Unknown network threat immunodetector generation method and device

An unknown network threat immune detector is generated through the hierarchical differential evolution algorithm of edge autoantigens, which solves the shortcomings of existing IDS in unknown attack detection and realizes efficient and accurate unknown network threat detection.

CN120764580APending Publication Date: 2025-10-10SICHUAN UNIV
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510965832.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-14
Publication Date
2025-10-10

AI Technical Summary

Technical Problem

Existing intrusion detection systems (IDS) have limited capabilities in detecting unknown network attacks. In particular, signature-matching-based IDS relies on existing attack feature libraries, and anomaly detection-based methods have a high false positive rate and are difficult to adapt to dynamically changing network environments.

Method used

The hierarchical differential evolution (HiDE) algorithm based on edge self-antigens is used to generate unknown network threat immune detectors through training samples, and unknown non-self antigens are deduced using edge self-antigens. Detectors are generated through tolerance training to simulate the attacker's unknown attack process and achieve adaptive optimization.

Benefits of technology

Generate an immune detector that can dynamically adapt to unknown network attack patterns, improve the detection accuracy and efficiency of unknown network threats, reduce the false alarm rate, and enhance the ability to identify unknown attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120764580A_ABST
    Figure CN120764580A_ABST
Patent Text Reader

Abstract

The invention discloses an unknown network threat immunodetector generation method and device, and relates to the technical field of network security, and the method comprises the steps: S1, obtaining a training sample; s2, performing antigen presentation to obtain a training autoantigen set and a training non-autoantigen set; s3, extracting an edge autoantigen; s4, deducing an unknown non-autologous antigen by using the edge autoantigen; s5, carrying out tolerance training on unknown non-autoantigen and autoantigen, adding the antigen subjected to tolerance training as a mature antibody into the t-th generation non-autoantigen set, and generating a network attack detector; s6, judging whether t reaches a preset number of times, and if so, ending; otherwise, entering S7; s7, enabling t + 1 to be equal to t, and returning to S3; according to the method, the autoevolution of the detector is realized, and the immune detector capable of detecting unknown is generated, so that the immune detector can dynamically adapt to an unknown network attack mode; according to the method, an edge benign detector can adaptively optimize and construct an unknown attack process, and unknown network threats can be efficiently and accurately detected.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a method and device for generating an unknown network threat immune detector. Background Art

[0002] In recent years, the rapid development of emerging information technologies such as the Internet of Things, digital twins, and 5G networks has led to increasingly complex and interconnected computer systems and communication networks, significantly promoting the digitalization of social production and life. However, the widespread use of these technologies has also spawned a large number of new cyberattacks, particularly unknown cyber threats that exploit mutation, stealth, and evasion techniques to bypass existing security mechanisms and wreak havoc on systems and networks.

[0003] Faced with an increasingly complex cyberattack environment, intrusion detection systems (IDS) have become a key means of network security defense. Currently, signature-matching-based IDSs have a high accuracy rate in detecting known attacks. However, due to their closed-set assumption, their detection capabilities rely heavily on existing attack signature libraries, making their ability to identify unknown attacks extremely limited. Anomaly-detection-based IDSs can detect unknown attacks to a certain extent by capturing data patterns that deviate significantly from normal behavior. Common methods include probability density modeling, local reachable density analysis, and feature space partitioning. However, because the accuracy of normal sample modeling is limited by a limited dataset, anomaly detection methods often suffer from a high false positive rate (FPR).

[0004] Therefore, with the continuous emergence of unknown network attacks in increasingly complex and heterogeneous network environments, developing a novel intrusion detection system for detecting unknown network attacks is a crucial task. Inspired by the biological immune system (BIS), artificial immunity (AIm) has been introduced into the field of intrusion detection. Based on immune principles, network traffic is mapped into multidimensional antigens and the identification of unknown attacks is achieved by calculating the affinity between self-antigens (normal samples) and non-self-antigens (abnormal samples). Some studies have used evolutionary computation to generate potential unknown attack patterns to enhance detection capabilities. However, existing AIm-based methods have difficulty adapting to dynamically changing network environments and are unable to efficiently generate detectors for unknown attacks, resulting in limited detection effectiveness. Summary of the Invention

[0005] The purpose of the present invention is to design a method and device for generating an unknown network threat immune detector in order to solve the above problems.

[0006] The present invention achieves the above-mentioned purpose through the following technical solutions:

[0007] A method for generating an unknown network threat immunity detector includes:

[0008] S1. Obtain training samples, which include known normal data and known network attack data;

[0009] S2. Perform antigen presentation on known normal data and known network attack data to obtain a training self-antigen set and a training non-self-antigen set;

[0010] S3. Use the training non-self antigens to extract the self antigens with the greatest affinity to the non-self region from the self antigen set as marginal self antigens, and add the marginal self antigens to the marginal self antigen set. ;

[0011] S4. Use marginal self-antigens to deduce unknown non-self antigens;

[0012] S5. Perform tolerance training on unknown non-self antigens and self antigens. The antigens that have passed the tolerance training are added as mature antibodies to the t-generation non-self antigen collection. and used to generate a network attack detector, t is a positive integer;

[0013] S6, determine whether the current number of cycles t reaches the preset number, if so, end; otherwise, enter S7;

[0014] S7. Set t+1=t and return to S3.

[0015] An unknown network threat immunity detector generating device includes:

[0016] a memory; a computer program being stored in the memory;

[0017] Executor; The executor is used to execute the computer program in the storage, and when the computer program is executed, the above-mentioned unknown network threat immune detector generation method is implemented.

[0018] The beneficial effects of the present invention are: a method for generating an immune detector for unknown network threats based on the evolution of edge self-antigens, which realizes the self-evolution of the detector and generates an immune detector capable of detecting the unknown, so that it can dynamically adapt to unknown network attack patterns; this method constructs an efficient immune detector evolution mechanism, so that the benign detectors at the edge can be adaptively optimized and evolved, simulating the process of attackers constructing unknown attacks, so as to detect unknown network threats more efficiently and accurately, thereby making up for the shortcomings of existing IDS in unknown attack detection. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Figure 1 is a schematic diagram of a method for generating an unknown network threat immune detector according to the present invention;

[0020] Figure 2 This is an example diagram of the distribution of non-self antigens and the self antigens closest to them;

[0021] Figure 3 This is an example diagram of the distribution of detectors and self-body areas;

[0022] Figure 4 Schematic diagram of hierarchical differential mutation and receptor editing. DETAILED DESCRIPTION

[0023] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more apparent, the technical solutions of the embodiments of the present invention will be described clearly and completely below in conjunction with the accompanying drawings of the embodiments of the present invention. It should be understood that the described embodiments are only a portion of the embodiments of the present invention, not all of them. Generally, the components of the embodiments of the present invention described and illustrated in the drawings herein may be arranged and designed in a variety of different configurations.

[0024] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the invention as claimed, but rather merely represents selected embodiments of the present invention. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present invention without creative effort shall fall within the scope of protection of the present invention.

[0025] It should be noted that similar reference numerals and letters denote similar items in the following drawings, and therefore, once an item is defined in one drawing, it does not need to be further defined or explained in subsequent drawings.

[0026] In the description of the present invention, it should be understood that the terms "upper", "lower", "inside", "outside", "left", "right", etc. indicate orientations or positional relationships based on the orientations or positional relationships shown in the accompanying drawings, or are the orientations or positional relationships in which the inventive product is conventionally placed when in use, or are the orientations or positional relationships conventionally understood by those skilled in the art. These are only for the convenience of describing the present invention and simplifying the description, and do not indicate or imply that the device or component referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be understood as a limitation on the present invention.

[0027] Furthermore, the terms “first”, “second”, etc. are merely used for distinguishing descriptions and should not be understood as indicating or implying relative importance.

[0028] In the description of the present invention, it should also be noted that, unless otherwise expressly specified or limited, terms such as "disposed" and "connected" should be understood in a broad sense. For example, "connected" can mean a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium; it can also mean internal communication between two components. Those skilled in the art will be able to understand the specific meanings of the above terms in the present invention based on specific circumstances.

[0029] The specific embodiments of the present invention are described in detail below with reference to the accompanying drawings.

[0030] Since the hierarchical differential evolution (HiDE) algorithm deduces unknown non-self antigens by making self antigens deviate from the self region, the fitness function of the parent antigen in the HiDE algorithm measures the affinity between the self antigen and the non-self region. The self antigen closest to the non-self region is selected to maximize the fitness function. The best individual in the is used as the parent antigen for the HiDE algorithm;

[0031] Definition 1: If for a self-antigen ( ), there is at least one self-region Dimension Point , so that it satisfies condition 1, which is expressed as: , then this autoantigen It is the self area marginal autoantigens, among which is the body radius, is a vector The second norm of .

[0032] From Definition 1, we can get that for a marginal self-antigen, there is at least one direction pointing outside the self-region. As long as the amplitude of the mutation vector in this direction is greater than the self-radius, the marginal self-antigen can be evolved outside the self-region through the perturbation of this mutation vector. Point q in the self region points to The unit vector of The direction of the mutation vector pointing outside the self region, then is A mutation vector with magnitude r pointing outside the self region.

[0033] Theorem 1: Any non-self antigen ( )or ( ) The closest autoantigens are marginal autoantigens, among which is the set of non-self antigens evolved by the HiDE algorithm in the tth generation.

[0034] Two-dimensional space and training non-self antigens For example, distance Recent autoantigens An example of the distribution of Figure 2 As shown. As the center, A circle with a radius The coverage area belongs to the autologous area. It's distance The nearest self-antigen, so in As the center of the circle, A circle with a radius There are no other autoantigens within the coverage area. Figure 2 The green shaded area (i.e. is the center of the circle and Tangent circle) does not belong to the self area, then the line segment Any point on the extended line segment (blue line segment) Both can be used satisfies Definition 1. Therefore, the distance from non-self antigen Recent autoantigens is a marginal self-antigen. Similarly, this proof is also true for the evolved non-self antigens Also holds true.

[0035] According to Theorem 1, the marginal self-antigen is the training self-set The individual closest to the non-self region, that is, the marginal self antigen is a collection The best individual for the HiDE algorithm. Although any self-antigen can be deduced to non-self-antigens outside the self-region by perturbation of the mutation vector, only for the edge self-antigen, the minimum amplitude of its mutation vector can be determined to be the self-radius. This is conducive to setting a reasonable mutation vector amplitude for marginal self-antigens. Therefore, the HiDE algorithm uses marginal self-antigens as the parent antigen population for evolution.

[0036] Lemma 1: Any non-self antigen ( or ) has a corresponding marginal autoantigen, and The corresponding edge bodies are respectively denoted as and , expressed as: 、 ,

[0037] Let the set of marginal self-antigens obtained in the t-th generation be denoted as , which is expressed as: ;

[0038] Lemma 2: For any marginal self-antigen ( ), there is at least one point in the self-region that satisfies condition 2 under the mutation vector amplitude , and condition 2 is expressed as: ;

[0039] Let the parent antigen population in the t-th generation in the HiDE algorithm be denoted as , and the number of antigens in be denoted as , , which is composed of new marginal self-antigens obtained in the t-th generation, and is expressed as: ; In the formula, the subtraction A-B of the set means deleting the elements in the intersection of A and B from the set A.

[0040] As shown in Figure 1 , the unknown network threat immune detector generation method comprises:

[0041] S1, obtaining training samples, the training samples including known normal data and known network attack data.

[0042] S2, performing antigen presentation on the known normal data and the known network attack data respectively to obtain a training self-antigen set and a training non-self antigen set; specifically comprising:

[0043] S21, representing a feature encoded dimensional network data sample as a dimensional antigen, and the known normal network data sample and the network attack data sample constitute a first set and a second set respectively;

[0044] S22, normalizing the first set and the second set to obtain a training self-antigen set and a training non-self antigen set , which is expressed as:

[0045] ;

[0046] ;

[0047] in, and is the normalized training autoantigen Non-self antigens The d-th dimension eigenvalue of and Normal network data and cyber attack data The d-th dimension eigenvalue of and for The minimum and maximum values ​​of the d-th dimension eigenvalues ​​in ;

[0048] ;

[0049] ;

[0050] in, , , , , , , .

[0051] S3. Use the training non-self antigens to extract the self antigens with the greatest affinity to the non-self region from the self antigen set as marginal self antigens, and add the marginal self antigens to the marginal self antigen set. ; Extracting the self-antigens corresponding to the non-self-antigens as marginal self-antigens; specifically:

[0052] When t=0, , among which non-self antigens , For self-antigens, is the marginal self-antigen, t is a positive integer;

[0053] When t is greater than 0, , among which non-self antigens , Marginal autoantigens, It is the tth generation non-self antigen collection.

[0054] S4. Use marginal self-antigens to deduce unknown non-self-antigens; specifically including:

[0055] S41. Extraction of marginal autoantigen collection The t-th marginal self-antigen in the parent antigen set , expressed as: ;

[0056] S42. Based on hierarchical differential evolution, the parent antigens are cloned, multiplied, hierarchical differential evolution, receptor editing, and antigen selection are sequentially performed to obtain an unknown non-self antigen set. ;

[0057] If the fitness of the parent antigen is measured by the maximum affinity to the non-self region, since the shortest distance between the marginal self antigen and the non-self region is , so the fitness of all parent antigens in the HiDE algorithm is the same. For marginal self-antigens, the magnitude of the mutation vector can be (l ) to determine the affinity between the variant antigen and the parent antigen, thereby estimating the deviation between the variant antigen and the autologous region. When the fitness of the variant antigen is measured by the deviation from the autologous region, the fitness of the variant antigen can be preset by the mutation vector amplitude. The larger the mutation vector amplitude, the greater the preset fitness of the variant antigen. The number of clonal proliferations of the parent antigen is related to the preset fitness of its variant antigen (i.e., the mutation vector amplitude). Because the closer the detector radius is to the autologous region, the smaller the detector radius is, the non-autologous region closer to the autologous region requires more detectors to cover it. The two-dimensional space example is shown in the figure below. Figure 3 Therefore, the number of variant antigens with smaller deviations from the self-region should be greater, so as to further generate more small-radius detectors to cover the non-self-region adjacent to the self-region, that is, the number of clonal proliferation of the parent antigen decreases with the increase of the mutation vector amplitude.

[0058] The specific steps for clonal proliferation of parent antigens are:

[0059] The total number of clones of the parent antigen is recorded as , is the magnitude of the variation vector The number of clones under , is expressed as: ,in, is a set of positive integers, is the adjustment parameter for the number of clones, is the maximum number of clones, e is the natural index, is the ceiling function;

[0060] Parental antigen The matrix form after clonal proliferation is expressed as: ,in, for In the variation vector magnitude The clonal antigen matrix under for A matrix with all "1" in one row and one column, is the transpose of the matrix, l , , To set the number of times the mutation vector amplitude is increased, , The amplitude of the mutation vector increases in each level to obtain the variant antigen with different degrees of deviation from the autologous region; the clonal proliferation operation makes each parent antigen Multiple copies are generated, and multiple copies undergo perturbations by different mutation vectors, thereby improving the diversity of single parent antigen mutations.

[0061] The hierarchical differential evolution of the parent antigen of the cloned proliferation is as follows:

[0062] In order to deviate the marginal self-antigens to outside the self-region, the parent antigen in the HiDE algorithm The initial calculation method of the mutation vector is expressed as: ,in: is a point in the self region, and is a random antigen that is different from the current parent antigen. is the main vector that guides the parental antigen away from the self region, The diversity of variant antigens is increased by adding random vector perturbations. According to Lemma 2, in order to set a reasonable mutation vector amplitude, the mutation vector is replaced by the mutation vector amplitude multiplied by the unit vector, expressed as: ;in, is the magnitude of the variation vector;

[0063] mutation vector magnitude (l ) is expressed as: ,in, is the multiplier between the magnitudes of the variation vectors; the minimum magnitude of the variation vector The default value range is The magnitude of the mutation vector is expressed as: ,in, is the adjustment parameter of the variation vector amplitude range, Normalized The maximum distance between two points in the dimensional space, both of which determine the farthest range that the mutant antigen can reach.

[0064] Due to irregular autologous areas It is difficult to describe it with a mathematical model, making it difficult to accurately select appropriate points in the autologous area. make Deviate from the self area. Select autoantigens that must be in the autologous region ;

[0065] In summary, parental antigen In the variation vector magnitude Next, clone the antigen matrix The variant antigen matrix is ​​denoted as , expressed as: ;in, is a clonal antigen matrix Middle The mutation vector of the row antigen, and are random parent antigens that are different from each other in the parent antigen set, and For everyone Repeatedly randomly selected antigens, m Due to the randomness of autoantigen selection, not all Both can make the variant antigens fall outside the autologous area, but those ineffective antigens will be eliminated by subsequent tolerance training;

[0066] Clonal Antigen Matrix The variant antigen matrix is ​​denoted as , expressed as: ;

[0067] In the variation vector magnitude Variant antigen matrix Expressed as: ,

[0068] exist Under the mutation vector amplitude of increasing levels, the t-th generation mutation antigen matrix Expressed as: ;

[0069] Receptor editing for variant antigens is specifically as follows:

[0070] Since the evolution path of marginal self-antigens in hierarchical differential evolution is a straight line vector, in order to keep the HiDE algorithm with a large search range of unknown non-self antigens during the evolution process, an arc evolution path is introduced in receptor editing. Specifically, some variant antigens are The maximum number of clones in 2D space is calculated by rotating at random angles in 2D space to achieve random jumps in receptor editing. As an example, the process diagram of hierarchical differential mutation and receptor editing is as follows Figure 4 As shown;

[0071] From the variant antigen matrix Randomly select Rows constitute a OK Column matrix , the center of rotation Set up for training autoantigens The center point is expressed as: , in the tth generation of evolution The edited antigen matrix obtained by rotation , expressed as: ,in, Variant antigen matrix the number of rows, The proportion of variant antigens involved in receptor editing; , is the number of rotations, for The orthogonal transformation matrix, for A matrix with all "1" in one row and one column; After rotation, edit the antigen matrix Expressed as: ;

[0072] Antigen selection for receptor editing and variant antigens is as follows:

[0073] The antigen selection operation is to select low-redundancy antigens from the mutated and edited antigens in the tth generation as the final evolved antigen of the HiDE algorithm in the tth generation. Redundant mutated / edited antigens refer to antigens that are too close to each other. Different detectors generated by redundant antigens will overlap. Overlapping detectors are an invalid superposition of the detector coverage, which not only fails to effectively improve the detection performance, but also increases unnecessary computational consumption. After the antigen mutation and receptor editing, The expanded form is expressed as:

[0074] ;

[0075] The expanded form is expressed as:

[0076] ;

[0077] in: Is the parental antigen In the variation vector magnitude The variant antigen produced by the next m-th clone copy; is the variant antigen matrix The pth row antigen is in The edited antigen obtained in the rotation, m , , ;

[0078] Depend on and The set of antigens in is expressed as:

[0079] ;

[0080] ;

[0081] The training set of non-self antigens Considered as the variant antigen of generation 0 , and there are .

[0082] Depend on Figure 3 It can be seen that the non-self region closer to the self region requires more detectors to cover it, so the mutant antigens obtained by smaller mutation vector amplitudes can maintain a closer distance. Therefore, the antigen selection operation independently targets the antigen sets obtained by different mutation vector amplitudes. with edited antigen collections The rule of antigen selection operation is: when the distance between two antigens in the antigen set G is less than When , one of them will be randomly removed, is the selection distance threshold of set G. Variant antigen set The distance threshold for selection (t>0) is ; and because the collection and The distances between the antigens contained in and the self-regions cannot be estimated, and their selected distance threshold is In the tth generation of evolution, and The individuals retained after antigen selection constitute the evolutionary antigen set of the tth generation of the HiDE algorithm .

[0083] Taking the t-th generation evolution as an example, the algorithm flow of hierarchical differential evolution HiDE is shown in Table 1.

[0084] Table 1 is the flow chart of the hierarchical differential evolution (HiDE) algorithm

[0085]

[0086] S5. Perform tolerance training on unknown non-self antigens and self antigens. The antigens that have passed the tolerance training are added as mature antibodies to the t-generation non-self antigen collection. and used to generate a network attack detector, t is a positive integer; specifically: when the antigen satisfy , then the antigen To successfully mature antibodies through self-tolerance training, the antigen Add the tth generation non-self antigen collection , that is, the generated unknown threat immunity detector.

[0087] S6. Determine whether the current number of cycles t reaches the preset number. If so, end; otherwise, enter S7.

[0088] S7. Set t+1=t and return to S3.

[0089] This method, based on artificial immunity, overcomes the limitation of most signature-based intrusion detection systems, which can only effectively detect known types of network attacks contained in the training samples. This method uses self-antigens to deduce unknown non-self antigens that deviate from normal data characteristics and uses these derived antigens to generate unknown attack detectors.

[0090] While traditional anomaly-based intrusion detection systems can detect unknown cyberattacks by checking whether observed data deviates significantly from normal data, it is difficult to accurately model normal data and set appropriate anomaly score thresholds to measure deviations using limited samples. This can result in a high false positive rate to achieve a satisfactory cyberattack detection rate. This method designs an evolutionary algorithm based on hierarchical differential evolution. This algorithm perturbs antigens by generating mutation vectors with hierarchical amplitudes, thereby inferring unknown non-self antigens. This method achieves good performance (both false positive rate and detection rate) in detecting known and unknown cyberattacks even when prior knowledge of the unknown attack is incomplete.

[0091] Most existing AI-based intrusion detection systems use random methods to generate possible non-self antigens. While this random method can generate unknown non-self antigens, it often introduces a large number of invalid antigens, making it ineffective in generating unknown network attack detectors and resulting in high training costs. This method utilizes a marginal self-antigen evolution algorithm to perturb marginal self-antigens based on hierarchical amplitude mutation vectors, causing them to deviate from the self region by varying degrees. This allows the generation of unknown non-self antigens with varying degrees of deviation from the self region.

[0092] An unknown network threat immunity detector generating device includes:

[0093] a memory; a computer program being stored in the memory;

[0094] Executor; The executor is used to execute the computer program in the storage, and when the computer program is executed, the above-mentioned unknown network threat immune detector generation method is implemented.

[0095] The technical solution of the present invention is not limited to the above-mentioned specific embodiments. Any technical variations made according to the technical solution of the present invention fall within the protection scope of the present invention.

Claims

1. A method for generating an unknown network threat immune detector, characterized in that: include: S1. Obtain training samples, which include known normal data and known network attack data; S2. Perform antigen presentation on known normal data and known network attack data to obtain a training self-antigen set and a training non-self-antigen set; S3. Use the training non-self antigens to extract the self antigens with the greatest affinity to the non-self region from the self antigen set as marginal self antigens, and add the marginal self antigens to the marginal self antigen set. ; S4. Use marginal self-antigens to deduce unknown non-self antigens; S5. Perform tolerance training on unknown non-self antigens and self antigens. The antigens that have passed the tolerance training are added as mature antibodies to the t-generation non-self antigen collection. and used to generate a network attack detector, t is a positive integer; S6, determine whether the current number of cycles t reaches the preset number, if so, end; otherwise, enter S7; S7. Set t+1=t and return to S3.

2. The method for generating an unknown network threat immune detector according to claim 1, characterized in that: Included in S2: S21, after encoding a feature dimensional network data sample is represented as a dimensional antigens, known normal network data samples and network attack data samples The first set and the second set ; S22, for the first set and the second set Normalize and obtain the training autologous antigen set and training non-self antigen sets , expressed as: ; ; in, and is the normalized training autoantigen Non-self antigens The d-th dimension eigenvalue of and Normal network data and cyber attack data The d-th dimension eigenvalue of and for The minimum and maximum values ​​of the d-th dimension eigenvalues ​​in ; ; ; in, , , , , , , .

3. The method for generating an unknown network threat immune detector according to claim 1, characterized in that: In S3, the self-antigens corresponding to the non-self-antigens are extracted as marginal self-antigens; specifically: When t=0, , among which non-self antigens , For self-antigens, It is a marginal self-antigen; When t>0, , among which non-self antigens , It is a marginal self-antigen.

4. The method for generating an unknown network threat immune detector according to claim 1, wherein: Specifically included in S4: S41. Extraction of marginal autoantigen collection The t-th marginal self-antigen in the parent antigen set , expressed as: ; S42. Based on hierarchical differential evolution, the parent antigens are cloned, multiplied, hierarchical differential evolution, receptor editing, and antigen selection are sequentially performed to obtain an unknown non-self antigen set. .

5. The method for generating an unknown network threat immune detector according to claim 4, characterized in that: The specific steps for clonal proliferation of parent antigens are: The total number of clones of the parent antigen is recorded as , is the magnitude of the variation vector The number of clones under , is expressed as: ,in, is a set of positive integers, is the adjustment parameter for the number of clones, is the maximum number of clones, e is the natural index, is the ceiling function; Parental antigen The matrix form after clonal proliferation is expressed as: ,in, for In the variation vector magnitude The clonal antigen matrix under for A matrix with all "1"s in one row and one column. is the transpose of the matrix, l , .

6. The method for generating an unknown network threat immune detector according to claim 4, characterized in that: The hierarchical differential evolution of the parent antigen of the cloned proliferation is as follows: Parental antigen In the variation vector magnitude Next, clone the antigen matrix The variant antigen matrix is ​​denoted as , expressed as: ;in, is a clonal antigen matrix Middle The mutation vector of the row antigen, and are random parent antigens that are different from each other in the parent antigen set, and For everyone Repeatedly randomly selected antigens, m ; Clonal Antigen Matrix The variant antigen matrix is ​​denoted as , expressed as: ; In the variation vector magnitude Variant antigen matrix Expressed as: , exist Under the mutation vector amplitude of increasing levels, the t-th generation mutation antigen matrix Expressed as: 。 7. The method for generating an unknown network threat immune detector according to claim 4, characterized in that: Receptor editing for variant antigens is specifically as follows: From the variant antigen matrix Randomly select Rows constitute a OK Column matrix , the center of rotation Set up for training autoantigens The center point is expressed as: , in the tth generation of evolution The edited antigen matrix obtained by rotation , expressed as: ,in, Variant antigen matrix the number of rows, The proportion of variant antigens involved in receptor editing; , is the number of rotations, for The orthogonal transformation matrix, for A matrix with all "1"s in one row and one column; After rotation, edit the antigen matrix Expressed as: 。 8. The method for generating an unknown network threat immune detector according to claim 4, characterized in that: The specific antigen selection for receptor editing and variant antigens is as follows: when the variant antigen matrix The selection distance threshold between any two antigens is less than When editing the antigen matrix, remove one of the antigens; The selection distance threshold between any two antigens is less than When one of the antigens is removed.

9. The method for generating an unknown network threat immune detector according to claim 1, characterized in that: In S5, when the antigen satisfy , then the antigen To successfully mature antibodies through self-tolerance training, the antigen Add the tth generation non-self antigen collection , that is, the generated unknown threat immunity detector.

10. An unknown network threat immune detector generation device, characterized in that: include: Storage; The memory has a computer program stored therein; Actuator; The executor is used to execute the computer program in the storage, and when executing the computer program, the method for generating an unknown network threat immune detector according to any one of claims 1 to 9 is implemented.

Citation Information

Patent Citations

  • Unknown threat detection method based on artificial immune thought

    CN114065933A

  • Sample attack resisting method and system based on improved adaptive differential evolution algorithm

    CN115272774A

  • Unknown network threat adaptive discovery method based on gene evolution and evolution

    CN116318881A

  • Antibody screening method and system based on differential evolution algorithm and artificial intelligence model

    CN119339804A