IP Library Granted Patent US 12,488,104
Granted Patent B2
US 12,488,104 · App. 18/620,303 · Granted Dec 2, 2025

Adaptive detection of security threats through training of computer-implemented models

Inventors: Lei Xu (New York, NY); Jeshua Alexis Bratman (New York, NY)
Assignee: Abnormal AI, Inc.
G06F21/554G06F2221/031
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,488,104
App. No.
18/620,303
Granted
Dec 2, 2025
Kind
B2
Abstract

A generated training set comprising a plurality of training samples is received. The generated training set includes at least one training sample constructed using one or more linguistic hints, comprising at least one keyword of phrase, about an attack for which malicious textual communications associated with the attack, when processed by a natural language processing model could be classified as benign textual communications before being trained using the generated training set. The natural language processing model is trained at least in part by using the generated training set, wherein the trained natural language processing model is configured to determine a likelihood that a received communication transmitted by a sender to a recipient poses a risk.

Claims (31)

1 . A system, comprising:

a processor configured to:

receive a user report identifying at least one malicious communication that was previously misclassified as a benign communication by a natural language processing model;

based at least in part in response to the user report associated with the misclassification by the natural language processing model, generate a training set comprising a plurality of training samples, wherein the generated training set includes at least one training sample constructed using one or more linguistic hints derived from the user-reported at least one malicious communication that was previously misclassified as benign, comprising at least one keyword or phrase, about an attack for which malicious textual communications associated with the attack, when processed by the natural language processing model, could be classified as benign textual communications before being trained using the generated training set; and

further train the natural language processing model at least in part by using the generated training set, wherein the trained natural language processing model is configured to determine a likelihood that a received communication transmitted by a sender to a recipient poses a risk; and

a memory coupled to the processor and configured to provide the processor with instructions.

2 . The system of claim 1 , wherein the natural language processing model is trained in response to a report of a malicious email.

3 . The system of claim 1 , wherein the natural language processing model is trained in response to a specification of a novel attack.

4 . The system of claim 1 , wherein the natural language processing model is trained in response to an indication that a threshold quantity of false negatives is available for training purposes.

5 . The system of claim 1 , wherein the generated training set is generated including by performing a text augmentation on an exemplar malicious message.

6 . The system of claim 5 , wherein performing the text augmentation includes programmatically altering individual characters of the exemplar malicious message.

7 . The system of claim 5 , wherein performing the text augmentation includes programmatically altering one or more words of the exemplar malicious message.

8 . The system of claim 5 , wherein performing the text augmentation includes programmatically altering one or more clauses of the exemplar malicious message.

9 . The system of claim 5 , wherein performing the text augmentation includes replacing an element of the exemplar malicious message with a semantic equivalent.

10 . The system of claim 9 , wherein the semantic equivalent comprises a word synonym.

11 . The system of claim 9 , wherein the semantic equivalent comprises a phrase.

12 . The system of claim 1 , wherein the generated training set of training samples is generated including by modifying a predetermined amount of an exemplar malicious message.

13 . The system of claim 1 , wherein training the natural language processing model includes training a word-level convolutional neural network that predicts an attack label of an email.

14 . The system of claim 1 , wherein training the natural language processing model includes training a character-level convolutional neural network that predicts an attack label of an email.

15 . The system of claim 1 , wherein the processor is further configured to take a remedial action in response to determining that the received communication poses the risk.

16 . A method, comprising:

receiving a user report identifying at least one malicious communication that was previously misclassified as a benign communication by a natural language processing model;

based at least in part in response to the user report associated with the misclassification by the natural language processing model, generating a training set comprising a plurality of training samples, wherein the generated training set includes at least one training sample constructed using one or more linguistic hints derived from the user-reported at least one malicious communication that was previously misclassified as benign, comprising at least one keyword or phrase, about an attack for which malicious textual communications associated with the attack, when processed by the natural language processing model, could be classified as benign textual communications before being trained using the generated training set; and

further training the natural language processing model at least in part by using the generated training set, wherein the trained natural language processing model is configured to determine a likelihood that a received communication transmitted by a sender to a recipient poses a risk.

17 . The method of claim 16 , wherein training the natural language processing model includes training a word-level convolutional neural network that predicts an attack label of an email.

18 . The method of claim 16 , wherein training the natural language processing model includes training a character-level convolutional neural network that predicts an attack label of an email.

19 . The method of claim 16 , further comprising taking a remedial action in response to determining that the received communication poses the risk.

20 . A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

receiving a user report identifying at least one malicious communication that was previously misclassified as a benign communication by a natural language processing model;

based at least in part in response to the user report associated with the misclassification by the natural language processing model, generating a training set comprising a plurality of training samples, wherein the generated training set includes at least one training sample constructed using one or more linguistic hints derived from the user-reported at least one malicious communication that was previously misclassified as benign, comprising at least one keyword or phrase, about an attack for which malicious textual communications associated with the attack, when processed by the natural language processing model, could be classified as benign textual communications before being trained using the generated training set; and

further training the natural language processing model at least in part by using the generated training set, wherein the trained natural language processing model is configured to determine a likelihood that a received communication transmitted by a sender to a recipient poses a risk.

Continuity (3)
Continuation 17871765 · Jul 22, 2022
Provisional Application 63225021 · Jul 23, 2021
Related Publication 20240289449A1 · Aug 29, 2024
References Cited (16)
US 10404745B2 · Verma · 2019 [cited by examiner]
US 10885469B2 · Brabec · 2021 [cited by examiner]
US 11222112B1 · Satpathy · 2022 [cited by examiner]
US 20170093771A1 · Gatti · 2017 [cited by examiner]
US 20190199736A1 · Howard · 2019 [cited by examiner]
US 20190215329A1 · Levy · 2019 [cited by examiner]
US 20200366712A1 · Onut · 2020 [cited by examiner]
US 20210352093A1 · Hassanzadeh · 2021 [cited by examiner]
US 20210406366A1 · Betser · 2021 [cited by examiner]
Alsufyani et al., Social Engineering Attack Detection Using Machine Learning: Text Phishing Attack, Indian Journal of Computer Science and Engineering (IJCSE), 2021, pp. 743-751, vol. 12, No. 3. [cited by applicant]
Information Security Media Group, ‘Multi-Channel Fraud: A Defense Plan’, Retrieved on Apr. 18, 2021 (Apr. 18, 2021) from <https ://www .bankInfosecurity.com/Interviews/multi-channel-fraud-defense-plan-i-1799>, Feb. 20, … [cited by applicant]
Lansley et al., SEADer: A Social Engineering Attack Detection Method Based on Natural Language Processing and Artificial Neural Networks, Nguyen, N., Chbeir, R., Exposito, E., Aniorté, P., Trawiński, B. (eds) Computatio… [cited by applicant]
Lansley et al., SEADer++: Social Engineering Attack Detection in Online Environments Using Machine Learning, Journal of Information and Telecommunication, 2020, pp. 346-362, vol. 4, No. 3. [cited by applicant]
Lauinger et al., Honeybot, Your Man in the Middle for Automated Social Engineering, LEET, Apr. 2010, pp. 1-8. [cited by applicant]
Proofpoint (Proofpoint Closed-Loop Email Analysis and Response, Aug. 2018, 2 pages) (Year: 2018). [cited by applicant]
Raskin et al., Ontological Semantic Technology for Detecting Insider Threat and Social Engineering, Proceedings of the 2010 New Security Paradigms Workshop, Sep. 2010, pp. 115-128. [cited by applicant]