IP Library Granted Patent US 12,645,920
Granted Patent B2
US 12,645,920 · App. 18/144,741 · Granted Jun 2, 2026

Explainable neural network for anomaly detection

Inventors: Raghavendra Gunnai (Marlboro, NJ); Raminder Deep Singh Kaler (Redwood City, CA); Sudhakar Peddibhotla (Seattle, WA)
Assignee: Ping Identity International, Inc.
G06N3/0455
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,645,920
App. No.
18/144,741
Granted
Jun 2, 2026
Kind
B2
Abstract

Disclosed are a process, system and medium for explaining an anomaly detected in an authentication request by a classifier, including. obtaining the anomaly detection model, with the anomaly detection model having been trained to detect anomalous authentication requests. Also disclosed is obtaining a multi-layer perceptron (MLP) model trained to provide MLP results similar to anomaly detection results when the same features are provided to both the anomaly detection model and the MLP model. During the MLP model training, the anomaly detection model results serve as ground truth; also, detecting, by the anomaly detection model, that the authentication request is anomalous and providing the authentication request features to an explanation tool using the MLP. Based on the detecting, also disclosed is obtaining, from the explanation tool, an explanation comprising at least one identification of the authentication request feature that contributed most to the detection of anomaly.

Claims (35)

1 . A method of explaining an anomaly detected in an authentication request by a classifier, the method comprising:

obtaining an unsupervised encoder-decoder model, the encoder-decoder model having been trained to detect authentication requests;

obtaining a multi-layer perceptron (MLP) model trained to provide MLP results similar to encoder-decoder results when the same features are provided to both the unsupervised encoder-decoder model and the MLP model, wherein the encoder-decoder results served as ground truth during the MLP model training, the MLP model is trained by providing, as input, the input to the encoder-decoder model, and targeting, as output, a reconstruction loss error of the encoder-decoder model;

embedding authentication request features from an authentication request into an embedding space to generate embedding features;

providing the embedding features to the encoder-decoder model;

detecting, by the encoder-decoder model, that the authentication request is anomalous, the anomaly is reflected by a risk score from the encoder-decoder model, and an explainability condition is satisfied when the risk score exceeds a threshold;

responsive to the detecting the authentication request as anomalous, providing the authentication request features to an explanation tool using the MLP model; and

obtaining, from the explanation tool, an explanation comprising at least an identification of at least one of the authentication request features that contributed most to the detecting the authentication request as anomalous.

2 . The method of claim 1 , wherein the explanation tool is integrated gradients (IG).

3 . The method of claim 1 , wherein the encoder-decoder model is a variational autoencoder (VAE).

4 . The method of claim 1 , wherein each authentication request feature in the explanation is paired with a score and the score reflects a degree of contribution to the detecting by the encoder-decoder model.

5 . The method of claim 4 , wherein a magnitude of the score reflects the degree of contribution.

6 . A non-transitory computer readable storage medium impressed with computer program instructions to explain an anomaly detected in an authentication request by a classifier, the instructions, when executed on a processor, implement a method comprising:

obtaining an unsupervised encoder-decoder model, the encoder-decoder model having been trained to detect anomalous authentication requests;

obtaining a multi-layer perceptron (MLP) model trained to provide MLP results similar to encoder-decoder results when the same features are provided to both the unsupervised encoder-decoder model and the MLP model, wherein the encoder-decoder results served as ground truth during the MLP model training, the MLP model is trained by providing, as input, the input to the encoder-decoder model, and targeting, as output, a reconstruction loss error of the encoder-decoder model;

embedding authentication request features from an authentication request into an embedding space to generate embedding features;

providing the embedding features to the encoder-decoder model;

detecting, by the encoder-decoder model, that the authentication request is anomalous, the anomaly is reflected by a risk score from the encoder-decoder model, and an explainability condition is satisfied when the risk score exceeds a threshold;

responsive to the detecting the authentication request as anomalous, providing the authentication request features to an explanation tool using the MLP model; and

obtaining, from the explanation tool, an explanation comprising at least an identification of at least one of the authentication request features that contributed most to the detecting the authentication request as anomalous.

7 . The non-transitory computer readable storage medium of claim 6 , wherein the explanation tool is integrated gradients (IG).

8 . The non-transitory computer readable storage medium of claim 6 , wherein the encoder-decoder model is a variational autoencoder (VAE).

9 . The non-transitory computer readable storage medium of claim 6 , wherein each authentication request feature in the explanation is paired with a score and the score reflects a degree of contribution to the detecting by the encoder-decoder model.

10 . The non-transitory computer readable storage medium of claim 9 , wherein a magnitude of the score reflects the degree of contribution.

11 . A system including one or more processors coupled to memory, the memory loaded with computer instructions to explain an anomaly detected in an authentication request by a classifier, the instructions, when executed on the one or more processors, implement actions comprising:

obtaining an unsupervised encoder-decoder model, the encoder-decoder model having been trained to detect anomalous authentication requests;

obtaining a multi-layer perceptron (MLP) model trained to provide MLP results similar to encoder-decoder results when the same features are provided to both the unsupervised encoder-decoder model and the MLP model, wherein the encoder-decoder results served as ground truth during the MLP model training, the MLP model is trained by providing, as input, the input to the encoder-decoder model, and targeting, as output, a reconstruction loss error of the encoder-decoder model;

embedding authentication request features from an authentication request into an embedding space to generate embedding features;

providing the embedding features to the encoder-decoder model;

detecting, by the encoder-decoder model, that the authentication request is anomalous, the anomaly is reflected by a risk score from the encoder-decoder model, and an explainability condition is satisfied when the risk score exceeds a threshold;

responsive to the detecting the authentication request as anomalous, providing the authentication request features to an explanation tool using the MLP model; and

obtaining, from the explanation tool, an explanation comprising at least an identification of at least one of the authentication request features that contributed most to the detecting the authentication request as anomalous.

12 . The system of claim 11 , wherein the explanation tool is integrated gradients (IG).

13 . The system of claim 11 , wherein the encoder-decoder model is a variational autoencoder (VAE).

14 . The system of claim 11 , wherein each authentication request feature in the explanation is paired with a score and the score reflects a degree of contribution to the detecting by the encoder-decoder model.

Assignments (3)
SECURITY INTEREST Recorded Nov 13, 2025
From: PING IDENTITY CORPORATION; PING IDENTITY INTERNATIONAL, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 073557/0093 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2024
From: FORGEROCK, INC.
To: PING IDENTITY INTERNATIONAL, INC.
Reel/Frame 066358/0483 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2023
From: GUNNAI, RAGHAVENDRA; KALER, RAMINDER DEEP SINGH; PEDDIBHOTLA, SUDHAKAR
To: FORGEROCK, INC.
Reel/Frame 065003/0162 →
Continuity (1)
Related Publication 20240378423A1 · Nov 14, 2024
References Cited (54)
US 10303576B1 · Seymour et al. · 2019 [cited by applicant]
US 11663067B2 · Anghel · 2023 [cited by examiner]
US 12361112B2 · Peddibhotla · 2025 [cited by examiner]
US 20150205708A1 · Michelsen · 2015 [cited by applicant]
US 20160140023A1 · Michelsen et al. · 2016 [cited by applicant]
US 20160217062A1 · Singi et al. · 2016 [cited by applicant]
US 20170295062A1 · Tang · 2017 [cited by applicant]
US 20180189033A1 · Narang et al. · 2018 [cited by applicant]
US 20190087075A1 · Dhayanithi et al. · 2019 [cited by applicant]
US 20200125483A1 · Lipke · 2020 [cited by applicant]
US 20210004253A1 · Barnes et al. · 2021 [cited by applicant]
US 20210048994A1 · Yu · 2021 [cited by examiner]
US 20210072966A1 · Zong et al. · 2021 [cited by applicant]
US 20210142476A1 · Cao · 2021 [cited by examiner]
US 20240362316A1 · Peddibhotla · 2024 [cited by examiner]
US 20240364729A1 · Kaler · 2024 [cited by examiner]
Liu et al. “Anomaly Detection in Manufacturing Systems Using Structured Neural Networks” 2018 IEEE, pp. 175-180. [cited by examiner]
Sani et al. “An overview of neural networks use in anomaly Intrusion Detection Systems” 2009 IEEE, 4 pages. [cited by examiner]
Srinivasan et al. “Cluster computing for neural network based anomaly detection” 2005 IEEE, pp. 130-134. [cited by examiner]
U.S. Appl. No. 18/139,290, filed Apr. 25, 2023, Pending. [cited by applicant]
U.S. Appl. No. 18/139,296, filed Apr. 25, 2023, Pending. [cited by applicant]
U.S. Appl. No. 18/139,295, filed Apr. 25, 2023, Pending. [cited by applicant]
Kingma et al, Auto-Encoding Variational Bayes, arXiv:1312.6114v11 [stat.ML] Dec. 10, 2022, 14 pages. [cited by applicant]
Bojanowski et al. EnrichingWord Vectors with Subword Information, Association for Computational Linguistics, vol. 5, pp. 135-146, 2017.12 pages (arXiv:1607.04606v2 [cs.CL] ). [cited by applicant]
Gunning, David, Explainable Artificial Intelligence (XAI), DARPA Information Innovation Office (I2O), Aug. 11, 2016. [cited by applicant]
AI Explainability 360, IMB Research, 2 pages (downloade Jan. 31, 2023 from http://aix360.mybluemix.net/?_ga=2.82831765.248878821.1675182248-995690514.1675182248). [cited by applicant]
Arriet et al, Explainable Artificial Intelligence (XAI): Concepts, Taxonomies, Opportunities and Challenges toward Responsible AI, Informatiom Fusiom, Dec. 26, 2019, 73 pages. [cited by applicant]
Sundararajan, Axiomatic Attribution for Deep Networks, Proceedings of the 34 th International Conference on Machine Learning, Sydney, Australia, PMLR 70, 2017 (arXiv: 1703.01365v2 [cs.LG] Jun. 13, 2017). [cited by applicant]
Feature Attribution, Stanford CS224U Natural Language Understanding, Spring 2021, YouTube video, published Jan. 6, 2022, (https://www.youtube.com/watch?v=RFE6xdfJvag). [cited by applicant]
Sigler, Vertex AI Example-based Explanations improve ML via explainability, Aug. 24, 2022, 9 pages (downloaded Apr. 6, 2023 from https://cloud.google.com/blog/products/ai-machine-learning/example-based-explanations-to-b… [cited by applicant]
Akers, A., What Is Step-Up Authentication When To Use It?, Okta, Auth0 Blog, Dec. 17, 2020, 14 pages (downloaded Apr. 6, 2023 from https://auth0.com/blog/what-is-step-up-authentication-when-to-use-it/. [cited by applicant]
Distinguish step-up from multi-factor authentication, IBM, Mar. 9, 2021, 2 pages, (downloaded Apr. 6, 2023 from https://www.ibm.com/docs/en/sva/9.0.1?topic=authentication-distinguish-step-up-from-multi-factor). [cited by applicant]
Jordan, J., Variational autoencoders, JeremyJordan. me, Mar. 19, 2019, 15 pages (downloaded Mar. 21, 2023 from https://www.jeremyjordan.me/variational-autoencoders/). [cited by applicant]
Huang, Z., Extensions to the k-Means Algorithm for Clustering Large Data Sets with Categorical Values, Data Mining and Knowledge Discovery, 2, 283-304 Sep. 1998 Kluwer Academic Publishers, 22 pages (https://doi.org/10.1… [cited by applicant]
About Autonomous Access—ForgeRock Identity Cloud Docs, ForgeRock, Inc. May 2022, 27 pages (downloaded Dec. 12, 2022 from https://backstage.forgerock.com/docs/idcloud/latest/auto-access/chap-about-autoaccess.html). [cited by applicant]
“Theme Node, Dynamically theme the ForgeRock out-of-the-box US on the fly”, Oct. 2020, ForgeRock, Inc., pp. 5 pgs. (downloaded from https://web.archive.org/web/20201024234908/https://backstage.forgerock.com/marketplace/… [cited by applicant]
“Theme Node, Dynamically theme the ForgeRock out-of-the-box US on the fly”, Apr. 2020, ForgeRock, Inc.,, 8 pgs (downloaded from https://github.com/vscheuber/ThemeNode). [cited by applicant]
McKendrick, What is low-code and no-code? A guide to development platforms, ZDNet, Mar. 3, 2021,9 pgs (downloaded from https://www.zdnet.com/article/special-report-what-is-low-code-no-code-a-guide-to-development-platfor… [cited by applicant]
Authentication and Single Sign-On Guide, ForgeRock Access Management 6.5, ForgeRock, Inc., Jul. 4, 2019, 482 pages. [cited by applicant]
Release Notes, AM 5.0.0, ForgeRock, Inc., Jun. 2, 2020. [cited by applicant]
Protect Users Witthout Frustrating Them Using AI-Driven Behavorial Biometrics, White Pater, Behavion Sec, 2020, (retrieved Dec. 14, 2021 from https://www.behaviosec.com/wp-content/uploads/2020/11/bhs-whitepaper.pdf). [cited by applicant]
Behavioral Biometrics for Mobile, BioCatch, 2021, 3 pages (retrieved Dec. 14, 2021 from https://www.biocatch.com/hubfs/New%20Boilerplate/BC%20SB%20Mobile%20Data%20v6%20NBP.pdf). [cited by applicant]
Innovating the Customer Experience Without Opening Fraud Floodgates, BioCatch, 10 pages (retrieved Dec. 14, 2021 from https://www.biocatch.com/hubfs/WP-Innovate-Customer-Experience-Without-Fraud.pdf). [cited by applicant]
Threat Matrix Guide, ID Dataweb, 7 pages (retrieved Dec. 14, 2021 from https://docs.iddataweb.com/docs/threatmetrix-1). [cited by applicant]
Cichonski et al., “Computer Security Incident Handling Guide”, National Institute of Standards and Technology, U.S. Department of Commerce, Special Publication 800-61, Revision 2, http://dx.doi.org/10.6028/NIST.SP.800-6… [cited by applicant]
“Hardening your cluster's security”, Kubernetes Engine, (https://cloud.google.com/kubernetes-engine/docs/concepts/security-overview), Jul. 2019, 10 pages. [cited by applicant]
Dempsey, et al., “Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations”, NIST National Institute of Standards and Technology, U.S. Dept. of Commerce, NIST Special Publicati… [cited by applicant]
“Configuring Vertical Pod Autoscaling”, Kubernetes Engine, Google Cloud (https://cloud.google.com/kubernetes-engine/), Aug. 14, 2019, 8 pages. [cited by applicant]
Wilkin, “Kubernetes Deployment Dependencies”, https://medium.com/google-cloud/kubernetes-deployment-dependencies-ef703e563956, Jul. 2, 2018, 21 pages. [cited by applicant]
“Vertical Pod Autoscaling”, Kubernetes Engine, https://cloud.google.com/kubernetes-engine/docs/concepts/verticalpodautoscaler), Aug. 29, 2019, 8 pages. [cited by applicant]
Sakimura et al, “OpenID Connect Dynamic Client Registration 1.0 incorporating errata set 1”, https://openid.net/specs/openid-connect-registration-1_0.html, Oct. 1, 2019, 19 pages. [cited by applicant]
Jayanandana, “Enable Rolling updates in Kubernetes with Zero downtime”, https://medium.com/platformer-blog/enable-rolling-updates-in-kubernetes-with-zero-downtime-31d7ec.388c81, Sep. 27, 2018, 6 pages. [cited by applicant]
“FAQ: IDM/OpenIDM performance and tuning”, https://backstage.forgerock.com/knowledge/kb/article/a32504603, Jun. 26, 2019, 7 pages. [cited by applicant]
Amazon; AWS Elastic Beanstalk Developer Guide; Aug. 2019; 924 pgs (https://web.archive.org/web/20190805110626/https:// docs.aws.amazon.com/elasticbeanstalk/latest/dg/awseb-dg.pdf). [cited by applicant]