drift detection model to the second dataset to determine a drift measure between the second dataset and the first dataset;

comparing the drift measure to a first threshold;

comparing the drift measure to a second threshold;

when the drift measure is greater than the first threshold, incrementally training the first machine learning model using a third dataset comprised of data including data from the second dataset; and

when the drift measure is greater than the second threshold, training a second machine learning model for use in the machine learning system and replacing the first machine learning model with the second machine learning model.

8. The non-transitory computer readable medium of claim 7 , wherein the drift prediction model is trained based on the first dataset.

9. The non-transitory computer readable medium of claim 7 , wherein the first dataset comprises data generated from performing graph embedding on at least a portion of the identity graph at the first time and the second dataset comprises data generated from performing graph embedding on at least a portion of the identity graph at the second time.

10. The non-transitory computer readable medium of claim 9 , wherein the graph embedding is performed using a graph embedding model.

11. The non-transitory computer readable medium of claim 7 , further comprising comparing the drift measure to a third threshold.

12. The non-transitory computer readable medium of claim 11 , further comprising when the drift measure is greater than the third threshold and less than the second threshold, generating an alert to a user indicating that data drift is occurring.

13. An identity management system, comprising:

a data store;

a processor;

a non-transitory, computer-readable storage medium, including computer instructions for:

generating an identity graph by:

obtaining identity management data from one or more identity management systems in a distributed enterprise computing environment, the identity management data comprising data associated with a set of entitlements and a set of identities utilized with identity management in the distributed enterprise computing environment, wherein each entitlement of the set of entitlements relates to an access right within the distributed enterprise computing environment;

generating the identity graph from the identity management data by creating a node in the identity graph for each identity and for each entitlement; and

for each identity that is associated with an entitlement of the set of entitlements, creating an edge in the identity graph representing a relationship between the nodes representing the respective identity and respective entitlement;

deriving a first dataset from the identity graph at a first time;

training a first machine learning model used by a machine learning system based on the first dataset;

deriving a second dataset from the identity graph at a second time;

applying a drift detection model to the second dataset to determine a drift measure between the second dataset and the first dataset;

comparing the drift measure to a first threshold;

comparing the drift measure to a second threshold;

when the drift measure is greater than the first threshold, incrementally training the first machine learning model using a third dataset comprised of data including data from the second dataset; and

when the drift measure is greater than the second threshold, training a second machine learning model for use in the machine learning system and replacing the first machine learning model with the second machine learning model.

14. The system of claim 13 , wherein the drift prediction model is trained based on the first dataset.

15. The system of claim 13 , wherein the first dataset comprises data generated from performing graph embedding on at least a portion of the identity graph at the first time and the second dataset comprises data generated from performing graph embedding on at least a portion of the identity graph at the second time.

16. The system of claim 15 , wherein the graph embedding is performed using a graph embedding model.

17. The system of claim 13 , further comprising comparing the drift measure to a third threshold.

18. The system of claim 17 , further comprising when the drift measure is greater than the third threshold and less than the second threshold, generating an alert to a user indicating that data drift is occurring.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Jun 27, 2025
From: GOLUB CAPITAL MARKETS LLC
To: SAILPOINT TECHNOLOGIES, INC.; SAILPOINT TECHNOLOGIES HOLDINGS, INC.
Reel/Frame 071776/0411 →
PATENT SECURITY AGREEMENT Recorded Jun 25, 2025
From: SAILPOINT TECHNOLOGIES, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071724/0511 →
SECURITY INTEREST Recorded Aug 17, 2022
From: SAILPOINT TECHNOLOGIES, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 061202/0540 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 17, 2022
From: BADAWY, MOHAMED M.; KABRA, RAJAT; HO, JOSTINE FEI
To: SAILPOINT TECHNOLOGIES, INC.
Reel/Frame 059037/0478 →
Continuity (2)
Continuation 17180357 · Feb 19, 2021
Related Publication 20220269990A1 · Aug 25, 2022
Cited By (1)
US 12,694,336