Lightweight dynamic causal reasoning-based power Internet of Things terminal attack tracing method

Through lightweight dynamic causal reasoning methods, attack samples are generated and traceability graphs are constructed, which solves the problems of sample imbalance and calculation delay in attack tracing of power Internet of Things terminals, realizes efficient and real-time attack tracing, and improves the security of power Internet of Things terminals.

CN120658465APending Publication Date: 2025-09-16ELECTRIC POWER RES INST OF GUANGXI POWER GRID CO LTD
View PDF 0 Cites 9 Cited by

Patent Information

Application Number
CN202510824383.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-19
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

Existing power Internet of Things terminal attack tracing technology faces problems such as sample imbalance, graph size expansion and computational delay, resulting in insufficient generalization ability and poor real-time performance, making it difficult to effectively trace the source in a complex and dynamic network environment.

Method used

A lightweight dynamic causal inference method is adopted to generate attack samples through a residual generation network, construct an attack tracing graph, and introduce graph neural network and attention mechanism. The causal confidence is dynamically adjusted by combining mutual information technology, and the knowledge distillation optimization model is used to achieve efficient tracing.

Benefits of technology

It improves the accuracy and real-time performance of attack tracing, reduces computational complexity and resource overhead, and is suitable for the real-time security needs of power IoT terminals.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120658465A_ABST
    Figure CN120658465A_ABST
Patent Text Reader

Abstract

The invention discloses a power Internet of Things terminal attack tracing method based on lightweight dynamic causal reasoning, relates to the technical field of network security, and solves the problems of sample unevenness, graph scale expansion and calculation delay in power Internet of Things terminal attack tracing in the prior art. The method comprises the following steps: processing a log text to obtain vector data; a residual error generation network is adopted, and the time sequence and logic relevance between attack events is introduced in the GAN training process; then, constructing a preliminary attack traceability graph, designing a graph neural network and attention mechanism combination method to calculate weights among nodes, and introducing a mutual information technology to dynamically adjust causal confidence among the nodes; and finally, generating high-quality embedding by utilizing the GAT teacher model, and migrating traceability knowledge of the teacher model to the lightweight GIN student model through knowledge distillation. In conclusion, the method can systematically construct an efficient attack traceability technical framework oriented to the power Internet of Things terminal from three key stages.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a method for tracing the source of attacks on power Internet of Things terminals based on lightweight dynamic causal reasoning. Background Art

[0002] Power IoT terminals are intelligent embedded devices deployed across the power system's generation, transmission, transformation, distribution, and utilization. They possess multiple functions, including sensing, communication, computing, and control. Leveraging IoT technology, they enable device interconnection, data collection, status monitoring, and intelligent decision-making, forming key edge nodes within the Power IoT. Typical terminal devices include smart meters, edge gateways, distribution automation terminals (such as DTUs and FTUs), and smart circuit breakers.

[0003] Power IoT terminal attacks refer to malicious cyberattacks targeting these devices. Attackers exploit software and hardware vulnerabilities, communication protocol flaws, or weak access control points to conduct data theft, command tampering, denial of service (DDoS), or remote control attacks, with the intent of disrupting device functionality or disrupting the normal operation of the power system. In practice, attackers often exploit vulnerabilities in terminal devices such as smart meters, sensors, and surveillance cameras, combined with vulnerabilities in edge nodes (such as communication gateways or controllers), to launch attacks, causing system anomalies, data tampering, and even triggering serious power safety incidents.

[0004] Attack tracing technology plays a key role in addressing these threats. By tracing attack paths and analyzing attack behaviors and technical means, the tracing process not only helps identify attackers and their intrusion chains, but also enables retrospective analysis of historical attack events, thereby improving existing defense strategies and enhancing overall system security and emergency response capabilities.

[0005] In recent years, the rapid development of deep learning technologies in image processing, natural language processing, and graph-structured data analysis, particularly the widespread application of convolutional neural networks (CNNs), knowledge graphs (KGs), and graph neural networks (GNNs), has brought new development opportunities to attack tracing technology. These technological breakthroughs enable the system to automatically extract potential correlations from multimodal, high-dimensional data, breaking away from traditional methods that rely on rule matching and significantly improving the intelligence level of tracing. The causal traceability graph technology developed based on this foundation, by constructing causal chains between attack events and combining graph algorithms with deep learning models, has promoted the automation, efficiency, and scalability of the tracing process. It has demonstrated significant advantages in handling complex attack paths and fusing multi-source data.

[0006] Despite this, existing attack tracing technologies still face the following core challenges:

[0007] (1) Unbalanced attack samples and insufficient tracing and generalization capabilities: In real network environments, the frequency of attack events varies significantly. Common attack types (such as worms and ransomware attacks) have abundant data, while attacks with high stealth or complexity (such as APTs and zero-day vulnerability exploits) are scarce. This sample imbalance limits the model's cognitive boundaries for diverse attack scenarios, making it difficult to accurately match attack features with tracing clues in complex and dynamic real-world attack and defense environments, ultimately leading to insufficient generalization capabilities.

[0008] (2) The traceability graph is large in scale and highly complex to process: As the attack chain continues to extend and historical data accumulates, the scale of the causal relationship graph grows exponentially, and the number of nodes and edges expands dramatically. This not only increases the system's computing and storage burden, but also significantly reduces the efficiency of visualization, path finding, and causal reasoning, limiting the system's application efficiency in real-world scenarios.

[0009] (3) Model computational overhead is high, making it difficult to meet real-time requirements: Models such as graph neural networks face computing resource bottlenecks when processing large-scale causal graphs. This is especially true in large-scale power IoT environments, where real-time processing becomes a bottleneck. If the attack tracing system cannot locate the attack source and formulate response measures within a short period of time after the attack occurs, it will inevitably affect the overall protection effect and emergency response level.

[0010] In summary, this patent aims to solve the problems of sample imbalance, graph scale expansion and calculation delay in the current power Internet of Things terminal attack tracing, and designs a more intelligent, scalable and real-time tracing model to provide reliable support for terminal-level network security.

[0011] In view of this, a lightweight dynamic causal reasoning method for tracing the attack source of power Internet of Things terminals is needed. Summary of the Invention

[0012] To address the existing issues of sample imbalance, graph expansion, and computational delay in power IoT terminal attack tracing, this paper provides a lightweight dynamic causal reasoning-based power IoT terminal attack tracing method. This method systematically constructs an efficient attack tracing framework for power IoT terminals, focusing on three key stages: attack sample generation, tracing graph construction, and attack path reasoning. The specific technical solution is as follows:

[0013] A lightweight dynamic causal reasoning method for tracing the source of attacks on power Internet of Things terminals includes the following steps:

[0014] S1: Clean, standardize, and vectorize the log text to obtain log text vector data. A residual generative network is used, which is embedded in the generator. A correlation-constrained loss function is designed to introduce temporal and logical correlations between attack events during GAN training.

[0015] S2: Based on the vector data of attack-generated samples and original samples, we capture the temporal and causal relationships of attack events and construct a preliminary attack traceability diagram. We design a method that combines a graph neural network with an attention mechanism to calculate the weights between nodes and optimize the strength of the association between nodes. We also introduce mutual information technology to dynamically adjust the causal confidence between nodes.

[0016] S3: Based on the multi-level traceability graph, the GAT teacher model is used to learn the causal relationship between nodes and generate high-quality embeddings. Then, the traceability knowledge of the teacher model is transferred to the lightweight GIN student model through knowledge distillation.

[0017] Preferably, step S1 includes designing a residual generator, designing correlation constraints, and forcing the generated attack samples to meet temporal coherence, causal correlation, and semantic consistency, as follows:

[0018] Assume that the attack event set is ε={e1,e2,...,e n}, each event e t =(y t ,x t ), where e t ∈ε is the event type, x t is the event feature vector;

[0019] In temporal consistency constraints, the generation order of constraint event types is expressed as:

[0020] y t ~P(y t ∣y 1:t-1 );

[0021]

[0022] Where y 1:t-1 Indicates the historical event type, ValidNext(y 1:t-1 ) is the set of event types that can be generated in the current state;

[0023] The goal of the causal relevance constraint is to ensure that the preceding event is a necessary condition for the subsequent event. j ,satisfy:

[0024]

[0025] Among them, Pre(e j ) is e j The set of all preceding events of , adds a causal violation penalty term to the loss function:

[0026]

[0027] Where, I is the indicator function;

[0028] The mathematical model of semantic consistency constraint is as follows: define the phase division function g:E→G, map the event type to the attack phase, and for each phase g k ∈G, its event characteristics must satisfy:

[0029]

[0030] in, Stage g k Event e i The key feature of , ò is the threshold of feature similarity, which is used to constrain the differences of events in the same stage;

[0031] Based on the correlation constraint, the total loss function L of the residual generator G Expressed as:

[0032] L G =L adv +λ1L causal +λ2L semantic ;

[0033] Among them, L adv is the adversarial training loss, λ1 and λ2 are hyperparameters that balance the constraint strength.

[0034] Preferably, step S1 also includes the design of a discriminator, and the discriminator loss function L D It is expressed as follows:

[0035]

[0036] in, It is the discriminant loss of the discriminator on the real data, indicating that the discriminator tries to correctly identify the real data x. is the discriminant loss of the discriminator on the generated data.

[0037] Preferably, step S1 includes designing a joint optimization objective function of the residual generative adversarial network, which is expressed as follows:

[0038]

[0039] The generator G finally trained can be used to generate pseudo attack samples in batches. The pseudo attack samples can be expressed as:

[0040]

[0041] In the formula, the generated sample Together with the original sample X, it forms the enhanced attack dataset X + , used for training and testing of subsequent attack tracing models.

[0042] Preferably, step S2 includes constructing an attack traceability graph based on temporal relationships and causal relationships, as follows:

[0043] In the attack traceability graph G(V, E, W), V represents a set, and each node corresponds to an attack log event; E is an edge set, which represents the relationship between different attack log events; W = {w ij}, represents the edge weight set, integrating three relationship features: temporal relationship, causal relationship and semantic similarity;

[0044] In the attack tracing graph, the weight of each edge is W ij It is used to indicate the strength of the relationship between two attack events. The edge weight takes into account the temporal relationship, causal relationship, and semantic similarity factors and is calculated through weighted sum. The specific formula is:

[0045] w ij =a1R tim (v i , v j )+a2R sim (v i , v j )+a3R cau (v i , v j );

[0046] a1+a2+a3=1;

[0047] Among them, w ij Represented as attack event v i and attack events v j The strength of the relationship between them, (a1, a2, a3) is expressed as the weight of each type of relationship.

[0048] Preferably, the process of introducing mutual information technology to dynamically adjust the causal confidence between nodes is as follows:

[0049] For each log stream in a window, the system records the number of times an event pair appears at the same or adjacent timestamps, and calculates the co-occurrence probability based on the total number of events in the window.

[0050] By comparing the difference between the co-occurrence probability and the independent occurrence probability of events, the causal dependence strength between attack events is quantified;

[0051] Causal confidence matrix CI(v i , v j ) is represented as follows:

[0052] CI(v i , v j )=max(MI)MI(vi , v j );

[0053] Among them, count(v i , v j ) is the maximum mutual information between all node pairs, MI(v i , v j ) is the node v i and v j The mutual information between them is as follows:

[0054]

[0055] Among them, P(v i , v j ) is the co-occurrence probability of the contrasting events, P(v i ) and P(v j ) is the probability of independent occurrence.

[0056] Preferably, step S2 further includes optimizing the confidence traceability graph, specifically as follows:

[0057] The causal confidence matrix comprehensively calculates the correlation credibility between nodes through historical time series data and real-time behavior patterns;

[0058] For existing edges, if their confidence level is continuously lower than the preset threshold, the system will automatically remove the edge (v i , v j ), the attack event edge deletion condition formula is expressed as:

[0059]

[0060] Among them, θ low Represented as the preset lower bound threshold, Expressed as the confidence of the k-th window;

[0061] On the contrary, if the newly detected abnormal event pair shows a high confidence correlation in the sliding window and its behavior sequence conforms to the known attack chain characteristics, the corresponding edge is dynamically added to expand the attack path (v i , v j ), by introducing mutual information to calculate the strength of causal relationships between nodes and optimizing the edges in the traceability graph through a dynamic adjustment mechanism, it is possible to more accurately identify key nodes and relationships in the attack path. The conditions for adding attack event edges can be expressed as follows:

[0062] c i,j >θ high and PatternMatch(i,j)=True;

[0063] Among them, θ highIt represents adding an upper threshold, and PatternMatch(i, j) represents matching the behavior sequence with the known attack chain pattern.

[0064] Preferably, in step S3:

[0065] According to the traceability graph, the node embedding is calculated using the graph attention network through the teacher model Expressed as:

[0066]

[0067] in: is the embedding vector of node i; N(i) is the set of neighbor nodes of node i, W is the learnable weight matrix; σ is the activation function ReLU; h j is the input feature or embedding vector of node j; α ij is the attention weight between node i and node j;

[0068] The node update rule of the lightweight graph isomorphic network is expressed as follows:

[0069]

[0070] Where, MLP (l) is the multi-layer perceptron at layer l; (l) is the learnable central node importance coefficient;

[0071] The total loss of knowledge distillation is expressed as:

[0072] L total =αL task +βL distill ;

[0073] Where, the hyperparameters α and β control the weights of the two types of losses; L task Expressed as task loss; L distill Expressed as distillation loss;

[0074] Node embedding based on student model Generate optimized path by similarity calculation:

[0075]

[0076] Where: PathScore(i,j) is the path score between nodes i and j, calculated by cosine similarity; is the embedding vector of node i generated by the student model; ‖·‖2 is the L2 norm of the vector.

[0077] A computer-readable storage medium includes a stored program, wherein when the program is running, the device where the computer-readable storage medium is located is controlled to execute the above-mentioned lightweight dynamic causal reasoning method for tracing attacks on power Internet of Things terminals.

[0078] A processor is used to run a program, wherein when the program is running, the power Internet of Things terminal attack tracing method based on lightweight dynamic causal reasoning as described above is executed.

[0079] Compared with the prior art, the present invention has the following beneficial effects:

[0080] The present invention first cleans, standardizes and vectorizes the log text to obtain log text vector data; adopts a residual generative network, embeds a residual network in the generator, and designs a correlation constraint loss function to introduce the temporal and logical correlation between attack events during the GAN training process; then, based on the vector data of the attack generation sample and the original sample, the temporal relationship and causal relationship of the attack event are captured, and a preliminary attack traceability graph is constructed; a method combining a graph neural network and an attention mechanism is designed to calculate the weights between nodes and optimize the correlation strength between nodes; mutual information technology is introduced to dynamically adjust the causal confidence between nodes; finally, based on the multi-level traceability graph, the GAT teacher model is used to learn the causal relationship between nodes and generate high-quality embeddings, and then the traceability knowledge of the teacher model is transferred to the lightweight GIN student model through knowledge distillation. After the above steps, the present invention can systematically construct an efficient attack traceability technology framework for power Internet of Things terminals from the three key stages of attack sample generation, traceability graph construction, and attack path reasoning, meeting the security requirements of power Internet of Things terminals for real-time performance and low resource overhead. BRIEF DESCRIPTION OF THE DRAWINGS

[0081] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following briefly describes the drawings required for the specific embodiments or the description of the prior art. Similar elements or parts are generally identified by similar reference numerals throughout the drawings. Elements or parts in the drawings are not necessarily drawn to scale.

[0082] Figure 1 is a flow chart of the method of the present invention;

[0083] Figure 2 Flowchart of the method for generating attack samples for power terminals based on residual generative adversarial networks;

[0084] Figure 3 Schematic diagram of the power terminal attack generation model based on residual generative adversarial network;

[0085] Figure 4Flowchart of the method for constructing a traceability graph for power IoT terminal attacks using dynamic graph convolution causal reinforcement;

[0086] Figure 5 A lightweight power IoT terminal attack tracing flowchart based on multi-level graph distillation;

[0087] Figure 6 This is a schematic diagram of the structure of a lightweight power IoT terminal attack tracing model based on multi-level graph distillation;

[0088] Figure 7 Statistical graph of the data set;

[0089] Figure 8 This is a comparison chart of the detection accuracy of different methods under few sample conditions;

[0090] Figure 9 Optimize edge weights for dynamic causal graphs;

[0091] Figure 10 Schematic diagram of the edge weight optimization process of the dynamic causal graph;

[0092] Figure 11 This is a comparison chart of traceability accuracy;

[0093] Figure 12 Schematic diagram comparing the lightweight effects of the model after knowledge distillation. DETAILED DESCRIPTION

[0094] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0095] It will be understood that when used in this specification and the appended claims, the terms “comprises” and “comprising” indicate the presence of described features, integers, steps, operations, elements and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof.

[0096] It should also be understood that the terms used in the present specification are only for the purpose of describing particular embodiments and are not intended to limit the present invention. As used in the present specification and the appended claims, the singular forms "a", "an", and "the" are intended to include the plural forms unless the context clearly indicates otherwise.

[0097] It should be further understood that the term "and / or" used in the present description and the appended claims refers to and includes any and all possible combinations of one or more of the associated listed items.

[0098] In one embodiment of the present invention, a lightweight dynamic causal reasoning method for tracing the source of attacks on power Internet of Things terminals is provided. Starting from the three key stages of attack sample generation, traceability graph construction, and attack path reasoning, an efficient attack traceability technology framework for power Internet of Things terminals is systematically constructed. Figure 1 shown.

[0099] First, during the attack data generation phase, this method introduces a residual structure (ResNet) based on a generative adversarial network (GAN), effectively alleviating the data degradation problem in deep generative models through a skip connection mechanism. Furthermore, by considering the temporal and logical correlations between attack behaviors on power IoT terminals, a correlation-constrained loss function is constructed to enhance the attack semantic consistency and logical rationality of the generated samples. This generates representative small-sample attack data (such as DDoS traffic and malicious command injection). This data not only compensates for the sparsity and concealment of real attack samples, but also helps the traceability model learn more comprehensive attack features and association patterns, enhancing the model's ability to identify attack links and source features during training. This allows the model to more accurately associate fragmented evidence when faced with real attacks, ultimately improving the reliability and generalization of traceability inferences.

[0100] Secondly, during the traceability graph construction phase, a dynamic causal optimization mechanism is proposed. This mechanism uses online learning algorithms (such as adaptive gradient descent) to dynamically adjust edge weights in the causal graph based on real-time attack data and operational environment changes (such as network load and device status). Furthermore, by combining metrics such as causal confidence and mutual information (MI), the edge structure in the graph is dynamically added and deleted, enabling the self-evolution and updating of the causal traceability graph. This results in a power IoT terminal attack traceability graph that can respond to attack changes in real time.

[0101] Finally, during the attack path inference phase, knowledge distillation technology is introduced to extract and compress key inference knowledge from the deep traceability model, building an efficient and lightweight attack traceability model. This model significantly reduces computational complexity and resource consumption while retaining the original causal reasoning capabilities. Suitable for edge node deployment, it enables rapid judgment and accurate traceability of attack paths, meeting the real-time and low-resource security requirements of power IoT terminals.

[0102] 1. Power Terminal Attack Sample Generation Method Based on Residual Generative Adversarial Network

[0103] In order to solve the problem of insufficient generalization of attack detection caused by imbalanced attack samples of power Internet of Things terminals, the present invention adopts residual generative adversarial network (ResGAN), embeds residual network (ResNet) in generator (Generator), and effectively alleviates the degradation problem of power Internet of Things terminal attack sample data in deep network through jump connection, thereby generating high-fidelity attack sample data and improving the generalization ability of attack detection. In order to ensure that the generated data conforms to the timing and logic of the power Internet of Things terminal attack, this paper designs a correlation constraint loss function, introduces the timing and logical correlation between attack events in the GAN training process, and generates a small number of sample data that conforms to the attack logic of the power Internet of Things terminal, thereby improving the practicality of the generated data and the accuracy of the attack simulation. The process of the power terminal attack sample generation method based on residual generative adversarial network is as follows: Figure 2 shown.

[0104] 1.1 Log text preprocessing method based on word vectorization

[0105] Power IoT terminal logs include various types, including operation logs, communication logs, event logs, security logs, fault logs, measurement and metering logs, and environmental logs. These logs record critical information such as device operating status, communication status, abnormal events, and security access, supporting power system operations and maintenance management and fault diagnosis. Because security event logs from power IoT terminals typically contain multi-dimensional, heterogeneous data, they require structured parsing and vectorization processing to provide input for subsequent threat analysis and machine learning modeling.

[0106] Step 1: Log text cleaning. Log text cleaning is the primary preprocessing step for attack analysis. Its core role is to ensure the validity and parsability of the data by eliminating noise and redundant information in the original log. Power security event logs follow standardized formats (such as IEC 62443, the international standard for Industrial Automation and Control Systems (IACS) security), and its entries cover key fields such as attack characteristics, device status, and response actions. To this end, this article defines parsing rules based on actual logs and extracts structured fields through regular expressions. The typical power security event log format is as follows:

[0107]

[0108] Among them, EventID is the unique identifier of the event, Timestamp is the exact time when the event occurred, DeviceID is the unique code of the attacked device, EventType is the event classification, ThreatLevel is the threat level, SourceIP is the attack source IP address, Protocol is the network or industrial protocol involved, Payload is the original attack payload, and ActionTaken is the automatic response measure. Therefore, the original log text sequence can be expressed as:

[0109] L={w1,w2,...,w i}(2)

[0110] Among them, w i is the i-th word in the log.

[0111] After obtaining the log word sequence, we first match the power equipment terms, protocol keywords, and event types with the power field-specific dictionary, and then use regular expression preprocessing to uniformly replace the timestamp, IP address, and hexadecimal value with placeholders. <timestamp> 、 <ip> 、 <hex>The remaining text is segmented by spaces and punctuation. Finally, common abbreviations and unit combinations are merged, such as merging "45" and "HZ" into "45HZ" to form a single word.

[0112] Taking an original log as an example, the operation process at this stage is as follows:

[0113] Original log:

[0114] [2025-04-22T14:05:33Z Device[192.168.1.100]Modbus Function Code 0x06AUTHFAIL]

[0115] Word segmentation results:

[0116] [" <timestamp>","Device","["," <ip>","]","MODBUS","FUNCTION","CODE"," <hex>","AUTHFAIL"]

[0117] Denoising is performed based on the word segmentation results. Using the segmentation results as input, a two-stage denoising approach is used to remove irrelevant or repetitive information. First, a static stop word list is used for word filtering. By defining a common stop word list for the power log domain, invalid words that are structural but not indicative of an attack are removed. Second, a dynamic noise detection mechanism based on BiLSTM is introduced. A shallow bidirectional LSTM network is constructed, taking word embedding vectors as input and outputting a noise probability score for each word:

[0118] P noise (w t )=σ(W·h t +b) (3)

[0119] Among them, h t Represents word w t The hidden state under the context, σ represents the Sigmoid activation function, W and b are learnable parameters. noise (w t )>θ, where θ∈[0.6,0.9] is the preset threshold, the word is considered as noise and deleted. The above static + dynamic two-level strategy significantly improves the semantic fidelity and the discriminative ability of vector expression.

[0120] Step 2: Log text standardization. By unifying the log's expression style, semantic format, and special field representation, we ensure consistent mapping of events of the same type in the vector space. This aims to eliminate format differences between heterogeneous log sources and improve the reliability of subsequent analysis through structured processing. Standardization primarily includes three sub-steps: field standardization, capitalization unification, and special symbol normalization.

[0121] (1) Word form unification. All reserved words are converted to uppercase to eliminate semantic duplication caused by case differences. For example, "modbus" is unified into "MODBUS" and "authfail" is unified into "AUTHFAIL".

[0122] (2) Semantic merging and field compression. We perform mapping and abbreviation processing on compound words with repeated semantics, for example, "Function Code 0x06" is merged into "FC06." Field compression and reconstruction are achieved through a mapping table. This mapping table is constructed based on the function code comparison standards of power communication protocols (such as DNP3 and MODBUS), improving the compactness of the log structure and the explicit expression of protocol behavior.

[0123] (3) Placeholder retention and format specification. To ensure the generalization ability of the model, all fields that have been desensitized or format abstracted, such as timestamps, IP addresses, port numbers, etc., are retained with unified placeholders (such as <timestamp> 、 <ip> 、 <port>), preventing specific values ​​from overfitting model training. Furthermore, the order of fields strictly maintains the original log sequence order to maintain the temporal semantics of events.

[0124] Take a denoised input as an example of normalization:

[0125] Denoised word sequence:

[0126] ["modbus","function","code","0x06","authfail"]

[0127] The results after standardization are:

[0128] ["MODBUS","FUNCTION","CODE","FC06","AUTHFAIL"]

[0129] After the above processing, the obtained standardized word sequence will be used as the input of the Log2vec vectorization module.

[0130] Step 3: Log document vectorization based on Log2vec. Log2vec vectorizes log documents, which provides vector data support for the generation of attack data for power smart terminals. Log2vec is a technology that converts log data into low-dimensional vectors. By learning the semantic information and temporal relationships of log sequences, it maps log keywords into vector representations. It draws on the idea of ​​Word2vec and captures the correlation between log events through context windows, thereby generating low-dimensional vectors that can reflect the log semantics. The objective function L for mapping log keywords into low-dimensional vectors is:

[0131]

[0132] Among them, w t is the current log keyword, w t+j is the context log keyword, T is the total number of words in the log, and c is the context window size. t+j ∣w t ) is the given current word w t When the context word w t+j The conditional probability of each log L i The word is mapped to a low-dimensional vector, which is obtained by averaging the word vectors:

[0133]

[0134] in Represents log L i The word vector of the jth word in

[0135] Finally, the log text is represented as a T×d embedding matrix, denoted as:

[0136]

[0137] 1.2 Power Terminal Attack Sample Generation Model Based on Residual Generative Adversarial Network

[0138] In response to the scarcity of attack samples for power IoT terminals and the insufficient generalization ability of traditional detection methods, an attack generation model based on residual generative adversarial networks is developed. Adding a residual network to the generative adversarial network can not only automatically generate a variety of realistic attack samples to make up for the lack of data, but also improve the generalization ability of the detection model to unknown attacks. Figure 3 shown.

[0139] Furthermore, in power IoT terminal attack scenarios, attack events typically adhere to strict temporal logic and causal dependencies (e.g., successfully escalating privileges and executing malicious commands after multiple failed login attempts). Traditional GAN-generated samples may lack these inherent connections, resulting in statistically realistic but logically flawed data. To address this, we introduce correlation constraints (temporal coherence, causal relevance, and semantic consistency) into our approach, forcing the generation of attack data that conforms to realistic attack logic.

[0140] The Generative Adversarial Network (GAN) consists of two neural networks: the generator G and the discriminator D. Data generation is achieved through an adversarial training mechanism. The goal of the generator is to generate realistic data to deceive the discriminator, while the goal of the discriminator is to distinguish between real data and generated data. The two are continuously optimized during the game, and ultimately the generator is able to generate samples that are highly similar to the real data distribution. The adversarial training optimization objective function is It can be expressed as:

[0141]

[0142] Where x represents the real data of the power terminal attack, z represents the random noise vector, which is used as the input of the generator to introduce generation diversity, G(z) represents the attack sample generated by the generator, D(x) represents the probability of the discriminator to distinguish the real data, D(G(z)) represents the probability of the discriminator to distinguish the generated data, and p data (x) represents the probability distribution of real data, Represents the expected value of the probability distribution of real data, p z (z) represents the probability distribution of the noise vector, Represents the expected value of the probability distribution of the noise vector. The input of the model is of dimension d z The random noise vector z~N(0,1) and the preprocessed structured vector Where n is the feature dimension.

[0143] The residual module is the core component of the residual adversarial generative network. Its basic idea is to add the input features to the features that have undergone nonlinear transformation through "skip connections" to alleviate the gradient vanishing problem. Its residual block can be expressed as:

[0144] y=σ(F(x,{W i })+x)(8)

[0145] Among them, F(x,{W i }) is the residual function, W i is the convolution weight, σ is the ReLU activation function, x is the input feature, and y is the output feature.

[0146] Step 1: Residual Generator Design. The residual generator is the core component of the attack sample generation model. By introducing a residual block structure, it enhances the modeling capabilities of power IoT terminal protocol features and attack behavior patterns. This generator utilizes skip connections to deeply fuse basic protocol features extracted by the shallow network (such as message format and communication cycle) with high-level attack features generated by the deep network (such as abnormal instruction injection and data tampering patterns). This effectively avoids the detail loss caused by gradient decay in traditional generators when modeling long sequences of data.

[0147] (1) Design the design goal of correlation constraints and force the generated attack samples to meet the following conditions:

[0148] a) Temporal consistency: The event sequence conforms to the real attack chain, such as Failed → Accepted → Executed.

[0149] b) Causal relevance: The preceding event is a necessary condition for the subsequent event, such as a command can only be executed after a successful login.

[0150] c) Semantic consistency: Events in the same attack phase have similar characteristics, such as multiple scans from the same source IP.

[0151] According to the above objectives, a mathematical model of correlation constraint is designed, assuming that the attack event set is ε={e1,e2,...,e n }, each event e t =(y t ,x t ), where e t ∈ε is the event type, x t is the event feature vector.

[0152] a) Temporal coherence is used to express that the order of event types must follow the attack chain logic. This can be expressed using a mathematical model to constrain the generation order of event types as follows:

[0153] y t ~P(y t ∣y 1:t-1 )

[0154]

[0155] Where y 1:t-1 Indicates the historical event type, ValidNext(y 1:t-1 ) is the set of event types that are allowed to be generated in the current state.

[0156] b) The goal of the causal relevance constraint is to ensure that the preceding event is a necessary condition for the subsequent event, so the edge e i →e j Indicates e i It is e j For each event e j , must meet the following requirements:

[0157]

[0158] Among them, Pre(e j ) is e j Therefore, a causal violation penalty term is added to the loss function:

[0159]

[0160] Where I is the indicator function, also called the indicator function or the 0-1 function.

[0161] c) The goal of semantic consistency constraint is to make the event characteristics of the same attack stage similar. Therefore, the mathematical model is: define the stage division function g:E→G, and map the event type to the attack stage. For each stage g k ∈G, its event characteristics must satisfy:

[0162]

[0163] in, Stage g k Event e i is the key feature of , and ò is the threshold of feature similarity, which is used to constrain the differences of events in the same stage.

[0164] Based on the correlation constraint, the total loss function L of the residual generator G It can be expressed as:

[0165] L G =L adv +λ1L causal +λ2L semantic

[0166] Among them, L adv is the adversarial training loss, λ1 and λ2 are hyperparameters that balance the constraint strength.

[0167] Step 2: Residual discriminator design. The residual discriminator adopts a hierarchical residual structure, focusing on capturing the microscopic differences between the generated attack samples and the real attack samples. Through the cross-layer feature aggregation mechanism, it integrates the protocol compliance features (such as CRC check validity) output by the low-level discriminator with the attack behavior abnormality features (such as instruction frequency offset, timing logic conflict) extracted by the high-level layer at multiple scales, thereby achieving accurate identification of covert attack modes (such as slow APT attacks). The discriminator loss function is used to optimize the parameters of the discriminator. Its loss function L D It can be expressed as:

[0168]

[0169] in, It is the discriminant loss of the discriminator on the real data, indicating that the discriminator tries to correctly identify the real data x. is the discriminant loss of the discriminator on the generated data.

[0170] Step 3: Design of joint optimization objective function of residual generative adversarial network. The generator and the discriminator achieve dynamic balance through adversarial game. The generator aims to minimize the distribution difference between generated samples and real attack data, and uses the multi-level feature reuse capability of residual blocks to strengthen the refined reconstruction of key features of the power protocol (such as message timing and instruction parameters) in gradient backpropagation; the discriminator maximizes the identification confidence of real attack samples and combines the multi-scale feature fusion mechanism of the residual structure to accurately capture the subtle flaws of the generated samples in the protocol logic (such as function code compliance) and attack behavior (such as abnormal operation chain). The two form adversarial constraints through alternating optimization. The residual connection further alleviates the mode collapse problem caused by gradient instability in traditional GAN, so that the generated samples achieve a balance between protocol legitimacy and attack concealment. At the same time, it forces the discriminator to establish a robust feature expression from the underlying byte stream to the high-level semantic level, and ultimately achieve the dual goals of high-quality generation of attack samples and coordinated improvement of the generalization ability of the detection model. The joint optimization objective function of the residual generative adversarial network can be expressed as:

[0171]

[0172] The generator G finally trained can be used to generate pseudo attack samples in batches, and its pseudo attack samples can be expressed as:

[0173]

[0174] In the formula, the generated sample Together with the original sample X, it forms the enhanced attack dataset X + , used for training and testing of subsequent attack tracing models.

[0175] 2. Construction of a Power IoT Terminal Attack Tracing Graph Based on Dynamic Graph Convolution Causal Reinforcement

[0176] When using the huge amount of data from the power Internet of Things system to construct an attack traceability graph, the attack path of the attack traceability graph is complex, and there are problems such as high tracing complexity and low path identification accuracy. To this end, the present invention proposes a method for constructing an attack traceability graph for a power Internet of Things terminal based on dynamic graph convolution causal reinforcement. First, based on the vector data of the attack generated samples and the original samples, the temporal relationship and causal relationship of the attack events are captured to construct a preliminary attack traceability graph. Secondly, a method combining a graph neural network and an attention mechanism is designed to calculate the weights between nodes and optimize the correlation strength between nodes. Finally, mutual information technology is introduced to dynamically adjust the causal confidence between nodes, further optimize the identification and reasoning of attack paths, and ensure the flexibility and accuracy of the traceability process. The process of the method for constructing an attack traceability graph for a power Internet of Things terminal based on dynamic graph convolution causal reinforcement is as follows: Figure 4 shown.

[0177] 2.1 Construction of Attack Tracing Graph Based on Temporal and Causal Relationships

[0178] In the construction of the attack traceability graph, we can capture the temporal relationship, causal relationship and semantic similarity between attack events through the vectorized vector data of attack events, and build the attack traceability graph based on these relationships. + , the vector representations of the original attack sample and the pseudo attack sample are:

[0179] V=[v1,v2,…,v n ] (14)

[0180]

[0181] Among them, v i is the vector representation of the i-th original attack sample, representing the attack event V i , is the vector representation of the i-th pseudo attack sample, representing the attack event n is the number of original attack samples, and m is the number of pseudo-attack samples.

[0182] Step 1: Definition of attack traceability graph relationships. In the constructed attack traceability graph G = (V, E, W), V represents a set, and each node corresponds to an attack log event; E is an edge set, which represents the relationship between different attack log events; W = {w ij}, represents the edge weight set, integrating three relationship features: temporal relationship, causal relationship and semantic similarity. For any two attack event nodes v i , v j ∈V, the three relations are defined as follows:

[0183] (1) Temporal relationship R time (v i , v j ). Timing relationship R time (v i ,v j ) is used to characterize the potential causal and progressive logic between attack events. i Immediately following the attack v j Occurs, indicating event v i With v j There is a strong temporal relationship between them. The conditional formula for the temporal relationship is as follows:

[0184]

[0185] Where Δt is the time difference between two events. τ is the maximum timing window threshold, exceeding which is considered as no direct correlation.

[0186] (2) Semantic similarity relationship R sim (v i , v j ). Semantic similarity relationship R sim (v i , v j ) is used to characterize the inherent correlation between attack events based on behavioral patterns, attack methods, or target characteristics. Specifically, if two attack events show significant similarity in dimensions such as attack vector, payload content, attack target type, or attack intent, it indicates that there is a correlation between the attack events. The formula for calculating semantic similarity is as follows:

[0187]

[0188] (3) Causal relationship R cau (v i , v j ). The causal relationship describes the potential triggering logic between attack events by integrating temporal constraints and semantic relevance. i Occurred in event v j Before, and the two have a high degree of semantic similarity, we believe that event v i Triggered event v j .Causality R cau (v i , v j ) can be expressed as:

[0189]

[0190] Among them, I(·;·|·) represents the conditional mutual information of the attack event; H(v i ) is expressed as the information entropy of the attack event; v k<i,j Represented as attack event v i and v j The correlation between them.

[0191] Step 2: Consider the weight calculation of multiple relationships. In the attack traceability graph, the weight of each edge is W ij Used to indicate the strength of the relationship between two attack events. The weights of these edges take into account the temporal relationship, causal relationship, and semantic similarity factors. Their weights can be calculated by weighted sum. The specific formula can be expressed as:

[0192] w ij =a1R tim (v i ,v j )+a2R sim (v i , v j )+a3R cau (v i , v j ) (19)

[0193] a1+a2+a3=1 (20)

[0194] Among them, w ij Represented as attack event v i and attack events v j The strength of the relationship between them, (a1, a2, a3) is expressed as the weight of each type of relationship.

[0195] 2.2 Calculation Method of Attack Node Attention Weight Based on Graph Neural Network

[0196] To address the problems of inaccurate causal relationship assessment and inefficient path generation caused by excessive redundant nodes and edges in traceability graphs, this paper proposes a graph neural network-based method. By calculating the attention weights between nodes, it identifies important causal relationships in attack nodes and provides a basis for path tracing. Graph neural networks are deep learning models capable of processing graph-structured data. They can capture complex dependencies by learning the topological relationships and feature information between nodes. In this paper, a graph attention network is used to calculate the attention weights between attack nodes. By introducing an attention mechanism, weights between nodes are dynamically assigned, which more accurately reflects the strength of the association between nodes and provides strong support for attack path optimization.

[0197] Step 1: Extract attack features from the traceability graph. Extract multi-dimensional features from the node entity (such as process behavior activity, abnormal connection frequency, permission change trajectory, etc.), construct a numerical feature vector describing the attack behavior, and integrate it into a node feature matrix. This process transforms complex attack behaviors into computable semantic representations by fusing temporal dynamic patterns and static attributes, combining feature screening and normalization processing, and providing a data basis for subsequent graph neural network analysis or causal reasoning. Given an attack traceability graph G = (V, E, W), each node v i ∈V has a eigenvector d is the feature dimension. The feature vectors of all nodes are combined to form the node feature matrix H, which is formulated as follows:

[0198] H=[h1,h2,…,h n ] (twenty one)

[0199] Among them, n is the number of nodes, H is the characteristics of all nodes in the entire traceability graph, and serves as the input for the subsequent calculation of node attention weights.

[0200] Step 2: Calculation of attention weights. The graph attention network dynamically captures potential threat associations between nodes through an adaptive attention mechanism. The network first performs nonlinear mapping and similarity measurement on the features of each node and its neighboring nodes based on the node semantic information in the feature matrix, and automatically learns the importance weights of different neighboring nodes to the current node through the attention coefficient. This weight not only reflects the connection strength in the topological structure, but also combines contextual semantics (such as the temporal association of abnormal operations and the logical dependency of authority diffusion) to enable the model to focus on key interaction nodes that are highly relevant to attack behaviors. Finally, a graph representation with attack intent directionality is generated, which provides an explainable association basis for accurately locating the source of the attack and restoring the multi-hop attack path. For each node pair (v i , v j ) calculation of the attention coefficient e ij :

[0201] e ij =LeakyReLU(a T [Wh i |Wh j ]) (twenty two)

[0202] Among them, W is a learnable weight matrix used to map node features to a high-dimensional space; a is a learnable attention vector; || represents the vector concatenation operation; LeakyReLU is the activation function.

[0203] Attention coefficient e ij Perform normalization to obtain the attention weight matrix W ij , its normalized formula is:

[0204]

[0205] Among them, N i For node V i The neighbor node set of , exp is the exponential function used to calculate the normalized weight.

[0206] Step 3: Attention weight optimization. Based on the attention weight matrix W, the graph attention network performs multi-dimensional semantic fusion on the features of the power Internet of Things terminal nodes through a multi-head attention mechanism to generate an optimized node embedding h′ containing dynamic association strength. i This embedding not only aggregates the behavioral attributes of the node itself (such as abnormal instruction frequency and sensitive API call sequence), but also strengthens the topological relationship that is strongly related to the attack path (such as abnormal cross-device communication and unauthorized access chain) through attention weight, so that key attack nodes (such as initial penetration point and lateral movement springboard) are expressed as highly distinguishable vectors in the embedding space. Generate the optimized node embedding h′ i , the calculation formula is as follows:

[0207]

[0208] Where σ is a nonlinear activation function. The final optimized node embedding h′ i It will serve as input for subsequent attack path optimization, helping to improve the accuracy and real-time performance of attack tracing.

[0209] 2.3 Dynamic Attack Path Adjustment Method Based on Mutual Information Causal Confidence

[0210] In power IoT terminal boundary attack tracing, the causal relationships within the attack path are complex and dynamically changing, making it difficult for traditional static analysis methods to accurately assess the causal strength between nodes. To address this issue, we introduce mutual information (MI) to assess the causal confidence between nodes. This dynamically adjusts edge weights, removing low-confidence edges and adding high-confidence edges to optimize the attack path structure. This dynamic optimization mechanism not only improves the accuracy of path generation but also significantly reduces computational complexity, enhancing the efficiency and real-time performance of attack tracing.

[0211] Step 1: Calculation of the co-occurrence probability of security events. In the dynamic attack path analysis, the sliding window mechanism intercepts continuous data segments of fixed length in chronological order, counts the co-occurrence probability of different security events (such as abnormal login, instruction tampering, data leakage, etc.) in the window, and quantifies the temporal correlation between nodes. Specifically, for the log stream in each window, the system records the number of times the event pair (such as abnormal access of node A and configuration change of node B) appears at the same or adjacent timestamps, and calculates the co-occurrence probability (such as conditional probability or kernel density estimation) based on the total number of events in the window, thereby providing a time-sensitive input for subsequent causal strength calculations (such as mutual information, transfer entropy), and enhancing the accuracy of attack stage division and path inference. As a preliminary basis for evaluating causal relationships. For node v i and v j , its co-occurrence probability P(v i , v j ) is calculated as follows:

[0212]

[0213] Among them, count(v i , v j ) is the node v i and v j The number of co-occurrences in the sliding window; Total count is the total number of events in the sliding window.

[0214] Step 2: Calculate mutual information between nodes. By comparing the event co-occurrence probability P(v i , v j ) and the probability of independent occurrence P(v i ), P(v j ) to quantify the causal dependency strength between attack events. Specifically, if two security events (such as vulnerability scanning and data theft) frequently co-occur within a sliding window, and their actual co-occurrence probability is significantly higher than the product of the two independent occurrence probabilities, it indicates that there is a non-random temporal correlation between the two, which may constitute a key link in the attack chain. Mutual information calculation captures the implicit logical relationship between attack behaviors by statistically analyzing the inherent deviation between the joint distribution and the marginal distribution. This method adopts a non-parametric design and can dynamically adapt to changing attack scenarios without pre-defining attack patterns. Node v i and v j Mutual information MI(v i , v j ), the formula is as follows:

[0215]

[0216] Mutual information measures the degree of information sharing between nodes. A higher mutual information value means that the two nodes are highly correlated in time and semantics, and there may be a strong causal relationship. In order to eliminate the absolute difference in mutual information values ​​between different pairs of nodes and facilitate comparison, the mutual information values ​​are normalized to obtain the causal confidence matrix CI (v i , v j ), the formula is as follows:

[0217] CI(v i , v j )=max(MI)MI(v i , v j ) (27)

[0218] Among them, count(v i , v j ) is the maximum mutual information between all pairs of nodes. The causal confidence matrix calculates the credibility of the association between nodes by combining historical time series data with real-time behavior patterns (such as the co-occurrence frequency of attack events, mutual information strength, time interval distribution, etc.).

[0219] For existing edges, if their confidence level is continuously lower than the preset threshold (e.g., due to a sudden change in node behavior or noise interference resulting in insufficient statistical significance), the system will automatically remove the edge (v i , v j ), the attack event edge deletion condition formula can be expressed as:

[0220]

[0221] Among them, θ low Represented as the preset lower bound threshold, It is expressed as the confidence of the k-th window.

[0222] On the contrary, if a newly detected abnormal event pair (such as a targeted phishing attack and lateral movement in the intranet) shows a high confidence correlation in the sliding window, and its behavior sequence conforms to the known attack chain characteristics, then the corresponding edge is dynamically added to expand the attack path (v i , v j By introducing mutual information to calculate the strength of causal relationships between nodes and optimizing the edges in the traceability graph through a dynamic adjustment mechanism, key nodes and relationships in the attack path can be more accurately identified. The conditions for adding attack event edges can be expressed as follows:

[0223] c i,j >θ high and PatternMatch(i, j)=True (29)

[0224] Among them, θ high It represents adding an upper threshold, and PatternMatch(i, j) represents matching the behavior sequence with the known attack chain pattern.

[0225] Through normalization, we ensure that the causal confidence value is between 0 and 1, which facilitates the subsequent dynamic adjustment of the causal relationship between nodes.

[0226] Step 3: Optimize the traceability graph based on confidence. Based on the causal confidence matrix CI(v i , v j ) real-time analysis, the system continuously optimizes the topology of the attack path graph through an adaptive mechanism. Specifically,

[0227] 3. Lightweight Power IoT Terminal Attack Tracing Model Based on Multi-Level Graph Distillation

[0228] The traditional traceability model is complex, resulting in high computational overhead and low real-time performance. Based on the multi-level traceability graph, the complex GAT teacher model is used to learn the causal relationship between nodes and generate high-quality embeddings. The traceability knowledge of the teacher model is then transferred to the lightweight GIN student model through knowledge distillation, so that the student model can efficiently reason and generate the traceability path of the attack. This method combines the efficient reasoning ability of graph neural networks and the low complexity advantages of knowledge distillation, significantly improving the accuracy and efficiency of attack tracing, and is suitable for dynamic analysis of large-scale log data of power Internet of Things terminals. The process of lightweight power Internet of Things terminal attack tracing model based on multi-level graph distillation is as follows: Figure 5 As shown, the model structure is as Figure 6 shown.

[0229] Step 1: GAT teacher model design. The core task of the GAT teacher model is to capture the complex causal relationships in the attack traceability graph and generate high-quality node embeddings. By introducing the multi-head attention mechanism, the model can dynamically calculate the attention weights between any two nodes in the graph, thereby quantifying the dependency strength between the nodes. Specifically, each attention head independently learns the feature interactions of different subspaces, and finally splices the outputs of multiple heads to form a comprehensive node representation. This process not only explicitly models the key causal relationships in the attack propagation path (such as the temporal dependencies and causal relationships between log events), but also ensures the rationality of the weight distribution through softmax normalization. The multi-layer stacking of GAT further enhances the model's ability to aggregate high-order neighbor information, providing semantically rich high-dimensional embeddings for subsequent knowledge distillation. According to the traceability graph, the node embedding is calculated using the graph attention network through the teacher model It can be expressed as:

[0230]

[0231] in: is the embedding vector of node i; N(i) is the set of neighbor nodes of node i, W is the learnable weight matrix; σ is the activation function ReLU; h j is the input feature or embedding vector of node j; α ij is the attention weight between node i and node j. The attention weight α between node i and j ij It can be defined as:

[0232] α ij =softmax j (LeakyReLU(a T [Wh i ||Wh j ])) (31)

[0233] Where: a is the parameter vector of the attention mechanism, used to calculate the correlation between nodes; || represents the splicing operation; LeakyReLU is the activation function of the rectified linear unit with leakage, and the slope in the negative interval is a fixed small value.

[0234] Step 2: GIN student model design. The design goal of the GIN student model is to achieve lightweight and efficient attack tracing reasoning. Its node update rule aggregates local structural information at a low computational cost through multi-layer perceptrons and neighborhood feature summation operations. Unlike GAT, GIN does not rely on the attention mechanism, but adaptively adjusts the fusion ratio of its own features and neighbor features through learnable central node weights. This simplified architecture greatly reduces the computational complexity, but may lead to insufficient modeling capabilities for complex causal relationships. Therefore, it is necessary to transfer the traceability knowledge of the GAT teacher model to GIN through knowledge distillation to make up for the limitations of its expression ability, and ultimately approach the accuracy of the teacher model while maintaining a high inference speed. Therefore, the node update rule of the lightweight graph isomorphism network:

[0235]

[0236] Where, MLP (l) is the multi-layer perceptron at layer l; (l) is the learnable central node importance coefficient. Knowledge transfer is achieved by minimizing the embedding difference between the teacher and the student.

[0237] Step 3: Design of knowledge distillation loss function. The knowledge distillation stage realizes the knowledge transfer from the teacher model to the student model by jointly optimizing the task loss and the distillation loss. The distillation loss directly constrains the node embedding of the student model to be aligned with the teacher model, forcing the latter to imitate the former's implicit encoding of causal relationships; the task loss ensures the discriminability of the student model in the attack path classification task. The adjustment of hyperparameters can balance the contribution of the two losses - initially focusing on embedding imitation to inherit the teacher's knowledge, and gradually increasing the weight of the task loss in the later stage to optimize the final classification performance. This dual-objective optimization strategy enables the student model to retain the advantages of the lightweight architecture while approaching the reasoning quality of the teacher model. The total loss of knowledge distillation can be expressed as:

[0238] L total =αL task +βL distill (33)

[0239] Where, the hyperparameters α and β control the weights of the two types of losses; L task Expressed as task loss, used for attack path classification; L distill Denoted as the distillation loss for node embedding alignment. Therefore, L task With L distill They can be expressed as:

[0240]

[0241] Where: L distill is the mean square error (MSE) of the embedding outputs of the teacher model (GAT) and the student model (GIN); N is the total number of nodes in the graph; The embedding vector of node i generated by the teacher model; is the embedding vector of node i generated by the student model; ‖·‖2 is the L2 norm, which is used to measure the difference between the embeddings of the teacher model and the student model; L task is the cross entropy loss of the student model on the attack path classification task; C is the number of categories of the attack path; y c is the one-hot encoding of the true label, y c =1 means it belongs to category c, otherwise it is 0; the student model predicts the probability of category c

[0242] Step 4: Dynamic attack path tracing. Based on the node embedding generated by the student model, the minimum attack path tree is dynamically constructed through cosine similarity calculation and threshold screening. Specifically, the cosine similarity of any two node embeddings is calculated as the path score, and the edges with scores higher than the preset threshold are retained as candidate attack paths. Subsequently, the candidate edges are topologically sorted in combination with timing constraints (such as the timestamp order of log events) to generate an attack propagation chain with causal coherence. The lightweight nature of this method enables it to process large-scale log streams generated by power IoT terminals in real time, quickly locate the source of the attack and visualize the propagation path, thereby meeting the needs of low latency and high interpretability in actual industrial scenarios. Node embedding based on student model Generate optimized path by similarity calculation:

[0243]

[0244] Where: PathScore(i,j) is the path score between nodes i and j, calculated by cosine similarity; is the embedding vector of node i generated by the student model; ‖·‖2 is the L2 norm of the vector.

[0245] 4. Experiment

[0246] The log data collected by the present invention from the power terminal monitoring system contains 20,000 log data, including various attacks such as SQL injection, DDoS attack, privilege escalation, data tampering, etc. Its data fields include: subject (user ID), object (device ID), operation type (read, write, execute), timestamp, operation result (success / failure). The number and proportion of log data are as follows: Figure 7 As shown. Figure 7 As can be seen from the figure, most of the log data is normal data, accounting for about 85.69%, while a small part of the data is attack data, accounting for a total of 14.31%.

[0247] In order to verify the detection performance of the proposed method under the condition of few samples, a comparative experiment was designed, setting the proportion of real data to 10%, 20%, and 30% of the total data, and using three training strategies: "only real data", "traditional GAN ​​+ real data", and "ResGAN + real data". The results are shown in Figure 2. Figure 8 As shown in the figure, as the proportion of real data increases, the detection accuracy of the three methods all improves. Among them, the "real data only" method performs worst when data is scarce (10%), with an accuracy of only 75.6%, which increases to 88.5% as the amount of data increases. The "traditional GAN ​​+ real data" method can alleviate the data shortage problem to a certain extent, and the detection accuracy is improved by about 5% compared to using only real data. The proposed "ResGAN + real data" method achieves the highest accuracy under all ratio conditions, especially reaching 87.5% at 10% data volume, which is significantly better than other methods, verifying its generation ability and detection support value in small sample scenarios.

[0248] Figure 9 The edge weight optimization effect of the dynamic causal graph in the attack tracing process is demonstrated. By comparing the initial and dynamically optimized edge weight matrices through the heat map, it can be clearly seen that the optimized edge weights are significantly increased on the key causal path (such as meter → gateway), indicating that the dynamic optimization mechanism can effectively identify and strengthen the important causal relationship in attack reasoning. In addition, the broken line Figure 10 The model further shows the changing trend of key edge weights over time. For example, the edge weight of "meter→gateway" gradually increases from 0.3 to 0.8, verifying the effectiveness of the dynamic weight adjustment mechanism in identifying critical paths and improving reasoning accuracy.

[0249] Figure 11 The paper presents a comparison of dynamic causal graphs, static causal graphs, and rule engines in terms of traceability accuracy under varying attack complexities. Experimental results demonstrate that dynamic causal graphs significantly outperform static causal graphs and rule engines across all attack complexities (single-device, cross-device, and cross-domain). In particular, in cross-device and cross-domain attack scenarios, dynamic causal graphs achieve traceability accuracies of 94% and 91%, respectively, significantly higher than static causal graphs (65% and 67%) and rule engines (58% and 60%). This result demonstrates the effectiveness of dynamic causal graphs in handling complex attack scenarios, providing more precise attack traceability paths.

[0250] Figure 12 The paper demonstrates the lightweighting effect of models after knowledge distillation in resource-constrained environments. A bar chart compares the differences between the teacher and student models in four key metrics: model size, inference latency, memory usage, and accuracy. The results show that the student model's size is compressed from 210MB to 42MB, inference latency is reduced from 120ms to 35ms, and memory usage is reduced from 300MB to 80MB, representing reductions of approximately 80%, 70%, and 73%, respectively. Although the student model's accuracy drops from 95% to 91%, its advantages in resource consumption and inference efficiency make it more suitable for deployment on edge devices, validating the potential of knowledge distillation technology in resource-constrained environments.

[0251] Those skilled in the art will appreciate that the units of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition of each example has been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.

[0252] In the embodiments provided by the present invention, it should be understood that the division of units is merely a logical function division, and there may be other division methods in actual implementation, for example, multiple units can be combined into one unit, one unit can be split into multiple units, or some features can be ignored, etc.

[0253] In addition, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0254] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-0nly Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk, etc., various media that can store program code.

[0255] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or make equivalent replacements for some or all of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of the present invention, and they should all be included in the scope of the claims and description of the present invention.< / port> < / ip> < / timestamp> < / hex> < / ip> < / timestamp> < / hex> < / ip> < / timestamp>

Claims

1. A lightweight dynamic causal reasoning method for tracing the source of attacks on power Internet of Things terminals, characterized by: The following steps are involved: S1: Clean, standardize, and vectorize the log text to obtain log text vector data. A residual generative network is used, which is embedded in the generator. A correlation-constrained loss function is designed to introduce temporal and logical correlations between attack events during GAN training. S2: Based on the vector data of attack-generated samples and original samples, we capture the temporal and causal relationships of attack events and construct a preliminary attack traceability diagram. We design a method that combines a graph neural network with an attention mechanism to calculate the weights between nodes and optimize the strength of the association between nodes. We also introduce mutual information technology to dynamically adjust the causal confidence between nodes. S3: Based on the multi-level traceability graph, the GAT teacher model is used to learn the causal relationship between nodes and generate high-quality embeddings. Then, the traceability knowledge of the teacher model is transferred to the lightweight GIN student model through knowledge distillation.

2. The method for tracing the attack source of the power Internet of Things terminal based on lightweight dynamic causal reasoning according to claim 1 is characterized in that: Step S1 includes the design of the residual generator and the design of correlation constraints to force the generated attack samples to meet temporal coherence, causal relevance, and semantic consistency, as follows: Assume that the attack event set is ε={e1,e2,...,e n }, each event e t =(y t ,x t ), where e t ∈ε is the event type, x t is the event feature vector; In temporal consistency constraints, the generation order of constraint event types is expressed as: and t ~P(and t ∣y 1:t-1 ); Where y 1:t-1 Indicates the historical event type, ValidNext(y 1:t-1 ) is the set of event types that can be generated in the current state; The goal of the causal relevance constraint is to ensure that the preceding event is a necessary condition for the subsequent event. j ,satisfy: Among them, Pre(e j ) is e j The set of all preceding events of , adds a causal violation penalty term to the loss function: Where, I is the indicator function; The mathematical model of semantic consistency constraint is as follows: define the phase division function g:E→G, map the event type to the attack phase, and for each phase g k ∈G, its event characteristics must satisfy: in, Stage g k Event e i The key features of is the threshold of feature similarity, which is used to constrain the differences of events in the same stage; Based on the correlation constraint, the total loss function L of the residual generator G Expressed as: L G =L adv +λ1L causal +λ2L semantic ; Among them, L adv is the adversarial training loss, λ1 and λ2 are hyperparameters that balance the constraint strength.

3. The method for tracing the attack source of the power Internet of Things terminal based on lightweight dynamic causal reasoning according to claim 1 is characterized in that: Step S1 also includes the design of the discriminator, the discriminator loss function L D It is expressed as follows: in, is the discriminant loss of the real data, indicating that the discriminator tries to correctly identify the real data x, is the discriminant loss of the discriminator on the generated data.

4. The method for tracing the attack source of the power Internet of Things terminal based on lightweight dynamic causal reasoning according to claim 1 is characterized in that: Step S1 includes designing the joint optimization objective function of the residual generative adversarial network, which is expressed as follows: The generator G finally trained can be used to generate pseudo attack samples in batches. The pseudo attack samples can be expressed as: In the formula, the generated sample Together with the original sample X, it forms the enhanced attack dataset X + , used for training and testing of subsequent attack tracing models.

5. The method for tracing the attack source of the power Internet of Things terminal based on lightweight dynamic causal reasoning according to claim 1 is characterized in that: Step S2 includes constructing an attack traceability graph based on temporal and causal relationships, as follows: In the attack traceability graph G = (V, E, W), V represents a set, and each node corresponds to an attack log event; E is an edge set, which represents the relationship between different attack log events; W = {w ij }, represents the edge weight set, integrating three relationship features: temporal relationship, causal relationship and semantic similarity; In the attack tracing graph, the weight of each edge is W ij It is used to indicate the strength of the relationship between two attack events. The edge weight takes into account the temporal relationship, causal relationship, and semantic similarity factors and is calculated through weighted sum. The specific formula is: w ij =a1R tim (v i ,v j )+a2R sim (v i ,v j )+a3R cau (v i ,v j ); a1+a2+a3=1; Among them, w ij Represented as attack event v i and attack events v j The strength of the relationship between them, (a1, a2, a3) is expressed as the weight of each type of relationship.

6. The method for tracing the attack source of the power Internet of Things terminal based on lightweight dynamic causal reasoning according to claim 5 is characterized in that: The specific process of introducing mutual information technology to dynamically adjust the causal confidence between nodes is as follows: For each log stream in a window, the system records the number of times an event pair appears at the same or adjacent timestamps, and calculates the co-occurrence probability based on the total number of events in the window. By comparing the difference between the co-occurrence probability and the independent occurrence probability of events, the causal dependence strength between attack events is quantified; Causal confidence matrix CI(v i , v j ) is represented as follows: CI(in i ,in j )=max(MI)MI(in i ,in j ); Among them, count(v i , v j ) is the maximum mutual information between all node pairs, MI(v i , v j ) is the node v i and v j The mutual information between them is as follows: Among them, P(v i , v j ) is the co-occurrence probability of the contrasting events, P(v i ) and P(v j ) is the probability of independent occurrence.

7. The method for tracing the attack source of the power Internet of Things terminal based on lightweight dynamic causal reasoning according to claim 6 is characterized in that: Step S2 also includes confidence traceability graph optimization, as follows: The causal confidence matrix comprehensively calculates the correlation credibility between nodes through historical time series data and real-time behavior patterns; For existing edges, if their confidence level is continuously lower than the preset threshold, the system will automatically remove the edge (v i , v j ), the attack event edge deletion condition formula is expressed as: Among them, θ low Represented as the preset lower bound threshold, Expressed as the confidence of the k-th window; On the contrary, if the newly detected abnormal event pair shows a high confidence correlation in the sliding window and its behavior sequence conforms to the known attack chain characteristics, the corresponding edge is dynamically added to expand the attack path (v i , v j ), by introducing mutual information to calculate the strength of causal relationships between nodes and optimizing the edges in the traceability graph through a dynamic adjustment mechanism, it is possible to more accurately identify key nodes and relationships in the attack path. The conditions for adding attack event edges can be expressed as follows: c i,j >θ high and PatternMatch(i,j)=True; Among them, θ high It represents adding an upper threshold, and PatternMatch(i, j) represents matching the behavior sequence with the known attack chain pattern.

8. The method for tracing the attack source of a power Internet of Things terminal based on lightweight dynamic causal reasoning according to claim 1 is characterized in that: In step S3: According to the traceability graph, the node embedding is calculated using the graph attention network through the teacher model Expressed as: in: is the embedding vector of node i; N(i) is the set of neighbor nodes of node i, W is the learnable weight matrix; σ is the activation function ReLU; h j is the input feature or embedding vector of node j; α ij is the attention weight between node i and node j; The node update rule of the lightweight graph isomorphic network is expressed as follows: Where, MLP (l) is the multi-layer perceptron at layer l; (l) is the learnable central node importance coefficient; The total loss of knowledge distillation is expressed as: L total =αL task +βL distill ; Where, the hyperparameters α and β control the weights of the two types of losses; L task Expressed as task loss; L distill Expressed as distillation loss; Node embedding based on student model Generate optimized path by similarity calculation: Where: PathScore(i,j) is the path score between nodes i and j, calculated by cosine similarity; is the embedding vector of node i generated by the student model; ‖·‖2 is the L2 norm of the vector.

9. A computer-readable storage medium, characterized in that The computer-readable storage medium includes a stored program, wherein, when the program is running, the device where the computer-readable storage medium is located is controlled to execute the power Internet of Things terminal attack tracing method based on lightweight dynamic causal reasoning as described in any one of claims 1 to 8.

10. A processor, characterized in that: The processor is used to run a program, wherein, when the program is running, the power Internet of Things terminal attack tracing method based on lightweight dynamic causal reasoning described in any one of claims 1 to 8 is executed.

Citation Information

Cited By

  • Machine room monitoring method and system based on multi-source data fusion intelligent inspection robot

    CN120873999A

  • Industrial product data compression and tracing system and method

    CN120994626A

  • Multi-level community data linkage analysis processing method and system

    CN121706115A

  • Abnormal behavior sample data generation method based on generative adversarial network

    CN121859003A

  • An abnormal behavior sample data generation method based on a generative adversarial network

    CN121859003B