IP Library › Granted Patent US 12,730,885
Granted Patent B2
US 12,730,885 · App. 18/393,652 · Granted Sep 8, 2026

Security threat mitigation

Inventors: Anush Sankaran (Burnaby, CA); Srisuma Movva (Seattle, WA); Andrew White Wicker (Snoqualmie, WA); Muhammed Fatih Bulut (Cambridge, MA); Melissa Ailem (Los Angeles, CA)
Assignee: Microsoft Technology Licensing, LLC
G06F21/554G06N3/0475G06N3/08H04L63/1425H04L63/1441H04L63/20G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,730,885
App. No.
18/393,652
Granted
Sep 8, 2026
Kind
B2
Abstract

The present disclosure provides methods, systems and computer readable media for training and implementing a generative machine learning model for identifying and mitigating security threats. Certain examples relate to generative model training, in which a training image is provided to a generative machine learning (ML) model in a training prompt, with an Indicator of Compromise (IoC) prediction instruction pertaining to the first security image. The model generates a predicted IoC and a parameter of the model is updated based on a loss function that quantifies error between a ground truth IoC and the predicted IoC. Other examples relate to the use of trained generative models for cybersecurity. A mitigation prompt comprising a second security image and an associated mitigation instruction is provided to a trained generative model. The model outputs an indication of a cybersecurity mitigation action based on the mitigation prompt, and the cybersecurity mitigation action is performed on the system. Certain example embodiments identify and automatically mitigate security issues using a multimodal generative model (MGM) though appropriate prompt engineering.

Claims (93)

1 . A computer-implemented method, comprising:

receiving, from a training set, a first security image and a ground truth indicator of compromise (IoC) associated with the first security image, wherein:

the ground truth IoC is a true reference IoC relating to a particular type or category of cyberthreat;

the first security image comprises a first visual representation of a first cybersecurity threat; and

the first visual representation depicts a relationship between an alert corresponding to the first cybersecurity threat and an entity associated with the alert;

inputting, to a generative machine learning (ML) model, at least one training prompt comprising the first security image and an IoC prediction instruction that requests identification of an IoC based on the depicted relationship between the alert and the entity;

receiving a predicted IoC generated by the generative ML model based on the at least one training prompt;

updating a parameter of the generative ML model based on a training loss function that quantifies error between the ground truth IoC and the predicted IoC, wherein the updating produces an updated generative ML model;

receiving a second security image pertaining to a system, wherein:

the second security image comprises a visual incident graph that visualizes a second cybersecurity threat and is generated or collected in response to detection of the second cybersecurity threat; and

the visual incident graph comprises an alert node representing the second cybersecurity threat and an entity node representing an entity associated with the alert node;

inputting, to the updated generative ML model, at least one mitigation prompt comprising:

the second security image;

an extraction instruction requesting extraction of a security insight from the visual incident graph; and

a mitigation instruction to determine a cybersecurity mitigation action based on the security insight;

receiving an indication of the cybersecurity mitigation action generated by the updated generative ML model based on the at least one mitigation prompt; and

causing the cybersecurity mitigation action to be performed on the system.

2 . The computer-implemented method of claim 1 , wherein:

the generative ML model is multi-modal;

the at least one training prompt comprises first text associated with the first security image; and

the at least one mitigation prompt comprises second text associated with the second security image.

3 . The computer-implemented method of claim 1 , wherein:

the second security image is received from a cybersecurity detector deployed in the system; and

the second security image is generated by the cybersecurity detector in response to the second cybersecurity threat.

4 . The computer-implemented method of claim 1 , wherein:

the at least one training prompt comprises both the first security image and text associated with the first security image; and

the generative ML model is configured to jointly process visual features extracted from the first security image and textual features extracted from the text associated with the first security image to identify the predicted IoC.

5 . The computer-implemented method of claim 1 , wherein the security insight is based on a connection between the entity node and the alert node in the second security image.

6 . The computer-implemented method of claim 5 , wherein:

the generative ML model is multi-modal;

the at least one mitigation prompt comprises third text associated with the second cybersecurity threat; and

the extraction instruction instructs the updated generative ML model to extract the security insight based on the third text.

7 . The computer-implemented method of claim 5 , wherein the security insight identifies a compromised entity, and the cybersecurity mitigation action comprises blocking, quarantining or isolating the compromised entity.

8 . The computer-implemented method of claim 1 , wherein:

the at least one mitigation prompt comprises a code generation instruction;

the indication of the cybersecurity mitigation action comprises computer-readable code embodying the cybersecurity mitigation action; and

the causing of the cybersecurity mitigation action to be performed comprises executing the computer-readable code.

9 . The computer-implemented method of claim 8 , wherein the mitigation instruction instructs the updated generative ML model to generate a report comprising generated text data and generated image data indicating the cybersecurity mitigation action, wherein the generated image data comprises at least one of: a security incident diagram, a visual mitigation workflow, or a graphical representation of one or more compromised components; and

the code generation instruction instructs the updated generative ML model to generate the computer-readable code based on the generated text data and the generated image data.

10 . The computer-implemented method of claim 8 , wherein the at least one mitigation prompt comprises:

a first mitigation prompt comprising the extraction instruction, and

a second mitigation prompt comprising the mitigation instruction and the code generation instruction.

11 . The computer-implemented method of claim 10 , wherein the first mitigation prompt is input to the updated generative ML model in a first chat session, and the second mitigation prompt is input to the updated generative ML model in a second chat session.

12 . The computer-implemented method of claim 1 , wherein:

responsive to the mitigation instruction, the updated generative ML model generates a report comprising generated text data and generated image data, wherein:

the report indicates the cybersecurity mitigation action; and

the generated image data comprises at least one of a security incident diagram, a visual mitigation workflow, or a graphical representation of one or more compromised components.

13 . A computer system comprising:

a memory configured to store computer-readable instructions; and

a hardware processor coupled to the memory, wherein the computer-readable instructions are configured to cause the hardware processor to:

receive a training security image and a ground truth indicator of compromise (IoC) associated with the training security image, wherein:

the ground truth IoC is a true reference IoC relating to a particular type or category of cyberthreat;

the training security image comprises a first visual representation of a first cybersecurity threat; and

the first visual representation depicts a relationship between an alert corresponding to the first cybersecurity threat and an entity associated with the alert;

input, to a multi-modal generative machine learning (ML) model, a training prompt comprising the training security image and an IoC prediction instruction that requests identification of an IoC based on the depicted relationship between the alert and the entity associated with the alert;

receive a predicted IoC generated by the generative ML model based on the training prompt; and

update a parameter of the generative ML model based on a training loss function that quantifies error between the ground truth IoC and the predicted IoC, wherein the updating produces an updated generative ML model;

receive a security image pertaining to a system, wherein:

the security image comprises a visual incident graph that visualizes a cybersecurity threat and is generated or collected in response to detection of the cybersecurity threat; and

the visual incident graph comprises an alert node representing the cybersecurity threat and an entity node representing an entity associated with the cybersecurity threat;

submit, to the updated generative ML model, a mitigation prompt comprising:

the security image;

an extraction instruction requesting extraction of a security insight from the visual incident graph; and

a mitigation instruction to determine a cybersecurity mitigation action based on the security insight; and

a code generation instruction that instructs the updated generative ML model to generate computer-readable code based on the cybersecurity mitigation action;

receive, from the updated generative ML model and based on the mitigation prompt, the computer-readable code, the computer-readable code embodying the cybersecurity mitigation action; and

execute the computer-readable code whereby the cybersecurity mitigation action is performed on the system.

14 . The system of claim 13 , wherein the training prompt comprises training text associated with the training security image.

15 . The system of claim 13 , wherein the security image is received from a cybersecurity detector deployed in the system, the security image having been generated by the cybersecurity detector in response to a cyberthreat detected in the system.

16 . The system of claim 13 , wherein:

the security insight identifies a compromised entity; and

the cybersecurity mitigation action includes blocking, quarantining, or isolating a compromised entity.

17 . The system of claim 13 , wherein the mitigation prompt comprises:

a first mitigation prompt comprising the extraction instruction, and

a second mitigation prompt comprising the mitigation instruction and the code generation instruction.

18 . The system of claim 17 , wherein the computer-readable instructions are further configured to cause the hardware processor to submit the first mitigation prompt as input to the updated generative ML model in a first chat session, and to submit the second mitigation prompt as input to the updated generative ML model in a second chat session.

19 . A non-transitory computer storage medium embodying computer-readable instructions, the computer-readable instructions configured upon execution on a hardware processor to cause the hardware processor to:

receive from a training set a first security image and a ground truth indicator of compromise (IoC) associated with the first security image, wherein:

the ground truth IoC is a true reference IoC relating to a particular type or category of cyberthreat;

the first security image comprises a first visual representation of a first cybersecurity threat; and

the first visual representation depicts a relationship between an alert corresponding to the first cybersecurity threat and an entity associated with the alert;

input, to a generative machine learning (ML) model, a training prompt comprising the first security image and an IoC prediction instruction that requests identification of an IoC based on the depicted relationship between the alert and the entity;

receive a predicted IoC generated by the generative ML model based on the training prompt;

update a parameter of the generative ML model based on a training loss function that quantifies error between the ground truth IoC and the predicted IoC, wherein the updating produces an updated generative ML model;

receive a second security image pertaining to a system, wherein:

the second security image comprises a visual incident graph that visualizes a second cybersecurity threat and is generated or collected in response to detection of the second cybersecurity threat;

the visual incident graph comprises an alert node representing the second cybersecurity threat and an entity node representing an entity associated with the alert node;

input, to the updated generative ML model, a mitigation prompt comprising:

the second security image;

an extraction instruction requesting extraction of a security insight from the visual incident graph; and

a mitigation instruction to determine a cybersecurity mitigation action based on the security insight;

receive an indication of the cybersecurity mitigation action generated by the updated generative ML model based on the mitigation prompt; and

cause the cybersecurity mitigation action to be performed on the system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 2, 2024
From: SANKARAN, ANUSH; MOVVA, SRISUMA; WICKER, ANDREW WHITE; BULUT, MUHAMMED FATIH; AILEM, MELISSA
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 068459/0318 →
Continuity (1)
Related Publication 20250209156A1 · Jun 26, 2025
References Cited (40)
US 10050868B2 · Porras · 2018 [cited by examiner]
US 10418036B1 · Roturier · 2019 [cited by examiner]
US 10643216B2 · Sadaghiani · 2020 [cited by examiner]
US 11757907B1 · Berger · 2023 [cited by examiner]
US 11829486B1 · Lambotte · 2023 [cited by examiner]
US 11882148B1 · Hagen · 2024 [cited by examiner]
US 11979425B2 · Thakur · 2024 [cited by examiner]
US 12019756B1 · Donovan · 2024 [cited by examiner]
US 20070192865A1 · Mackin · 2007 [cited by examiner]
US 20080010225A1 · Gonsalves · 2008 [cited by examiner]
US 20130298244A1 · Kumar · 2013 [cited by examiner]
US 20160164919A1 · Satish · 2016 [cited by examiner]
US 20160219048A1 · Porras · 2016 [cited by examiner]
US 20180146002A1 · Canfield · 2018 [cited by examiner]
US 20190334933A1 · Teshome · 2019 [cited by examiner]
US 20220038489A1 · Thakur · 2022 [cited by examiner]
US 20220414463A1 · Mittal et al. · 2022 [cited by applicant]
US 20230009127A1 · Boyer · 2023 [cited by examiner]
US 20230336573A1 · Jones · 2023 [cited by examiner]
US 20230336574A1 · Rozenbaum · 2023 [cited by examiner]
US 20240045990A1 · Boyer · 2024 [cited by examiner]
US 20240111665A1 · Berko · 2024 [cited by examiner]
US 20250209156A1 · Sankaran · 2025 [cited by examiner]
US 20250260708A1 · Miron · 2025 [cited by examiner]
US 20250379885A1 · Murphy · 2025 [cited by examiner]
International Search Report and Written Opinion received for PCT Application No. PCT/US2024/057584, mailed on Nov. 12, 2025, 15 pages. [cited by applicant]
Adam C, et al., “Large Language Models and Intelligence Analysis”, Retrieved From: https://cetas.turing.ac.uk/publications/large-language-models-and-intelligence-analysis, Jul. 5, 2023, 14 pages. [cited by applicant]
Bolanos, et al., “What is Semantic Kernel?”, Retrieved From: https://web.archive.org/web/20230711204340/https://learn.microsoft.com/en-us/semantic-kernel/overview/, Jul. 11, 2023, 7 pages. [cited by applicant]
Bolanos, Matthew, “Understanding the kernel”, Retrieved From: https://learn.microsoft.com/en-us/semantickernel/concepts/kernel?tabs=Csharp&pivots=programming-language-csharp, Apr. 16, 2025, 4 pages. [cited by applicant]
Driess, Danny, “Palm-E: An Embodied Multimodal Language Model”, Retrieved From: https://research.google/blog/palm-e-an-embodied-multimodal-language-model/, Mar. 10, 2023, 10 pages. [cited by applicant]
Ferrag, et al., “Revolutionizing Cyber Threat Detection with Large Language Models: A privacy-preserving BERT-based Lightweight Model for Iot/IIot Devices”, In Repository of arXiv:2306. 14263v2, Feb. 8, 2024, 16 pages. [cited by applicant]
Geib, et al., “Microsoft Threat Modeling Tool”, Retrieved From: https://learn.microsoft.com/en-us/azure/security/develop/threat-modeling-tool, Aug. 25, 2022, 2 pages. [cited by applicant]
Huang, et al., “Language Is Not All You Need: Aligning Perception with Language Models”, In Repository of arXiv:2302.14045v2, Mar. 1, 2023, 26 pages. [cited by applicant]
Lemos, Robert, “Large Language AI Models Have Real Security Benefits”, Retrieved From: https://www.darkreading.com/cyber-risk/large-language-ai-models-have-real-security-benefits, Aug. 3, 2022, 4 pages. [cited by applicant]
Saxe, et al., “GPT-3 and Me: How Supercomputer-scale Neural Network Models Apply to Defensive Cybersecurity Problems”, Retrieved From: https://i.blackhat.com/USA-22/Wednesday/US-22-Saxe-GPT3-and-Me.pdf, Aug. 10, 2023, 5… [cited by applicant]
Shostack, Adam, “Security Briefs—Getting Started With The SDL Threat Modeling Tool”, Retrieved From: https://learn.microsoft.com/en-us/archive/msdn-magazine/2009/january/security-briefs-getting-started-with-the-sdl-thre… [cited by applicant]
Wei, et al., “Language Models Perform Reasoning via Chain of Thought”, Retrieved From: https://research.google/blog/language-models-perform-reasoning-via-chain-of-thought/, May 11, 2022. [cited by applicant]
Yin, et al., “A Survey on Multimodal Large Language Models”, In Repository of arXiv:2306.13549v4, Nov. 29, 2024, 18 pages. [cited by applicant]
Zhang, et al., “Multimodal Chain-of-Thought Reasoning in Language Models”, In Repository of arXiv:2302.00923v1, Feb. 2, 2023, 18 pages. [cited by applicant]
International Preliminary Report on Patentability (Chapter I) received for PCT Application No. PCT/US2024/057584, mailed on Jul. 2, 2026, 09 pages. [cited by applicant]