IP Library Granted Patent US 12,131,121
Granted Patent B2
US 12,131,121 · App. 18/447,085 · Granted Oct 29, 2024

Detecting information operations campaigns in social media with machine learning

Inventor: Philip Tully (New York, NY)
Assignee: GOOGLE LLC
G06F40/284G06F40/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,131,121
App. No.
18/447,085
Granted
Oct 29, 2024
Kind
B2
Abstract

A processor-implemented method for detecting an information operations campaign includes retrieving a first neural network language model including a natural language model trained on a first dataset. The first neural network language model is modified, via transfer learning and based on a second dataset, to produce a second neural network language model. Social media post data associated with a social media post is received, and features are extracted from the social media post data. The features are tokenized to produce at least one token including a value. A prediction score for the at least one token is generated using the trained neural network language model. If the prediction score exceeds a threshold value, a threat warning including a representation associated with at least one of the social media post or an account associated with the social media post is generated.

Claims (50)

1. A non-transitory processor-readable storage medium storing processor- executable instructions to:

receive social media post data associated with a social media post; extract a plurality of features from the social media post data;

tokenize the plurality of features to produce at least one token;

send a representation of the at least one token to a neural network language model for generation of a prediction score for the at least one token;

if the prediction score exceeds a threshold value:

generate a threat warning including a representation associated with at least one of the social media post or an account associated with the social media post, and

generate a threat report for presentation to a data analyst, the threat report including the representation associated with the at least one of the social media post or the account associated with the social media post;

assign a classification to the social media post, the classification being based on a multidimensional representation including a value of a maliciousness metric and a value of an authenticity metric; and

include a representation of the classification in the threat report.

2. The non-transitory processor-readable storage medium of claim 1 , further storing processor-executable instructions to receive, from the neural network language model, a classification for the social media post that includes a representation of an information operations campaign.

3. The non-transitory processor-readable storage medium of claim 1 , wherein the instructions to tokenize the plurality of features include instructions to:

partition the social media post data into a plurality of data partitions based on pre-defined locations within the social media post data; and

associate each data partition from the plurality of data partitions with a value, the instructions to generate the prediction score for the at least one token include instructions to send the values to the neural network language model.

4. The non-transitory processor-readable storage medium of claim 1 , wherein the neural network language model is configured to generate the prediction score using a neural attention mechanism.

5. The non-transitory processor-readable storage medium of claim 1 , further storing processor-executable instructions to determine a scope of an information operations campaign based on at least one of the social media post data or the prediction score.

6. A method, comprising:

receiving social media post data associated with a social media post; extract a plurality of features from the social media post data;

tokenizing the plurality of features to produce at least one token;

sending a representation of the at least one token to a neural network language model for generation of a prediction score for the at least one token;

if the prediction score exceeds a threshold value:

generating a threat warning including a representation associated with at least one of the social media post or an account associated with the social media post, and

generating a threat report for presentation to a data analyst, the threat report including the representation associated with the at least one of the social media post or the account associated with the social media post;

assigning a classification to the social media post, the classification being based on a multidimensional representation including a value of a maliciousness metric and a value of an authenticity metric; and

including a representation of the classification in the threat report.

7. The method of claim 6 , further comprising:

receiving, from the neural network language model, a classification for the social media post that includes a representation of an information operations campaign.

8. The method of claim 6 , further comprising:

partitioning the social media post data into a plurality of data partitions based on pre-defined locations within the social media post data;

associating each data partition from the plurality of data partitions with a value; and

generating the prediction score for the at least one token include instructions to send the values to the neural network language model.

9. The method of claim 6 , wherein the neural network language model is configured to generate the prediction score using a neural attention mechanism.

10. The method of claim 6 , further storing processor-executable instructions to determine a scope of an information operations campaign based on at least one of the social media post data or the prediction score.

11. A system, comprising:

a processor; and

a memory operably coupled to the processor, the memory storing instructions that, when executed by the processor, cause the processor to perform operations, the operations comprising:

receiving social media post data associated with a social media post; extract a plurality of features from the social media post data;

tokenizing the plurality of features to produce at least one token;

sending a representation of the at least one token to a neural network language model for generation of a prediction score for the at least one token;

if the prediction score exceeds a threshold value:

generating a threat warning including a representation associated with at least one of the social media post or an account associated with the social media post, and

generating a threat report for presentation to a data analyst, the threat report including the representation associated with the at least one of the social media post or the account associated with the social media post;

assigning a classification to the social media post, the classification being based on a multidimensional representation including a value of a maliciousness metric and a value of an authenticity metric; and

including a representation of the classification in the threat report.

12. The system of claim 11 , further comprising:

receiving, from the neural network language model, a classification for the social media post that includes a representation of an information operations campaign.

13. The system of claim 11 , further comprising:

partitioning the social media post data into a plurality of data partitions based on pre-defined locations within the social media post data; and

associating each data partition from the plurality of data partitions with a value, the instructions to generate the prediction score for the at least one token include instructions to send the values to the neural network language model.

14. The system of claim 11 , wherein the neural network language model is configured to generate the prediction score using a neural attention mechanism.

15. The system of claim 11 , further storing processor-executable instructions to determine a scope of an information operations campaign based on at least one of the social media post data or the prediction score.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 9, 2024
From: TULLY, PHILIP
To: FIREEYE, INC.
Reel/Frame 067041/0931 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 9, 2024
From: MANDIANT, INC.
To: GOOGLE LLC
Reel/Frame 067041/0941 →
CHANGE OF NAME Recorded Apr 9, 2024
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 067042/0068 →
Continuity (2)
Division 17012924 · Sep 4, 2020
Related Publication 20230385548A1 · Nov 30, 2023