Network security entity identification method based on fine-grained denoising diffusion boundary detection

By employing a fine-grained denoising diffusion boundary detection method, combined with a lightweight cybersecurity entity recognition framework and a hybrid attention mechanism, the generalization and boundary recognition problems of cybersecurity entity recognition are solved, achieving efficient and accurate cybersecurity entity recognition.

CN120825323APending Publication Date: 2025-10-21CIVIL AVIATION UNIV OF CHINA
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511076287.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-01
Publication Date
2025-10-21

AI Technical Summary

Technical Problem

Existing network security entity identification methods suffer from insufficient targeted research, difficulty in achieving effective generalization, inability to fully extract network security entity features, and high error rates in boundary identification.

Method used

We adopt a fine-grained denoised diffusion boundary detection method, which optimizes entity detection and classification tasks by extracting fine-grained character-level features, fusing multi-dimensional features, and predicting denoised diffusion boundaries. This is achieved through a lightweight cybersecurity entity recognition framework, a character-level dynamic partially convolutional attention network, a boundary diffusion mask generation network, and a hybrid attention mechanism.

Benefits of technology

It improves the accuracy and efficiency of network security entity identification, reduces computational overhead, and enables efficient identification of complex network security entities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120825323A_ABST
    Figure CN120825323A_ABST
Patent Text Reader

Abstract

The invention discloses a network security entity identification method based on fine-grained denoising diffusion boundary detection, and relates to the field of network security, in particular to a network security entity identification method. The objective of the invention is to solve the problems that effective generalization is difficult to realize, network security entity features are difficult to fully extract and the boundary identification error rate is high due to insufficient targeted research of the existing network security entity identification method. The method comprises the following steps of: 1, acquiring marked network security entity data; 2, constructing an entity recognition model based on fine-grained denoising diffusion boundary detection, and obtaining a trained entity recognition model based on fine-grained denoising diffusion boundary detection; and 3, obtaining to-be-detected network security entity data, inputting the to-be-detected network security entity data into the trained entity recognition model based on the fine-grained denoising diffusion boundary detection, and outputting the category of the entity by the trained entity recognition model based on the fine-grained denoising diffusion boundary detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security, and in particular to a network security entity identification method. Background Art

[0002] Named entity recognition (NER), a key subtask of information extraction, automatically extracts predefined entity names from unstructured text. It plays a vital role in natural language processing (NLP) tasks such as knowledge graphs, machine translation, and automatic text summarization. Named entities are widely targeted for extraction, encompassing common general-purpose entities like names and geographic locations, as well as entities composed of specialized vocabulary within various fields.

[0003] In recent years, with the growing influence of the internet and the frequent occurrence of cyber threats, cybersecurity has become a highly sought-after topic. In this environment, Cyber ​​Threat Intelligence (CTI) has become a crucial tool for discovering, identifying, and responding to cyber threats, and cybersecurity entity recognition (CER) has become a crucial tool for leveraging CTI's value. CER obtains unstructured text from the internet and extracts the underlying cybersecurity-related information. This helps analyze and summarize past cybersecurity incidents, build correlations between threat intelligence, and monitor and prevent potential cybersecurity incidents.

[0004] As a core task in threat intelligence analysis and knowledge graph construction, cybersecurity entity recognition has strong practicality and research value. However, due to the complexity and diversity of cybersecurity entities and the lack of large-scale, high-quality annotated datasets in the field, existing research mainly focuses on mainstream methods in general fields, which has the following limitations:

[0005] 1. Insufficient targeted research leads to difficulties in achieving effective generalization. Existing research on entity recognition in the cybersecurity field is limited. General domain methods are difficult to optimize specifically when transferred to the cybersecurity field. Consequently, they suffer from insufficient suppression of domain feature drift, low efficiency in incremental learning of new entities, and a lack of robustness against interference.

[0006] 2. Difficulty in fully extracting the characteristics of network security entities. Entities in the network security field include not only common entities in daily life, such as time and region, but also a large number of proper nouns and complex concepts. These include relatively difficult-to-understand domain terms, common words with different meanings within the field, and many special entities that contain mixed numbers and special characters. Conventional methods struggle to accurately capture their characteristics.

[0007] 3. High boundary recognition error rate. Named entity recognition tasks consist of two parts: entity boundary detection and entity classification. Due to the specific content and structure of entities within the domain, most existing methods have difficulty accurately understanding entity meaning and capturing entity boundaries in cybersecurity entity data, thereby reducing the accuracy of the overall task. Summary of the Invention

[0008] The purpose of this invention is to solve the problems of insufficient targeted research in existing network security entity recognition methods, which makes it difficult to achieve effective generalization, difficult to fully extract network security entity features, and high boundary recognition error rate, and propose a network security entity recognition method based on fine-grained denoising diffusion boundary detection.

[0009] The specific process of network security entity recognition method based on fine-grained denoising diffusion boundary detection is as follows:

[0010] Step 1: Obtain labeled network security entity data;

[0011] Step 2: Construct an entity recognition model based on fine-grained denoising diffusion boundary detection. Based on the labeled network security entity data obtained in step 1, the entity recognition model based on fine-grained denoising diffusion boundary detection is trained to obtain a trained entity recognition model based on fine-grained denoising diffusion boundary detection.

[0012] Step 3: Obtain the network security entity data to be tested, input the network security entity data to be tested into the trained entity recognition model based on fine-grained denoising diffusion boundary detection, and the trained entity recognition model based on fine-grained denoising diffusion boundary detection outputs the entity category.

[0013] The beneficial effects of the present invention are:

[0014] This paper proposes an efficient and robust method for identifying cybersecurity entities. Its core technologies include fine-grained character-level feature extraction, multi-dimensional feature fusion, and denoising diffusion boundary prediction. Specifically, the invention is innovative in the following four aspects:

[0015] (1) Lightweight network security entity recognition framework:

[0016] In view of the structural characteristics of network security entities, the present invention proposes a two-stage entity recognition framework, which consists of two parts: parallel entity detection and entity classification. This simplifies the overall task and focuses on optimizing and improving the various modules of the entity detection part: using fine-grained character-level features to capture special entities that are semantically difficult to understand but have distinct formal characteristics, while using hybrid attention to retain attention to details and global context understanding capabilities, so that it can accurately detect both conventional type entities and unconventional structure entities with special characters, etc., combined with an efficient boundary prediction network to effectively improve the performance of network security entity recognition. In the entity detection stage, the input sentence encoded using the Transformer-based Bidirectional Encoder Representations from Transformers (BERT) model is first subjected to multi-dimensional fine-grained feature extraction, and the character-level dynamic partial convolutional attention network is used to extract semantic and morphological features from the data at the character level. The feature is then spliced ​​with the part-of-speech and dependency features obtained using the annotation tool spaCy to obtain a fused feature. Secondly, a boundary diffusion mask generation network is used to process the feature data, forming entity boundary information and generating boundary masks for feature sequences to guide entity detection. Hybrid attention is then used to capture global and local features of the processed feature sequences. The entity detection results are then fed into the entity classification stage, where they are encoded by a pre-trained language model in the field of network security and the entity classifier performs specific type determination, ultimately outputting the classification result.

[0017] (2) Character level feature extraction:

[0018] In order to better adapt to the complex structure of network security entities and fully capture the characteristics of network security entities, this paper proposes a fine-grained character-level dynamic partial convolution attention network (CDPAN) model. This network extracts entity features of different dimensions from the character level, including semantic features extracted using the BERT model. At the same time, this paper designs a dynamic depthwise separable convolutional attention (Dynamic Depthwise Separable Convolutional Attention), which uses channel attention to capture global channel dependencies, taking into account local details and overall sentence features, and more accurately capturing entity features.

[0019] (3) Denoising diffusion boundary prediction:

[0020] In order to optimize boundary detection and enable it to more accurately capture the boundaries of complex network security entities, the present invention proposes a boundary diffusion mask generation network (BDMGN) model based on the denoising diffusion probability model (Denoising Diffusion Probabilistic Model, DDPM). DDPM can effectively improve the accuracy of entity boundary prediction, but the large-scale diffusion model used for complete entity recognition tasks has high requirements for the hardware environment, and has high computational overhead and time cost during training and inference. To solve this problem, the present invention designs a lightweight boundary diffusion mask generation network to achieve a balance between performance and cost from two aspects: first, the diffusion model is only used for entity boundary prediction, and it is constructed as a plug-and-play network integrated into the entity detection model. Since the task of the diffusion model is simplified, it can achieve higher prediction effects at a smaller scale; second, the traditional DDPM training and inference efficiency is low, and the generated boundary accuracy is limited. Therefore, the present invention optimizes the structure of BDMGN, converts the diffusion process into differential equation solution to accelerate the training and inference of the model, and greatly improves the model inference speed while ensuring the generation quality.

[0021] (4) Hybrid Attention Mechanism:

[0022] In order to take into account the fusion of global and local features in the process of feature data processing, the present invention proposes a hybrid attention, which optimizes the fusion efficiency of semantic, syntactic and character features from the two levels of frequency and channel through cross-modal attention weight distribution. Among them, Orthogonal Channel Attention forces different channels to pay attention to different subspaces of input features through orthogonal constraints, effectively reducing the common feature redundancy problem in traditional self-attention mechanisms; Frequency Domain Self-Attention adopts an improved frequency domain transformation method, and maps sequence features to the frequency domain space through fast Fourier transform to realize local-global feature joint modeling, thereby more effectively capturing long-distance features. Hybrid attention realizes channel dimension feature selection and spatial dimension frequency domain feature enhancement by establishing two-way parallel attention branches, and finally forms complementary feature representation through dynamic weight fusion.

[0023] The network security entity recognition method based on fine-grained denoising diffusion boundary detection (FDDBD) proposed in this paper breaks through the bottlenecks of traditional entity recognition methods in feature extraction and boundary detection, and has the following significant advantages:

[0024] Strong feature extraction capability: By combining fine-grained character semantics with morphological features, part of speech, and dependency features, multi-dimensional fusion feature extraction is achieved, thereby effectively enhancing the feature extraction capability of network security entities.

[0025] High boundary detection accuracy: BDMGN based on the diffusion algorithm is used to generate more accurate entity boundary prediction information, improving the performance of entity detection.

[0026] Low computational overhead: By designing the boundary prediction module as a plug-and-play small-scale network and focusing on the boundary generation task, the hardware requirements and computational overhead of the detection process are reduced. At the same time, the improved denoising diffusion process accelerates boundary generation, making the detection process more efficient.

[0027] In summary, the present invention proposes a novel network security entity recognition method, which can fully extract specific entities in unstructured text, improve the accuracy of boundary recognition, and provide a key basis for the analysis of network threat intelligence and the handling of network security incidents. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1 This is the overall architecture diagram of the present invention;

[0029] Figure 2 It is a flow chart of the present invention. DETAILED DESCRIPTION

[0030] Specific implementation method 1: Combination Figure 1 、 Figure 2 The specific process of the network security entity identification method based on fine-grained denoising and diffusion boundary detection is as follows:

[0031] Step 1: Obtain annotated cybersecurity entity data (such as cyber attacks, malware, vulnerabilities, threat time, etc.);

[0032] Step 2: Construct an entity recognition model based on fine-grained denoising diffusion boundary detection. Based on the labeled network security entity data obtained in step 1, train the entity recognition model based on fine-grained denoising diffusion boundary detection to obtain a trained entity recognition model based on fine-grained denoising diffusion boundary detection (until all data in step 1 are input to obtain a trained entity recognition model based on fine-grained denoising diffusion boundary detection);

[0033] Step 3: Obtain the network security entity data to be tested, input the network security entity data to be tested into the trained entity recognition model based on fine-grained denoising diffusion boundary detection, and the trained entity recognition model based on fine-grained denoising diffusion boundary detection outputs the entity category.

[0034] Specific embodiment 2: This embodiment differs from specific embodiment 1 in that: in step 2, an entity recognition model based on fine-grained denoising diffusion boundary detection is constructed, and based on the labeled network security entity data obtained in step 1, the entity recognition model based on fine-grained denoising diffusion boundary detection is trained to obtain a trained entity recognition model based on fine-grained denoising diffusion boundary detection (until all data in step 1 are input to obtain a trained entity recognition model based on fine-grained denoising diffusion boundary detection); the specific process is as follows:

[0035] Step 21: Preprocess the labeled network security entity data to obtain part-of-speech and dependency relationship features;

[0036] Step 22: Input the labeled cybersecurity entity data into the BERT model, and the BERT model outputs semantic features;

[0037] Step 23: input the semantic features outputted from step 22 into the character-level feature extraction network CDPAN, and the character-level feature extraction network CDPAN outputs character-level features;

[0038] Step 24: Concatenate the part-of-speech and dependency features obtained in step 21, the semantic features output by the BERT model in step 22, and the character-level features output by the CDPAN character-level feature extraction network in step 23 to obtain feature X. att ;

[0039] Step 25: The feature X obtained in step 24 att Input the entity boundary diffusion mask generation network (BoundaryDiffusionMaskGenerationNetwork, BDMGN) to perform boundary prediction and generate boundary prediction information s info , based on the boundary prediction information s info Generate mask M i,j,k , the mask M i,j,k Splice on feature X att On the top, the enhanced feature space H is formed;

[0040] Step 26: Process the enhanced feature space H output in step 25 to obtain the output sequence H after mixed attention processing out ;

[0041] Step 27: The output sequence H after the mixed attention processing in step 26 out Input a classifier consisting of a fully connected layer to output entity detection results;

[0042] Step 28: Due to the targeted optimization of the entity boundary detection part, the model can obtain more efficient prediction results in the entity detection stage. Therefore, in the entity classification stage, the model only needs to learn to determine the extracted entity category.

[0043] Input the entity detection result outputted from step 27 (unstructured text BIO annotated data with entity boundary information) into the pre-trained language model CySecBERT in the field of network security, and the pre-trained language model CySecBERT outputs the encoding result;

[0044] The encoding result of the pre-trained language model CySecBERT is input into an entity classifier consisting of a fully connected layer, and the entity classifier outputs the category of the entity;

[0045] Step 27 is the output of the entity detection phase. The classifier outputs entity / non-entity but does not determine the specific category. Step 28 is the output of the entity classification phase. The classifier does not consider the entity boundary but only determines the category.

[0046] Step 29: Train the entity recognition model based on fine-grained denoising diffusion boundary detection to obtain a trained entity recognition model based on fine-grained denoising diffusion boundary detection (until all data in step 1 are input to obtain a trained entity recognition model based on fine-grained denoising diffusion boundary detection).

[0047] The present invention relates to a method for network security entity recognition, which optimizes entity boundary detection based on fine-grained feature fusion and boundary denoising diffusion technology, thereby improving the efficiency of network security entity recognition.

[0048] To address the above problems, the present invention focuses on network security entity recognition. It is noted that previous studies often make mistakes due to the difficulty in accurately capturing the morphology of network security entities. Therefore, the challenge of network security entity recognition is addressed by strengthening entity detection in the pipeline NER method. A network security entity recognition method based on fine-grained denoising diffusion boundary detection (FDDBD) is proposed. The network security entity recognition task is divided into two subtasks: entity boundary detection task and entity classification task. In the entity detection model, fine-grained character-level features are used to fully deconstruct network security entities, and multi-dimensional feature representation is obtained by combining the semantic features of sentences and the part-of-speech and dependency relationship features of words. In the boundary prediction stage, a boundary diffusion mask generation network based on the denoising diffusion probabilistic model (DDPM) is constructed to generate boundary information as a feature mask to assist decision-making. Hybrid attention is used to integrate multi-level features, thereby improving the boundary detection accuracy and the recognition efficiency of the model on network security entities. In the entity classification model, a simplified pre-trained model encoding is combined with fully connected layer classification to achieve fast and efficient model reasoning. The pre-trained language model in the field of network security is used to gain the ability to understand the terminology in the field, thereby accurately judging the entity category without increasing the model size. The main innovations of this invention include:

[0049] Fine-grained feature fusion: This paper proposes a fine-grained and efficient fusion of part-of-speech and dependency features, semantic features, and character-level features for entity boundary detection, so that it can more fully represent the diverse information of network security entities.

[0050] Efficient boundary diffusion: This paper proposes a lightweight and highly flexible boundary diffusion mask generation network for generating entity boundaries. The mask is obtained based on boundary information and spliced ​​into the fusion feature sequence, thereby achieving more effective boundary detection effects with a smaller network scale and computational complexity.

[0051] Hybrid attention that takes into account both local and global features: A hybrid attention method is proposed for boundary detection tasks. By processing entity boundary features from two dimensions, channel and frequency domain, it balances global semantic understanding and local detail capture.

[0052] Overall performance improvement of entity recognition tasks: The present invention constructs the entity boundary detection and entity classification modules including the above network into a complete network security entity recognition model to achieve efficient network security entity recognition.

[0053] Specific embodiment three: This embodiment differs from specific embodiment one or two in that: in step 21, the labeled network security entity data is preprocessed to obtain part of speech and dependency relationship features; the specific process is:

[0054] Step 2: Use spaCy to tag the data.

[0055] Step 2:2: Use the spaCy tool to perform dependency annotation on the data after part-of-speech annotation in step 2:1;

[0056] Step 213: Segment the data obtained in step 212 to obtain subwords, and fill in the sentence sequence after segmentation;

[0057] Step 214: input the data filled in step 213 into the bidirectional recurrent neural network structure, and the bidirectional recurrent neural network structure outputs part of speech and dependency relationship features;

[0058] In step 2, spaCy is used to perform part-of-speech tagging on the data. The specific process is as follows:

[0059] Perform part-of-speech tagging on the data based on the pre-trained model en_core_web_sm for part-of-speech provided by spaCy;

[0060] The deep learning tool spaCy, as an open-source high-level natural language processing library, provides a pre-trained model en_core_web_sm, which is a lightweight neural network model.

[0061] en_core_web_sm is trained based on a large amount of English text data, takes up little memory, and has fast startup and processing speeds, making it suitable for applications that require fast response.

[0062] Part-of-speech tagging assigns each word in a sentence a corresponding part of speech (such as noun, verb, adjective, etc.) or syntactic category (such as subject, predicate, etc.), providing basic information for subsequent text processing tasks;

[0063] The process of obtaining the pre-trained model en_core_web_sm for parts of speech provided by spaCy is as follows:

[0064] The model en_core_web_sm is pre-trained using the part-of-speech tagging set Penn Treebank to obtain the pre-trained model en_core_web_sm for part-of-speech;

[0065] The part-of-speech tags in the Penn Treebank include: noun (NOUN), verb (VERB), adjective (ADJ), adverb (ADV), proper noun (PROPN), determiner (DET), pronoun (PRON), punctuation (PUNCT), etc.

[0066] In step 212, the tool spaCy is used to perform dependency annotation on the data after part-of-speech annotation in step 21. The specific process is as follows:

[0067] Based on the pre-trained dependency model en_core_web_sm provided by spaCy, the data after part-of-speech labeling in step 2 is labeled with dependencies;

[0068] Dependency is the grammatical relationship between words in a sentence. Dependency annotation is a syntactic analysis method used to represent the dependency between words in a sentence, that is, the interaction between words in the syntactic structure, and determine the master-slave relationship and dependency type of each word in the sentence.

[0069] The acquisition process of the pre-trained model en_core_web_sm for dependency relationships is as follows:

[0070] Use the dependency annotation set UD to pre-train the model en_core_web_sm to obtain the pre-trained model en_core_web_sm for the dependency relationship;

[0071] The dependency labels in the dependency annotation set UD include: noun subject (nsubj), direct object (dobj), indirect object (iobj), preposition (prep), parallel relation (conj), sentence root node (ROOT), etc.

[0072] In step 213, the data obtained in step 212 is segmented to obtain subwords, and the sentence sequence after segmentation is filled; the specific process is:

[0073] 1) Use AutoTokenizer to segment the data obtained in step 212 to obtain segmented data, and at the same time build a mapping relationship between the segmented data and the data after dependency annotation;

[0074] 2) Set the maximum sequence length;

[0075] The segmented data is divided into several (greater than or equal to 2) sequences according to the maximum sequence length to obtain sequences of uniform length, each of which contains several (greater than or equal to 2) subwords;

[0076] The tail of the sequence that does not reach the maximum sequence length is padded with the mark [PAD] to the maximum sequence length; after padding, the original content is marked as 1 and the padded part is marked as 0;

[0077] The label value corresponding to each [PAD] is -100;

[0078] The label sequence padding value is set to -100 to avoid interference in gradient calculation;

[0079] Tokenization and padding: AutoTokenizer is used to decompose the original text into subword units that conform to the pre-trained model. A mapping relationship between subwords and original words is constructed to maintain label alignment. A dynamic label assignment mechanism is designed for different labeling schemes to support switching between labeling schemes. A dynamic padding strategy is implemented during the batch processing phase. The input sequence is padded at the end based on the maximum sequence length of the current batch. A specific masking mechanism is used to distinguish between valid content and padded parts. The padded value of the label sequence is set to -100 to avoid interference with gradient calculations.

[0080] Other steps and parameters are the same as those in the first or second embodiment.

[0081] Specific embodiment 4: This embodiment differs from any one of specific embodiments 1 to 3 in that: in step 23, the semantic features output from step 22 are input into the character-level feature extraction network CDPAN, and the character-level feature extraction network CDPAN outputs character-level features; the specific process is as follows:

[0082] Step 231: Split the semantic features output from step 22 to obtain a discrete character ID sequence

[0083] Sequence of discrete character IDs Mapping to dense vector

[0084] Slice the dense vector E on the sequence dimension S to obtain the features of each sequence position

[0085] Among them, B is the batch size, S is the sequence length, W is the word length, d e is the embedding dimension; is a real number;

[0086] Step 232: The features Divided into feature X conv and feature X identity ;

[0087] in,

[0088]

[0089] n div is the ratio of split channels;

[0090] Step 2, 3, 3. Feature X conv Apply dilated convolution to obtain feature X′ conv :

[0091] X′ conv =DilatedConv(X conv ,d)

[0092] Among them, DilatedConv is dilated convolution;

[0093] d is the expansion rate as the depth of the CDPAN network increases;

[0094] And X identity Maintaining the identity mapping, thereby reducing the amount of computation while retaining valid data information;

[0095] Step 2, 3, 4, feature X' conv and feature X identity Splicing to get the spliced ​​feature X partial_out :

[0096] X partial_out =Concat(X′ conv ,X identity )

[0097] Among them, Concat means splicing;

[0098] Step 2, 3, and 5: Based on the spliced ​​feature X partial_out Get character feature X out ; The specific process is:

[0099] Afterwards, the multi-branch features composed of the convolution outputs at different expansion rates and the identity mapping data enter the feature expansion layer composed of the inverse residual MLP block. The feature expansion layer operation consists of two stages: in the expansion stage, the number of channels is doubled to enhance nonlinearity; in the compression stage, the number of channels is reduced back to the original number to achieve information distillation. The process is expressed as:

[0100] X out =X+γ·IR_MLP(X partial_out )

[0101] Where γ is a learnable layer scaling factor set using a layer scaling strategy;

[0102] X is the feature of each sequence position;

[0103] IR_MLP represents the sequential processing of X partial_outExpand in the channel dimension, perform nonlinear transformation after expansion, and then compress back to the original dimension in the channel dimension after nonlinear transformation;

[0104] ·It is a vector multiplication operation;

[0105] X out is the character feature;

[0106] Step 236: Character feature X obtained based on step 235 out Get dynamic depth-separable convolutional attention α c , based on dynamic depth-wise separable convolutional attention α c Get the output features after adding attention Expressed as:

[0107] α c =σ(DSConv(GAP(X out )))

[0108]

[0109] Among them, DSConv is depth-wise separable convolution;

[0110] GAP stands for global average pooling;

[0111] σ is the Sigmoid activation function;

[0112] ⊙ is the element-by-element multiplication at the channel level;

[0113] α c Dynamic depth-wise separable convolutional attention;

[0114] As a feature extraction network, CDPAN outputs character-level features;

[0115] The dynamic convolution kernel size k of the depthwise separable convolution DSConv is adaptively adjusted by the following formula:

[0116]

[0117] Where, d c is the channel dimension;

[0118] a is the scale scaling factor, which adjusts the influence of the number of channels on the kernel size. The larger the value, the more gradual the kernel size growth.

[0119] b is the baseline offset, which controls the baseline of the logarithmic value of the number of channels to prevent the kernel size from being too small when the number of channels is small;

[0120] Indicates taking the nearest odd number.

[0121] This design enables the network to automatically adjust the receptive field according to the feature complexity, using small kernels in shallow layers to capture local patterns and large kernels in deep layers to model global dependencies.

[0122] The other steps and parameters are the same as those in the first to third embodiments.

[0123] Specific embodiment 5: This embodiment differs from any one of specific embodiments 1 to 4 in that: in step 25, the feature X obtained in step 24 is att Input the entity boundary diffusion mask generation network (BoundaryDiffusionMaskGenerationNetwork, BDMGN) for boundary prediction, and the generated boundary prediction information s info , based on the boundary prediction information s info Generate entity mask matrix M i,j,k , the entity mask matrix M i,j,k Splice on feature X att On the other hand, the enhanced feature space H is formed; the specific process is:

[0124] The feature sequence is processed through the BDMGN for boundary prediction. The core idea of ​​the diffusion model is to gradually add noise to the data distribution, then train the network to recover the original data. In the task of entity boundary detection, the coordinates of the entity boundary, namely the start and end positions, are considered as the target signals to be generated. Starting from random noise, the model gradually approximates the true entity boundary distribution through multi-step iterative denoising.

[0125] Step 251: Map discrete time to a d-dimensional continuous vector space by constructing a sinusoidal position encoding function. The input of the sinusoidal position encoding function is a discrete time step, and the output is a d-dimensional continuous vector, thereby using the phase difference of the sinusoidal function to capture the periodic characteristics of time evolution;

[0126] Specifically:

[0127] The sinusoidal position encoding function is as follows:

[0128] Φ(t)=concat[sin(ω1t),cos(ω1t),...,sin(ω d / 2 t),cos(ω d / 2 t)]

[0129] in,

[0130] t is the discrete time step of the diffusion process;

[0131] d represents the dimension of the continuous vector space;

[0132] For the Frequency modulation parameters, Used to control the intensity of time perception in different dimensions;

[0133] Φ(t) is the time embedding vector output by the sinusoidal position encoding function; Concat represents concatenation; · is the vector multiplication operation;

[0134] Step 252: Input the time embedding vector Φ(t) output by the sinusoidal position encoding function into the temporal MLP network. The temporal MLP network outputs a semantically enhanced time embedding vector of the same dimension as the time embedding vector Φ(t), thereby encoding the temporal information of different stages of the diffusion process.

[0135] Strengthen the semantic representation ability of temporal embedding through a temporal MLP network that includes linear transformation and nonlinear activation;

[0136] The time series MLP consists of a fully connected network consisting of an input layer, a hidden layer, and an output layer;

[0137] The time series MLP network is a method that uses the multi-layer perceptron MLP architecture to process time series data;

[0138] The time embedding generated by the time series MLP serves as a global conditional signal, guiding the model to perceive the dynamic attenuation of noise intensity with the number of iterations, thereby assisting in the progressive correction of the probability distribution of entity boundaries;

[0139] Step 253: Based on the time embedding vector obtained in step 252, forward diffusion is performed step by step to generate x at time step t t ; The specific process is:

[0140] Because the model cannot directly use discrete t as input, a continuous time embedding vector is generated as the time condition. This vector is a representation of t, so the time embedding vector can be simply understood as t;

[0141] Forward noise diffusion starts from the actual boundary coordinates and gradually adds Gaussian noise in steps according to a preset noise scheduling strategy. The noise intensity at each step is controlled by a cosine scheduling function. Initially, a small amount of noise is added to preserve the structure, and the noise intensity is increased later until the boundary coordinates are completely blurred.

[0142] The forward diffusion noise injection process is defined as:

[0143]

[0144] in,

[0145] q(x t |x t-1 ) represents the noise boundary x at a given time step t-1 t-1 When the noise boundary x at time step t is t The transition probability distribution of

[0146] I is the identity matrix; t represents the time step t;

[0147] represents a normal distribution;

[0148] represents the noise boundary x for time step t-1 t-1 Zoom in and out and keep some historical information;

[0149] β t I is a diagonal matrix with independent dimensions and equal variance, which is used to ensure the consistency of noise perturbation intensity at each boundary coordinate;

[0150] β t is the continuous noise scheduling function, generated by the improved cosine scheduling function:

[0151]

[0152] Where T represents the total number of diffusion steps; · is the vector multiplication operation;

[0153] s′ is the phase shift factor, which controls the noise injection rate;

[0154] ρ is the scale factor, which controls the overall noise amplitude and prevents gradient explosion;

[0155] Step 254: In step 253, forward diffusion is performed to generate the noise boundary x at time step t. t After that, the reverse diffusion process is performed to restore the original boundary x0 and generate the boundary prediction information s info ; The specific process is:

[0156] The inverse denoising process is the process by which the neural network learns to predict noise from noisy boundary coordinates. When noisy coordinates are input, the network needs to infer the actual deviation and finally obtain the accurate boundary through multiple corrections.

[0157] The reverse diffusion process is defined as:

[0158]

[0159] Among them, pθ(x t-1 |x t ) represents the noise boundary x from time step t t Predict the noise boundary x at time step t-1 t-1 The conditional probability distribution of ;

[0160] μ θ represents the mean; Represents variance, controlling sampling randomness;

[0161] Mean μθ The calculation method is:

[0162]

[0163] Among them, α t =1-β t is the single-step retention coefficient, which controls the signal retention ratio of the forward process;

[0164] is the cumulative retention coefficient, representing the transition from the initial noiseless state x0 to x t The degree of signal attenuation; α s =1-β s is the single-step retention coefficient, β s is the continuous noise scheduling function;

[0165] ∈ θ (x t ,t) is the predicted noise;

[0166] Through this forward diffusion process of adding noise and backward diffusion of prediction and removal of noise, the network can more fully learn the key features of the entity and thus improve the effectiveness of boundary detection.

[0167] Step 255: Based on the boundary prediction information s generated in step 254 info Generate boundary mask M i,j,k ; Finally, the mask M i,j,k and the feature X obtained in step 24 att Perform channel splicing to form the enhanced feature space H; the specific process is:

[0168] The boundary prediction information s info Split into left boundary S i,k and right boundary E i,k (Each entity boundary includes a left boundary (entity start position) and a right boundary (entity end position)), and the left boundary and the right boundary are broadcasted to generate the entity mask matrix M i,j,k ;

[0169] The broadcast mechanism is a mechanism that automatically expands the array dimension to support element-by-element operations. Here, the model predicts multiple entities for the same input sequence. For each predicted entity, the position index is compared to see if it is between the start and end tags.

[0170] The mathematical representation of the two-dimensional mask matrix is:

[0171]

[0172] Among them, S i,k and E i,kThey represent the start and end position predictions of the k-th entity in the i-th sentence respectively;

[0173] M i,j,k represents the candidate entity mask;

[0174] j represents the position of the currently processed subword in the sequence;

[0175] Finally, the mask M i,j,k and the feature X obtained in step 24 att Perform channel splicing to form the enhanced feature space H:

[0176] H=Concat(X att ,M i,j,k )

[0177] Among them, H represents the enhanced feature space;

[0178] Concat(X att ,M i,j,k ) means to mask M i,j,k and the feature X obtained in step 24 att Perform channel splicing.

[0179] This mask mechanism enables the model to maintain deep semantic understanding while explicitly perceiving boundary location information.

[0180] The other steps and parameters are the same as those in the first to fourth embodiments.

[0181] Specific embodiment 6: This embodiment differs from specific embodiments 1 to 5 in that the solution process of the reverse diffusion process in step 254 is:

[0182] The sampling operation in the reverse diffusion process generates increasingly accurate prediction data through iteration. Traditional diffusion models require thousands of iterations to generate more accurate results, which cannot meet real-time requirements. DPM-Solver transforms the diffusion process into a differential equation through mathematical reconstruction, and uses high-order approximations to significantly reduce the number of sampling steps while maintaining high-quality generation. Therefore, the DPM-Solver second-order accelerator is used in the network to achieve fast convergence. DPM-Solver models the reverse diffusion process as a noise boundary x at time step t. t The continuous ordinary differential equation from x0 to x0 (the state update is calculated by the ordinary differential equation solver at each step); the expression is:

[0183]

[0184] in, is the drift coefficient, which is used to control the deterministic evolution direction of the data and simulate the denoising process;

[0185] βt is the continuous noise scheduling function;

[0186] Provide gradient information for the score function, gradually correct the data direction, and thus guide the process of gradually recovering the original data from the noisy data;

[0187] p t (x) is the probability distribution of data x at time step t;

[0188] is the diffusion coefficient, which adjusts the impact of the score function on the generation process;

[0189] The update process of DPM-Solver adopts the prediction-correction strategy. Through the second-order Taylor expansion, the network forward calculation is performed at each time step in the reverse diffusion process of step 254 to provide gradient information for the numerical integration of ordinary differential equations.

[0190] The updating process of data x in ordinary differential equations is:

[0191]

[0192] Among them, x n+1 is the state of the next time step, x n is the current state;

[0193] Δt is the time step, which is automatically determined by the solver based on the time discretization and the number of steps;

[0194] k1 is the initial gradient in the estimation phase, and k2 is the revised gradient in the correction phase;

[0195] When t = t n When x t =x n , and the next state is x t-1 =x n+1 ; Since the reverse diffusion process is caused by x t ,x t-1 ,…,x0 (i.e. t decreases), and using the gradually increasing n as the subscript is more intuitive to reflect the change of state with the steps, so here the state is represented by x n express;

[0196] The calculation of k1 and k2 is the process of estimation-correction: the estimation stage is at time t n Based on the current state x n and the estimated gradient direction, calculate the initial rate of change k1; in the correction phase, based on the k1 calculation result, the same calculation method is used to predict the state of the next time step to obtain a more accurate rate of change k2. The specific formula is:

[0197] k1=f(tn )x n +g 2 (t n )∈ θ (x n ,t n )

[0198] k2=f(t n +Δt)(x n +Δtk1)+g 2 (t n +Δt)∈ θ (x n +Δtk1,t n +Δt)

[0199] in,

[0200] f(t n ) is t n Drift coefficient at the moment;

[0201] g(t n ) is the diffusion process t n The noise injection intensity at the moment;

[0202] ∈ θ (x n ,t n ) is the reverse diffusion process according to the current time t n and the current state x n Noisy residuals of the predictions;

[0203] f(t n +Δt) is the next moment (t n +Δt) drift coefficient;

[0204] g(t n +Δt) is the next moment (t n +Δt) noise injection intensity;

[0205] The feature X obtained in step 24 att After the diffusion process of steps 2, 5, and 4, each step uses the ordinary differential equation solver to calculate the state update and execute the noise x t After several cycles to the original data x0, the boundary prediction information s is generated info ;

[0206] Through this method, the network can generate high-quality boundary prediction data in fewer steps, thereby significantly accelerating inference speed and reducing computational overhead.

[0207] The other steps and parameters are the same as those in the first to fifth embodiments.

[0208] Specific embodiment 7: The difference between this embodiment and any one of the specific embodiments 1 to 6 is that in step 26, the enhanced feature space H outputted in step 25 is processed to obtain the output sequence H after mixed attention processing. out ; The specific process is:

[0209] After BDMGN, the data is processed by a hybrid attention based on orthogonal channel attention and frequency domain self-attention. This module establishes two parallel attention branches to achieve channel dimension feature selection and spatial dimension frequency domain feature enhancement, and finally forms a complementary feature representation through dynamic weight fusion.

[0210]

[0211] Among them, α, β∈[0,1] are learnable weight parameters;

[0212] and They represent the orthogonal channel attention function (OrthoNets:OrthogonalChannel AttentionNetworks) and the frequency domain self-attention function (EfficientFrequencyDomain-basedTransformers forHigh-QualityImageDeblurring) respectively;

[0213] H out represents the output sequence after mixed attention processing, and represents the vector multiplication operation.

[0214] The other steps and parameters are the same as those in the first to sixth embodiments.

[0215] Specific embodiment eight: This embodiment differs from any one of specific embodiments one to seven in that: the orthogonal channel attention function The specific solution process is:

[0216] Gram-Schmidt orthogonalization is used to construct the filter bank, and the channel weights are calculated through the projection matrix. The weight matrix is ​​expressed as:

[0217]

[0218] Where GS represents the Gram-Schmidt orthogonalization process; σ is the Sigmoid activation function; the superscript T represents the transpose; MLP is the multi-layer perceptron; W ortho is the orthogonal channel attention function The output matrix of .

[0219] To perform Gram-Schmidt orthogonalization on the feature channel covariance matrix; To represent the transposition of the feature map H, it is used to calculate the covariance matrix between channels;

[0220] This module forces different channels to focus on different subspaces of input features through orthogonal constraints, effectively reducing the feature redundancy problem common in traditional self-attention mechanisms.

[0221] The other steps and parameters are the same as those in the first to seventh embodiments.

[0222] Specific embodiment 9: This embodiment differs from any one of specific embodiments 1 to 8 in that: the frequency domain self-attention function The specific solution process is:

[0223] Perform fast Fourier transform (FFT) on the enhanced feature space H output in step 25, map the enhanced feature space H to the frequency domain, and realize local-global feature joint modeling:

[0224]

[0225] Among them, Q and K are Query and Key respectively;

[0226] W Q , W K is the linear projection weight matrix;

[0227] represents the output sequence after fast Fourier transform of Q;

[0228] represents the output sequence after fast Fourier transform of K;

[0229] Partition(W Q H) represents the operation of linearly projecting the feature space H to generate Q and splitting Q into δ (8, patch_size is an adjustable hyperparameter) local blocks;

[0230] Partition(W K H) represents the operation of linearly projecting the feature space H to generate K and dividing K into δ (8, patch_size is an adjustable hyperparameter) local blocks;

[0231] ⊙ represents the frequency domain dot product operation;

[0232] Represents inverse fast Fourier transform, which is used to map frequency domain features back to the spatial domain;

[0233] FSA(Q,K) represents the frequency domain self-attention function The output matrix of .

[0234] The partition operation divides the feature map into smaller local blocks, thereby reducing the complexity of global attention;

[0235] Functional complementarity in the orthogonal-frequency domain is achieved through the fused attention mechanism. The spatial domain orthogonal attention realizes feature decoupling through the Gram-Schmidt process, improving the model's sensitivity to local semantic boundaries; the frequency domain global attention utilizes the global characteristics of Fourier transform to enhance the ability to model long-distance dependencies.

[0236] The other steps and parameters are the same as those in the first to eighth embodiments.

[0237] Specific embodiment 10: This embodiment differs from any one of specific embodiments 1 to 9 in that: in step 27, the output sequence H after the mixed attention processing in step 26 is out Input a classifier consisting of a fully connected layer to output entity detection results; the specific process is:

[0238] After BDMGN adds a boundary mask to the feature sequence and hybrid attention performs global and local attention on the feature sequence, the entity detection model will make the final boundary judgment on the fully processed feature sequence and output the entity detection result.

[0239] The output sequence H after the mixed attention processing in step 26 is out The input is a classifier consisting of a fully connected layer. The classifier outputs the confidence of the word on each label. The argmax function selects the entity or non-entity result corresponding to the maximum confidence category corresponding to each word.

[0240] A classifier consisting of fully connected layers maps the feature sequence obtained in step 5 to the label space. The confidence level of each word in each label is calculated and output. Finally, the Argmax function outputs the maximum confidence level category for each word in the data, determining whether the word is part of an entity. (For example, for data labeled with BIO (label categories are "B" (entity start), "I" (entity inside), and "O" (non-entity)), the classifier outputs confidence levels [0.4, 2.8, 0.2] for the word "word" belonging to the B, I, and O categories, respectively. Argmax selects the label "I" with the highest confidence level of 2.8 and outputs it.)

[0241] The entity detection phase simply labels the entity without determining its specific type. This output serves as input to the entity classification phase, where a separately trained entity classification model makes further type determinations. Due to the parallel training of entity detection and classification models, the complete entity recognition task process is simplified and accelerated.

[0242] The other steps and parameters are the same as those in the first to ninth embodiments.

[0243] The following examples are used to verify the beneficial effects of the present invention:

[0244] Example 1:

[0245] In the model performance evaluation stage, precision, recall, and F1-score are selected as performance evaluation indicators. Precision reflects the proportion of samples predicted by the method to be entities that are actually entities; recall indicates the proportion of samples that are correctly identified among all samples that are actually entities. The F1 score comprehensively evaluates the overall performance of the method through the harmonic mean of precision and recall. The higher the F1 score, the better the balance between precision and recall. Especially in the case of uneven category distribution, the F1 score can more reasonably reflect the performance of the method. The calculation method of the above three indicators is as follows:

[0246]

[0247] Among them, TP is true positive, FP is false positive, and FN is false negative;

[0248] The comparison of the detection results of the present invention and different baseline models is shown in Table 1:

[0249] Table 1 Performance comparison of the present invention and different baseline models

[0250]

[0251] The experimental results show that the method proposed in this paper can effectively improve the detection accuracy, recall rate and F1 score in the field of network security entity recognition.

[0252] The present invention may have many other embodiments. Without departing from the spirit and essence of the present invention, those skilled in the art may make various corresponding changes and modifications based on the present invention, but these corresponding changes and modifications should all fall within the scope of protection of the claims attached to the present invention.

Claims

1. A network security entity recognition method based on fine-grained denoising diffusion boundary detection, characterized by: The specific process of the method is: Step 1: Obtain labeled network security entity data; Step 2: Build an entity recognition model based on fine-grained denoising diffusion boundary detection. Based on the labeled network security entity data obtained in step 1, train the entity recognition model based on fine-grained denoising diffusion boundary detection to obtain a trained entity recognition model based on fine-grained denoising diffusion boundary detection. Step 3: Obtain the network security entity data to be tested, input the network security entity data to be tested into the trained entity recognition model based on fine-grained denoising diffusion boundary detection, and the trained entity recognition model based on fine-grained denoising diffusion boundary detection outputs the entity category.

2. The network security entity identification method based on fine-grained denoising diffusion boundary detection according to claim 1 is characterized by: In the second step, an entity recognition model based on fine-grained denoising diffusion boundary detection is constructed. The entity recognition model based on fine-grained denoising diffusion boundary detection is trained based on the labeled network security entity data obtained in the first step to obtain a trained entity recognition model based on fine-grained denoising diffusion boundary detection. The specific process is as follows: Step 21: Preprocess the labeled network security entity data to obtain part-of-speech and dependency relationship features; Step 22: Input the labeled cybersecurity entity data into the BERT model, and the BERT model outputs semantic features; Step 23: input the semantic features outputted from step 22 into the character-level feature extraction network CDPAN, and the character-level feature extraction network CDPAN outputs character-level features; Step 24: Concatenate the part-of-speech and dependency features obtained in step 21, the semantic features output by the BERT model in step 22, and the character-level features output by the CDPAN character-level feature extraction network in step 23 to obtain feature X. att ; Step 25: The feature X obtained in step 24 att Input entity boundary diffusion mask generation network to perform boundary prediction and generate boundary prediction information s info , based on the boundary prediction information s info Generate mask M i,j,k , the mask M i,j,k Splice on feature X att On the top, the enhanced feature space H is formed; Step 26: Process the enhanced feature space H output in step 25 to obtain the output sequence H after mixed attention processing out ; Step 27: The output sequence H after the mixed attention processing in step 26 out Input a classifier consisting of a fully connected layer to output entity detection results; Step 28: Input the entity detection result outputted in step 27 into the pre-trained language model CySecBERT, which outputs the encoding result. The encoding result of the pre-trained language model CySecBERT is input into an entity classifier consisting of a fully connected layer, and the entity classifier outputs the category of the entity; Step 29: Train the entity recognition model based on fine-grained denoising diffusion boundary detection to obtain a trained entity recognition model based on fine-grained denoising diffusion boundary detection.

3. The network security entity identification method based on fine-grained denoising diffusion boundary detection according to claim 2 is characterized by: In step 21, the labeled network security entity data is preprocessed to obtain part-of-speech and dependency relationship features; the specific process is as follows: Step 2: Use spaCy to tag the data. Step 2:2: Use the spaCy tool to perform dependency annotation on the data after part-of-speech annotation in step 2:1; Step 213: Segment the data obtained in step 212 to obtain subwords, and fill in the sentence sequence after segmentation; Step 214: input the data filled in step 213 into the bidirectional recurrent neural network structure, and the bidirectional recurrent neural network structure outputs part of speech and dependency relationship features; In step 2, spaCy is used to perform part-of-speech tagging on the data. The specific process is as follows: Perform part-of-speech tagging on the data based on the pre-trained model en_core_web_sm for part-of-speech provided by spaCy; The process of obtaining the pre-trained model en_core_web_sm for parts of speech provided by spaCy is as follows: The model en_core_web_sm is pre-trained using the part-of-speech tagging set Penn Treebank to obtain the pre-trained model en_core_web_sm for part-of-speech; In step 212, the tool spaCy is used to perform dependency annotation on the data after part-of-speech annotation in step 21. The specific process is as follows: Based on the pre-trained dependency model en_core_web_sm provided by spaCy, the data after part-of-speech labeling in step 2 is labeled with dependencies; The acquisition process of the pre-trained model en_core_web_sm for dependency relationships is as follows: Use the dependency annotation set UD to pre-train the model en_core_web_sm to obtain the pre-trained model en_core_web_sm for the dependency relationship; In step 213, the data obtained in step 212 is segmented to obtain subwords, and the sentence sequence after segmentation is filled; the specific process is: 1) Use AutoTokenizer to segment the data obtained in step 212 to obtain segmented data, and at the same time build a mapping relationship between the segmented data and the data after dependency annotation; 2) Set the maximum sequence length; The segmented data is divided into several sequences according to the maximum sequence length to obtain sequences of uniform length, each of which contains several subwords; The tail of the sequence that does not reach the maximum sequence length is padded with the mark [PAD] to the maximum sequence length; after padding, the original content is marked as 1 and the padded part is marked as 0; The label value corresponding to each [PAD] is -100.

4. The network security entity identification method based on fine-grained denoising diffusion boundary detection according to claim 3 is characterized by: In step 23, the semantic features outputted in step 22 are inputted into the character-level feature extraction network CDPAN, and the character-level feature extraction network CDPAN outputs the character-level features. The specific process is as follows: Step 231: Split the semantic features output from step 22 to obtain a discrete character ID sequence Sequence of discrete character IDs Mapping to dense vector Slice the dense vector E on the sequence dimension S to obtain the features of each sequence position Among them, B is the batch size, S is the sequence length, W is the word length, d e is the embedding dimension; is a real number; Step 232: The features Divided into feature X conv and feature X identity ; in, n div is the ratio of split channels; Step 2, 3, 3. Feature X conv Apply dilated convolution to obtain feature X′ conv : X′ conv =DilatedConv(X conv ,d) Among them, DilatedConv is the dilated convolution, and d is the dilation rate; Step 2, 3, 4, feature X' conv and feature X identity Splicing to get the spliced ​​feature X partial_out : X partial_out =Concat(X′ conv ,X identity ) Among them, Concat means splicing; Step 2, 3, and 5: Based on the spliced ​​feature X partial_out Get character feature X out ; The specific process is: X out =X+γ·IR_MLP(X partial_out ) Where γ is the layer scaling factor; X is the feature of each sequence position; IR_MLP represents the sequential processing of X partial_out Expand in the channel dimension, perform nonlinear transformation after expansion, and then compress back to the original dimension in the channel dimension after nonlinear transformation; ·It is a vector multiplication operation; X out is the character feature; Step 236: Character feature X obtained based on step 235 out Get dynamic depth-separable convolutional attention α c , based on dynamic depth-wise separable convolutional attention α c Get the output features after adding attention Expressed as: a c =σ(DSConv(GAP(X out ))) Among them, DSConv is depth-wise separable convolution; GAP stands for global average pooling; σ is the Sigmoid activation function; ⊙ is the element-by-element multiplication at the channel level; α c Dynamic depth-wise separable convolutional attention; As a feature extraction network, CDPAN outputs character-level features; The dynamic convolution kernel size k of the depthwise separable convolution DSConv is adaptively adjusted by the following formula: Where, d c is the channel dimension; a is the scale scaling factor; b is the reference offset; Indicates taking the nearest odd number.

5. The network security entity identification method based on fine-grained denoising diffusion boundary detection according to claim 4 is characterized by: In step 25, the feature X obtained in step 24 is att Input entity boundary diffusion mask generation network to perform boundary prediction, and the generated boundary prediction information s info , based on the boundary prediction information s info Generate entity mask matrix M i,j,k , the entity mask matrix M i,j,k Splice on feature X att On the other hand, the enhanced feature space H is formed; the specific process is: Step 251: Map the discrete time to a d-dimensional continuous vector space by constructing a sinusoidal position encoding function; Specifically: The sinusoidal position encoding function is as follows: Φ(t)=concat[sin(ω1t),cos(ω1t),...,sin(ω d / 2 t),cos(ω d / 2 (t)] in, t is the discrete time step of the diffusion process; d represents the dimension of the continuous vector space; For the Frequency modulation parameters, Φ(t) is the time embedding vector output by the sinusoidal position encoding function; Concat represents concatenation; · is the vector multiplication operation; Step 252: Input the temporal embedding vector Φ(t) output by the sinusoidal position encoding function into the temporal MLP network, and the temporal MLP network outputs a temporal embedding vector containing semantic enhancement; Step 253: Based on the time embedding vector obtained in step 252, forward diffusion is performed step by step to generate the noise boundary x at time step t t ; The specific process is: The forward diffusion noise injection process is defined as: in, q(x t |x t-1 ) represents the noise boundary x at a given time step t-1 t-1 When the noise boundary x at time step t is t The transition probability distribution of I is the identity matrix; t represents the time step t; represents a normal distribution; represents the noise boundary x for time step t-1 t-1 Zoom in or out; β t is the continuous noise scheduling function, generated by the improved cosine scheduling function: Where T represents the total number of diffusion steps; · is the vector multiplication operation; s′ is the phase shift factor; ρ is the scale factor; Step 254: In step 253, forward diffusion is performed to generate the noise boundary x at time step t. t After that, the reverse diffusion process is performed to restore the original boundary x0 and generate the boundary prediction information s info ; The specific process is: The reverse diffusion process is defined as: Among them, pθ(x t-1 |x t ) represents the noise boundary x from time step t t Predict the noise boundary x at time step t-1 t-1 The conditional probability distribution of ; μ θ represents the mean; represents variance; Step 255: Based on the boundary prediction information s generated in step 254 info Generate boundary mask M i,j,k ; Finally, the mask M i,j,k and the feature X obtained in step 24 att Perform channel splicing to form the enhanced feature space H; the specific process is: The boundary prediction information s info Split into left and right boundaries, and generate the entity mask matrix M through the broadcast mechanism. i,j,k ; The mathematical representation of the two-dimensional mask matrix is: Among them, S i,k and E i,k They represent the start and end position predictions of the k-th entity in the i-th sentence respectively; M i,j,k represents the candidate entity mask; j represents the position of the currently processed subword in the sequence; Finally, the mask M i,j,k and the feature X obtained in step 24 att Perform channel splicing to form the enhanced feature space H: H=Concat(X att ,M i,j,k ) Among them, H represents the enhanced feature space; Concat(X att ,M i,j,k ) means to mask M i,j,k and the feature X obtained in step 24 att Perform channel splicing.

6. The network security entity identification method based on fine-grained denoising diffusion boundary detection according to claim 5 is characterized by: The solution process of the reverse diffusion process in step 254 is: The DPM-Solver models the inverse diffusion process as a noise boundary x at time step t. t The continuous ordinary differential equation from x to x0 is expressed as: in, is the drift coefficient; β t is the continuous noise scheduling function; is the scoring function; p t (x) is the probability distribution of data x at time step t; is the diffusion coefficient; The updating process of data x in ordinary differential equations is: Among them, x n+1 is the state of the next time step, x n is the current state; Δt is the time step; k1 is the initial gradient, k2 is the modified gradient; k1=f(t n )x n +g 2 (t n )∈ θ (x n ,t n ) k2=f(t n +Δt)(x n +Δtk1)+g 2 (t n +Δt)∈ θ (x n +Δtk1,t n +Δt) in, f(t n ) is t n The drift coefficient at the moment; g(t n ) is the diffusion process t n The noise injection intensity at the moment; ∈ θ (x n ,t n ) is the reverse diffusion process according to the current time t n and the current state x n Noisy residuals of the predictions; f(t n +Δt) is the next moment (t n +Δt) drift coefficient; g(t n +Δt) is the next moment (t n +Δt) noise injection intensity.

7. The network security entity identification method based on fine-grained denoising diffusion boundary detection according to claim 6 is characterized by: In step 26, the enhanced feature space H outputted in step 25 is processed to obtain the output sequence H after mixed attention processing. out ; The specific process is: Among them, α, β∈[0,1] are learnable weight parameters; and They represent the orthogonal channel attention function and the frequency domain self-attention function respectively; H out represents the output sequence after mixed attention processing, and represents the vector multiplication operation.

8. The network security entity identification method based on fine-grained denoising diffusion boundary detection according to claim 7 is characterized by: The orthogonal channel attention function The specific solution process is: Gram-Schmidt orthogonalization is used to construct the filter bank, and the channel weights are calculated through the projection matrix. The weight matrix is ​​expressed as: Where GS represents the Gram-Schmidt orthogonalization process; σ is the Sigmoid activation function; the superscript T represents the transpose; MLP is the multi-layer perceptron; W ortho is the orthogonal channel attention function The output matrix of .

9. The network security entity identification method based on fine-grained denoising diffusion boundary detection according to claim 8 is characterized by: The frequency domain self-attention function The specific solution process is: Perform fast Fourier transform (FFT) on the enhanced feature space H output in step 25, map the enhanced feature space H to the frequency domain, and realize local-global feature joint modeling: Among them, Q and K are Query and Key respectively; W Q , W K is the linear projection weight matrix; represents the output sequence after fast Fourier transform of Q; represents the output sequence after fast Fourier transform of K; Partition(W Q H) represents the operation of linearly projecting the feature space H to generate Q and dividing Q into δ local blocks; Partition(W K @H) represents the operation of linearly projecting the feature space H to generate K and dividing K into δ local blocks; ⊙ represents the frequency domain dot product operation; represents the inverse fast Fourier transform; FSA(Q,K) represents the frequency domain self-attention function The output matrix of .

10. The network security entity identification method based on fine-grained denoising diffusion boundary detection according to claim 9 is characterized in that: In step 27, the output sequence H after the mixed attention processing in step 26 is out Input a classifier consisting of a fully connected layer to output entity detection results; the specific process is: The output sequence H after the mixed attention processing in step 26 is out A classifier consisting of a fully connected layer is input. The classifier outputs the confidence of the word on each label, and the argmax function selects the entity or non-entity result corresponding to the maximum confidence category corresponding to each word.

Citation Information

Cited By

  • Method, device and equipment for optimizing power grid security domain based on de-noising diffusion model

    CN122118886A