Network attack detection model training method, training device, detection method, storage medium and computer equipment
By optimizing the weight parameters through the variational quantum neural network model and quantum particle swarm optimization algorithm, the detection accuracy and convergence speed problems of the network attack detection system under high-dimensional data are solved, and efficient network attack detection is achieved.
Patent Information
- Application Number
- CN202510757372.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-06
- Publication Date
- 2025-09-16
AI Technical Summary
Existing network attack detection systems, when faced with high-dimensional data or complex feature associations, have problems such as low detection accuracy, slow convergence, weak model generalization ability, and high cost of storing and computing high-dimensional data.
A variational quantum neural network model is adopted, and weight parameters are optimized through quantum state encoding and quantum particle swarm optimization algorithm. A flexible network attack detection model is designed, and the feature extraction and pattern recognition capabilities of quantum computing are utilized to improve detection accuracy.
While using fewer quantum bits, efficient network attack detection is achieved, detection accuracy and the model's feature extraction capability are improved, the local minimum problem in traditional methods is solved, and global search capabilities are enhanced.
Smart Images

Figure CN120654063A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of quantum computing, and in particular to a network attack detection model training method, training device, detection method, storage medium and computer equipment. Background Art
[0002] With the development of artificial intelligence, big data, and the internet, network security is becoming increasingly important across various fields. Implementing an efficient network attack detection system is one of the key challenges in network security. This system must rapidly detect various attacks within a short period of time to protect network security.
[0003] Existing network attack detection is generally based on intrusion detection systems (IDS), which are based on classical neural networks and machine learning methods. Due to the limitations of classical computing capabilities, when faced with high-dimensional data or complex feature associations, they suffer from low detection accuracy, slow convergence, weak model generalization ability, and high cost of storing and computing high-dimensional data. Summary of the Invention
[0004] In order to address the shortcomings of the existing technology, the present invention proposes a network attack detection model training method, training device, detection method, storage medium and computer equipment, which can flexibly design a variational quantum neural network model to determine whether there is network attack behavior in network traffic data, and can achieve higher detection accuracy while using fewer quantum bits.
[0005] To achieve the above objectives, the present disclosure provides a method for training a network attack detection model, the method comprising:
[0006] Obtain a network attack training dataset;
[0007] Preprocessing the network attack training data set and performing quantum state encoding to form a first input quantum state;
[0008] Inputting the first input quantum state into a variational quantum circuit, wherein the variational quantum circuit forms optimal parameters through dynamic adjustment, and processing the first input quantum state based on the optimal parameters to obtain a first output quantum state, wherein the first output quantum state is used to obtain a first detection result through conversion, and the first detection result is used to indicate whether there is a network attack behavior in the network traffic data;
[0009] The optimal parameters are assigned to a variational quantum neural network model to form a network attack detection model.
[0010] Optionally, preprocessing the network attack training data set includes performing feature selection, normalization, and quantum feature mapping on the network attack training data set to form training data to be quantum state encoded.
[0011] Optionally, the training data to be quantum state encoded is encoded to form a first input quantum state.
[0012] Optionally, the variational quantum circuit forming optimal parameters through dynamic adjustment includes:
[0013] Obtaining weight parameters of training data of the variational quantum circuit;
[0014] The weight parameters of the training data are optimized by a quantum particle swarm optimization algorithm to obtain the optimal weight parameters of the training data, where the optimal weight parameters are the optimal parameters.
[0015] Optionally, the optimizing the weight parameters of the training data by using a quantum particle swarm optimization algorithm to obtain the optimal weight parameters of the training data includes:
[0016] Initialize weight parameters;
[0017] Randomly generate a particle swarm containing N particles, where each particle represents a weight parameter;
[0018] Get the prediction error of each particle, record the fitness value, and obtain the current weight parameters;
[0019] Update the weight parameters according to the historical best position, global best position and inertia weight factor of each particle;
[0020] Until the weight parameter value of the global best particle is selected as the optimal parameter.
[0021] Optionally, updating the weight parameters includes enabling particles to obtain different weight parameters and converge to a global optimal solution based on quantum behavior and a global optimization strategy.
[0022] The present disclosure also includes a network attack detection method, comprising:
[0023] Obtain cyber attack datasets;
[0024] Inputting the network attack data set into the network attack detection model described in the above technical solution;
[0025] The network attack detection model is used to perform quantum state encoding on the network attack data set after preprocessing to form a second input quantum state; and
[0026] Inputting the second input quantum state into a variational quantum circuit, applying parameterization processing to the second input quantum state to obtain a second output quantum state; and
[0027] The second output quantum state is used to obtain a second detection result through conversion, and the second detection result is used to characterize whether there is a network attack behavior in the network traffic data.
[0028] The present disclosure also includes a training device for a network attack detection model, comprising:
[0029] A data acquisition module is used to obtain a network attack training data set from network traffic data;
[0030] A preprocessing module, for preprocessing the network attack training data set;
[0031] an encoding module, performing quantum state encoding on the preprocessed network attack training data set to form a first input quantum state;
[0032] a parameter optimization module, inputting the first input quantum state into a variational quantum circuit, wherein the variational quantum circuit forms optimal parameters through dynamic adjustment, and performing parameterized processing on the first input quantum state based on the optimal parameters to obtain a first output quantum state, wherein the first output quantum state is used to obtain a first detection result through conversion, and the first detection result is used to indicate whether there is a network attack behavior in the network traffic data;
[0033] The parameter processing module assigns the optimal parameters to a variational quantum neural network model to form a network attack detection model.
[0034] The present disclosure also includes a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements a network attack detection method described in the above technical solution.
[0035] The present disclosure also includes a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements a network attack detection method described in the above technical solution when executing the program.
[0036] The above technical solution has the following beneficial effects:
[0037] 1. After preprocessing the obtained network attack training data set, quantum state encoding is performed to form a first input quantum state, the first input quantum state is input into the variational quantum circuit to obtain a first detection result, the variational quantum circuit is dynamically adjusted to form optimal parameters, and the optimal parameters are input into the variational quantum neural network model to form a network attack detection model. The variational quantum neural network model can be flexibly designed. The network attack detection model processes the second input quantum state based on the optimal parameters to obtain a second output quantum state and obtains a second detection result through conversion. The detection result is obtained to characterize whether there is network attack behavior in the network traffic data, and a higher detection accuracy can be achieved even when using fewer quantum bits.
[0038] 2. After preprocessing the network attack training data set, the training data to be quantum state encoded is formed, and the weight parameters of the training data of the variational quantum circuit are obtained. The weight parameters of the training data are optimized using the quantum particle swarm optimization algorithm, and the optimal weight parameters of the training data are obtained as the optimal parameters. The optimal parameters are input into the variational quantum neural network model, which improves the feature extraction and pattern recognition capabilities of the variational quantum neural network model, enhances the detection performance, solves the problems of slow convergence speed and easy falling into local minima in the later stage of the search, and enhances the global search capability. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] In order to more clearly illustrate the embodiments of the present disclosure or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0040] Figure 1 A flowchart of the training method proposed for this disclosure;
[0041] Figure 2 A flow chart showing how to dynamically adjust the optimal parameters of a variable quantum circuit in the present disclosure;
[0042] Figure 3 A flowchart of optimizing the weight parameters of training data to obtain the optimal weight parameters of training data in the present disclosure;
[0043] Figure 4 A flow chart of the detection method proposed in the present disclosure;
[0044] Figure 5 This is a schematic diagram of the structural principle of the training device proposed in the present disclosure.
[0045] Legend:
[0046] 1. Data acquisition module; 2. Preprocessing module; 3. Encoding module; 4. Parameter optimization module; 5. Parameter processing module. DETAILED DESCRIPTION
[0047] The following will be combined with the accompanying drawings in the embodiments of the present disclosure to clearly and completely describe the technical solutions in the embodiments of the present disclosure. Obviously, the embodiments described are only part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by ordinary technicians in this field without making any creative efforts are within the scope of protection of the present disclosure.
[0048] In some embodiments of the present disclosure, referring to Figure 1 The present disclosure provides a method for training a network attack detection model, the method comprising:
[0049] S1: Obtain network attack training dataset;
[0050] S2: Preprocess the network attack training data set and perform quantum state encoding to form a first input quantum state;
[0051] S3: Inputting the first input quantum state into the variational quantum circuit, wherein the variational quantum circuit forms optimal parameters through dynamic adjustment, and processes the first input quantum state based on the optimal parameters to obtain a first output quantum state, wherein the first output quantum state is used to obtain a first detection result through conversion, and the first detection result is used to indicate whether there is a network attack behavior in the network traffic data;
[0052] S4: Assign the optimal parameters to a variational quantum neural network model to form a network attack detection model.
[0053] Specifically, network traffic data is input to obtain a network attack training dataset. This dataset is then preprocessed to unify its data type. Quantum state encoding is then used to convert the dataset into a first input quantum state, which can be input into a variational quantum circuit. The variational quantum circuit is composed of parameterized quantum gates (such as rotation gates and CNOT gates). Through this variational quantum circuit, the dataset is mapped into Hilbert space and, through quantum superposition and entanglement, the complex correlations within the data are captured. Adjusting the parameters in the variational quantum circuit can optimize the model's performance and improve the accuracy of detecting network attacks.
[0054] A parameterized quantum gate is used to perform a unitary transformation on the encoded first input quantum state to capture the high-order features of the input data. The processed quantum state is measured to obtain the probability distribution of quantum bits, which can be converted into a first detection result through decoding. The first detection result is the quantum state distribution of the training data. The optimal parameters are formed through dynamic adjustment, which can adapt to the changes in the feature distribution of different attack types, avoiding the insufficient generalization ability of traditional machine learning models due to fixed features. The optimal parameters are applied to transform the first input quantum state to generate a first output quantum state, and the first detection result is obtained through the conversion. The first detection result is used to determine whether a network attack has occurred, and is used to characterize whether there is a network attack in the network traffic data.
[0055] The optimal parameters obtained from the optimized variational quantum circuit are embedded in the variational quantum neural network model to form a network attack detection model, which is used to detect attack data sets in network traffic in real time, and can achieve higher detection accuracy even when using fewer quantum bits.
[0056] In some embodiments of the present disclosure, preprocessing the network attack training data set includes: performing feature selection, normalization, and quantum feature mapping on the network attack training data set to form training data to be quantum state encoded.
[0057] Specifically, a network attack training data set is obtained from the original network traffic data, and feature selection is performed to obtain the corresponding eigenvalues. Through statistical analysis or feature importance evaluation methods, eigenvalues with strong correlation with network attacks are selected, and redundant or noisy eigenvalues are removed to reduce data complexity, improve computing efficiency, reduce computing burden, and improve generalization ability.
[0058] Eigenvalue normalization is performed to scale the eigenvalues of the training dataset to a uniform scale, such as the interval [0, 1] or [-1, 1]. For example, methods include minimum-maximum normalization or standard normal distribution normalization. After normalization, the various features in the training dataset have a balanced impact on the training of the network attack detection model, avoiding bias caused by scale differences.
[0059] Quantum feature mapping is used to convert a normalized training dataset into quantum feature parameters usable for quantum computing through a specific mapping function. These parameters serve as the training data for quantum state encoding, preserving the characteristics of the training data while adapting to the characteristics of quantum computing. For example, amplitude encoding, phase encoding, or other methods are used to embed the training data into the quantum state space.
[0060] Through feature selection, normalization and quantum feature mapping, the network attack training data set is converted into training data to be quantum state encoded, reducing redundant data, lowering quantum computing resource consumption, and enhancing the ability to identify network attacks.
[0061] In some embodiments of the present disclosure, training data to be quantum-state encoded is encoded to form a first input quantum state.
[0062] Specifically, quantum state encoding uses quantum gate operations to encode quantum characteristic parameters into the initial state of the quantum bit, forming a first input quantum state |ψinput> for input. Multiple first input quantum states form a quantum superposition state, so that subsequent quantum gate operations can directly act on these data.
[0063] In some embodiments of the present disclosure, referring to Figure 2 , the optimal parameters of the variational quantum circuit are formed through dynamic adjustment, including:
[0064] S31: Obtain weight parameters of training data of variational quantum circuit;
[0065] S32: Optimizing the weight parameters of the training data by using a quantum particle swarm optimization algorithm to obtain the optimal weight parameters of the training data, where the optimal weight parameters are the optimal parameters.
[0066] Specifically, the first input quantum state is transmitted to the variational quantum circuit, and parameterized quantum circuit operations are applied. The variational quantum circuit consists of a series of parameterized quantum gates, including rotation gates (such as RX, RY, RZ) and entanglement gates (such as CNOT gates). The parameters of the quantum gates include the weight parameter θ to be optimized. Through these gate operations, entanglement and interference are achieved between quantum bits.
[0067] According to the parameterized quantum gate and weight parameter θ, the quantum state evolves, and the first output quantum state |ψoutput> is obtained after the first input quantum state is processed by the variational quantum circuit. The formula is as follows:
[0068] |ψoutput>=U(θ)|ψinput>;
[0069] Here, U(θ) represents the unitary transformation determined by the weight parameter θ, which determines how the variational quantum circuit evolves the input quantum state.
[0070] By adjusting the weight parameter θ through the quantum particle swarm optimization algorithm (QPSO), the corresponding first output quantum state can be obtained. The weight parameter θ is optimized and the obtained optimal weight parameter is used as the optimal parameter in the variational quantum neural network model, which can effectively improve the convergence speed, feasibility and accuracy of the detection results.
[0071] In some embodiments of the present disclosure, referring to Figure 3, the weight parameters of the training data are optimized by the quantum particle swarm optimization algorithm, and the optimal weight parameters of the training data are obtained, including:
[0072] S321: Initialize weight parameters;
[0073] S322: randomly generating a particle swarm comprising N particles, wherein each particle represents a weight parameter;
[0074] S323: Obtain the prediction error of each particle, record the fitness value, and obtain the current weight parameter;
[0075] S324: updating the weight parameters according to the historical best position, the global best position and the inertia weight factor of each particle;
[0076] S325: until the weight parameter value of the global best particle is selected as the optimal parameter.
[0077] Specifically, the quantum particle swarm optimization algorithm searches for the optimal solution to find a set of initial weight parameters θ, so that the unitary transformation of the variational quantum circuit can effectively capture the data characteristics and randomly assign values to the initial weight parameters θ.
[0078] A swarm of N particles is randomly generated, each representing a weight parameter. The initial position and velocity of each particle are randomly set. The prediction error of each particle is calculated, and the particle is placed into a variational quantum neural network model. Using the training data, the first output quantum state is obtained and compared with the expected output. The resulting error is the fitness value, which represents the performance of the model at the current value of θ. The fitness value is evaluated, for example, using a prediction error-based evaluation function such as the mean squared error (MSE). The minimum fitness value fmin and maximum fitness value fmax in the current iteration are determined. The historical best position of each particle from the initial stage to the current iteration t (i.e., the parameter corresponding to the minimum fitness value) is determined, as well as the global best position of the entire particle swarm (i.e., the position of the particle with the minimum fitness value).
[0079] According to the weight parameters corresponding to the fitness value, the quantum particle swarm optimization algorithm is used to update the particle's θ value based on the particle's historical best position and global best position, as well as the inertia weight factor θ1. This combines quantum behavior and global optimization strategies, allowing particles to explore new solutions in the parameter space and converge to the global optimal solution.
[0080] Inertia weight factor formula:
[0081]
[0082] Here, fmin and fmax represent the minimum and maximum fitness values of the current swarm, corresponding to the best and worst performing individuals, respectively. fmin and fmax are dynamically updated by iteratively calculating the fitness of each particle, used to evaluate the quality of the weight parameters in the current state. tmax is the maximum number of iterations, and t is the current iteration number. Based on the current iteration number, the inertia weight factor formula is used to gradually adjust the particle's inertia weight, enhancing convergence to the optimal solution while avoiding local minima.
[0083] The process of calculating fitness values and updating particle positions is repeated until the maximum number of iterations tmax is reached or convergence conditions are met. After optimization, the value θ of the globally optimal particle is selected as the optimal weight parameter for the variational quantum neural network model. The optimized weight parameters can improve the classification and detection accuracy of quantum circuits. The weight parameter θ controls the operation of the parameterized quantum gates in the variational quantum circuit and directly affects the evolution of quantum states. After the first input quantum state is processed by the variational quantum circuit, the form of the first output quantum state |ψoutput> depends on the weight parameter θ. The process of optimizing the weight parameter θ is actually adjusting the variational quantum circuit's data processing method to ensure that the output is as consistent as possible with the expected output. Therefore, by adjusting the weight parameter value, the variational quantum neural network's ability to extract features and recognize patterns from data is improved, enhancing the model's detection performance.
[0084] In some embodiments of the present disclosure, updating the weight parameters includes: based on quantum behavior and a global optimization strategy, enabling particles to obtain different weight parameters and converge to a global optimal solution.
[0085] Specifically, the inertia weight factor θ1 is an important parameter that affects the particle velocity update and is continuously updated as the number of iterations increases. The update of the inertia weight factor θ1 is related to the number of iterations and the maximum number of iterations tmax, for example:
[0086] θ1=θmax-(θmax-θmin)(t / tmax);
[0087] Among them, θmax and θmin are the initial value and minimum value of the inertia weight, respectively. θmax controls the global exploration capability, allowing particles to search the solution space over a large range, and θmin is used to ensure local development accuracy.
[0088] The particle position is updated using the update formula of the quantum particle swarm optimization algorithm, combined with quantum behavior. In this embodiment, quantum behavior is a mathematical abstraction based on the probabilistic properties of quantum mechanics. By introducing the probabilistic uncertainty and state superposition principle in quantum mechanics, it is used to simulate the random transitions of particle positions, breaking through the limitations of traditional optimization algorithms. The particle position update formula contains the following relationship:
[0089] xi(t+1)=pi(t)+θ1|pi(t)-xi(t)|ln(1 / r);
[0090] xi(t+1)=pi(t)-θ1|pi(t)-xi(t)|ln(1 / r);
[0091] Where xi(t) is the position of particle i at iteration t. pi(t) is the best historical position of particle i, r is a random number between [0, 1], and θ1 is the inertia weighting factor. The above update formula reflects the quantum transition of a particle between its best historical position and the global best position.
[0092] Iterate according to the update formula: increase t by 1 and repeat the above steps until the maximum number of iterations tmax is reached or the convergence condition is met. The weight parameter θ of the test data is compared with the optimal θ1 of the training to obtain the weight error. The formula is as follows:
[0093] e1=|θ1-θ|;
[0094] The smaller the weight error e1 is, the better the detection model performance is. A threshold range is preset. When the weight error is less than the threshold range, it is determined that the convergence condition is met.
[0095] In some embodiments of the present disclosure, referring to Figure 4 , the present disclosure also includes a network attack detection method, comprising:
[0096] P1: Obtain network attack dataset;
[0097] P2: Input the network attack dataset into the network attack detection model in the above technical solution;
[0098] P3: The network attack detection model is used to pre-process the network attack dataset and then perform quantum state encoding to form a second input quantum state;
[0099] P4: Input the second input quantum state into the variational quantum circuit, and process the second input quantum state to obtain a second output quantum state;
[0100] P5: The second output quantum state is used to obtain a second detection result through conversion, and the second detection result is used to characterize whether there is a network attack behavior in the network traffic data.
[0101] Specifically, the trained network attack detection model is used to conduct actual attack detection. A network attack dataset is obtained based on real-time network traffic data. The network attack dataset is preprocessed and then quantum-encoded to obtain a second input quantum state. This second input quantum state is then input into a variational quantum circuit to obtain a corresponding second output quantum state. A second detection result is then converted to determine whether the traffic data represents normal or a network attack. If the detection result is normal, the network attack detection model maintains normal operation and does not trigger security alerts or defensive measures. If the network attack detection model identifies an anomaly in the network traffic, it may be a potential attack. The network attack detection method can trigger appropriate security mechanisms based on the second detection result, such as logging an alert; notifying a security administrator; initiating a defensive strategy to block suspicious network connections; and conducting further data analysis to determine the type and source of the attack. Accurate detection results enable timely response to network security threats, protecting network resources and data. If no attack is detected, the system operates in a secure state, but continuous monitoring is possible to prevent potential threats. If an attack is detected, timely response and action can prevent further damage.
[0102] In some embodiments of the present disclosure, referring to Figure 5 The present disclosure also includes a training device for a network attack detection model, comprising:
[0103] Data acquisition module 1, used to obtain network attack training data set from network traffic data;
[0104] Preprocessing module 2, preprocesses the network attack training data set;
[0105] Encoding module 3, performing quantum state encoding on the preprocessed network attack training data set to form a first input quantum state;
[0106] Parameter optimization module 4 inputs the first input quantum state into the variational quantum circuit, wherein the variational quantum circuit forms optimal parameters through dynamic adjustment, and processes the first input quantum state based on the optimal parameters to obtain a first output quantum state, wherein the first output quantum state is used to obtain a first detection result through conversion, and the first detection result is used to indicate whether there is a network attack behavior in the network traffic data;
[0107] The parameter processing module 5 assigns the optimal parameters to a variational quantum neural network model to form a network attack detection model.
[0108] Specifically, the data acquisition module 1 obtains a network attack training data set from network traffic data, such as real-time traffic capture or log collection.
[0109] The preprocessing module 2 receives the network attack training data set sent by the data acquisition module 1, and performs feature selection, normalization, and quantum feature mapping on the network attack training data set to form training data to be quantum state encoded.
[0110] The encoding module 3 encodes the training data to be quantum state encoded formed by the preprocessing module 2 to form a first input quantum state, wherein the quantum state encoded data is converted into classical calculations and transmitted to the hardware device through the classical-quantum interface for subsequent operation of the variational quantum neural network model.
[0111] The parameter optimization module 4 trains the first input quantum state formed by the encoding module 3 through a variational quantum circuit, and adjusts the optimized weight parameters through unitary transformation to obtain the optimal parameters.
[0112] The parameter processing module 5 assigns the obtained optimal parameters to the variational quantum neural network model to form a network attack detection model for performing network attack detection.
[0113] In some embodiments of the present disclosure, the present disclosure further includes a computer-readable storage medium storing a computer program for executing the detection method, wherein the computer program causes a computer to execute the following steps:
[0114] P1: Obtain network attack dataset;
[0115] P2: Input the network attack dataset into the network attack detection model in the above technical solution;
[0116] P3: The network attack detection model is used to pre-process the attack data set and then perform quantum state encoding to form a second input quantum state;
[0117] P4: Input the second input quantum state into the variational quantum circuit, apply parameterization processing to the second input quantum state to obtain the second output quantum state;
[0118] P5: The second output quantum state is used to obtain a second detection result through conversion, and the second detection result is used to characterize whether there is a network attack behavior in the network traffic data.
[0119] Among them, the computer-readable storage medium can be a computer storage medium or a communication medium. The communication medium includes any medium that facilitates the transmission of a computer program from one place to another. The computer storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer. For example, a computer-readable storage medium is coupled to a processor so that the processor can read information from the computer-readable storage medium and write information to the computer-readable storage medium. Of course, the computer-readable storage medium can also be an integral part of the processor. The processor and the computer-readable storage medium can be located in an application-specific integrated circuit (ASIC). In addition, the ASIC can be located in a user device. Of course, the processor and the computer-readable storage medium can also exist in a communication device as discrete components.
[0120] Specifically, the computer-readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random-access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0121] The present disclosure also includes a computer device comprising:
[0122] one or more processors; memory; and
[0123] One or more programs, wherein the one or more programs are stored in a memory and configured to be executed by one or more processors, the programs comprising steps for performing the following steps:
[0124] P1: Obtain network attack dataset;
[0125] P2: Input the network attack dataset into the network attack detection model in the above technical solution;
[0126] P3: The network attack detection model is used to pre-process the attack data set and then perform quantum state encoding to form a second input quantum state;
[0127] P4: Input the second input quantum state into the variational quantum circuit, apply parameterization processing to the second input quantum state to obtain the second output quantum state;
[0128] P5: The second output quantum state is used to obtain a second detection result through conversion, and the second detection result is used to characterize whether there is a network attack behavior in the network traffic data.
[0129] Memory is used to store computer programs. This memory may include high-speed random access memory (RAM) and non-volatile memory (NVM), such as at least one disk storage device. It can also be a USB flash drive, a mobile hard drive, a read-only memory, a magnetic disk, or an optical disk.
[0130] A processor is used to execute a computer program stored in a memory. The processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), or application-specific integrated circuits (ASICs). A general-purpose processor may be a microprocessor or any conventional processor. The steps of the method disclosed in the present invention may be directly implemented by a hardware processor or implemented by a combination of hardware and software modules in the processor.
[0131] Optionally, the memory can be independent or integrated with the processor.
[0132] When the memory is a device independent of the processor, the computer device may also include a bus. The bus is used to connect the memory and the processor. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. Buses can be divided into address buses, data buses, control buses, etc.
[0133] It should be noted that, through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus the necessary general hardware platform. Based on this understanding, the above technical solution is essentially or the part that contributes to the prior art can be embodied in the form of a software product, which can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or certain parts of the embodiment. In this article, relational terms such as first and second are merely used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. Without further constraints, an element defined by the phrase "comprises a..." does not preclude the existence of additional identical elements in the process, method, article or apparatus that includes the element.
[0134] Finally, it should be noted that the above is only a preferred embodiment of the present disclosure and is not intended to limit the present disclosure. Although the present disclosure has been described in detail with reference to the aforementioned embodiments, those skilled in the art can still modify the technical solutions described in the aforementioned embodiments or make equivalent replacements for some of the technical features therein. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present disclosure should be included in the scope of protection of the present disclosure.
Claims
1. A training method for a network attack detection model, characterized in that: The method comprises: Obtain a network attack training dataset; Preprocessing the network attack training data set and performing quantum state encoding to form a first input quantum state; Inputting the first input quantum state into a variational quantum circuit, wherein the variational quantum circuit forms optimal parameters through dynamic adjustment, and processing the first input quantum state based on the optimal parameters to obtain a first output quantum state, wherein the first output quantum state is used to obtain a first detection result through conversion, and the first detection result is used to indicate whether there is a network attack behavior in the network traffic data; The optimal parameters are assigned to a variational quantum neural network model to form a network attack detection model.
2. The training method of the network attack detection model according to claim 1, characterized in that: Preprocessing the network attack training data set includes: The network attack training data set is subjected to feature selection, normalization processing, and quantum feature mapping processing to form training data to be quantum state encoded.
3. The training method of the network attack detection model according to claim 2, characterized in that: The training data to be quantum-state encoded is encoded to form the first input quantum state.
4. The training method of the network attack detection model according to claim 3, characterized in that: The variational quantum circuit forms optimal parameters through dynamic adjustment, including: Obtaining weight parameters of training data of the variational quantum circuit; The weight parameters of the training data are optimized by a quantum particle swarm optimization algorithm to obtain the optimal weight parameters of the training data, where the optimal weight parameters are the optimal parameters.
5. The training method of the network attack detection model according to claim 4, characterized in that: Optimizing the weight parameters of the training data by using the quantum particle swarm optimization algorithm to obtain the optimal weight parameters of the training data includes: Initialize weight parameters; Randomly generate a particle swarm containing N particles, where each particle represents a weight parameter; Get the prediction error of each particle and obtain the current weight parameters; Update the weight parameters according to the historical best position, global best position and inertia weight factor of each particle; Until the weight parameter value of the global best particle is selected as the optimal parameter.
6. The training method of the network attack detection model according to claim 5, characterized in that: The updating of the weight parameters includes: Based on quantum behavior and global optimization strategy, particles acquire different weight parameters and converge to the global optimal solution.
7. A network attack detection method, characterized in that: include: Obtain cyber attack datasets; Inputting the network attack data set into the network attack detection model described in claims 1-7; The network attack detection model is used to perform quantum state encoding on the network attack data set after preprocessing to form a second input quantum state; as well as Inputting the second input quantum state into a variational quantum circuit, and processing the second input quantum state to obtain a second output quantum state; as well as The second output quantum state is used to obtain a second detection result through conversion, and the second detection result is used to characterize whether there is a network attack behavior in the network traffic data.
8. A training device for a network attack detection model, characterized in that: include: A data acquisition module is used to obtain a network attack training data set from network traffic data; A preprocessing module, for preprocessing the network attack training data set; an encoding module, performing quantum state encoding on the preprocessed network attack training data set to form a first input quantum state; a parameter optimization module, inputting the first input quantum state into a variational quantum circuit, wherein the variational quantum circuit forms optimal parameters through dynamic adjustment, and processing the first input quantum state based on the optimal parameters to obtain a first output quantum state, wherein the first output quantum state is used to obtain a first detection result through conversion, and the first detection result is used to indicate whether there is a network attack behavior in the network traffic data; The parameter processing module assigns the optimal parameters to a variational quantum neural network model to form a network attack detection model.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the network attack detection method described in claim 7 is implemented.
10. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the network attack detection method according to claim 7 is implemented.
Citation Information
Cited By
Quantum attack method and system for detecting continuous variable quantum key distribution
CN121261890A