Quantum-enhanced multi-scale network intrusion detection method and device, and storage medium
Through quantum-enhanced multi-scale network intrusion detection methods, the problem of identifying high-dimensional dynamic traffic and cross-protocol attacks in the industrial Internet has been solved, more efficient feature extraction and stronger defense capabilities have been achieved, and detection accuracy and credibility have been improved.
Patent Information
- Application Number
- CN202510985319.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-16
- Publication Date
- 2025-10-10
AI Technical Summary
In the context of the industrial Internet and critical information infrastructure, existing technologies face systemic bottlenecks in high-dimensional dynamic traffic feature extraction, cross-protocol attack identification, and adversarial sample defense, including excessive compression of feature representation dimensions, fragmentation of spatiotemporal context modeling, lack of multi-scale feature fusion capabilities, and lack of uncertainty quantification and decision interpretability.
A quantum-enhanced multi-scale network intrusion detection method is adopted. Through quantum Hilbert space mapping, complex domain transformation and multi-head attention mechanism, combined with multi-scale convolution branches and gated fusion, dynamic feature enhancement and spatiotemporal feature fusion are achieved, and a three-dimensional feature tensor is generated. It is then evaluated in parallel through classification network, uncertainty network and threat classification network.
It improves the defense capability and accuracy of industrial Internet intrusion detection, enhances the feature extraction capability of high-dimensional dynamic traffic, breaks through the fragmentation of context modeling of cross-protocol attacks, and improves the robustness against interference and the credibility of decision-making.
Smart Images

Figure CN120768627A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of artificial intelligence, in particular to a quantum-enhanced multi-scale network intrusion detection method, device and storage medium. BACKGROUND
[0002] Industrial Internet and critical information infrastructure security face challenges such as high-dimensional dynamic traffic feature extraction, cross-protocol attack identification, and adversarial sample defense. The popularity of edge computing and Internet of Things brings new threats such as quantumized covert penetration and long-period APT attacks. Traditional detection models are difficult to cope with due to problems such as excessive feature compression and fragmented context modeling. Existing solutions have defects such as poor adaptability of static rule base and inability of shallow algorithms to capture nonlinear features, resulting in insufficient identification of coordinated attacks.
[0003] Recent research has proposed various improvement schemes, including: developing a heuristic intrusion detection system (DQN-HIDS) using deep Q network (DQN), which can effectively identify zero-day attacks and reduce dependence on artificial labels, and performs well in resource efficiency and accuracy: using one-dimensional CNN to detect 14 types of threats in industrial Internet of Things, which shows strong generalization ability on Edge-IIoTset dataset; combining deep learning and genetic algorithm to propose IoT-Defender framework, which realizes efficient real-time detection (average intersection over union 0.68) in edge environment. In addition, the fuzzy logic-random forest hybrid method achieves very high accuracy on the NSL-KDD dataset. Although the Res-tranBiLstm model has real-time fluctuations, the spatiotemporal feature fusion significantly improves the detection potential. Based on the improved BERT-of-Theseus technology, a lightweight model BT-TPF is constructed, which reduces the computational cost while maintaining performance through knowledge distillation, suitable for resource-constrained environments.
[0004] The above-mentioned existing technologies, although have made significant progress in dealing with the complex intrusion detection requirements of industrial Internet and critical information infrastructure environment, still have a series of interrelated systemic bottlenecks that limit their effectiveness in handling high-dimensional dynamic traffic, identifying cross-protocol attacks, and resisting adversarial interference. Specifically, there are defects such as excessive compression of feature representation dimension and information loss, fragmented spatiotemporal context modeling and insufficient dependence relationship capture, lack of multi-scale feature fusion capability and weak defense robustness, and lack of uncertainty quantification and decision explainability. SUMMARY
[0005] The present application provides a quantum-enhanced multi-scale network intrusion detection method, device and storage medium, which integrates quantum mechanisms and multi-scale modeling to comprehensively improve the defense capability, precision and credibility of industrial Internet intrusion detection.
[0006] In one aspect, the present application provides a quantum-enhanced multi-scale network intrusion detection method, the method comprising:
[0007] The original traffic feature matrix Calculate the covariance matrix, obtain the eigenvalues and eigenvectors through eigendecomposition, and transform each sample x i Mapping to quantum Hilbert space to generate enhanced characteristic matrix
[0008] Performing a complex domain transformation on the enhanced feature matrix to generate an entangled feature tensor, and realizing dynamic feature enhancement based on quantum probability amplitude and a multi-head attention mechanism;
[0009] Perform spatiotemporal attention calculation and gate fusion on the feature tensor after dynamic feature enhancement to obtain spatiotemporal fusion features;
[0010] Converting the spatiotemporal fusion features into a time series form, extracting behavioral features through multi-scale convolution branches and fusing them to obtain a three-dimensional feature tensor;
[0011] Calculate the mean of the three-dimensional feature tensor in the sequence dimension to generate a two-dimensional feature matrix
[0012] The two-dimensional feature matrix F is respectively analyzed based on the classification network, uncertainty network and threat classification network. agg Conduct parallel assessments of classification predictions, uncertainty quantification, and threat classification.
[0013] On the other hand, the present application provides a quantum-enhanced multi-scale network intrusion detection device, the device comprising:
[0014] Feature reconstruction module, used to reconstruct the original traffic feature matrix Calculate the covariance matrix, obtain the eigenvalues and eigenvectors through eigendecomposition, and transform each sample x i Mapping to quantum Hilbert space to generate enhanced characteristic matrix
[0015] An enhancement module is configured to perform a complex domain transformation on the enhanced feature matrix to generate an entangled feature tensor, and implement dynamic feature enhancement based on quantum probability amplitude and through a multi-head attention mechanism;
[0016] The spatiotemporal fusion module is used to perform spatiotemporal attention calculation and gated fusion on the feature tensor after dynamic feature enhancement to obtain spatiotemporal fusion features;
[0017] An analysis module is used to convert the spatiotemporal fusion features into a time series form, extract behavioral features through multi-scale convolution branches and fuse them to obtain a three-dimensional feature tensor;
[0018] Aggregation module, used to calculate the mean of the three-dimensional feature tensor in the sequence dimension to generate a two-dimensional feature matrix
[0019] An evaluation module is used to evaluate the two-dimensional feature matrix F based on the classification network, the uncertainty network and the threat classification network. agg Conduct parallel assessments of classification predictions, uncertainty quantification, and threat classification.
[0020] In a third aspect, the present application provides an electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the steps of the technical solution of the above-mentioned quantum-enhanced multi-scale network intrusion detection method are implemented.
[0021] In a fourth aspect, the present application provides a storage medium storing a computer program, which, when executed by a processor, implements the steps of the technical solution of the above-mentioned quantum enhanced multi-scale network intrusion detection method.
[0022] From the technical solutions provided by the above application, it can be seen that, on the one hand, due to the use of quantum Hilbert space projection, the original features are mapped to the high-dimensional complex domain, while retaining the nonlinear coherence effect between features, the information loss of traditional dimensionality reduction is avoided, and the distortion problem of high-dimensional dynamic traffic feature extraction is solved; on the other hand, through the spatiotemporal attention gating fusion and coordinated quantum entanglement enhancement features, the latent propagation path of attack behavior in a long period is simulated, breaking through the limitations of traditional methods on the fragmentation of cross-protocol attack context modeling; thirdly, based on the adaptive multi-scale convolutional pyramid, the receptive field size is dynamically adjusted to simultaneously capture the cross-level behavior trajectories of short-term burst attacks and long-latent APT attacks, overcoming the perception blind spots of single-scale models. In summary, the technical solution of this application integrates quantum mechanisms and multi-scale modeling to comprehensively improve the defense capability, accuracy and credibility of industrial Internet intrusion detection. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0024] Figure 1 This is a flow chart of the quantum-enhanced multi-scale network intrusion detection method provided by an embodiment of the present application;
[0025] Figure 2Schematic diagram of the structure of the quantum-enhanced multi-scale network intrusion detection device provided in an embodiment of the present application;
[0026] Figure 3 It is a schematic diagram of the structure of the electronic device provided in the embodiment of the present application. DETAILED DESCRIPTION
[0027] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0028] In this specification, adjectives such as first and second may be used only to distinguish one element or action from another element or action, without necessarily requiring or implying any actual such relationship or order. Where circumstances permit, reference to an element or component or step (etc.) should not be construed as being limited to only one of the elements, components, or steps, but may be one or more of the elements, components, or steps, etc.
[0029] In this specification, for the convenience of description, the sizes of various parts shown in the drawings are not drawn according to the actual proportions.
[0030] In the security of the Industrial Internet and critical information infrastructure, intrusion detection systems, as core components of active defense systems, face the triple technical challenges of extracting high-dimensional dynamic traffic features, identifying cross-protocol attack behaviors, and defending against adversarial interference. With the increasing application of edge computing and ubiquitous IoT connectivity, modern cyberattacks are exhibiting new threat characteristics, such as quantum-based covert penetration, long-term APT infiltration, and protocol-level session hijacking. Traditional detection models are limited by systemic bottlenecks, including excessive dimensionality compression of feature representations, fragmented spatiotemporal context modeling, and weak robustness of defense mechanisms. Existing solutions often suffer from inherent flaws, such as static rule bases that are difficult to adapt to the evolution of zero-day attacks, shallow machine learning algorithms that cannot capture high-dimensional nonlinear correlations, and early deep learning architectures that lack the ability to fuse multi-scale features. These flaws result in significantly insufficient recognition of cross-device coordinated attacks involving false data injection, creating a security gap for critical infrastructure. Shigen Shen et al., leveraging the deep Q-network (DQN) technique from deep reinforcement learning, proposed a heuristic intrusion detection system (DQN-HIDS) for zero-day attacks in edge SIoT networks. This approach effectively identifies new malicious traffic and reduces reliance on manual labeling. Experiments show that compared to state-of-the-art deep learning models and typical machine learning methods, DQN-HIDS improves classifier accuracy while reducing resource overhead and demonstrates superior performance with a small number of SIoT network traffic samples. Karima Hassini et al. proposed a deep learning model based on a one-dimensional convolutional neural network (CNN1D) to detect 14 complex intrusion threats in Industrial Internet of Things (I-IoT) environments. Trained on the Edge-IIoTset dataset, the model demonstrated excellent generalization and defense effectiveness against various threats in dynamic I-IoT security environments. Yakub Kayode Saheed et al. proposed a comprehensive intrusion detection framework, IoT-Defender, using deep learning techniques and genetic algorithm (GA) parameter optimization to address the dynamic and diverse challenges in Internet of Things (IoT) security. Research demonstrated that IoT-Defender excels across multiple performance metrics, particularly achieving efficient real-time intrusion detection in edge computing environments without the need for complex hardware, achieving an average intersection-over-union (IoU) ratio of 0.68. Awotunde JB et al. proposed a multi-level intrusion detection method based on fuzzy logic system and random forest, aiming to enhance the attack detection capability in the Internet of Things environment. The method achieved an accuracy of 99.46% on the NSL-KDD dataset. By selecting a set of unique features for classification, it effectively improved the ability to identify different types of attacks.Meanwhile, in 2023, Wang S et al. developed an intelligent intrusion detection method that combines spatial and temporal features. Using the Res-tranBiLstm model, they achieved high accuracy on the NSL-KDD and CIC-IDS datasets. Although this method exhibits certain instability during real-time analysis, it demonstrates significant potential for improving IoT security. Zhendong Wang et al. proposed BT-TPF, an IoT intrusion detection model based on an improved BERT-of-Theseus technique. This model reduces the number of model parameters and improves detection performance through knowledge distillation. On the CIC-IDS2017 and TON_IoT datasets, it achieved detection results comparable to or even superior to those of large models, while significantly reducing computational cost and model size. This approach addresses the issue of efficient intrusion detection for IoT devices in resource-constrained environments and demonstrates the potential for lightweight model design while maintaining high performance.
[0031] While existing technologies have made significant progress in addressing the complex intrusion detection needs of the Industrial Internet and critical information infrastructure, they still face a series of interrelated systemic bottlenecks that limit their effectiveness in processing high-dimensional dynamic traffic, identifying cross-protocol attacks, and resisting adversarial interference. Specifically, they suffer from the following key shortcomings:
[0032] 1) Excessive dimensionality compression and information loss in feature representations. This is primarily manifested in existing methods, whether based on traditional machine learning (e.g., random forests, fuzzy logic), classic deep learning (e.g., CNN1D, LSTM, RNN variants), or lightweight models (e.g., knowledge distillation, model pruning). These methods generally suffer from insufficient feature space representation capabilities. When processing high-dimensional, sparse, and dynamically changing network traffic features, they often reduce computational complexity through dimensionality reduction, feature selection, or model structure restrictions (e.g., convolution with a fixed receptive field, limited hidden layer dimensions). This active or passive dimensionality compression inevitably leads to the loss of subtle correlations, nonlinear patterns, and potential long-tail anomalies inherent in the raw traffic data. For example, reinforcement learning models (e.g., DQN-HIDS) may overlook key feature combinations due to simplified state representation; lightweight models (e.g., BT-TPF) may sacrifice the capture of the completeness of high-dimensional features in pursuit of efficiency. The root cause lies in the lack of a method that can effectively model the complex quantized correlation between features while retaining or even enhancing the original high-dimensional feature information, and is unable to map the original feature space to a mathematical structure with stronger representation capabilities (such as quantum Hilbert space).
[0033] 2) Fragmented spatiotemporal context modeling and inadequate dependency capture are prominent manifestations of modern cyberattacks, particularly APT attacks and protocol-level session hijacking, which exhibit long-range dependencies across time steps and device / protocol dimensions. Existing technologies face significant limitations in modeling such complex spatiotemporal patterns. On the one hand, CNN-based methods excel at capturing local spatial patterns (such as protocol fields) but struggle to capture long-range temporal dependencies. While RNN / Transformer-based methods can process sequences, they often require simplified structures (e.g., reducing the number of attention heads and layers) in resource-constrained scenarios, resulting in fragmented or inadequate modeling of global spatiotemporal dependencies. Furthermore, existing architectures typically separate or simply stack attention or feature extraction mechanisms for the temporal and spatial (feature correlation) dimensions, lacking the ability to collaboratively optimize and deeply coupled spatiotemporal joint modeling. For example, spatiotemporal fusion models (e.g., Res-tranBiLstm) can be unstable in real-time, partly due to inefficient and inefficient spatiotemporal interaction mechanisms. This results in a low recognition rate for subtle temporal linkages and feature space coordinated anomaly patterns in cross-device coordinated attacks (for example, the covert propagation path of false data injection).
[0034] 3) Lack of multi-scale feature fusion capabilities and weak robustness of defense mechanisms are primarily manifested in the fact that network attack behaviors often manifest at different granularities (packets, flows, sessions, host interactions) and levels of abstraction (raw bytes, protocol semantics, behavioral patterns). Existing intrusion detection systems generally lack a systematic and adaptive multi-scale feature extraction and fusion framework. Traditional methods (e.g., rule-based, feature engineering) struggle to automatically capture multi-scale information; deep learning models (e.g., single CNN or LSTM) have limited scale-awareness and typically rely on fixed convolution kernels or time windows. Even genetic algorithm optimization (e.g., IoT-Defender) or feature selection (e.g., fuzzy logic + random forest) primarily focus on feature subsets rather than the organic fusion of multi-scale features. This lack of multi-scale capabilities makes the model less adaptable to attack modes with varying temporal or spatial scopes (e.g., fast-bursting DoS attacks and slow-penetrating APT attacks), leading to false positives and missed detections. More importantly, existing technologies generally lack defense modules specifically designed to combat adversarial perturbations. The model's decision boundary is easily perturbed by carefully constructed adversarial examples, resulting in a significant performance degradation in adversarial environments (e.g., when an attacker attempts to bypass detection). The root cause is that the model's internal feature representation is overly sensitive to small perturbations and lacks inherent robustness enhancement mechanisms, such as adversarial feature space transformation and uncertainty perception.
[0035] 4) Lack of uncertainty quantification and decision-making explainability, mainly manifested in the fact that in the field of critical infrastructure where security is at stake, it is far from enough to provide only binary or categorical decisions. Most existing solutions lack the ability to quantify the confidence of prediction results (epistemic uncertainty) and the inherent noise of the data (accidental uncertainty), and it is also difficult to provide clear attribution of key features and decision-making basis. This makes it difficult for security operations personnel to evaluate the credibility of detection results (especially when detecting new or fuzzy attacks), and it is impossible to understand the fundamental reasons why the model makes specific judgments, which hinders the rapid response to threats and root cause analysis. Although some methods (for example, genetic algorithms, reinforcement learning, etc.) have some interpretability exploration, systematic, end-to-end uncertainty quantification and gradient-based interpretability engines are still generally missing links.
[0036] In response to the above problems of the prior art, this application proposes a quantum-enhanced multi-scale network intrusion detection method, the flow chart of which is shown in the attached figure. Figure 1 As shown, it mainly includes steps S101 to S106, which are detailed as follows:
[0037] Step S101: original traffic feature matrix Calculate the covariance matrix, obtain the eigenvalues and eigenvectors through eigendecomposition, and transform each sample x i Mapping to quantum Hilbert space to generate enhanced characteristic matrix
[0038] As mentioned above, linear dimensionality reduction methods such as PCA force the features to be orthogonalized, destroying the nonlinear coherent structure of the original features, such as the conjugate symmetry of the covariance matrix. In order to resolve the contradiction between the nonlinear feature correlation of high-dimensional traffic and the information loss of linear dimensionality reduction, this application extracts the orthogonal basis system of the eigenvector and the corresponding energy distribution (i.e., eigenvalue) by eigendecomposing the covariance matrix of the original traffic feature, and constructs a mapping function of the sample based on the principle of quantum state superposition. The mapping function represents each sample as a weighted linear combination of the eigenvector on the orthogonal basis, and its weight is dynamically determined by the inner product of the square root of the eigenvalue and the eigenvector. Specifically, for the original traffic feature matrix Calculate the covariance matrix, obtain the eigenvalues and eigenvectors through eigendecomposition, and transform each sample x i Mapping to quantum Hilbert space to generate enhanced characteristic matrix This energy-weighted orthogonal basis expansion mechanism expands the feature dimension to twice the original dimension while strictly retaining the nonlinear coupling relationship and energy distribution characteristics between features, constructing a high-fidelity quantized feature basis for subsequent processing.
[0039] As an embodiment of the present application, the original traffic feature matrix Calculate the covariance matrix, obtain the eigenvalues and eigenvectors through eigendecomposition, and transform each sample x i Mapping to quantum Hilbert space to generate enhanced characteristic matrix This can be achieved through steps S1011 to S1013, which are described in detail as follows:
[0040] Step S10 11: Calculate the covariance matrix based on the original traffic feature matrix X
[0041] Original traffic feature matrix Contains m network flows, each sample has n flow features, where m is much larger than n.
[0042] Step S1012: The covariance matrix C is calculated according to C=UAU T Perform eigendecomposition and obtain eigenvalue λ k With the eigenvector u k .
[0043] For the covariance matrix C, C=UΛU T Perform eigendecomposition to generate n eigenvalues λ k and the corresponding n eigenvectors u k .
[0044] Step S1013: According to the formula Mapping quantum states.
[0045] In the above quantum state mapping formula, x i represents the i-th sample (a complete sample containing n features, i.e., a 1×n vector), λ k represents the kth eigenvalue, u k represents the corresponding k-th eigenvector, k , x i > represents the inner product of the kth eigenvector and the i-th sample. The inner product gets a specific value. |v k > is an orthonormal basis.
[0046] Assume n = 3, indicating that network traffic has only three features, then the corresponding standard basis is:
[0047]
[0048] Through the above process, the mapping result of each sample obtained by quantum Hilbert space projection can be calculated, and finally the The traffic data after feature enhancement is the enhanced feature matrix, which enables lossless extraction of the essential features of high-dimensional traffic and eliminates the information distortion caused by traditional dimensionality reduction schemes.
[0049] As can be seen from step S101 of the above embodiment, an orthogonal basis system and energy distribution are obtained through the eigendecomposition of the original traffic feature covariance matrix, and an eigenvalue-weighted orthogonal basis expansion mapping is constructed based on the principle of quantum state superposition. This mechanism expands the feature dimension to twice the original dimension while strictly preserving the nonlinear correlation and energy distribution characteristics of high-dimensional traffic. This significantly improves the model's ability to capture weak abnormal signals in industrial Internet environments, laying a high-fidelity quantized feature foundation for subsequent in-depth processing.
[0050] Step S102: Perform a complex domain transformation on the enhanced feature matrix to generate an entangled feature tensor, and realize dynamic feature enhancement based on the quantum probability amplitude and through a multi-head attention mechanism.
[0051] Since real domain models such as CNN and RNN cannot express the quantum entanglement effect in the complex domain, for example, it is impossible to simulate the phase interference of the imaginary component I·E, therefore, in order to break the cross-protocol attack identification bottleneck caused by the separation of spatiotemporal feature modeling and solve the contradiction between isolated statistical modeling between features and the coordinated evolution of multiple features of attack behavior, in an embodiment of the present application, a complex domain transformation can be performed on the enhanced feature matrix to generate an entangled feature tensor, and dynamic feature enhancement can be achieved based on the quantum probability amplitude and through a multi-head attention mechanism.
[0052] Furthermore, considering that the real domain attention mechanism (e.g., Transformer) cannot express the imaginary phase interference, resulting in the failure of cross-protocol attack collaborative behavior modeling, and in order to resolve the contradiction between cross-feature collaborative evolution of attack behavior and isolated feature analysis, as an embodiment of the present application, performing a complex domain transformation on the enhanced feature matrix to generate an entangled feature tensor can be implemented through steps S1021 to S1023, as detailed below:
[0053] Step S1021: reshape the enhanced feature matrix of dimension m×2n into a tensor of dimension m×1×2n.
[0054] Specifically, the enhanced feature matrix of dimension m×2n is converted into a three-dimensional tensor by adding a single sequence dimension, and the output shape is m×1×2n.
[0055] Step S1022: Generate real part projections of the m×1×2n tensor through two independent fully connected layers and the imaginary part projection
[0056] Specifically, the first fully connected layer projects the m×1×2n tensor to the real component, and the second fully connected layer projects the m×1×2n tensor to the imaginary component. Both of them uniformly transform the dimension of the tensor from 2n to the hidden dimension h, that is, the output shape is m×1×h, where h is the preset hidden dimension parameter.
[0057] Step S1023: According to the formula entangled_real=R·EI·E T and entangled_imag = I·E + R·E T Perform complex field entanglement operations to generate entangled feature tensors.
[0058] Then, project the real part and the imaginary part projection Perform quantum entanglement simulation operations, that is, introduce a learnable parameter matrix E (dimension h×h), and generate an entanglement feature tensor through complex field matrix operations. Specifically, the real part of the entanglement is obtained by subtracting the product of the imaginary part projection and the transpose of the parameter matrix from the product of the real part projection and the parameter matrix; at the same time, the imaginary part of the entanglement is obtained by adding the product of the imaginary part projection and the parameter matrix to the product of the real part projection and the transpose of the parameter matrix. The operation is formally expressed as follows:
[0059] entangled_real=RvE-I·ET and entangled_imag=I·E+R·E T
[0060] Among them, R and I are the projection outputs of the real and imaginary parts respectively (both have shapes of m×1×h), and E is the entanglement parameter matrix automatically optimized during the training phase. After this operation, the output shape remains as the entangled feature tensors of m×1×h, namely entangled_real and entangled_imag.
[0061] Furthermore, as an embodiment of the present application, dynamic feature enhancement based on quantum probability amplitude and through a multi-head attention mechanism can be achieved through steps S'1021 to S'1025, as detailed below:
[0062] Step S'1021: Press the formula Compute the probability amplitude tensor probability_amplitudes, where ε=10.
[0063] Specifically, the sum of the squares of each position is calculated by element-wise operation, that is, the square of the real part of the entanglement plus the square of the imaginary part of the entanglement, and the square root is taken and added with a very small constant ε (ε = 10 -6 ) maintains numerical stability and obtains the probability amplitude tensor probability_amplitudes. The dimension of the probability amplitude tensor probability_amplitudes is still m×1×h, which represents the probability distribution characteristics of the quantum state.
[0064] Step S'1022: Perform a dimension reordering operation on the probability amplitude tensor probability_amplitudes.
[0065] Step S'1023: Input the rearranged probability amplitude tensor into the multi-head attention layer to generate attention features.
[0066] Specifically, the rearranged probability amplitude tensor is input into the multi-head attention layer, and the multi-head attention mechanism realizes feature enhancement through self-attention calculation: first, the similarity between the query, key and value is calculated, and then the attention weight is generated by normalization through the Softmax function, and weighted aggregation is performed to capture global dependencies and generate attention features.
[0067] Step S'1024: Superimpose the attention features to the real component R of the entangled feature tensor through the residual connection.
[0068] Specifically, the attention feature undergoes a dimension recovery operation and is regularized by a dropout layer to reduce the risk of overfitting, and a residual connection mechanism is used to superimpose it element-wise to the real component R of the entangled feature tensor.
[0069] Step S'1025: perform layer normalization on the superposition result and output a dynamic feature enhanced feature tensor with a dimension of m×1×h.
[0070] Finally, the layer normalization module (LayerNorm) normalizes the resulting features, maintaining the output dimension as an m×1×h enhanced feature representation, or the feature tensor after dynamic feature enhancement. This entire process achieves the coordinated optimization of quantum entanglement simulation and the attention mechanism, transforming the feature dimension from the input n to the hidden dimension h, while maintaining the sequence dimension at 1, forming a complete three-dimensional feature processing pipeline.
[0071] Step S103: Perform spatiotemporal attention calculation and gated fusion on the feature tensor after dynamic feature enhancement to obtain spatiotemporal fusion features.
[0072] In the prior art, time series models such as LSTM ignore the spatial correlation between protocols, while spatial models such as GCN ignore the temporal evolution, resulting in the break of APT attack trajectories. In order to resolve the contradiction between the spatiotemporal continuity characteristics of long-term attacks and the fragmented analysis of discrete modeling, spatiotemporal attention calculation and gated fusion can be performed on the feature tensor after dynamic feature enhancement to simulate the latent propagation path of attack behavior in a long period, breaking through the limitations of traditional methods on the fragmentation of cross-protocol attack context modeling. As an embodiment of the present application, spatiotemporal attention calculation and gated fusion are performed on the feature tensor after dynamic feature enhancement to obtain spatiotemporal fusion features, which can be achieved through steps S1031 to S1033, as detailed below:
[0073] Step S1031: Enhance the temporal attention feature T attn With spatial attention enhancement feature S attnConcatenate along feature dimensions.
[0074] The spatiotemporal attention calculation for the dynamic feature enhanced feature tensor can be completed by the spatiotemporal transformation module. The spatiotemporal transformation module processes the dynamic feature enhanced feature tensor with dimensions of m×1×h, where m is the number of samples, 1 is the sequence length, and h is the hidden feature dimension. The spatiotemporal transformation module first performs the temporal dimension attention calculation, that is, it performs a dimensionality rearrangement operation on the dynamic feature enhanced feature tensor with dimensions of m×1×h and inputs it into the multi-head attention layer. The self-attention mechanism is used to capture the feature dependencies in the temporal dimension and calculate the temporal attention enhanced feature T attn Temporal Attention Enhanced Feature T attn After the dimensionality restoration operation, it is converted back to the shape m×1×h, regularized by the dropout layer, and then residually connected with the original input, and layer normalization is performed. Subsequently, the spatial dimension attention calculation is performed based on the features enhanced by temporal attention through dimensionality reshaping, that is, the multi-head attention layer is directly applied to capture spatial dependencies. The output is also restored after dimensionality restoration and regularized by the dropout layer, and then residually connected with the output of the previous stage, and layer normalization is performed. The output of this stage is recorded as the spatial attention enhanced feature S attn In order to fuse the spatiotemporal attention features, this application designs a dynamic gating fusion mechanism, that is, firstly, the temporal attention enhancement feature T attn With spatial attention enhancement feature S attn Splicing along the feature dimension, we get a fusion tensor with a shape of m×1×2h [T attn ;S attn ] and output it to the gating unit.
[0075] Step S1032: Generate fusion weight G=σ(W g [T attn ;S attn ]).
[0076] The gate unit consists of a linear transformation layer and a Sigmoid activation function to generate a fusion weight with a value range of [0, 1], which is expressed as:
[0077] G=σ(W g [T attn ;S attn ])
[0078] Among them, σ represents the Sigmoid function, W g are learnable gating weights.
[0079] Step S1033: According to formula F fusion =G⊙Tattn +(1-G)⊙S attn Fusion is performed to obtain the fused spatiotemporal feature F fusion .
[0080] Learnable gating weight W g The spatiotemporal features are adaptively filtered and fused through element-level multiplication, and the output dimension is m×1×h fused spatiotemporal feature F fusion Finally, the spatiotemporal features F are integrated fusion Nonlinear enhancement is performed through a feedforward neural network. That is, the feedforward neural network contains two layers of linear transformation, with a Gaussian error linear unit (GELU) activation function introduced in the middle, and two dropout layers (Dropout) are applied for regularization; the output of the feedforward network is added to the spatial attention enhancement feature via a residual connection, and the final output feature of the transformation block is obtained after layer normalization, with the shape maintained at m×1×h.
[0081] From steps S102 to S103 of the above embodiment, it can be seen that the collaborative design of the complex-domain quantum entanglement encoder and the spatiotemporal gating fusion architecture breaks through the limitations of traditional spatiotemporal modeling separation: the quantum entanglement encoder projects features into complex space to form real and imaginary components, introduces a learnable entanglement matrix to simulate the coherence effect between quantum bits, and the generated quantum probability amplitude drives a multi-head attention mechanism to achieve global dependency capture; the spatiotemporal transformation block innovatively uses an independent temporal attention stream to analyze the attack sequence evolution pattern, and the spatial attention stream captures the nonlinear dependencies between features, ultimately achieving adaptive weighted fusion of the two-stream features through a dynamic gating function. This deeply coupled modeling mechanism improves the system's sensitivity to the spatiotemporal coupling features in cross-protocol session hijacking attacks by more than 7%, effectively alleviating the historical problem of fragmented modeling of latent transmission paths for APT attacks.
[0082] Step S104: convert the spatiotemporal fusion features into a time series form, extract the behavioral features through multi-scale convolution branches and fuse them to obtain a three-dimensional feature tensor.
[0083] Cyberattack behaviors often manifest themselves at different granularities (packets, flows, sessions, host interactions) and levels of abstraction (raw bytes, protocol semantics, behavioral patterns). Existing intrusion detection systems generally lack a systematic, adaptive multi-scale feature extraction and fusion framework. Traditional methods (such as rule-based and feature engineering) struggle to automatically capture multi-scale information; deep learning models (e.g., single CNN or LSTM) have limited scale-awareness and typically rely on fixed convolution kernels or time windows. Even genetic algorithm optimization (e.g., IoT-Defender) or feature selection (e.g., fuzzy logic + random forest) primarily focus on feature subsets rather than the organic fusion of multi-scale features. This lack of multi-scale capability makes the model less adaptable to attack patterns with different time spans or spatial scopes (e.g., fast-bursting DoS attacks and slow-penetrating APT attacks), making it prone to missed and false positives. More importantly, existing technologies generally lack defense modules specifically designed to combat adversarial perturbations. The decision boundary of the model is easily disturbed by carefully constructed adversarial examples, resulting in a significant performance degradation in adversarial environments (for example, when attackers try to bypass detection). The fundamental reason is that the internal feature representation of the model is too sensitive to small perturbations and lacks inherent robustness enhancement mechanisms, such as adversarial feature space transformation and uncertainty perception mechanisms. In short, the single-scale convolution of existing technologies (for example, 3x3 convolution) can only capture fixed-duration behaviors and cannot simultaneously identify DDoS (second-level) and APT (month-level) attacks. In order to resolve the contradiction between the cross-level behavior of hybrid attacks and the local blind spots of single-scale perception, the spatiotemporal fusion features can be converted into a time series form, and the behavioral features can be extracted and fused through multi-scale convolution branches to obtain a three-dimensional feature tensor.
[0084] As an embodiment of the present application, converting the spatiotemporal fusion features into a time series form, extracting and fusing behavioral features through multi-scale convolution branches, and obtaining a three-dimensional feature tensor can be achieved through steps S1041 to S1043, as detailed below:
[0085] Step S1041: reconstruct the spatiotemporal fusion features from [m, 1, h] into a three-dimensional time series tensor of [m, h, 1].
[0086] Specifically, the fusion spatiotemporal features F fusion Convert from [batch, sequence, feature] to a three-dimensional time series form of [batch, feature, sequence].
[0087] Step S1042: Parallel execution of the preset scale factor set {1, 2, 4}: For each scale factor s, use the convolution kernel size k sThe one-dimensional convolution layer with size = 3s-2 performs convolution operation on the three-dimensional time series tensor, performs batch normalization and GELU activation processing on the convolution output, and compresses the activated features into a feature vector of dimension m×h×1 through adaptive average pooling.
[0088] Specifically, the parallel convolution branches can be instantiated based on the preset scale factor set {1, 2, 4}, and each branch is adaptively convolution kernel size formula k s = 3s-2 to dynamically adjust the receptive field size (where s is the scale factor, and each branch takes values of 1, 2, and 4 respectively).
[0089] Each convolution branch performs three layers of processing:
[0090] 1) One-dimensional convolutional layer: performs convolution operations on the extended time dimension, using symmetric padding to maintain the size of the feature map;
[0091] 2) Batch Normalization Layer: Standardizes the distribution of convolutional output features;
[0092] 3) GELU activation function: introduces smooth nonlinear feature transformation.
[0093] After the convolution process, an adaptive average pooling operation is applied to compress the feature map of each scale into a global feature vector of dimension m×h×1.
[0094] As can be seen from the above examples, by dynamically generating differentiated convolution kernels through preset multi-level scale factors, parallel convolution branches are constructed to independently capture local burst features (small scale), session-level patterns (medium scale), and global behavior trajectories (large scale). The features at each scale are adaptively pooled and compressed before being integrated across multiple layers. This adaptive receptive field adjustment mechanism has enabled the model to achieve a 99.7% accuracy rate in identifying hybrid attacks (e.g., APT penetration disguised as DoS) during power grid attack and defense testing.
[0095] Step S1043: Concatenate the feature vectors output from all scales along the feature dimension to form a three-dimensional feature tensor.
[0096] Specifically, the feature vectors of all scales are concatenated along the feature dimension to form a multi-dimensional feature set (with a dimension of m×(3×h), where 3 is the number of scale factors). The concatenated result is input into the fusion module, which compresses the feature dimension to the original hidden dimension h through a fully connected layer. Batch normalization and GELU activation processing are then performed to complete the organic fusion of multi-scale features. The final output feature is restored to a three-dimensional feature tensor of m×1×h through dimensionality adjustment to maintain compatibility with downstream modules.
[0097] The adversarial defense module of the present application takes a three-dimensional feature tensor with dimension m x 1 x h as input, enhances the robustness of the model through nonlinear transformation, and adopts a two-stage linear transformation structure: first, the input feature dimension is expanded from h to 2h (i.e., twice the hidden dimension) through a fully connected layer, and a Gaussian error linear unit (GELU) activation function is introduced for nonlinear transformation; then the feature dimension is compressed back to the original hidden dimension h through a second fully connected layer. This process enhances the defense capability of the model against adversarial samples through nonlinear mapping and dimension scaling of the feature space, while maintaining the core information of the feature representation. The output shape is strictly maintained as m x 1 x h to ensure compatibility with downstream modules. Through nonlinear scaling of the feature dimension (expanded to 2 times and then compressed back to the original dimension) and Gaussian error activation, the adversarial defense module hardens the robustness of the feature representation to adversarial perturbations.
[0098] Step S105: Calculate the mean of the three-dimensional feature tensor in the sequence dimension to generate a two-dimensional feature matrix
[0099] Specifically, for a three-dimensional feature tensor with dimension m x 1 x h, the feature mean is calculated in the sequence dimension (length 1), and the three-dimensional feature tensor with dimension m x 1 x h is compressed into a two-dimensional feature matrix
[0100] Step S106: Based on the classification network, the uncertainty network and the threat grading network respectively, the two-dimensional feature matrix F agg Parallel evaluation of classification prediction, uncertainty quantification and threat grading is performed.
[0101] In the field of security-critical critical infrastructure, providing only binary or classification decisions is far from enough. Most existing solutions lack the ability to quantify the confidence of the prediction results (cognitive uncertainty) and the inherent noise of the data (accidental uncertainty), and it is also difficult to provide clear attribution of key features and decision basis. This makes it difficult for security operation personnel to assess the credibility of the detection results (especially when detecting new or ambiguous attacks), and also makes it difficult to understand the root cause of the model's specific judgment, hindering the rapid response and root cause analysis of threats. Although some methods (such as genetic algorithms, reinforcement learning) have certain exploratory interpretability, systematic and end-to-end uncertainty quantification and gradient-based explainability engines are still generally missing. In order to solve the problems of the prior art, parallel evaluation of classification prediction, uncertainty quantification and threat grading is performed based on the classification network, the uncertainty network and the threat grading network respectively for the two-dimensional feature matrix F agg
[0102] Furthermore, considering that existing solutions such as the Softmax classifier cannot quantify confidence (for example, misclassifying adversarial samples as highly confident), which leads to malfunction of critical infrastructure, in order to resolve the contradiction between the decision-making credibility requirement in adversarial environments and the risk of binary output out of control, the uncertainty network performs uncertainty quantification evaluation, including: converting the two-dimensional feature matrix F agg Input a two-layer fully connected network; the first fully connected layer compresses the feature dimension to 128 dimensions and applies GELU activation; the second fully connected layer outputs a single-dimensional scalar and then executes the Softplus function.
[0103] Furthermore, the above embodiment is based on the classification network, for the two-dimensional feature matrix F agg The evaluation of classification prediction can be achieved by using a two-layer fully connected network to realize traffic classification prediction. Specifically, the first-layer linear transformation transforms the two-dimensional feature matrix Fa gg The dimension is expanded from h to 256. After the feature distribution is standardized by the batch normalization layer, a nonlinear transformation is introduced through the Gaussian Error Linear Unit (GELU) activation function, and the Dropout layer is applied for regularization. The second layer of linear transformation compresses the feature dimension to the number of categories num_classes (intrusion detection is a classification task, and the traffic is classified into num_classes). The output is a classification logical value with a shape of m×num_classes. That is, a judgment probability will be generated for each sample judged to be num_classes, and finally the category with the highest probability will be used as the intrusion detection result of the model.
[0104] Furthermore, the above embodiment is based on the threat classification network, and for the two-dimensional feature matrix F agg Threat classification can be assessed using a fully connected network to assess the threat level of traffic. A first-layer linear transformation compresses the feature dimension from h to 128. After processing with the ReLU activation function, a second-layer linear transformation outputs a three-dimensional threat level score (m×3 shape) representing the probability distribution of low, medium, and high threats.
[0105] Finally, based on the classification network, uncertainty network and threat classification network, the two-dimensional feature matrix F agg Parallel evaluation of classification prediction, uncertainty quantification and threat classification is performed, and its output includes three types of evaluation results: classification result score (shape m×num_classes), accidental uncertainty score (shape m×1), and threat level score (shape m×3), forming a multidimensional traffic evaluation system.
[0106] As can be seen from step S106 of the aforementioned embodiment, the uncertainty assessment head innovatively and concurrently outputs classification predictions, data aleatory uncertainty scores, and three-level threat probability distributions, forming a three-dimensional assessment system for quantifying decision credibility. Combined with a multi-task joint training strategy (cross entropy + mean squared error + KL divergence loss), this approach reduced the high-threat underreporting rate to 0.2% in field testing of critical financial infrastructure. This comprehensive technical solution, through a progressively innovative approach—quantum space reconstruction → complex domain entanglement → spatiotemporal gating fusion → multiscale pyramid → robust decision chain—achieved an average detection accuracy of 99.8% and millisecond-level real-time response speeds in benchmarks such as CIC-IDS2017 and TON_IoT, establishing a new generation of quantum computing-inspired active defense paradigm for critical information infrastructure.
[0107] The above embodiment also includes model training, that is, joint optimization according to multi-task loss: the classification task adopts cross entropy loss L cls ; Uncertainty prediction uses mean square error loss The threat level uses KL divergence loss L thr =D KL (P thr ||Q thr ); total loss L = L = λ1*L cls +λ2*L unc +λ3*L thr Furthermore, the above model training also includes the use of AdamW optimizer, initial learning rate 0.1, weight decay 10 -5 ; When the validation set F1 score does not improve for 5 consecutive epochs, the learning rate is decayed to half of its original value: gradient clipping (threshold 1.0) is performed on each training batch.
[0108] More specifically, the model training process uses a multi-task joint optimization strategy, achieving efficient convergence through adaptive learning rate adjustment and gradient clipping techniques. The training process first initializes the AdamW optimizer (with a default learning rate of 0.1 and a weight decay coefficient of 1e-5) and configures a performance-based learning rate scheduler. Furthermore, if the F1 score on the validation set does not improve for five consecutive epochs, the learning rate is decayed to half its original value. A multi-task loss function system is defined: cross-entropy loss is used for classification tasks, mean squared error loss is used for uncertainty prediction, and KL divergence loss (logarithmic target mode) is used for threat level assessment. The training loop includes the following core operations: For each epoch, the model switches to training mode and traverses the training data loader. During each batch, the gradient buffer is first cleared, and the input data and labels are transferred to the GPU computing device. A forward pass computes the classification logistic value, uncertainty score, and threat level distribution. A triple loss is calculated: a cross-entropy loss based on the difference between the true label and the predicted logistic value; a KL divergence loss based on a prediction error indicator (a target value of 1 when the predicted category does not match the true label, and 0 otherwise); and a threat level loss based on a target distribution constructed using a predefined threat mapping rule (normal traffic corresponds to low threat, specific attack types correspond to medium threat, and high-risk attacks correspond to high threat). The total loss is a weighted sum (classification loss weighted by 1.0, uncertainty loss weighted by 0.5, and threat level loss weighted by 0.3). After backpropagation calculates the gradients, gradient clipping (with a threshold of 1.0) is applied to prevent gradient explosion, and the optimizer updates the model parameters. The current loss and time are output every 10 batches. After each epoch, the average training loss is calculated. Model performance is evaluated on the validation set: validation loss is calculated, a classification report (including metrics such as precision, recall, and F1 score) is generated, and the best F1 score is recorded. As the validation F1 score improves, the optimal model parameters are saved. The training termination condition is to reach the preset number of epochs (50 by default), and finally obtain the best intrusion detection model.
[0109] Furthermore, the method of the above embodiment may also include the deployment of a threat analysis engine module, that is, receiving traffic data in real time; executing steps S101 to S106 to generate predicted categories, confidence levels, uncertainty scores, and threat levels; calculating the importance of input features through gradient backpropagation; generating an interpretable report based on the importance weighted Top-K features, wherein the calculation of the input feature importance may be: constructing a differentiable input tensor Z; calculating the gradient of the predicted category probability with respect to the input According to the formula Normalization; screening positive and negative correlation Top-K features for decision explanation. Specifically, the threat analysis engine module realizes real-time traffic security evaluation for each traffic data in the actual scene based on the trained quantum intrusion detection model. The analysis process includes the following core operations: performing model forward propagation to obtain triple output: classification score, uncertainty score and threat level score; converting the classification logic value into a probability distribution through the Soffmax function to determine the prediction category and the corresponding confidence; extracting the scalar value of the uncertainty score; mapping the threat level distribution to low, medium and high threat probabilities after Softmax normalization, and taking the maximum probability corresponding to the level as the final threat judgment. Key feature analysis is achieved through gradient back propagation: construct a derivable input tensor, calculate the gradient of the prediction category probability with respect to the input feature, take the absolute value and normalize to obtain the feature importance weight. Based on the importance weight, Top-K key features are screened, and the feature value and gradient direction (positive / negative correlation) are combined to generate an explainable decision basis. Finally, a structured security report is generated, including the prediction category, confidence, uncertainty score, threat level, detailed threat distribution, category probability distribution, key feature list and natural language decision explanation, forming a comprehensive traffic security situation evaluation.
[0110] From the above attached Figure 1From the example of quantum-enhanced multi-scale network intrusion detection method, it can be seen that the technical solution of this application has systematically broken through the core bottlenecks in the field of industrial Internet security in terms of high-dimensional feature fidelity, spatiotemporal attack modeling, multi-scale perception and robustness to adversarial forces, and achieved a coordinated leap in detection accuracy, environmental adaptability and decision-making credibility. In the feature representation dimension, the innovative application of quantum Hilbert space projection technology fundamentally solves the problem of information distortion caused by traditional linear dimensionality reduction: the orthogonal basis system and energy distribution are obtained through the eigendecomposition of the original traffic feature covariance matrix, and the eigenvalue-weighted orthogonal basis expansion mapping is constructed according to the principle of quantum state superposition. This mechanism strictly retains the nonlinear correlation and energy distribution characteristics of high-dimensional traffic while expanding the feature dimension to twice the original dimension, which significantly improves the model's ability to capture weak abnormal signals in the industrial Internet environment and lays a high-fidelity quantized feature foundation for subsequent deep processing. In terms of modeling complex attack behaviors, the collaborative design of a complex-domain quantum entanglement encoder and a spatiotemporal gating fusion architecture breaks through the limitations of traditional spatiotemporal modeling separation: the quantum entanglement encoder projects features into complex space to form real and imaginary components, introduces a learnable entanglement matrix to simulate the coherence effect between quantum bits, and the generated quantum probability amplitude drives a multi-head attention mechanism to capture global dependencies. The spatiotemporal transformation block innovatively uses an independent temporal attention stream to analyze the evolution of attack sequences, while the spatial attention stream captures nonlinear dependencies between features. Ultimately, a dynamic gating function is used to achieve adaptive weighted fusion of dual-stream features. This deeply coupled modeling mechanism improves the system's sensitivity to spatiotemporal coupling features in cross-protocol session hijacking attacks by over 7%, effectively alleviating the historical problem of fragmented modeling of latent transmission paths for APT attacks. To address the challenges of multi-scale threat perception, the innovative design of a hierarchical feature pyramid architecture overcomes the constraints of a fixed convolutional receptive field: By dynamically generating differentiated convolution kernels through pre-set multi-level scaling factors, parallel convolution branches are constructed to independently capture local burst features (small scale), session-level patterns (medium scale), and global behavioral trajectories (large scale). Features at each scale are adaptively pooled and compressed before being integrated across multiple layers using fully connected layers. This adaptive receptive field adjustment mechanism has enabled the model to achieve 99.7% accuracy in identifying hybrid attacks (e.g., APT penetration disguised as DoS) during power grid attack and defense testing. In the dimension of defense and decision-making mechanisms, the construction of an integrated endogenous defense-assessment system has achieved a dual breakthrough in adversarial robustness and decision credibility: the adversarial defense module hardens the feature representation to represent the robustness of adversarial disturbances through nonlinear scaling of feature dimensions and Gaussian error activation, and suppresses the model deception success rate to below 3% in adversarial sample testing; the uncertainty assessment head innovatively outputs classification predictions, data accidental uncertainty scores and three-level threat probability distribution in parallel, forming a three-dimensional evaluation system for quantitative decision credibility. Combined with the multi-task joint training strategy (cross entropy + mean square error + KL divergence loss), the high threat omission rate was reduced to 0.2% in actual measurements of key financial facilities.The entire technical solution achieves an average detection accuracy of 99.8% and a millisecond-level real-time response speed in benchmark tests such as CIC-IDS2017 and TON_IoT through progressive innovation of quantum space reconstruction → complex domain entanglement → space-time gating fusion → multi-scale pyramid → robust decision chain, building a new generation of active defense paradigm inspired by quantum computing for critical information infrastructure.
[0111] Please see the attached Figure 2 , is a quantum-enhanced multi-scale network intrusion detection device provided in an embodiment of the present application. The device may include a feature reconstruction module 201, an enhancement module 202, a spatiotemporal fusion module 203, an analysis module 204, an aggregation module 205, and an evaluation module 206, as detailed below:
[0112] Feature reconstruction module 201 is used to reconstruct the original traffic feature matrix Calculate the covariance matrix, obtain the eigenvalues and eigenvectors through eigendecomposition, and transform each sample x i Mapping to quantum Hilbert space to generate enhanced characteristic matrix
[0113] An enhancement module 202 is configured to perform a complex domain transformation on the enhancement feature matrix to generate an entangled feature tensor, and implement dynamic feature enhancement based on quantum probability amplitude and through a multi-head attention mechanism;
[0114] The spatiotemporal fusion module 203 is used to perform spatiotemporal attention calculation and gated fusion on the feature tensor after dynamic feature enhancement to obtain spatiotemporal fusion features;
[0115] An analysis module 204 is used to convert the spatiotemporal fusion features into a time series form, extract behavioral features through multi-scale convolution branches, and fuse them to obtain a three-dimensional feature tensor;
[0116] Aggregation module 205 is used to calculate the mean of the three-dimensional feature tensor in the sequence dimension to generate a two-dimensional feature matrix
[0117] The evaluation module 206 is used to evaluate the two-dimensional feature matrix F based on the classification network, the uncertainty network and the threat classification network. agg Conduct parallel assessments of classification predictions, uncertainty quantification, and threat classification.
[0118] From the above attached Figure 2From the example of quantum-enhanced multi-scale network intrusion detection device, it can be seen that the technical solution of this application has systematically broken through the core bottlenecks in the field of industrial Internet security in terms of high-dimensional feature fidelity, spatiotemporal attack modeling, multi-scale perception and robustness to adversarial forces, and achieved a coordinated leap in detection accuracy, environmental adaptability and decision-making credibility. In the feature representation dimension, the innovative application of quantum Hilbert space projection technology fundamentally solves the problem of information distortion caused by traditional linear dimensionality reduction: the orthogonal basis system and energy distribution are obtained through the eigendecomposition of the original traffic feature covariance matrix, and the eigenvalue-weighted orthogonal basis expansion mapping is constructed based on the principle of quantum state superposition. This mechanism strictly retains the nonlinear correlation and energy distribution characteristics of high-dimensional traffic while expanding the feature dimension to twice the original dimension, significantly improving the model's ability to capture weak abnormal signals in the industrial Internet environment, and laying a high-fidelity quantized feature foundation for subsequent deep processing. In terms of modeling complex attack behaviors, the collaborative design of a complex-domain quantum entanglement encoder and a spatiotemporal gating fusion architecture breaks through the limitations of traditional spatiotemporal modeling separation: the quantum entanglement encoder projects features into complex space to form real and imaginary components, introduces a learnable entanglement matrix to simulate the coherence effect between quantum bits, and the generated quantum probability amplitude drives a multi-head attention mechanism to capture global dependencies. The spatiotemporal transformation block innovatively uses an independent temporal attention stream to analyze the evolution of attack sequences, while the spatial attention stream captures nonlinear dependencies between features. Ultimately, a dynamic gating function is used to achieve adaptive weighted fusion of dual-stream features. This deeply coupled modeling mechanism improves the system's sensitivity to spatiotemporal coupling features in cross-protocol session hijacking attacks by over 7%, effectively alleviating the historical problem of fragmented modeling of latent transmission paths for APT attacks. To address the challenges of multi-scale threat perception, the innovative design of a hierarchical feature pyramid architecture overcomes the constraints of a fixed convolutional receptive field: By dynamically generating differentiated convolution kernels through pre-set multi-level scaling factors, parallel convolution branches are constructed to independently capture local burst features (small scale), session-level patterns (medium scale), and global behavioral trajectories (large scale). Features at each scale are adaptively pooled and compressed before being integrated across multiple layers using fully connected layers. This adaptive receptive field adjustment mechanism has enabled the model to achieve 99.7% accuracy in identifying hybrid attacks (e.g., APT penetration disguised as DoS) during power grid attack and defense testing. In the dimension of defense and decision-making mechanisms, the construction of an integrated endogenous defense-assessment system has achieved a dual breakthrough in adversarial robustness and decision credibility: the adversarial defense module hardens the feature representation to represent the robustness of adversarial disturbances through nonlinear scaling of feature dimensions and Gaussian error activation, and suppresses the model deception success rate to below 3% in adversarial sample testing; the uncertainty assessment head innovatively outputs classification predictions, data accidental uncertainty scores and three-level threat probability distribution in parallel, forming a three-dimensional evaluation system for quantitative decision credibility. Combined with the multi-task joint training strategy (cross entropy + mean square error + KL divergence loss), the high threat omission rate was reduced to 0.2% in actual measurements of key financial facilities.The whole technical scheme realizes progressive innovation through quantum space reconstruction, complex domain entanglement, space-time gate fusion, multi-scale pyramid and robust decision chain, and achieves 99.8% average detection accuracy and millisecond-level real-time response speed in CIC-IDS2017, TON_IoT and other benchmark tests, thereby constructing a new generation of active defense paradigm with quantum computing inspiration for key information infrastructure.
[0119] Figure 3 is a structural schematic diagram of an electronic device provided by an embodiment of the present application. As shown in the figure, the electronic device 3 of the embodiment mainly comprises a processor 30, a memory 31, and a computer program 32 stored in the memory 31 and executable on the processor 30, such as a program of the quantum-enhanced multi-scale network intrusion detection method. The processor 30 implements the steps in the above-mentioned embodiment of the quantum-enhanced multi-scale network intrusion detection method when executing the computer program 32, such as steps S101 to S106 shown in the figure. Figure 3 Alternatively, the processor 30 implements the functions of each module / unit in the above-mentioned embodiment of each device when executing the computer program 32, such as the functions of the feature reconstruction module 201, the enhancement module 202, the space-time fusion module 203, the analysis module 204, the aggregation module 205 and the evaluation module 206 shown in the figure. Figure 1 Figure 2
[0120] Exemplarily, the computer program 32 of the quantum-enhanced multi-scale network intrusion detection method mainly comprises: calculating a covariance matrix of an original traffic feature matrix , obtaining eigenvalues and eigenvectors through eigenvalue decomposition, mapping each sample x i to a quantum Hilbert space to generate an enhanced feature matrix Performing complex domain transformation on the enhanced feature matrix to generate an entangled feature tensor, realizing dynamic feature enhancement based on quantum probability amplitude and through a multi-head attention mechanism; performing space-time attention calculation and gate fusion on the feature tensor after dynamic feature enhancement to obtain space-time fusion features; converting the space-time fusion features into a time sequence form, extracting behavior features through a multi-scale convolution branch and fusing them to obtain a three-dimensional feature tensor; calculating the mean value of the three-dimensional feature tensor in the sequence dimension to generate a two-dimensional feature matrix agg Perform parallel evaluation of classification prediction, uncertainty quantification and threat classification. The computer program 32 can be divided into one or more modules / units, one or more modules / units are stored in the memory 31 and executed by the processor 30 to complete the present application. One or more modules / units can be a series of computer program instruction segments that can complete specific functions. The instruction segments are used to describe the execution process of the computer program 32 in the electronic device 3. For example, the computer program 32 can be divided into the functions of the feature reconstruction module 201, the enhancement module 202, the spatiotemporal fusion module 203, the analysis module 204, the aggregation module 205 and the evaluation module 206 (modules in the virtual device). The specific functions of each module are as follows: Feature reconstruction module 201, used to reconstruct the original traffic feature matrix Calculate the covariance matrix, obtain the eigenvalues and eigenvectors through eigendecomposition, and transform each sample x i Mapping to quantum Hilbert space to generate enhanced characteristic matrix The enhancement module 202 is used to perform complex domain transformation on the enhanced feature matrix to generate an entangled feature tensor, and realize dynamic feature enhancement based on quantum probability amplitude and through a multi-head attention mechanism; the spatiotemporal fusion module 203 is used to perform spatiotemporal attention calculation and gated fusion on the feature tensor after dynamic feature enhancement to obtain spatiotemporal fusion features; the analysis module 204 is used to convert the spatiotemporal fusion features into a time series form, extract behavioral features through multi-scale convolution branches and fuse them to obtain a three-dimensional feature tensor; the aggregation module 205 is used to calculate the mean of the three-dimensional feature tensor in the sequence dimension to generate a two-dimensional feature matrix The evaluation module 206 is used to evaluate the two-dimensional feature matrix F based on the classification network, the uncertainty network and the threat classification network. agg Conduct parallel assessments of classification predictions, uncertainty quantification, and threat classification.
[0121] The electronic device 3 may include but is not limited to a processor 30 and a memory 31. Those skilled in the art will appreciate that Figure 3 It is only an example of electronic device 3 and does not constitute a limitation of electronic device 3. It may include more or fewer components than shown in the figure, or a combination of certain components, or different components. For example, the electronic device may also include input and output devices, network access devices, buses, etc.
[0122] The processor 30 may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor.
[0123] The memory 31 can be an internal storage unit of the electronic device 3, such as a hard drive or memory of the electronic device 3. The memory 31 can also be an external storage device of the electronic device 3, such as a plug-in hard drive, a Smart Media Card (SMC), a Secure Digital (SD) card, a flash memory card, etc. equipped on the electronic device 3. Furthermore, the memory 31 can include both an internal storage unit of the electronic device 3 and an external storage device. The memory 31 is used to store computer programs and other programs and data required by the electronic device. The memory 31 can also be used to temporarily store data that has been output or is about to be output.
[0124] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of this application. The specific working process of the units and modules in the above-mentioned device can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.
[0125] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant description of other embodiments.
[0126] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0127] In the embodiments provided in this application, it should be understood that the disclosed devices / equipment and methods can be implemented in other ways. For example, the device / equipment embodiments described above are merely schematic. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0128] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0129] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0130] If the integrated module / unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a storage medium. Based on this understanding, the present application implements all or part of the processes in the above-mentioned embodiment method, and can also be completed by instructing the relevant hardware through a computer program. The computer program of the quantum enhanced multi-scale network intrusion detection method can be stored in a storage medium. When the computer program is executed by the processor, it can implement the steps of the above-mentioned various method embodiments, that is, the original traffic feature matrix Calculate the covariance matrix, obtain the eigenvalues and eigenvectors through eigendecomposition, and transform each sample x i Mapping to quantum Hilbert space to generate enhanced characteristic matrix Perform complex domain transformation on the enhanced feature matrix to generate an entangled feature tensor, and realize dynamic feature enhancement based on quantum probability amplitude and multi-head attention mechanism; perform spatiotemporal attention calculation and gated fusion on the feature tensor after dynamic feature enhancement to obtain spatiotemporal fusion features; convert the spatiotemporal fusion features into a time series form, extract behavioral features through multi-scale convolution branches and fuse them to obtain a three-dimensional feature tensor; calculate the mean of the three-dimensional feature tensor in the sequence dimension to generate a two-dimensional feature matrix Based on the classification network, uncertainty network and threat classification network, the two-dimensional feature matrix F agg Conduct parallel assessments of classification prediction, uncertainty quantification, and threat classification. The computer program includes computer program code, which may be in source code form, object code form, executable file, or some intermediate form. Storage media may include: any entity or device capable of carrying computer program code, recording media, USB flash drives, mobile hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signals, telecommunications signals, and software distribution media. It should be noted that the content of the storage medium may be appropriately increased or decreased based on the requirements of legislation and patent practice within a jurisdiction. For example, in some jurisdictions, based on legislation and patent practice, storage media do not include electric carrier signals and telecommunications signals.
[0131] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application. The specific implementation methods described above further explain the purpose, technical solutions and beneficial effects of the present application in detail. It should be understood that the above description is only the specific implementation method of the present application and is not used to limit the protection scope of the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included in the protection scope of the present invention.
Claims
1. A quantum-enhanced multi-scale network intrusion detection method, characterized in that: The method comprises: For the original traffic feature matrix Calculate the covariance matrix, obtain the eigenvalues and eigenvectors through eigendecomposition, and transform each sample x i Mapping to quantum Hilbert space to generate enhanced characteristic matrix Performing a complex domain transformation on the enhanced feature matrix to generate an entangled feature tensor, and realizing dynamic feature enhancement based on quantum probability amplitude and a multi-head attention mechanism; Perform spatiotemporal attention calculation and gate fusion on the feature tensor after dynamic feature enhancement to obtain spatiotemporal fusion features; Converting the spatiotemporal fusion features into a time series form, extracting behavioral features through multi-scale convolution branches and fusing them to obtain a three-dimensional feature tensor; Calculate the mean of the three-dimensional feature tensor in the sequence dimension to generate a two-dimensional feature matrix Based on the classification network, uncertainty network and threat classification network respectively, for the two-dimensional feature matrix F agg Conduct parallel assessments of classification predictions, uncertainty quantification, and threat classification.
2. The quantum-enhanced multi-scale network intrusion detection method according to claim 1 is characterized in that: The original traffic feature matrix Calculate the covariance matrix, obtain the eigenvalues and eigenvectors through eigendecomposition, and transform each sample x i Mapping to quantum Hilbert space to generate enhanced characteristic matrix include: Calculate the covariance matrix based on the original traffic feature matrix X For the covariance matrix C, C=UΛU T Perform eigendecomposition and obtain eigenvalue λ k With the eigenvector u k ; According to the formula Mapping quantum states.
3. The quantum-enhanced multi-scale network intrusion detection method according to claim 1, characterized in that: The performing a complex domain transformation on the enhanced feature matrix to generate an entangled feature tensor comprises: Reshape the augmented feature matrix of dimension m×2n into a tensor of dimension m×1×2n; Through two independent fully connected layers, the m×1×2n tensor is respectively generated into a real part projection and the imaginary part projection According to the formula entangled_real=R·EI·E T and entangled_imag = I·E + R·E T Perform complex field entanglement operations to generate entangled feature tensors.
4. The quantum-enhanced multi-scale network intrusion detection method according to claim 3 is characterized in that: The dynamic feature enhancement based on quantum probability amplitude and multi-head attention mechanism includes: According to the formula Calculate the probability amplitude tensor probability_amplitudes, the ε=10 -6 ; Perform a dimension reordering operation on the probability amplitude tensor probability_amplitudes; The rearranged probability amplitude tensor is input into the multi-head attention layer to generate attention features; Superimposing the attention feature to the real component R of the entangled feature tensor through a residual connection; The superposition result is layer-normalized, and the output is a dynamic feature enhanced feature tensor with a dimension of m×1×h.
5. The quantum-enhanced multi-scale network intrusion detection method according to claim 1, characterized in that: The spatiotemporal attention calculation and gated fusion are performed on the feature tensor after dynamic feature enhancement to obtain spatiotemporal fusion features including: The temporal attention enhances the feature T attn With spatial attention enhancement feature S attn Splicing along feature dimensions; Generate fusion weight G = σ(W g [T attn ;S attn ]); According to formula F fusion =G⊙T attn +(1-G)⊙S attn Fusion is performed to obtain the fused spatiotemporal feature F fusion .
6. The quantum-enhanced multi-scale network intrusion detection method according to claim 1, characterized in that: The process of converting the spatiotemporal fusion features into a time series form, extracting and fusing behavioral features through multi-scale convolution branches, and obtaining a three-dimensional feature tensor includes: Reconstructing the spatiotemporal fusion features from [m, 1, h] into a three-dimensional time series tensor of [m, h, 1]; Parallel execution for the preset scale factor set {1, 2, 4}: for each scale factor s, use the convolution kernel size k s A one-dimensional convolutional layer with size = 3s-2 performs a convolution operation on the three-dimensional time series tensor, performs batch normalization and GELU activation processing on the convolution output, and compresses the activated features into a feature vector with a dimension of m×h×1 through adaptive average pooling; The feature vectors output from all scales are concatenated along the feature dimension to form the three-dimensional feature tensor.
7. The quantum-enhanced multi-scale network intrusion detection method according to claim 1, characterized in that: The uncertainty network performs uncertainty quantification assessments including: The two-dimensional feature matrix F agg Input two-layer fully connected network; The first fully connected layer compresses the feature dimension to 128 dimensions and applies GELU activation; The second fully connected layer outputs a single-dimensional scalar and then executes the Softplus function.
8. A quantum-enhanced multi-scale network intrusion detection device, characterized in that: The device comprises: Feature reconstruction module, used to reconstruct the original traffic feature matrix Calculate the covariance matrix, obtain the eigenvalues and eigenvectors through eigendecomposition, and transform each sample x i Mapping to quantum Hilbert space to generate enhanced characteristic matrix An enhancement module is configured to perform a complex domain transformation on the enhanced feature matrix to generate an entangled feature tensor, and implement dynamic feature enhancement based on quantum probability amplitude and through a multi-head attention mechanism; The spatiotemporal fusion module is used to perform spatiotemporal attention calculation and gated fusion on the feature tensor after dynamic feature enhancement to obtain spatiotemporal fusion features; An analysis module is used to convert the spatiotemporal fusion features into a time series form, extract behavioral features through multi-scale convolution branches and fuse them to obtain a three-dimensional feature tensor; Aggregation module, used to calculate the mean of the three-dimensional feature tensor in the sequence dimension to generate a two-dimensional feature matrix The evaluation module is used to evaluate the two-dimensional feature matrix F based on the classification network, the uncertainty network and the threat classification network. agg Conduct parallel assessments of classification predictions, uncertainty quantification, and threat classification.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Cited By
Intrusion detection method based on visual self-attention mechanism
CN121984749A
3D human body posture estimation method and device and storage medium
CN122244960A
A 3D human pose estimation method, device and storage medium
CN122244960B