IP Library › Granted Patent US 12,621,317
Granted Patent B1
US 12,621,317 · App. 18/886,580 · Granted May 5, 2026

Unsupervised anomalous access detection using sentence-based feature embeddings

Inventor: Chenming Xu (Seattle, WA)
Assignee: Amazon Technologies, Inc.
H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,621,317
App. No.
18/886,580
Granted
May 5, 2026
Kind
B1
Abstract

Techniques for unsupervised anomalous access detection using sentence-based feature embeddings are described. Entity data describing users having access to a particular computing resource is obtained from a computing system and utilized, according to a sentence template, to construct descriptive sentences in a natural language format. The sentences are used to create dense vector embeddings via a sentence transformer machine learning (ML) model. The dense vector embeddings are used as input to an unsupervised anomaly detection ML model to detect anomalous users, which can be presented to an administrator.

Claims (57)

1 . A computer-implemented method comprising:

receiving a request, at an anomalous access service (AAS) of a cloud provider network, to determine whether a permission for a user to access a computing resource hosted in the cloud provider network is anomalous;

generating, by the AAS, a string value based on a template and at least some metadata associated with the user, the string value comprising a natural language sentence, the natural language sentence including, from the metadata, at least a job title of the user and a geographic location of the user;

transforming, by the AAS, the string value into a vector embedding based on use of a first machine learning (ML) model, wherein the first ML model is a sentence transformer model;

determining, by the AAS, that the permission for the user to access the computing resource is anomalous, comprising providing the vector embedding as an input to a second ML model, wherein the second ML model comprises an unsupervised anomaly detection model that was trained based on a collection of embeddings corresponding to other users;

causing, by the AAS, an indication to be presented, via a user interface, that the user having the permission to access the computing resource is anomalous;

receiving, at the cloud provider network, a request to remove or disable the permission to access the computing resource for the user; and

updating, by the cloud provider network, a permissions datastore to remove or disable the permission to access the computing resource for the user.

2 . The computer-implemented method of claim 1 , wherein determining that the permission to access the computing resource is anomalous comprises:

obtaining an anomaly score as a result of providing the vector embedding as the input to the second ML model; and

determining that the anomaly score meets or exceeds a threshold value.

3 . The computer-implemented method of claim 2 , wherein:

the threshold value is a user-configured value provided by a different user; or

the threshold value is determined as part of a training of the second ML model.

4 . A computer-implemented method comprising:

receiving a request, at an anomalous access service (AAS) of a cloud provider network, to determine whether an access or permission involving a user for a computing resource hosted in the cloud provider network is anomalous;

generating, by the AAS, a string value based on a template and at least some metadata associated with the user, the string value comprising a natural language sentence;

transforming, by the AAS, the string value into a vector embedding based on use of a first machine learning (ML) model;

determining, by the AAS, that the access or permission is anomalous, comprising providing the vector embedding as an input to a second ML model, wherein the second ML model was trained using other vector embeddings generated based on sentences corresponding to other users; and

causing, by the AAS, an indication of the determination to be provided.

5 . The computer-implemented method of claim 4 , wherein determining that the access or permission is anomalous comprises obtaining an anomaly score as a result of providing the vector embedding as the input to the second ML model.

6 . The computer-implemented method of claim 5 , wherein determining that the access or permission is anomalous further comprises determining that the anomaly score meets or exceeds a threshold value.

7 . The computer-implemented method of claim 6 , wherein the threshold value is a user-configured value provided by a different user.

8 . The computer-implemented method of claim 6 , wherein the threshold value is determined as part of the training of the second ML model.

9 . The computer-implemented method of claim 4 , wherein the metadata comprises employee information of an organization, and wherein the method further comprises obtaining, by the AAS, the metadata from the electronic directory.

10 . The computer-implemented method of claim 9 , wherein the string value includes a textual description of one or more of:

a job title of the user;

a work location of the user;

a job title of a manager of the user;

a department name or department identifier of the user; or

an amount of time that the user has been with the organization or within a subgroup of the organization.

11 . The computer-implemented method of claim 4 , wherein the metadata comprises computing activity metadata collected from one or more host computing devices of the cloud provider network.

12 . The computer-implemented method of claim 4 , wherein the request pertains to a proposed addition of the user to a group of an organization or a proposed configuration of permissions for the user.

13 . The computer-implemented method of claim 4 , wherein:

the first ML model is a sentence transformer model; and

the second ML model is an unsupervised anomaly detection model.

14 . The computer-implemented method of claim 4 , further comprising:

selecting, by the AAS based on the request, at least one of the first ML model or the second ML model for use.

15 . A system comprising:

a first one or more computing devices to implement a storage service in a multi-tenant cloud provider network, the storage service to store metadata associated with a user; and

a second one or more computing devices to implement an anomalous access service (AAS) in the multi-tenant cloud provider network, the AAS including instructions that upon execution cause the AAS service to:

receive a request to determine whether an access or permission involving the user for a computing resource hosted in the cloud provider network is anomalous;

obtain the metadata from the storage service;

generate a string value based on a template and at least some of the metadata associated with the user, the string value comprising a natural language sentence;

transform the string value into a vector embedding based on use of a first machine learning (ML) model;

determine that the access or permission is anomalous, comprising providing the vector embedding as an input to a second ML model, wherein the second ML model was trained using other vector embeddings generated based on sentences corresponding to other users; and

cause an indication of the determination to be provided.

16 . The system of claim 15 , wherein to determine that the access or permission is anomalous the AAS is at least to obtain an anomaly score as a result of providing the vector embedding as the input to the second ML model.

17 . The system of claim 16 , wherein to determine that the access or permission is anomalous the AAS is at least further to determine that the anomaly score meets or exceeds a threshold value.

18 . The system of claim 17 , wherein the threshold value is a user-configured value provided by a different user.

19 . The system of claim 17 , wherein the threshold value is determined as part of a training of the second ML model.

20 . The system of claim 15 , wherein the string value includes a textual description of one or more of:

a job title of the user;

a work location of the user;

a job title of a manager of the user;

a department name or department identifier of the user; or

an amount of time that the user has been with an organization or within a subgroup of the organization.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2024
From: XU, CHENMING
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 068667/0344 →
References Cited (26)
US 10803169B1 · Flatten · 2020 [cited by examiner]
US 11977536B2 · Gonzalez Macias · 2024 [cited by examiner]
US 12033048B1 · Callot · 2024 [cited by examiner]
US 12073182B2 · Orhan · 2024 [cited by examiner]
US 12112252B1 · Chen · 2024 [cited by examiner]
US 12210622B1 · Zhang · 2025 [cited by examiner]
US 12393773B1 · Dolan · 2025 [cited by examiner]
US 20170118239A1 · Most · 2017 [cited by examiner]
US 20200285737A1 · Kraus · 2020 [cited by examiner]
US 20200412726A1 · Nevatia · 2020 [cited by examiner]
US 20210397971A1 · Pardeshi · 2021 [cited by examiner]
US 20220124110A1 · Chhabra · 2022 [cited by examiner]
US 20220171995A1 · Balasubramanian · 2022 [cited by examiner]
US 20220342860A1 · Gonzalez Macias · 2022 [cited by examiner]
US 20220358289A1 · Chen · 2022 [cited by examiner]
US 20230033818A1 · Baughman · 2023 [cited by examiner]
US 20230267198A1 · Karpovsky · 2023 [cited by examiner]
US 20240112015A1 · Inzelberg · 2024 [cited by examiner]
US 20240126795A1 · Zhong · 2024 [cited by examiner]
US 20240305453A1 · Alsahnawi · 2024 [cited by examiner]
US 20250086521A1 · Farnan · 2025 [cited by examiner]
US 20250088529A1 · Douglas · 2025 [cited by examiner]
US 20250150347A1 · Niv · 2025 [cited by examiner]
“Benchmarks: Latest ADBench (2022)”; pyod 2.0.2 documentation; downloaded from <https://pyod.readthedocs.io/en/latest/benchmark.html> on Sep. 16, 2024, 6 pages. [cited by applicant]
Han, Songqiao et al., “ADBench: Anomaly Detection Benchmark”; 36th Conference on Neural Information Processing Systems, 2022; arXiv:2206.09426v2; 45 pages. [cited by applicant]
“Isolation Forest”; Wikipedia; downloaded from <https://en.wikipedia.org/w/index.php?title=Isolation_forest&oldid=1194896889> on Jul. 1, 2024, 5 pages. [cited by applicant]