IP Library › Granted Patent US 12,647,457
Granted Patent B2
US 12,647,457 · App. 18/954,031 · Granted Jun 2, 2026

Invalid traffic detection using explainable unsupervised graph ML

Inventors: Valentin Venzin (Zurich, CH); Rhicheek Patra (Zurich, CH); Sungpack Hong (Palo Alto, CA); Hassan Chafi (San Mateo, CA)
Assignee: Oracle International Corporation
H04L63/1483G06N20/00H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,647,457
App. No.
18/954,031
Filed
Nov 20, 2024
Granted
Jun 2, 2026
Kind
B2
Examiner
DOAN, HUAN V
Art Unit
2499
USPC
726/23
Abstract

Herein are graph machine learning explainability (MLX) techniques for invalid traffic detection. In an embodiment, a computer generates a graph that contains: a) domain vertices that represent network domains that received requests and b) address vertices that respectively represent network addresses from which the requests originated. Based on the graph, domain embeddings are generated that respectively encode the domain vertices. Based on the domain embeddings, multidomain embeddings are generated that respectively encode the network addresses. The multidomain embeddings are organized into multiple clusters of multidomain embeddings. A particular cluster is detected as suspicious. In an embodiment, an unsupervised trained graph model generates the multidomain embeddings. Based on the clusters of multidomain embeddings, feature importances are unsupervised trained. Based on the feature importances, an explanation is automatically generated for why an object is or is not suspicious. The explained object may be a cluster or other batch of network addresses or a single network address.

Claims (56)

1 . A method comprising:

generating, by an unsupervised trained graph model, a plurality of multidomain embeddings, wherein:

each multidomain embedding of the plurality of multidomain embeddings represents a distinct network address of a plurality of network addresses, and

each multidomain embedding of the plurality of multidomain embeddings is based on a plurality of network domains that received requests from said distinct network address;

clustering the plurality of multidomain embeddings into a plurality of clusters of multidomain embeddings;

unsupervised training, based on the plurality of clusters of multidomain embeddings, a plurality of importances;

generating, based on the plurality of importances, an explanation for why an object is or is not suspicious, wherein the object is at least one selected from the group consisting of: a particular cluster of the plurality of clusters of multidomain embeddings and a particular multidomain embedding of the plurality of multidomain embeddings.

2 . The method of claim 1 wherein:

the plurality of importances includes a disjoint subset of importances for each cluster of the plurality of clusters of multidomain embeddings;

said generating the explanation for said particular cluster is not based on importances for the plurality of clusters other than the particular cluster.

3 . The method of claim 1 wherein said unsupervised training the plurality of importances is based on centroids of the plurality of clusters of multidomain embeddings.

4 . The method of claim 1 wherein an importance of the plurality of importances corresponds to one selected from the group consisting of:

a feature of a network address of the plurality of network addresses, and

a network domain of the plurality of network domains.

5 . The method of claim 1 wherein said unsupervised training the plurality of importances is based on at least one selected from the group consisting of:

a loss function that uses a centroid of a cluster of the plurality of clusters,

a loss function that uses an inner product,

a loss function that uses an entropy measurement,

a loss function that penalizes a sum of multiple importances of the plurality of importances,

a loss function that penalizes mid-range importances, and

a loss function that uses multiple multidomain embeddings of the plurality of multidomain embeddings.

6 . The method of claim 1 wherein said unsupervised training the plurality of importances comprises measuring a difference between:

a) an inner product of a multidomain embedding of a particular network address and a centroid of a particular cluster of the plurality of clusters that contains the multidomain embedding of the particular network address and

b) an average of respective inner products of a respective centroid of each cluster of the plurality of clusters that is not said particular cluster and the multidomain embedding of the particular network address.

7 . The method of claim 1 wherein said plurality of importances consists of a respective disjoint subset of importances for each multidomain embedding of the plurality of multidomain embeddings.

8 . The method of claim 7 wherein said subsets of importances for a first multidomain embedding of the plurality of multidomain embeddings and a second multidomain embedding of the plurality of multidomain embeddings consist of different counts of importances.

9 . The method of claim 1 wherein a multidomain embedding of the plurality of multidomain embeddings is based on more than two domain embeddings.

10 . The method of claim 1 wherein said unsupervised training the plurality of importances is based on a loss function that does not use a domain embedding.

11 . One or more non-transitory computer-readable media storing instructions that, when executed by one or more processors, cause:

generating, by an unsupervised trained graph model, a plurality of multidomain embeddings, wherein:

each multidomain embedding of the plurality of multidomain embeddings represents a distinct network address of a plurality of network addresses, and

each multidomain embedding of the plurality of multidomain embeddings is based on a plurality of network domains that received requests from said distinct network address;

clustering the plurality of multidomain embeddings into a plurality of clusters of multidomain embeddings;

unsupervised training, based on the plurality of clusters of multidomain embeddings, a plurality of importances;

generating, based on the plurality of importances, an explanation for why an object is or is not suspicious, wherein the object is at least one selected from the group consisting of: a particular cluster of the plurality of clusters of multidomain embeddings and a particular multidomain embedding of the plurality of multidomain embeddings.

12 . The one or more non-transitory computer-readable media of claim 11 wherein:

the plurality of importances includes a disjoint subset of importances for each cluster of the plurality of clusters of multidomain embeddings;

said generating the explanation for said particular cluster is not based on importances for the plurality of clusters other than the particular cluster.

13 . The one or more non-transitory computer-readable media of claim 11 wherein said unsupervised training the plurality of importances is based on centroids of the plurality of clusters of multidomain embeddings.

14 . The one or more non-transitory computer-readable media of claim 11 wherein an importance of the plurality of importances corresponds to one selected from the group consisting of:

a feature of a network address of the plurality of network addresses, and

a network domain of the plurality of network domains.

15 . The one or more non-transitory computer-readable media of claim 11 wherein said unsupervised training the plurality of importances is based on at least one selected from the group consisting of:

a loss function that uses a centroid of a cluster of the plurality of clusters,

a loss function that uses an inner product,

a loss function that uses an entropy measurement,

a loss function that penalizes a sum of multiple importances of the plurality of importances,

a loss function that penalizes mid-range importances, and

a loss function that uses multiple multidomain embeddings of the plurality of multidomain embeddings.

16 . The one or more non-transitory computer-readable media of claim 11 wherein said unsupervised training the plurality of importances comprises measuring a difference between:

a) an inner product of a multidomain embedding of a particular network address and a centroid of a particular cluster of the plurality of clusters that contains the multidomain embedding of the particular network address and

b) an average of respective inner products of a respective centroid of each cluster of the plurality of clusters that is not said particular cluster and the multidomain embedding of the particular network address.

17 . The one or more non-transitory computer-readable media of claim 11 wherein said plurality of importances consists of a respective disjoint subset of importances for each multidomain embedding of the plurality of multidomain embeddings.

18 . The one or more non-transitory computer-readable media of claim 17 wherein said subsets of importances for a first multidomain embedding of the plurality of multidomain embeddings and a second multidomain embedding of the plurality of multidomain embeddings consist of different counts of importances.

19 . The one or more non-transitory computer-readable media of claim 11 wherein a multidomain embedding of the plurality of multidomain embeddings is based on more than two domain embeddings.

20 . The one or more non-transitory computer-readable media of claim 11 wherein said unsupervised training the plurality of importances is based on a loss function that does not use a domain embedding.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2024
From: VENZIN, VALENTIN; PATRA, RHICHEEK; HONG, SUNGPACK; CHAFI, HASSAN
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 069357/0499 →
Continuity (2)
Division 17558342 · Dec 21, 2021
Related Publication 20250119453A1 · Apr 10, 2025
References Cited (12)
US 9516053B1 · Muddu · 2016 [cited by applicant]
US 11003717B1 · Eswaran · 2021 [cited by applicant]
US 11126493B2 · Guha et al. · 2021 [cited by applicant]
US 11397808B1 · Prabhu · 2022 [cited by examiner]
US 20180219888A1 · Apostolopoulos · 2018 [cited by examiner]
US 20180336437A1 · Cheng · 2018 [cited by applicant]
US 20190132344A1 · Lem · 2019 [cited by applicant]
US 20200045049A1 · Apostolopolous et al. · 2020 [cited by applicant]
US 20200142957A1 · Patra · 2020 [cited by applicant]
US 20210075805A1 · Cavallari · 2021 [cited by applicant]
Ying et al., “GNNExplainer: Generating Explanations for Graph Neural Networks”, 2019, 13 pages. [cited by applicant]
Hamilton et al., “Inductive Representation Learning on Large Graphs”, Neural Information Processing Systems, 2017, 19 pages. [cited by applicant]