Graph neural network anomaly detection method based on high-order topology and personalized PageRank

By combining high-order topological structures and personalized PageRank algorithms, the problem of insufficient accuracy of anomaly detection in heterogeneous graphs by traditional graph neural networks is solved, and efficient identification and feature expression of abnormal nodes are achieved, which is suitable for complex scenarios such as network security and social networks.

CN120633707APending Publication Date: 2025-09-12TIANJIN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510587161.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-08
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

Traditional graph neural networks lack the accuracy to detect anomalies in heterogeneous graph structures, especially when dealing with multi-scale high-order topological structures. They cannot effectively capture long-distance dependencies and are easily affected by noise.

Method used

A graph neural network anomaly detection method based on high-order topological structure and personalized PageRank is adopted. The high-order PPR matrix is ​​calculated through the HiPwrPushSOR algorithm and a high-order adaptive spectral convolution is designed to fuse multi-scale topological information to enhance the feature expression ability of abnormal nodes.

Benefits of technology

It improves the detection accuracy of abnormal nodes in heterogeneous graphs, reduces noise interference, and improves the detection effect in complex graph structures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120633707A_ABST
    Figure CN120633707A_ABST
Patent Text Reader

Abstract

The invention discloses a graph neural network anomaly detection method based on a high-order topological structure and a personalized PageRank. According to the method, high-order topological information is integrated into a personalized PageRank (PPR) algorithm, a novel high-order personalized PageRank (HiPPR) matrix is constructed, and in combination with high-order adaptive spectral convolution (HiASC), effective capture of a multi-scale node relation in a complex graph structure is achieved. For an abnormal detection scene, the noise interference is reduced by utilizing HiPPR, and the feature expression capability of abnormal nodes is enhanced through HiASC, so that the detection precision and robustness are improved. Experiments show that the method has excellent performance on the same illustration image and the different illustration image, and is particularly suitable for the fields of network security, social network anomaly detection and the like.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of graph neural network technology, and in particular to a graph neural network anomaly detection method based on high-order topology and personalized PageRank. Background Art

[0002] Graph Neural Networks (GNNs) have made significant progress in graph representation learning in recent years and are widely used in tasks such as node classification, clustering, and anomaly detection. Traditional GNN models are designed based on the homophily assumption, which states that adjacent nodes have similar features or categories. However, in the real world, many graph structures exhibit heterogeneity, meaning that connected nodes may have different characteristics, resulting in a decrease in the performance of traditional methods. In anomaly detection scenarios, anomalous nodes often exhibit significant differences from their neighbors, such as abnormal accounts in financial fraud transactions and fake users in social networks. Furthermore, existing anomaly detection methods often rely on pairwise relationships when dealing with such heterogeneous graphs. This over-reliance on local neighborhood information fails to effectively capture multi-scale information in multi-scale high-order topological structures (such as triangles and tetrahedrons), resulting in insufficient accuracy in detecting anomalous nodes in noisy environments.

[0003] Personalized PageRank (PPR), a random walk-based algorithm, can capture long-range dependencies between nodes and reduce computational complexity through efficient approximation methods. However, existing PPR methods primarily target pairwise graphs and fail to consider the multidimensional interactive nature of higher-order structures. For anomaly detection tasks, effectively identifying anomalous nodes in complex graph structures while mitigating noise remains a pressing technical challenge. Summary of the Invention

[0004] In response to the shortcomings of the existing technology, the present invention proposes a graph neural network anomaly detection method based on high-order topology structure and personalized PageRank, which solves the above problems through the following core innovations.

[0005] The technical solution of the present invention is a graph neural network anomaly detection method based on high-order topology and personalized PageRank, comprising the following steps:

[0006] 1) Data preprocessing: Input graph data G = (V, E) and node feature matrix X and adjacency matrix A, extract all simplices and construct a high-order simplicial complex K;

[0007] 2) High-order personalized PageRank calculation: For each node s, the high-order PPR matrix is ​​calculated based on the proposed HiPwrPushSOR algorithm The formula is:

[0008]

[0009] Among them, α is the restart probability, is the high-order normalized adjacency matrix, I P is the identity matrix corresponding to the number of simplexes of order p;

[0010] It is a high-order normalized adjacency matrix, which incorporates a higher-order simplex structure and represents the adjacency relationship matrix between a 0-order simplex (node) and a p-order simplex (p>0);

[0011] 3) High-order adaptive spectral convolution: The personalized PageRank matrix calculated by each order topology structure is used as a high-order Laplace matrix L p , design a polynomial filter:

[0012]

[0013] Among them, p represents the high-order order, k represents the number of convolutional layers, β p,k is a learnable parameter used to capture the influence of each hop neighbor in each order view in a high-order complex system;

[0014] Fuse the convolution results of each order to generate node embedding representation:

[0015]

[0016] in is the normalized HiPPR matrix, Θ p and W are learnable parameters;

[0017] 4) Anomaly Detection

[0018] Based on the generated node embedding Y, a classifier or anomaly scoring function is used to determine whether the node is abnormal; when calculating the cosine distance, for each node i, its embedding vector Y is calculated i and the reference embedded node vector Y ref The cosine distance of :

[0019]

[0020] The cosine distance of each of the above nodes relative to the reference point is the anomaly score that needs to be calculated.

[0021] This paper discloses a graph neural network anomaly detection method based on high-order topology and personalized PageRank. By integrating simplicial complex theory and the high-order PageRank algorithm, it addresses the problem of insufficient anomaly detection accuracy in heterogeneous graphs using traditional GNNs. This method is suitable for complex scenarios such as network security and social networks.

[0022] 1. High-order Personalized PageRank (HiPPR): By incorporating high-order topological information into PPR, a high-order personalized PageRank algorithm (HiPwrPushSOR) is proposed to capture long-distance, multi-scale node relationships in the graph structure, suppress noise interference, and highlight the local influence of abnormal nodes.

[0023] 2. Adaptive High-Order Spectral Convolution (HiASC): Introduces a high-order personalized PageRank matrix into spectral convolution as a high-order Laplacian operator, dynamically fusing topological information of different orders to achieve multi-scale anomaly feature extraction and enhance the feature expression capability of abnormal nodes. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] Figure 1 Architecture diagram of the graph neural network anomaly detection system based on high-order topology and personalized PageRank.

[0025] Figure 2 Anomaly detection results. DETAILED DESCRIPTION

[0026] The present invention proposes a graph neural network anomaly detection method based on high-order topology and personalized PageRank, which includes the following steps:

[0027] 1) Data preprocessing: Input graph data G = (V, E) and node feature matrix X and adjacency matrix A, extract all simplices and construct a high-order simplicial complex K;

[0028] 2) High-order personalized PageRank calculation: For each node s, the high-order PPR matrix is ​​calculated based on the proposed HiPwrPushSOR algorithm The formula is:

[0029]

[0030] Among them, α is the restart probability, is the high-order normalized adjacency matrix;

[0031] HiPwrPushSOR algorithm pseudo code:

[0032] Algorithm HiPwrPushSOR

[0033] Input: K,∈,α,s,λ,ω / / K represents the constructed simplicial complex; ω represents the residual threshold, which controls sparsity and error accuracy. The smaller ∈ is, the more accurate the algorithm is, and in this method, it is taken as 1e-8; α is the restart probability of the random walk; s is the starting node, and this algorithm calculates the ppr vector of the s node. In this patent, the ppr vector is calculated for each node in the graph one by one, and the ppr matrix can be obtained for subsequent convolution operations; λ is the switching threshold. When the residual is small, push is efficient, but when the residual becomes larger and larger, push becomes slower, so it is necessary to switch to sequential scanning; ω is the SOR acceleration parameter, which speeds up the distribution of residuals by introducing a relaxation factor, thereby improving the overall convergence speed of the algorithm;

[0034] Output: π s Estimated value of

[0035] Step 1: Algorithm Preparation

[0036] 1. Set epochNum = 8; / / The parameter that controls the number of scan stages is used to gradually relax the requirements and improve stability and efficiency.

[0037] 2. Set scanThreshold = n / 4; / / If the queue Q is too large and exceeds the scanThreshold, switch directly to sequential scan mode.

[0038] 3. For all σ∈K, initialize and r(s,σ)←0; r(s,s)

[0039] ←1;

[0040] 4. Initialize a first-in-first-out queue

[0041] 5. Add s to Q;

[0042] 6.r max ←λ / m;

[0043] Step 2: Scan the queue when conditions are met

[0044] 7. When Q is not empty and Q.size()≤scanThreshold and r sum >λ:

[0045] 8.σ←Q.pop()

[0046] 9. Update

[0047] 10. For each τ∈N out (σ):

[0048] 11. Update r(s,τ)←r(s,τ)+ω(1-α)r(s,σ) / dσ

[0049] 12. If and active and|r σ |≥∈σ d , then add τ to Q

[0050] 13. Update r(s,σ)←0

[0051] Step 3: When the conditions are not met or the queue scanning efficiency is not high enough, switch to sequential scanning

[0052] 14. If rsum > λ: / / switch to using sequential scan:

[0053] 15. For i = 1 to epochNum:

[0054] 16. Update t′ max ←λ i / epochNum / m / / allows for a larger l1-error

[0055] 17. When r sum >m·r′ max hour:

[0056] 18. For each σ∈K:

[0057] 19. If σ is active and |r σ |≥∈d σ , then update

[0058] 20. For each τ∈N Out (σ):

[0059] 21. Update r(s,τ)←r(s,τ)+ω(1-α)r(s,σ) / d σ

[0060] 22. Update r(s,σ)←0

[0061] Step 4: Calculation is completed, the ppr vector is obtained and returned

[0062] 23. Return all σ∈K As a vector

[0063] 3) High-order adaptive spectral convolution: The personalized PageRank matrix calculated by each order topology structure is used as a high-order Laplace matrix L p , design a polynomial filter:

[0064]

[0065] Among them, p represents the high-order order, k represents the number of convolutional layers, β p,k is a learnable parameter used to capture the influence of each hop neighbor in each order view in high-order complex systems.

[0066] Fuse the convolution results of each order to generate node embedding representation:

[0067]

[0068] in is the normalized HiPPR matrix, Θ p and W are learnable parameters.

[0069] 4) Anomaly Detection

[0070] Based on the generated node embedding Y, a classifier (such as softmax) or anomaly scoring function (such as anomaly metric based on Euclidean distance) is used to determine whether the node is abnormal. When calculating the cosine distance, for each node i, the cosine distance between its embedding vector and the reference embedded node vector is calculated:

[0071]

[0072] The cosine distance of each of the above nodes relative to the reference point is the anomaly score that needs to be calculated.

[0073] There are several methods to choose from for determining the reference point. First, you can use the average embedding of all surrounding nodes as the reference point. This method is suitable when most nodes are considered normal and you want to find those that deviate from the normal pattern. Second, if there are some known "normal" nodes, you can use the embeddings of these nodes to construct the reference point.

[0074] Example 1: Abnormal Traffic Detection in Network Security

[0075] Application scenario: Detecting abnormal traffic (such as DDoS attacks) in computer networks

[0076] Input data: network traffic graph G = (V, E), where nodes V represent IP addresses, edges E represent traffic interactions, and feature matrix X represents traffic statistical features (such as packet size and frequency).

[0077] step:

[0078] 1. Preprocessing: Construct high-order simplicial complexes to extract triangles and other high-order structures to represent the collaborative traffic patterns among multiple nodes.

[0079] 2. HiPPR calculation: Set α = 0.15 and use HiPwrPushSOR calculation Capture the long-distance impact of abnormal IPs.

[0080] 3. HiASC convolution: Perform high-order spectral convolution with K=2 to generate the embedded representation Y.

[0081] 4. Anomaly detection: Use support vector machine (SVM) to classify Y and mark abnormal IPs.

[0082] Results: The detection accuracy of abnormal traffic in computer networks is improved by 14% compared with traditional GCN-based neural network detection.

[0083] Example 2: Abnormal User Detection in Social Networks

[0084] Application scenario: Identifying malicious users (such as fake accounts) in social networks.

[0085] Input data: social graph G = (V, E), where nodes V represent users, edges E represent follow-up relationships, and the feature matrix X contains user behavior features (such as posting frequency and interaction patterns).

[0086] step:

[0087] 1. Preprocessing: extract high-order structures (such as common attention groups) and construct simplicial complexes.

[0088] 2. HiPPR calculation: set ∈ = 10 -4 , calculate the HiPPR matrix and reduce the noise interference of normal users.

[0089] 3. HiASC convolution: With P = 3 (considering the highest 3-order structure), generate the embedding Y.

[0090] 4. Anomaly detection: Calculate anomaly scores based on cosine distance and use thresholds to filter out abnormal users.

[0091] Results: Identifying malicious users (such as fake accounts) in social networks is 16% more accurate than traditional GCN-based neural network detection.

[0092] The above two embodiments show that the advantages of the method proposed in the present invention are that the detection accuracy of heterogeneous graphs (abnormal nodes are significantly different from their neighbors) is improved, and multi-scale topological analysis is supported, which is suitable for complex group anomalies, such as distributed attacks, collaborative fraud and other scenarios.

[0093] like Figure 2 As shown in the figure, the anomaly detection results are highly accurate, where Class A and Class B are different classification nodes under the same type. For example, Class A (Chinese users) and Class B (English users) in the "user" type in a social network.

[0094] For anomaly detection scenarios, this method uses HiPPR to reduce noise interference and HiASC to enhance the ability to express the characteristics of abnormal nodes, thereby improving detection accuracy and robustness. Experiments show that this method performs well on both homogeneous and heterogeneous graphs, making it particularly suitable for network security and social network anomaly detection.

Claims

1. A graph neural network anomaly detection method based on high-order topology and personalized PageRank, characterized by: The following steps are involved: 1) Data preprocessing: Input graph data G = (V, E) and node feature matrix X and adjacency matrix A, extract all simplices and construct a high-order simplicial complex K; 2) High-order personalized PageRank calculation: For each node s, the high-order PPR matrix is ​​calculated based on the proposed HiPwrPushSOR algorithm The formula is: Among them, α is the restart probability, is the high-order normalized adjacency matrix, I P is the identity matrix corresponding to the number of simplexes of order p; 3) High-order adaptive spectral convolution: The personalized PageRank matrix calculated by each order topology structure is used as a high-order Laplace matrix L p , design a polynomial filter: Among them, p represents the high-order order, k represents the number of convolutional layers, β p,k is a learnable parameter used to capture the influence of each hop neighbor in each order view in a high-order complex system; Fuse the convolution results of each order to generate node embedding representation: in is the normalized HiPPR matrix, Θ p and W are learnable parameters; 4) Anomaly Detection Based on the generated node embedding Y, a classifier or anomaly scoring function is used to determine whether the node is abnormal. When calculating the cosine distance, for each node i, the cosine distance between its embedding vector and the reference embedded node vector is calculated: The cosine distance of each of the above nodes relative to the reference point is the anomaly score that needs to be calculated.

2. The method according to claim 1, characterized in that The high-order topology structure modeling converts the original graph into a simplicial complex by clique complex lifting, and extracts multi-node interaction patterns.

3. The method according to claim 1, characterized in that The HiPPR algorithm HiPwrPushSOR achieves fast approximate calculation of high-order adjacency matrices by improving the PwrPushSOR method.

4. The method according to claim 1, wherein The adaptive high-order spectral convolution dynamically fuses the outputs of PPR matrix operators of different orders, suppresses noise and enhances abnormal features.