IP Library › Granted Patent US 12,462,153
Granted Patent B2
US 12,462,153 · App. 16/898,290 · Granted Nov 4, 2025

Behavior modeling using client-hosted neural networks

Inventors: Christopher Ian Schneider (Hillend, GB); Amy Leigh Rose (Chapel Hill, NC); Andrew James Woodard (Buckinghamshire, GB); Benjemin Thomas Waine (Cheshunt, GB)
Assignee: NVIDIA Corporation
G06N3/08G06N3/045H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,462,153
App. No.
16/898,290
Filed
Jun 10, 2020
Granted
Nov 4, 2025
Kind
B2
Art Unit
2641
USPC
706/20
Abstract

Apparatuses, systems, and techniques to detect abnormal behavior on clients using one or more neural networks on said clients. In at least one embodiment, use of or behavior on one or more clients is analyzed by a first neural network to detect abnormal behavior compared to a baseline of accepted behavior, and said baseline of accepted behavior is revised over time by a second neural network based on behavior observed on said one or more clients.

Claims (60)

1. A system comprising:

one or more processors to use one or more local neural networks to identify abnormal activity within one or more first computer systems within a plurality of computer systems based, at least in part, on abnormal activity identified within one or more second computer systems within the plurality of computer systems using one or more baseline neural networks, wherein a determination of whether one or more activities are to be identified by the one or more baseline neural networks as abnormal is updated using the one or more activities identified by the one or more local neural networks.

2. The system of claim 1 , wherein:

the one or more first computer systems determines a set of first activities;

the one or more second computer systems of the plurality of computer systems determine a set of second activities;

the one or more baseline neural networks infer a set of accepted activities based, at least in part, on the set of first activities and the set of second activities; and

the one or more local neural networks within the one or more first computer systems identify the abnormal activity based, at least in part, on the set of accepted activities.

3. The system of claim 2 , wherein each computer of the plurality of computer systems comprises a reputation value, and the one or more baseline neural networks infers the set of accepted activities based, at least in part, on the reputation value for each computer system of the plurality of computer systems.

4. The system of claim 2 , wherein the one or more local neural networks infer whether one or more third activities are based, at least in part, on if the one or more third activities comprise activities not included in the set of accepted activities.

5. The system of claim 2 , wherein:

the one or more first computer systems compute a cryptographic signature based, at least in part, on the set of first activities; and

the one or more baseline neural networks infer the set of accepted activities based, at least in part, on the set of first activities if the cryptographic signature indicates the set of first activities is from the one or more first computer systems.

6. The system of claim 1 , wherein the abnormal activity comprises a behavior by one or more users of the one or more first computer systems.

7. One or more processors, comprising:

circuitry to use one or more local neural networks to identify abnormal activity within one or more first computer systems within a plurality of computer systems based, at least in part, on abnormal activity identified within one or more second computer systems within the plurality of computer systems using one or more baseline neural networks, wherein a determination of whether one or more activities are to be identified by the one or more baseline neural networks as abnormal is updated using one or more activities identified by the one or more local neural networks.

8. The one or more processors of claim 7 , wherein:

the one or more local neural networks identify the abnormal activity based, at least in part on a first set of activities of the one or more first computer systems and a set of accepted activities;

the set of accepted activities is inferred by the one or more baseline neural networks based, at least in part, on a second set of activities of the plurality of computer systems and a third set of activities of the one or more first computer systems; and

the one or more local neural networks identify the abnormal activity when the set of accepted activities does not contain the one or more activities from the first set of activities.

9. The one or more processors of claim 8 , wherein the one or more baseline neural networks infer the set of accepted activities based, at least in part, on the third set of activities of the one or more first computer systems comprise a reputation value above a threshold value.

10. The one or more processors of claim 8 , wherein:

the one or more first computer systems cryptographically sign the third set of activities into a signed set of activities;

the signed set of activities is authenticated by a computer of the plurality of computer systems, the computer able to authenticate the one or more first computer systems and another of the plurality of computer systems; and

the one or more second computer systems infer the set of accepted activities based, at least in part, on the third set of activities if the signed set of activities is successfully authenticated.

11. The one or more processors of claim 8 , wherein:

the one or more first computer systems comprise a first reputation value;

the one or more baseline neural networks infer a second reputation value based, at least in part, on the third set of activities; and

the one or more first computer system updates the first reputation value based on the second reputation value.

12. The one or more processors of claim 8 , wherein each set of activities comprises data values representing one or more first users on the one or more first computer systems and one or more second users on each of the plurality of computer systems.

13. The one or more processors of claim 7 , wherein the one or more baseline neural networks infer new data values for the one or more local neural networks based, at least in part, on a plurality of activities from the plurality of computer systems.

14. A machine-readable medium having stored thereon a set of instructions, which if performed by one or more processors, cause the one or more processors to at least:

use one or more local neural networks to identify abnormal activity within one or more first computer systems within a plurality of computer systems based, at least in part, on abnormal activity identified within one or more second computer systems within the plurality of computer systems using one or more baseline neural networks, wherein a determination of whether one or more activities are to be identified by the one or more baseline neural networks as abnormal is updated using one or more activities identified by the one or more local neural networks.

15. The machine-readable medium of claim 14 , wherein:

the one or more local neural networks identify the abnormal activity based, at least in part on a first set of activities of the one or more first computer systems and a set of accepted activities;

the set of accepted activities is inferred by the one or more baseline neural networks based, at least in part, on a second set of activities of the plurality of computer systems and a third set of activities of the one or more first computer systems; and

the one or more local neural networks identify the abnormal activity when the set of accepted activities does not contain the one or more activities from the first set of activities.

16. The machine-readable medium of claim 15 , wherein the set of accepted activities comprise neural network data values representing the one or more activities by one or more users on the one or more first computer systems and the plurality of computer systems.

17. The machine-readable medium of claim 15 , wherein the one or more local neural networks infer that the one or more activities in the first set of activities are abnormal activities using one or more neural network data values received from the one or more baseline neural networks.

18. The machine-readable medium of claim 15 , wherein the set of accepted activities is inferred by the one or more baseline neural networks based, at least in part, on the second set of activities on the one or more first computer systems and the third set of activities on the one or more baseline neural networks.

19. The machine-readable medium of claim 18 , wherein the second set of activities comprises one or more neural network data values for training the one or more local neural networks.

20. The machine-readable medium of claim 18 , wherein:

the second set of activities are cryptographically signed by the one or more first computer systems;

the second set of activities are authenticated by an authority; and

if the second set of activities are successfully authenticated by the authority, the set of accepted activities is inferred based, at least in part, on the second set of activities.

21. The machine-readable medium of claim 14 , wherein the abnormal activity on the one or more first computer systems comprises one or more first behaviors by one or more first users of the one or more first computer systems, and the abnormal activity on the plurality of computer systems comprises one or more second behaviors by one or more second users on each of the plurality of computer systems.

22. A method comprising:

using one or more local neural networks to identify abnormal activity within one or more first computer systems within a plurality of computer systems based, at least in part, on abnormal activity identified within one or more second computer systems within the plurality of computer systems using one or more baseline neural networks, wherein a determination of whether one or more activities are to be identified by the one or more baseline neural networks as abnormal is updated using one or more activities identified by the one or more local neural networks.

23. The method of claim 22 , further comprising:

determining, by the one or more first computer systems, a first set of activities;

determining, by the plurality of computer systems, a second set of activities;

inferring, by the one or more baseline neural networks, a third set of activities based, at least in part, on the first set of activities and the second set of activities;

determining, by the one or more first computer systems, a fourth set of activities; and

detecting an abnormal activity by inferring, using the one or more local neural networks, whether the one or more activities of the fourth set of activities are contained in the third set of activities.

24. The method of claim 23 , wherein:

the one or more baseline neural networks infer one or more neural network values representing the third set of activities based, at least in part, on the first set of activities and the second set of activities; and

the one or more local neural networks are updated based, at least in part, on the one or more neural network values.

25. The method of claim 23 , wherein the one or more first computer systems cryptographically sign the first set of activities to obtain a set of signed activities, and the one or more baseline neural networks infer the third set of activities based, at least in part, on whether the set of signed activities is authenticated by an authority.

26. The method of claim 23 , wherein the one or more first computer systems comprises a reputation value, and the one or more baseline neural networks infer the third set of activities based, at least in part, on the reputation value.

27. The method of claim 26 , wherein the one or more baseline neural networks infer the third set of activities based, at least in part, on the first set of activities if the reputation value is greater than a threshold value.

28. The method of claim 22 , wherein the abnormal activity on the one or more first computer systems comprises one or more behaviors by one or more users of the one or more first computer systems.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 13, 2020
From: SCHNEIDER, CHRISTOPHER IAN; ROSE, AMY LEIGH; WOODARD, ANDREW JAMES; WAINE, BENJEMIN THOMAS
To: NVIDIA CORPORATION
Reel/Frame 053491/0822 →
Continuity (1)
Related Publication 20210397940A1 · Dec 23, 2021
References Cited (70)
US 5822741A · Fischthal · 1998 [cited by examiner]
US 6513025B1 · Rosen · 2003 [cited by examiner]
US 7275047B2 · Howard · 2007 [cited by examiner]
US 7681235B2 · Chesla · 2010 [cited by examiner]
US 8398546B2 · Pacione · 2013 [cited by examiner]
US 8800036B2 · Khayam · 2014 [cited by examiner]
US 9038178B1 · Lin · 2015 [cited by examiner]
US 9787705B1 · Love · 2017 [cited by examiner]
US 10884760B2 · Jung · 2021 [cited by examiner]
US 10938562B2 · Liu · 2021 [cited by examiner]
US 10970395B1 · Bansal · 2021 [cited by examiner]
US 11010233B1 · Golden · 2021 [cited by examiner]
US 11108795B2 · Lee · 2021 [cited by examiner]
US 11178170B2 · Kuppa · 2021 [cited by examiner]
US 11363037B2 · Karin · 2022 [cited by examiner]
US 11367323B1 · Shahidzadeh · 2022 [cited by examiner]
US 11522895B2 · Caithness · 2022 [cited by examiner]
US 11663500B2 · Rogers · 2023 [cited by examiner]
US 20040250124A1 · Chesla · 2004 [cited by examiner]
US 20070043690A1 · Inakoshi · 2007 [cited by examiner]
US 20070112824A1 · Lock · 2007 [cited by examiner]
US 20070245420A1 · Yong et al. · 2007 [cited by applicant]
US 20080222717A1 · Rothstein et al. · 2008 [cited by applicant]
US 20110185422A1 · Khayam · 2011 [cited by examiner]
US 20150100530A1 · Mnih · 2015 [cited by examiner]
US 20160098723A1 · Feeney · 2016 [cited by examiner]
US 20160125184A1 · Mahaffey · 2016 [cited by examiner]
US 20160191561A1 · Eskin · 2016 [cited by examiner]
US 20170262761A1 · Yan · 2017 [cited by examiner]
US 20180007003A1 · Hodgman · 2018 [cited by examiner]
US 20180007014A1 · Neal · 2018 [cited by examiner]
US 20180343238A1 · Tola · 2018 [cited by examiner]
US 20190012592A1 · Beser · 2019 [cited by examiner]
US 20190068627A1 · Thampy · 2019 [cited by examiner]
US 20190319987A1 · Levy · 2019 [cited by examiner]
US 20190364063A1 · Lee · 2019 [cited by examiner]
US 20200218543A1 · Jung · 2020 [cited by examiner]
US 20200242114A1 · Klenk · 2020 [cited by examiner]
US 20200314119A1 · Karin · 2020 [cited by examiner]
US 20200372154A1 · Bacher · 2020 [cited by examiner]
US 20200372394A1 · Kulkarni · 2020 [cited by examiner]
US 20200382527A1 · Mitelman · 2020 [cited by examiner]
US 20210011741A1 · Bartfai-Walcott · 2021 [cited by examiner]
US 20210073002A1 · Jung · 2021 [cited by examiner]
US 20210073678A1 · Chu · 2021 [cited by examiner]
US 20210081800A1 · Zhang · 2021 [cited by examiner]
US 20210133577A1 · Srinivasan · 2021 [cited by examiner]
US 20210202067A1 · Williams · 2021 [cited by examiner]
US 20210234890A1 · Bansal · 2021 [cited by examiner]
US 20210264025A1 · Givental · 2021 [cited by examiner]
US 20210273961A1 · Humphrey et al. · 2021 [cited by applicant]
US 20210320871A1 · Savarese · 2021 [cited by examiner]
US 20210374502A1 · Roth · 2021 [cited by examiner]
US 20210374518A1 · Zhu · 2021 [cited by examiner]
US 20240113974A1 · Savarese · 2024 [cited by examiner]
US 20240320267A1 · Sriharsha · 2024 [cited by examiner]
CN 101557441A · 2009 [cited by applicant]
CN 106778583A · 2017 [cited by applicant]
GB 2321364A · 1998 [cited by applicant]
KR 20190061690A · 2019 [cited by applicant]
KR 102101974B1 · 2020 [cited by applicant]
IEEE, “IEEE Standard 754-2008 (Revision of IEEE Standard 754-1985): IEEE Standard for Floating-Point Arithmetic,” Aug. 29, 2008, 70 pages. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/US2021/036677, mailed Sep. 1, 2021, filed Jun. 9, 2021, 12 pages. [cited by applicant]
Society of Automotive Engineers On-Road Automated Vehicle Standards Committee, “Taxonomy and Definitions for Terms Related to Driving Automation Systems for On-Road Motor Vehicles,” Standard No. J3016-201609, issued Jan… [cited by applicant]
Society of Automotive Engineers On-Road Automated Vehicle Standards Committee, “Taxonomy and Definitions for Terms Related to Driving Automation Systems for On-Road Motor Vehicles,” Standard No. J3016-201806, issued Jan… [cited by applicant]
Office Action for Chinese Application No. 202180013196.6, mailed Jun. 21, 2024, 24 pages. [cited by applicant]
Chen et al., “Application of Honeypot Technology in Mobile Network Intrusion Detection,” Telecommunication Technology, 49(6): Jun. 2009, 5 pages. [cited by applicant]
Office Action for Chinese Application No. 202180013196.6, mailed Feb. 5, 2025, 27 pages. [cited by applicant]
Office Action for Chinese Application No. 202180013196.6, mailed Jun. 25, 2025, 24 pages. [cited by applicant]
Office Action for Chinese Application No. 202180013196.6, mailed Aug. 15, 2025, 18 pages. [cited by applicant]
Cited By (1)
US 12,608,837