Internet-of-things terminal vulnerability detection method based on artificial intelligence
By using a generative adversarial network framework and adversarial training between autoencoders and discriminators, the problem of identifying unknown attacks in IoT terminal vulnerability detection is solved, achieving efficient and accurate detection of abnormal traffic and eliminating the dependence on attack signature databases.
Patent Information
- Application Number
- CN202511094229.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-06
- Publication Date
- 2025-11-11
AI Technical Summary
Existing IoT terminal vulnerability detection methods are difficult to effectively identify new and unknown attacks and are costly when facing diverse terminal devices. Traditional methods rely on attack signature databases and are difficult to obtain high-quality attack samples, resulting in poor detection performance.
We adopt an AI-based generative adversarial network architecture, using an autoencoder as a generator combined with a discriminator. Through adversarial training, we learn the inherent distribution patterns of normal traffic and construct a generative adversarial network framework to achieve sensitive and accurate detection of unknown vulnerabilities.
It can efficiently identify unknown vulnerabilities without relying on attack signature databases. Through a dual judgment mechanism of generator and discriminator, it can achieve keen detection of abnormal traffic, improving the accuracy and generalization ability of detection.
Smart Images

Figure CN120934820A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of vulnerability detection, and more specifically, to an artificial intelligence-based method for detecting vulnerabilities in IoT terminals. Background Technology
[0002] With the rapid development and deep penetration of IoT technology, the number of IoT terminals is exploding across various fields, from smart homes and wearable devices to industrial automation and smart cities. While these terminal devices bring great convenience to social life and production, their widespread connectivity, complex network environment, and limited computing resources make them a prime target for cyberattacks. Security vulnerabilities in IoT terminals can not only lead to user privacy leaks and unauthorized control of devices, but also be exploited by attackers as springboards to launch large-scale, coordinated cyberattacks against critical information infrastructure, posing a serious threat to social and national security. Therefore, building an efficient and accurate IoT terminal vulnerability detection solution to proactively discover and defend against potential security risks is crucial for ensuring the safe and stable operation of the entire IoT ecosystem.
[0003] Currently, anomaly detection in network traffic is a common method for discovering terminal vulnerabilities and attack behaviors. Traditional vulnerability detection methods mainly rely on signature-based detection technology, which involves maintaining a large, constantly updated attack signature database and matching network traffic with known attack signatures in the database. However, the drawbacks of this method are becoming increasingly apparent: First, it cannot effectively identify new and unknown (i.e., zero-day) attacks because the characteristics of these attacks have not yet been included, making it inadequate in the face of a constant stream of new attacks; second, the diverse types and protocols of IoT terminals make maintaining a comprehensive attack signature database for each device and scenario costly and impractical. Another approach uses supervised machine learning models, training them on a large amount of labeled normal and anomalous (attack) traffic to learn the ability to distinguish between the two. However, this method also faces practical challenges: in real network environments, attack traffic samples are extremely scarce and imbalanced compared to the massive amount of normal traffic, and attack methods are highly varied, making it difficult to obtain high-quality, diverse attack samples. This severely restricts the model's generalization ability and its effectiveness in detecting unknown attacks.
[0004] Therefore, an optimized IoT terminal vulnerability detection solution is desired. Summary of the Invention
[0005] To address the aforementioned technical problems, this application is proposed. Embodiments of this application provide an artificial intelligence-based method for detecting vulnerabilities in IoT terminals.
[0006] According to one aspect of this application, an AI-based IoT terminal vulnerability detection method is provided, which includes: a model training phase and a vulnerability detection phase;
[0007] The model training phase includes:
[0008] S1: Obtain training data, which is a set of network traffic sessions labeled as normal traffic;
[0009] S2: Extract traffic features from each network traffic session labeled as normal traffic to obtain a set of normal traffic feature vectors;
[0010] S3: Fixed generator, the discriminator is trained based on the set of normal traffic feature vectors to obtain an updated discriminator;
[0011] S4: Fix the update discriminator, and train the generator based on the set of normal traffic feature vectors to obtain the update generator;
[0012] S5: Repeat steps S3 and S4 until the reconstruction error and discrimination score meet the preset conditions to obtain the trained generator and the trained discriminator;
[0013] The vulnerability detection phase includes:
[0014] S6: Obtain the traffic feature vector of the IoT terminal to be detected;
[0015] S7: Input the feature vector of the traffic to be detected into the trained generator and the trained discriminator to obtain a comprehensive anomaly score;
[0016] S8: Based on the comparison between the comprehensive anomaly score and the preset threshold, determine whether the IoT terminal to be detected has vulnerabilities.
[0017] The above-mentioned AI-based IoT terminal vulnerability detection method includes: the generator is an autoencoder, which includes an encoder and a decoder.
[0018] In the above-mentioned IoT terminal vulnerability detection method based on artificial intelligence, step S2 includes: extracting time features, data packet features, and byte features from each network traffic session marked as normal traffic; and normalizing the time features, data packet features, and byte features to form a feature vector to obtain the normal traffic feature vector.
[0019] In the above-mentioned AI-based IoT terminal vulnerability detection method, step S3 includes: extracting the first batch of normal traffic feature vectors from the set of normal traffic feature vectors; inputting the first batch of normal traffic feature vectors into the discriminator to obtain the genuine product loss; inputting the first batch of normal traffic feature vectors into a fixed generator to obtain the first batch of reconstructed traffic feature vectors; inputting the first batch of reconstructed traffic feature vectors into the discriminator to obtain the counterfeit product loss; and updating the internal parameters of the discriminator based on the counterfeit product loss and the genuine product loss through backpropagation to obtain the updated discriminator.
[0020] In the above-mentioned AI-based IoT terminal vulnerability detection method, step S4 includes: extracting a second batch of normal traffic feature vectors from the set of normal traffic feature vectors; inputting the second batch of normal traffic feature vectors into the generator to obtain a second batch of reconstructed traffic feature vectors; inputting the second batch of reconstructed traffic feature vectors into the update discriminator to obtain adversarial loss; calculating the reconstruction loss between the second batch of normal traffic feature vectors and the second batch of reconstructed traffic feature vectors; and updating the internal parameters of the generator based on the reconstruction loss and the adversarial loss through backpropagation to obtain the update generator.
[0021] In the aforementioned AI-based IoT terminal vulnerability detection method, inputting the second batch of normal traffic feature vectors into the generator to obtain the second batch of reconstructed traffic feature vectors includes: inputting the normal traffic feature vectors into the encoder of the generator to obtain a normal traffic pattern feature implicit encoding vector; performing pattern feature sparsification on the normal traffic pattern feature implicit encoding vector to obtain a sparse normal traffic pattern feature implicit encoding vector; and inputting the sparse normal traffic pattern feature implicit encoding vector into the decoder of the generator to obtain the reconstructed traffic feature vector.
[0022] In the aforementioned AI-based IoT terminal vulnerability detection method, the normal traffic pattern feature implicit coding vector is subjected to pattern feature sparsification to obtain a sparse normal traffic pattern feature implicit coding vector. This includes: performing feature optimization representation on the normal traffic pattern feature implicit coding vector to obtain a refined feature vector of normal traffic pattern implicit coding; calculating the feature distribution redundancy of the refined feature vector of normal traffic pattern implicit coding relative to the normal traffic pattern feature implicit coding vector; and, in response to the feature distribution redundancy satisfying a preset condition, setting the refined feature vector of normal traffic pattern implicit coding as the sparse normal traffic pattern feature implicit coding vector.
[0023] In the above-mentioned IoT terminal vulnerability detection method based on artificial intelligence, in response to the feature distribution redundancy meeting a preset condition, the refined feature vector of the normal traffic pattern hidden encoding is set as the sparse normal traffic pattern feature hidden encoding vector, including: in response to the distance between the feature distribution redundancy and the target redundancy meeting a preset tolerance, the refined feature vector of the normal traffic pattern hidden encoding is set as the sparse normal traffic pattern feature hidden encoding vector.
[0024] In the above-mentioned IoT terminal vulnerability detection method based on artificial intelligence, step S7 includes: inputting the traffic feature vector to be detected into the trained generator to obtain a generator anomaly score; inputting the traffic feature vector to be detected into the trained discriminator to obtain a discriminator anomaly score; and calculating the weighted sum between the generator anomaly score and the discriminator anomaly score to obtain the comprehensive anomaly score.
[0025] Compared with existing technologies, this application provides an AI-based IoT terminal vulnerability detection method that uses an autoencoder as a generator and combines it with a discriminator to form a generative adversarial network (GAN) framework. Through adversarial training, the model is forced to deeply learn and accurately grasp the inherent distribution patterns and essential characteristics of normal network traffic. Therefore, during the detection phase, when abnormal traffic containing vulnerability exploitation behavior is input, because its pattern deviates from the learned normal paradigm, the trained generator will be unable to effectively reconstruct the traffic, resulting in significant reconstruction errors. Simultaneously, the discriminator can also keenly identify the difference between the traffic and the normal pattern. Ultimately, by comprehensively considering the generator's reconstruction performance and the discriminator's discrimination results, it can achieve sensitive and accurate detection of unknown vulnerabilities without relying on any prior attack knowledge, effectively overcoming the limitations of existing technologies. Attached Figure Description
[0026] The above and other objects, features, and advantages of this application will become more apparent from the more detailed description of the embodiments of this application in conjunction with the accompanying drawings. The drawings are provided to further illustrate the embodiments of this application and form part of the specification. They are used together with the embodiments of this application to explain this application and do not constitute a limitation thereof. In the drawings, the same reference numerals generally represent the same components or steps.
[0027] Figure 1 This is a flowchart of an AI-based IoT terminal vulnerability detection method according to an embodiment of this application;
[0028] Figure 2 This is a flowchart of step S3 of the AI-based IoT terminal vulnerability detection method according to an embodiment of this application;
[0029] Figure 3This is a flowchart of step S4 of the AI-based IoT terminal vulnerability detection method according to an embodiment of this application;
[0030] Figure 4 A flowchart illustrating how the second batch of normal traffic feature vectors are input into the generator to obtain the second batch of reconstructed traffic feature vectors according to the AI-based IoT terminal vulnerability detection method of this application. Detailed Implementation
[0031] Hereinafter, exemplary embodiments according to this application will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of this application, and not all embodiments of this application. It should be understood that this application is not limited to the exemplary embodiments described herein.
[0032] As indicated in this application and claims, unless the context clearly indicates otherwise, the words "a," "an," "an," and / or "the" are not specifically singular and may include plural forms. Generally speaking, the terms "comprising" and "including" only indicate the inclusion of explicitly identified steps and elements, which do not constitute an exclusive list, and the method or apparatus may also include other steps or elements.
[0033] While this application makes various references to certain modules of the systems according to embodiments of this application, any number of different modules can be used and run on user terminals and / or servers. The modules described are merely illustrative, and different aspects of the systems and methods may use different modules.
[0034] Flowcharts are used in this application to illustrate the operations performed by the system according to embodiments of this application. It should be understood that the preceding or following operations are not necessarily performed in exact order. Instead, various steps can be processed in reverse order or simultaneously as needed. Furthermore, other operations can be added to these processes, or one or more steps can be removed from them.
[0035] Hereinafter, exemplary embodiments according to this application will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of this application, and not all embodiments of this application. It should be understood that this application is not limited to the exemplary embodiments described herein.
[0036] To address the technical challenge of existing IoT terminal vulnerability detection technologies, which generally rely on attack samples and struggle to detect unknown attacks, this solution constructs an intelligent detection model that can be trained using only normal traffic data, eliminating reliance on attack signature databases. This solution uses an autoencoder as the generator, forming a generative adversarial network (GAN) with a discriminator. During training, through adversarial competition between the two, the autoencoder, acting as the generator, learns and masters the inherent patterns and deep characteristics of normal traffic, striving for lossless reconstruction of normal traffic. Simultaneously, the trained discriminator can keenly distinguish subtle differences between real normal traffic and the traffic reconstructed by the generator. In this technical solution, a dual-judgment mechanism is utilized: when abnormal traffic containing exploit behavior is input, not only will the generator generate a large reconstruction error due to its inability to understand the pattern (i.e., generator anomalous score), but it will also be identified as abnormal by the trained discriminator (i.e., discriminator anomalous score). Finally, by weighted summation of the anomalous scores from these two dimensions, unknown attacks deviating from normal behavior can be efficiently and accurately identified, effectively solving the fundamental shortcomings of existing technologies.
[0037] Figure 1 This is a flowchart of an AI-based IoT terminal vulnerability detection method according to an embodiment of this application. Figure 1 As shown, the IoT terminal vulnerability detection method based on artificial intelligence according to an embodiment of this application includes a model training stage and a vulnerability detection stage; wherein, the model training stage includes: S1: acquiring training data, the training data being a set of network traffic sessions labeled as normal traffic; S2: extracting traffic features from each of the network traffic sessions labeled as normal traffic to obtain a set of normal traffic feature vectors; S3: fixing the generator, and training the discriminator based on the set of normal traffic feature vectors to obtain an updated discriminator; S4: fixing the updated discriminator, and training the generator based on the set of normal traffic feature vectors to obtain an updated generator; S5: repeatedly executing steps S3 and S4 until the reconstruction error and the discrimination score meet preset conditions to obtain a trained generator and a trained discriminator. The vulnerability detection phase includes: S6: obtaining the traffic feature vector of the IoT terminal to be detected; S7: inputting the traffic feature vector to be detected into the trained generator and the trained discriminator to obtain a comprehensive anomaly score; S8: determining whether the IoT terminal to be detected has a vulnerability based on the comparison between the comprehensive anomaly score and a preset threshold.
[0038] Specifically, in steps S1 and S2, training data is acquired. This training data consists of a set of network traffic sessions labeled as normal traffic. Traffic features are extracted from each of these labeled normal traffic sessions to obtain a set of normal traffic feature vectors. It should be understood that malicious traffic samples are scarce and difficult to obtain comprehensively in the real world, while normal traffic is relatively stable and easy to collect. Therefore, the technical solution of this application employs a Generative Adversarial Network (GAN) or Autoencoder (AE) architecture for anomaly detection. The core idea is to allow the model to deeply learn patterns of normal behavior, rather than directly learning abnormal behavior. By training using only normal traffic, the dependence on a large number of diverse attack samples can be effectively avoided. That is, by acquiring network traffic sessions labeled as normal traffic, the aim is to provide the model with a clean and unbiased baseline of normal behavior. Extracting traffic features from these original sessions is to transform high-dimensional, unstructured raw network data into low-dimensional, structured numerical representations, thereby reducing the input complexity of the model, improving learning efficiency, and enabling the model to capture key information related to device behavior and communication patterns in network traffic.
[0039] More specifically, in a concrete example of this application, firstly, the data acquisition phase continuously captures raw network data packets flowing through the IoT terminal under test in the IoT terminal deployment environment through methods such as network mirroring, network splitters, or deploying lightweight agents on IoT gateways / terminals. These data packets contain all information about the terminal's communication with external networks or other internal devices. Secondly, the session reconstruction and labeling phase reconstructs the collected raw data packets into complete network traffic sessions according to the five-tuple (source IP, destination IP, source port, destination port, protocol) or application layer protocol logic. For example, all data packets belonging to the same TCP connection or UDP stream are aggregated into a single logical unit. Subsequently, these reconstructed sessions are tested in a controlled environment with known normal behavior to ensure that they are accurately labeled as normal traffic. This step is crucial to ensuring the purity of the training data.
[0040] Specifically, in this embodiment, step S2 includes: first, extracting time features, packet features, and byte features from each network traffic session labeled as normal traffic. Time features: measuring session duration, average / maximum / minimum packet interval time, average / maximum / minimum session throughput (bytes / second or packets / second), etc., to reflect the temporal behavior pattern of the traffic. Packet features: statistically analyzing the total number of packets in the session, the ratio of packets in the source / destination directions, average / maximum / minimum packet size, packet distribution of different protocols (such as TCP, UDP, MQTT, CoAP, etc.), and the frequency of TCP flags (SYN, ACK, FIN, RST, etc.), etc., to characterize the structure and interaction characteristics of the traffic. Byte features: analyzing the total number of bytes transmitted in the session, the average / maximum / minimum number of bytes per packet, and the statistical characteristics of the payload (such as byte entropy, reflecting data randomness or encryption level), etc., to reveal the attributes of the data content.
[0041] Then, the time features, packet features, and byte features are combined into a feature vector, which is then normalized to obtain the normal traffic feature vector. After combining the above features into a high-dimensional feature vector, normalization is performed to eliminate the impact of differences in the dimensions and numerical ranges of different features on model training. A common method is Min-Max normalization, which linearly scales all feature values to the range of [0,1], ensuring that the model does not overemphasize certain features due to excessively large values during the learning process, thereby improving the model's convergence speed and training stability. In this way, a high-quality set of normal traffic feature vectors can be obtained. This set serves as the input for training the generator and discriminator, enabling the model to accurately learn the complex and subtle network behavior patterns of IoT terminals under normal operating conditions. This deep understanding of normality is the foundation for effectively identifying any abnormal behavior that deviates from the normal pattern during the vulnerability detection phase. Even previously unseen attacks can be accurately captured due to their significant deviation from the normal baseline.
[0042] Specifically, in step S3, the generator is fixed, and the discriminator is trained based on the set of normal traffic feature vectors to obtain an updated discriminator. It should be understood that during the training process of a generative adversarial network (GAN), the generator and discriminator compete against each other and improve together. To enable the discriminator to effectively learn to distinguish between real data (normal traffic features) and generator-generated fake data (reconstructed traffic features), it needs to be specifically trained first. Fixing the generator's parameters at this stage ensures that the discriminator has a stable opponent during training, meaning the generator's ability to generate data does not change in the current iteration. In this way, the discriminator can focus on learning how to more accurately identify the differences between fake data generated by the generator at its current level and real normal data. This improves the discriminator's discrimination ability, enabling it to become a high-level discriminator and providing accurate feedback signals for subsequent generator optimization.
[0043] Figure 2 This is a flowchart of step S3 of the AI-based IoT terminal vulnerability detection method according to an embodiment of this application. Figure 2 As shown, step S3 includes: S31, extracting the first batch of normal traffic feature vectors from the set of normal traffic feature vectors; S32, inputting the first batch of normal traffic feature vectors into the discriminator to obtain the genuine product loss; S33, inputting the first batch of normal traffic feature vectors into a fixed generator to obtain the first batch of reconstructed traffic feature vectors; S34, inputting the first batch of reconstructed traffic feature vectors into the discriminator to obtain the counterfeit product loss; S35, based on the counterfeit product loss and the genuine product loss, updating the internal parameters of the discriminator through backpropagation to obtain the updated discriminator.
[0044] In other words, firstly, a first batch of normal traffic feature vectors is randomly selected or extracted in batches from a pre-prepared set of normal traffic feature vectors. This batch of data will serve as the basis for the discriminator to learn from real samples. Secondly, this first batch of real normal traffic feature vectors is input into the discriminator. The discriminator will attempt to determine whether these inputs are real and calculate a authenticity loss based on its judgment. This loss value reflects the degree to which the discriminator misclassifies real data as fake data. For example, if the discriminator output is close to 0 (indicating fake data) when it is actually real data, the loss will be very high.
[0045] Next, during the discriminator training phase, the generator's parameters are frozen and not updated. The same batch of real, normal traffic feature vectors are input into the currently fixed generator. The generator reconstructs this real data based on its current capabilities, outputting a batch of reconstructed traffic feature vectors. These reconstructed vectors can be considered forgeries in the generator's current stage. Subsequently, this batch of reconstructed traffic feature vectors is input into the discriminator. The discriminator attempts to determine whether this reconstructed data is forged and calculates a forgery loss based on its judgment. This loss value reflects the degree to which the discriminator misclassifies forged data as real data. For example, if the discriminator output is close to 1 (indicating real data) when it is actually forged data, the loss will be high. Finally, the discriminator's total loss is a combination of the real loss and the forgery loss (e.g., summation or weighted summation). Based on this total loss, the gradients of the discriminator's internal parameters (weights and biases) are calculated using backpropagation algorithms and optimizers (such as Adam, SGD, etc.), and these parameters are updated along the direction of gradient descent. Through continuous iteration and adjustment, the discriminator will gradually improve its ability to distinguish between real normal traffic and generator-reconstructed traffic, making its output approach 1 for real data and approach 0 for reconstructed data.
[0046] Specifically, in step S4, the updated discriminator is fixed, and the generator is trained based on the set of normal traffic feature vectors to obtain an updated generator. It should be understood that after the discriminator has undergone training in the previous stage, its discrimination ability has been significantly improved, enabling it to more accurately distinguish between real normal traffic and reconstructed traffic generated by the generator at its current level. To further advance the entire adversarial training process, the parameters of the discriminator need to be fixed at this point to make it more stable. Based on this, the generator is given new training objectives: on the one hand, it must improve the authenticity of its generated data so that it can deceive the more powerful discriminator into judging it as real data; on the other hand, as an autoencoder, the generator also needs to ensure that its reconstructed traffic feature vectors are as close as possible to the original normal traffic feature vectors to accurately capture the inherent patterns of normal traffic. Through feedback from the discriminator, the generator is prompted to continuously optimize its internal parameters, enabling it to generate reconstructed data highly similar to real normal traffic, thereby more accurately learning and representing the network behavior patterns of normal IoT terminals.
[0047] Figure 3 This is a flowchart of step S4 of the AI-based IoT terminal vulnerability detection method according to an embodiment of this application. Figure 3As shown, according to the embodiment of this application, the IoT terminal vulnerability detection method based on artificial intelligence includes step S4, which includes: S41, extracting a second batch of normal traffic feature vectors from the set of normal traffic feature vectors; S42, inputting the second batch of normal traffic feature vectors into the generator to obtain a second batch of reconstructed traffic feature vectors; S43, inputting the second batch of reconstructed traffic feature vectors into the update discriminator to obtain adversarial loss; S44, calculating the reconstruction loss between the second batch of normal traffic feature vectors and the second batch of reconstructed traffic feature vectors; and S45, updating the internal parameters of the generator based on the reconstruction loss and the adversarial loss through backpropagation to obtain the update generator.
[0048] In other words, firstly, a second batch of normal traffic feature vectors is randomly selected or extracted in batches from a pre-prepared set of normal traffic feature vectors. This batch of data will serve as input for the generator to learn and reconstruct. Secondly, this batch of normal traffic feature vectors is input into the generator. The generator (usually containing an encoder and a decoder) attempts to encode and decode this input data, thereby outputting a batch of reconstructed traffic feature vectors. These reconstructed vectors are the generator's current understanding and reproduction of the input normal traffic pattern.
[0049] Next, the reconstructed traffic feature vectors output by the generator are input into the discriminator, whose parameters are now fixed. The discriminator, based on its discriminative ability, judges these reconstructed data and outputs a score representing the probability that it considers the data to be genuine. The goal of generator training is to make the discriminator consider these reconstructed data to be genuine; therefore, the discriminator's output score is used to calculate the adversarial loss. The adversarial loss measures the generator's ability to deceive the discriminator; the generator aims to minimize the probability that the discriminator identifies its reconstructed data as fake. Simultaneously, in addition to the adversarial loss, the difference between the reconstructed traffic feature vectors output by the generator and the original input normal traffic feature vectors also needs to be calculated. This is typically measured by calculating the distance between the two (such as mean squared error or L1 norm), forming the reconstruction loss. The reconstruction loss ensures that while the generator strives to "deceive" the discriminator, it does not deviate from its essential task as an autoencoder to accurately reconstruct normal patterns.
[0050] Finally, the adversarial loss and reconstruction loss are weighted and combined to form the generator's total loss function. Based on this total loss, the gradients of the generator's internal parameters (weights and biases) are calculated using backpropagation algorithms and optimizers (such as Adam and SGD), and these parameters are updated along the direction of gradient descent. Through continuous iteration and adjustment, the generator will gradually improve its ability to generate high-quality reconstructed data, enabling it to both pass the discriminator's identification and faithfully reflect the characteristics of the original normal traffic.
[0051] Specifically, in step S42, the second batch of normal traffic feature vectors is input into the generator to obtain the second batch of reconstructed traffic feature vectors. It should be understood that during the model training phase, once the discriminator's discrimination ability is improved and fixed, the focus of training shifts to the generator. Inputting the second batch of normal traffic feature vectors into the generator is the core step driving the generator's learning and optimization. That is, the generator in this scheme is designed as an autoencoder, its essential task being to learn how to efficiently encode and decode input data, thereby achieving accurate reconstruction of the original data. By using real normal traffic feature vectors as input, the encoder part of the generator attempts to extract the implicit codes that best represent its pattern, while the decoder uses these implicit codes to attempt to reconstruct the original traffic feature vectors. This enables the generator to deeply understand and master the inherent distribution patterns and complex patterns of normal IoT terminal network traffic, allowing it to reconstruct these normal behaviors with high fidelity. Simultaneously, generating these reconstructed traffic feature vectors also allows the generator to submit these forged normal data to the updated and fixed discriminator for evaluation during adversarial training. The generator aims to make its reconstructed data appear genuine to the discriminator, thereby obtaining adversarial loss feedback from the discriminator and adjusting its parameters accordingly to enhance its deception capabilities. Through this process, the generator obtains a second batch of reconstructed traffic feature vectors. These second batch of reconstructed traffic feature vectors not only directly reflect the generator's current understanding of normal traffic patterns but also serve as a necessary intermediate product for calculating the key losses (including reconstruction loss and adversarial loss) required for generator optimization. Repeatedly executing this step, combined with loss calculation and backpropagation, allows the generator to continuously improve its modeling accuracy and reconstruction quality of normal traffic, ultimately enabling it to accurately capture subtle features of normal behavior and providing a solid foundation for identifying abnormal traffic in subsequent detection phases.
[0052] Figure 4 This is a flowchart illustrating how the second batch of normal traffic feature vectors is input into the generator to obtain the second batch of reconstructed traffic feature vectors, according to an embodiment of the AI-based IoT terminal vulnerability detection method of this application. Figure 4 As shown, according to the embodiment of the IoT terminal vulnerability detection method based on artificial intelligence in this application, step S42 includes: S421, inputting the normal traffic feature vector into the encoder of the generator to obtain the normal traffic pattern feature implicit encoding vector; S422, performing pattern feature sparsification on the normal traffic pattern feature implicit encoding vector to obtain the sparse normal traffic pattern feature implicit encoding vector; S423, inputting the sparse normal traffic pattern feature implicit encoding vector into the decoder of the generator to obtain the reconstructed traffic feature vector.
[0053] Specifically, in step S421, the normal traffic feature vector is input into the encoder of the generator to obtain the normal traffic pattern feature latent encoding vector. It should be understood that although the original normal traffic feature vector has undergone preliminary feature engineering, its dimensionality may still be high, and it may contain some redundant information or noise. Directly performing pattern learning in such a high-dimensional space is not only computationally inefficient, but may also make it difficult to capture the most essential and discriminative features of the data. The generator, as an autoencoder, compresses the high-dimensional input into a low-dimensional latent space through the encoder, forcing the model to learn the core representation of the data. This prompts the encoder to automatically extract the inherent, low-dimensional, and most representative normal traffic pattern features from the complex normal traffic features, forming a compact and semantically rich latent encoding vector. This normal traffic pattern feature latent encoding vector is not only an efficient compression of the original data, but also an abstract representation of the essential laws of normal traffic behavior. It filters out noise and redundant information in the original data, retaining the core information crucial to the normal pattern. In this way, the model can more effectively capture the deep patterns of IoT terminals in normal communication and behavior, rather than just staying at the surface statistical characteristics.
[0054] More specifically, in a concrete example of this application, the encoder is a multi-layer neural network structure designed to progressively map high-dimensional input data to a low-dimensional space. In practice, it receives a preprocessed and normalized normal flow feature vector as its input layer. Subsequently, the data flows through a series of hidden layers, typically composed of fully connected layers, each containing a certain number of neurons and a non-linear activation function (such as ReLU). As the data passes through these hidden layers, its dimensionality gradually decreases, and the network learns to extract abstract and high-level representations from the input features. Finally, the encoder's output layer produces a fixed-dimensional vector, namely the normal flow pattern feature latent encoding vector. This vector is a compact and information-rich representation of the original high-dimensional features in a low-dimensional space. The encoder parameters are not learned independently but are indirectly optimized as part of the overall autoencoder training process by minimizing the reconstruction loss (i.e., the difference between the decoder output and the original input), thereby ensuring that the generated latent encoding can effectively support the accurate reconstruction of the original data. Through the encoder's processing, the normal flow pattern feature latent encoding vector is obtained. This vector is a refined representation of the original normal flow feature vector in a low-dimensional space, carrying the core pattern information of normal flow. This compact and semantically rich encoding lays the foundation for accurate reconstruction by the decoder in the subsequent generator, and also enables the model to learn and identify subtle changes in normal traffic more efficiently. During the detection phase, any anomalous behavior that deviates from these normal patterns will show significant differences in the latent space, leading to difficulties in reconstruction or anomaly detection, thus enabling effective identification and achieving sensitive detection of unknown vulnerabilities.
[0055] Specifically, in step S422, the normal traffic pattern feature latent encoding vector is subjected to pattern feature sparsification to obtain a sparse normal traffic pattern feature latent encoding vector. It should be understood that although the normal traffic pattern feature latent encoding vector initially generated by the encoder has achieved dimensionality reduction and abstraction of the original high-dimensional traffic features, it is still not the optimal or purest representation. To achieve the highest sensitivity and accuracy in subsequent vulnerability detection, the model needs an extreme, non-redundant representation of the normal pattern. Therefore, in the technical solution of this application, the normal traffic pattern feature latent encoding vector is further subjected to pattern feature sparsification processing. Through a dynamic and adaptive refinement process, the initial normal traffic pattern feature latent encoding vector is further optimized to remove potential noise and information redundancy until it reaches a stable representation state with the highest information density. This process is not a simple feature selection or traditional sparsification, but aims to dynamically find the optimal representation fixed point for each normal traffic sample.
[0056] Specifically, the initial normal traffic pattern feature latent encoding vector is fed into a core feature refinement module. This module, through a series of learnable transformations, produces a theoretically higher-quality sparse normal traffic pattern feature latent encoding vector. The key to this process lies in its loop control logic: after each refinement, the network immediately calculates the redundancy of the newly generated refined features of the normal traffic pattern relative to the previous state's normal traffic pattern feature distribution. This redundancy serves as a feedback signal. If its value is low, it means that the features are still undergoing meaningful changes, and the refinement process continues, using the new normal traffic pattern feature latent encoding vector as the input for the next round. Conversely, if the redundancy is high, it indicates that the feature representation has stabilized, and subsequent refinement can no longer provide substantial improvement. At this point, the loop automatically terminates, and the last generated, converged refined feature vector is set as the final sparse normal traffic pattern feature latent encoding vector. This sparse normal traffic pattern feature latent encoding vector is not only more efficient and pure in an information-theoretic sense but also provides the highest quality input for the subsequent decoder's accurate reconstruction. This allows the model to minimize the reconstruction error of normal traffic, thereby greatly amplifying the difference between abnormal traffic (because it cannot be effectively refined and reconstructed) and normal traffic, and improving the detection performance and robustness of the entire vulnerability detection system.
[0057] More specifically, in this embodiment of the application, the normal traffic pattern feature latent coding vector is subjected to pattern feature sparsification to obtain a sparse normal traffic pattern feature latent coding vector, including: performing feature optimization characterization on the normal traffic pattern feature latent coding vector to obtain a refined feature vector of normal traffic pattern latent coding; calculating the feature distribution redundancy of the refined feature vector of normal traffic pattern latent coding relative to the normal traffic pattern feature latent coding vector; and, in response to the feature distribution redundancy satisfying a preset condition, setting the refined feature vector of normal traffic pattern latent coding as the sparse normal traffic pattern feature latent coding vector.
[0058] That is, the latent coding vector of the normal traffic pattern is refined to obtain a sparse latent coding vector of the normal traffic pattern. The steps are as follows: First, the latent coding vector of the normal traffic pattern is optimized to obtain a refined feature vector of the latent coding of the normal traffic pattern, which is expressed by the following formula:
[0059] y = g(Wx + b)
[0060] g(z) = ReLU(z) + α·Dropout(z)
[0061] Where x is the latent encoding vector of normal traffic pattern features, W is the learnable weight matrix, b is the learnable bias vector, α is the random perturbation coefficient, Dropout introduces random noise to improve robustness, ReLU is the ReLU activation function, g(z) is the feature refinement function, and y is the refined feature vector of the latent encoding of normal traffic pattern.
[0062] It is understandable that although the encoder has compressed the original implicit encoding vectors of normal traffic patterns into implicit codes, these codes still contain subtle noise or redundant information and have not yet achieved the purest and most essential abstraction of normal patterns. To ensure that the model can learn the essence of normal behavior to the fullest extent and, based on this, exhibit high sensitivity to any abnormal behavior, it is necessary to further refine these preliminary implicit encoding vectors of normal traffic patterns. By performing feature optimization on the implicit encoding vectors of normal traffic patterns, the aim is to delve deeper into the patterns within the normal traffic pattern features, effectively eliminate potential noise interference, and enhance its ability to distinguish between normal and abnormal behavior. Through this optimization, the model can obtain a refined feature vector of normal traffic pattern implicit codes with higher information density and better quality. This refined vector represents a purer and more robust understanding of the normal behavior patterns of IoT terminals, laying the foundation for subsequent iterative refinement processes and ultimately enabling the generator to reconstruct normal traffic with extremely high accuracy, thereby more clearly identifying any vulnerability behaviors that deviate from the normal baseline during the detection phase.
[0063] Then, the feature distribution redundancy of the refined feature vector of the normal traffic pattern latent coding relative to the feature latent coding vector of the normal traffic pattern is calculated, expressed by the following formula:
[0064]
[0065] Where I(x; y) represents the mutual information between the latent encoding vector of the normal traffic pattern features and the refined feature vector of the latent encoding of the normal traffic pattern, and H(x) represents the information entropy of the latent encoding vector of the normal traffic pattern features. To ensure information reliability in normal traffic mode, For the redundancy compression ratio of the normal traffic mode, KL(·‖·) is the KL divergence. The refined feature vector of the invisible coding of the normal traffic mode is divided into k sub-vectors {y1,...,y k}, K L (p(y i ||x)||p(y i )) indicates calculating each group of y i The conditional distribution p(y) i ||x) and marginal distribution p(y) i The KL divergence between y and x is given by λ, where λ is the weight of the control redundancy term, and R(y,x) represents the feature distribution redundancy.
[0066] It should be understood that feature refinement is not a linear process with a fixed number of iterations, but rather requires dynamic adjustment based on the complexity of the features and the current level of refinement. After one feature optimization representation, it's impossible to directly determine whether the initial normal traffic pattern feature latent encoding vector generated by the encoder is sufficient or whether it has brought substantial information gain. To avoid unnecessary computational overhead and ensure that features are refined to their optimal state, a quantitative metric is needed to evaluate the effectiveness of each refinement operation. Therefore, by calculating the feature distribution redundancy of the refined feature vector relative to the latent encoding vector of the normal traffic pattern, the information gain or representational change of the normal traffic pattern features brought about by a single feature refinement operation is quantified. A feature distribution redundancy is obtained by comparing the differences or similarities in the distribution of the normal traffic pattern features before and after refinement. This feature distribution redundancy metric accurately reflects whether the current refinement step has effectively removed redundant information in the normal traffic pattern features, enhanced key normal traffic patterns, or whether the feature representation has stabilized and reached a fixed point. As a key feedback signal in the iterative refinement process, it guides the network on whether to proceed to the next round of refinement.
[0067] Finally, in response to the feature distribution redundancy meeting a preset condition, the refined feature vector of the normal traffic pattern implicit coding is set as the sparse normal traffic pattern feature implicit coding vector, including: in response to the distance between the feature distribution redundancy and the target redundancy meeting a preset tolerance, the refined feature vector of the normal traffic pattern implicit coding is set as the sparse normal traffic pattern feature implicit coding vector, expressed by the following formula:
[0068] |R(y,x)-η|≤∈
[0069] Where η is the target redundancy, ∈ is the tolerance, and |·| is the absolute value;
[0070] If the conditions are met, the output y is the sparse normal traffic pattern feature latent encoding vector; otherwise, y is used as a new normal traffic pattern latent encoding feature and refined iteratively.
[0071] It should be understood that the feature refinement process is not an infinite loop, but requires an intelligent termination mechanism. After each refinement iteration, the feature distribution redundancy of the newly generated normal traffic pattern implicit encoding refined feature vector relative to its previous state is calculated. This redundancy quantifies the information gain or representational change of the normal traffic pattern brought about by a single refinement operation. When this redundancy reaches a preset condition, it means that the normal traffic pattern feature representation has tended to a representational fixed point or representational equilibrium, that is, subsequent refinement operations can no longer bring substantial information gain or significant representational optimization. Continuing refinement would be a waste of computational resources and may introduce unnecessary noise. Therefore, it is crucial to accurately determine when to stop feature refinement, thereby finding the optimal balance between computational efficiency and the purity of the final normal traffic pattern feature representation. Specifically, by setting a target redundancy and a preset tolerance, the model can determine whether the redundancy achieved by the current normal traffic pattern refinement is sufficiently close to the desired ideal state representing the full convergence of the normal traffic pattern features. When the distance between the two meets the preset tolerance, it is considered that the normal traffic pattern features have reached the optimal sparsity and refinement level. This yields the final, purest, and most compact representation of normal IoT terminal traffic patterns: a sparse normal traffic pattern feature latent encoding vector. This vector, after multiple rounds of adaptive refinement, has been proven to be beyond significant optimization. It removes redundant information and noise to the maximum extent, preserving the most essential features of normal behavior patterns. This highly refined normal pattern representation enables the model to identify any abnormal behavior deviating from this baseline with extremely high sensitivity and accuracy in the subsequent vulnerability detection stage. Even minute, unprecedented attack patterns will produce significant reconstruction errors because they cannot be accurately reconstructed into this extremely sparse normal pattern by the generator, thus being effectively captured, improving the practicality and generalization ability of IoT terminal vulnerability detection.
[0072] Specifically, in step S423, the sparse normal traffic pattern feature latent encoding vector is input into the decoder of the generator to obtain the reconstructed traffic feature vector. It should be understood that the original normal traffic pattern feature latent encoding vector has been compressed and refined into a low-dimensional, pure, and highly information-dense sparse normal traffic pattern feature latent encoding vector. This vector is an essential abstraction of the normal traffic pattern, but it is not a direct representation of the original traffic features. In order to remap this abstract pattern back to the original traffic feature space for comparison with the original input (calculating reconstruction loss) or submission to the discriminator for evaluation (calculating adversarial loss), in the technical solution of this application, the sparse normal traffic pattern feature latent encoding vector is further input into the decoder of the generator. The decoder reversely and as losslessly as possible, restores this highly abstract, low-dimensional normal pattern representation to a high-dimensional traffic feature vector. This process aims to verify whether the generator (autoencoder) has truly learned the inherent distribution and generation mechanism of normal traffic, that is, whether it can accurately generate data highly similar to real normal traffic from the normal essence it extracts.
[0073] Specifically, the decoder is a multi-layer neural network structure designed to progressively map low-dimensional input data back to a high-dimensional space. In a specific example of this application, a refined sparse normal traffic pattern feature latent encoding vector is first received as the input layer. Subsequently, the data flows through a series of hidden layers, typically composed of fully connected layers, with the number of neurons in each layer gradually increasing to progressively expand the dimensionality of the data. Non-linear activation functions (such as ReLU) are typically used in these layers to introduce the model's expressive power. Finally, the decoder's output layer produces a vector with the same dimension as the original normal traffic feature vector, i.e., the reconstructed traffic feature vector. The decoder parameters, along with the encoder parameters, are optimized through backpropagation throughout the generator training process. The goal is to minimize the reconstruction loss (i.e., the difference between the reconstructed traffic feature vector and the original normal traffic feature vector) and the adversarial loss, thereby ensuring that the decoder can complete the reconstruction task efficiently and accurately. Through the decoder's processing, the reconstructed traffic feature vector is obtained. If the generator is trained properly, this reconstructed traffic feature vector will be highly similar to the original input normal traffic feature vector. This high similarity indicates that the generator has successfully learned and mastered the complex patterns of normal IoT terminal network traffic. During the vulnerability detection phase, when the traffic to be detected (whether normal or abnormal) passes through this trained generator, if it is normal traffic, the generator will be able to accurately reconstruct it, resulting in a low reconstruction error. However, if the traffic to be detected is abnormal (e.g., caused by vulnerability exploitation), because its pattern deviates from the normal distribution learned by the generator, the generator will struggle to accurately reconstruct it, resulting in a significant reconstruction error. This difference in reconstruction error is the key basis for this solution to identify unknown vulnerabilities, demonstrating the core value of the generator in anomaly detection.
[0074] Specifically, in step S5, steps S3 and S4 are executed iteratively until the reconstruction error and discrimination score meet preset conditions to obtain a trained generator and a trained discriminator. That is, the generator and discriminator play competing and mutually reinforcing roles in the adversarial training framework. The discriminator needs to learn how to accurately distinguish between real normal traffic and reconstructed traffic generated by the generator, while the generator needs to learn how to generate reconstructed traffic sufficient to deceive the discriminator, while ensuring that its reconstructed traffic is as close as possible to the original normal traffic. This dynamic, mutually reinforcing adversarial relationship allows both to promote each other and continuously improve their performance. If only trained once, the discriminator or generator may not achieve sufficient discrimination or generation capabilities, causing the model to fail to effectively capture the complex distribution of normal traffic. Therefore, through iterative iteration, the discriminator continuously improves its discrimination capabilities, forcing the generator to continuously optimize its reconstruction capabilities and the authenticity of the generated data; conversely, the improvement of the generator's capabilities provides the discriminator with more challenging forgeries, prompting it to further improve its discrimination accuracy. Through this continuous adversarial game, a highly trained generator and discriminator are ultimately obtained. Specifically, a well-trained generator will be able to learn and characterize the inherent distribution and patterns of normal IoT terminal network traffic with extremely high accuracy. This means it can reconstruct any normal traffic data with high quality and produce very low reconstruction errors. Simultaneously, a well-trained discriminator will possess strong discrimination capabilities, accurately distinguishing between genuine normal traffic and any abnormal traffic deviating from normal patterns (including reconstructed traffic generated by the generator), and providing corresponding discrimination scores. The preset reconstruction error and discrimination score conditions are the standards for measuring whether this training effect has achieved the expected goals, ensuring that the model achieves sufficient accuracy and robustness in learning normal patterns.
[0075] Specifically, after obtaining the trained generator and the trained discriminator, these generator and discriminator are used in the vulnerability detection phase.
[0076] Specifically, in step S6, the target traffic feature vector of the IoT terminal to be detected is obtained. It should be understood that the primary prerequisite for any security detection is obtaining the data to be analyzed. In the IoT terminal vulnerability detection scenario, this means capturing the network communication behavior of the target terminal in real-time or near real-time to obtain the target traffic feature vector of the IoT terminal to be detected, providing raw input data for subsequent anomaly analysis and ensuring that the model can evaluate the actual operating state of the current terminal. The system obtains a preprocessed and normalized target traffic feature vector consistent with the training data format. These vectors contain information in dimensions such as time, data packets, and bytes, preparing them for model input. The implementation method is similar to that of the training phase S2, typically involving network traffic mirroring, session reconstruction, and feature extraction and normalization processing to ensure consistency between the target data and the training data in the feature space.
[0077] Specifically, in step S7, the feature vector of the traffic to be detected is input into the trained generator and the trained discriminator to obtain a comprehensive anomaly score. It should be understood that the trained generator and discriminator have deeply learned the complex patterns of normal IoT terminal traffic. Any traffic deviating from this normal pattern, whether due to vulnerability exploitation or other abnormal behavior, will exhibit anomalous signals in these two components. By quantifying the degree of deviation from the normal pattern through the generator and discriminator's response to the input traffic, a comprehensive anomaly score reflecting the potential vulnerability risk is obtained. A single, continuous value is calculated for each feature vector of the traffic to be detected; the higher the value, the more abnormal the traffic and the greater the risk of a vulnerability.
[0078] More specifically, in the embodiments of this application, step S7 includes: inputting the traffic feature vector to be detected into the trained generator to obtain a generator anomaly score; inputting the traffic feature vector to be detected into the trained discriminator to obtain a discriminator anomaly score; and calculating a weighted sum between the generator anomaly score and the discriminator anomaly score to obtain the comprehensive anomaly score.
[0079] In other words, firstly, the feature vector of the traffic to be detected is input into the trained generator, which (as an autoencoder) is trained to accurately reconstruct normal traffic. If the input traffic to be detected is normal, the generator can reconstruct it with very low error; conversely, if the traffic is abnormal, the generator will struggle to reconstruct it accurately, resulting in significant reconstruction errors. The degree to which the feature vector of the traffic to be detected deviates from the normal pattern learned by the generator is measured by calculating the difference (e.g., mean squared error or L1 norm) between the feature vector of the traffic to be detected and the generator's reconstruction output. This difference value is the generator's anomaly score, which intuitively reflects the abnormality of the input traffic. Secondly, the feature vector of the traffic to be detected is input into the trained discriminator to obtain the discriminator's anomaly score. The discriminator is trained to distinguish between real normal traffic and (or any) abnormal traffic generated by the generator. If the input traffic to be detected is abnormal, the discriminator can identify it as abnormal or fake data with high confidence. By directly classifying the input traffic using the discriminator, an assessment of the normality of the traffic is obtained. The discriminator typically outputs a probability value between 0 and 1, representing the likelihood that it considers the input to be genuine, normal traffic. The discriminator's anomaly score can be derived from this probability value; for example, subtracting this probability value from 1 results in a higher score for anomalous traffic. Finally, a weighted sum of the generator's and discriminator's anomaly scores is calculated to obtain the comprehensive anomaly score. The generator and discriminator capture anomalies from different perspectives: the generator focuses on reconstruction capabilities, while the discriminator focuses on direct classification. Weighting and combining the anomaly scores from both mechanisms leverages their respective strengths, providing a more comprehensive and robust anomaly assessment. By fusing evidence from the generator and discriminator, a unified and more discriminative anomaly index is formed, resulting in a final comprehensive anomaly score that more accurately reflects the degree of anomaly in the detected traffic, reducing the risk of misjudgment that might arise from a single index. The implementation uses a simple linear weighted summation model: Comprehensive Anomaly Score = w1 × Generator Anomaly Score + w2 × Discriminator Anomaly Score, where w1 and w2 are predefined trainable weights.
[0080] Specifically, in step S8, based on the comparison between the comprehensive anomaly score and a preset threshold, it is determined whether the IoT terminal to be detected has a vulnerability. It should be understood that the comprehensive anomaly score obtained in the previous stage is a continuous numerical value that quantifies the degree to which the traffic being detected deviates from the normal pattern. However, in actual IoT security operation and maintenance scenarios, a clear binary judgment is needed: whether the terminal has a vulnerability. A continuous anomaly score alone cannot directly trigger a security response or provide a clear risk indication. Therefore, a mechanism is needed to transform this quantified degree of anomaly into an actionable decision. Based on the model's quantitative assessment of the degree of traffic anomaly, a final judgment is made regarding the security status of the IoT terminal, thereby providing clear guidance to security administrators or triggering an automated security response mechanism.
[0081] Specifically, the system compares the comprehensive anomaly score calculated from the traffic to be detected with a pre-set threshold. If the comprehensive anomaly score exceeds this threshold, the IoT terminal under test is deemed to have a vulnerability; conversely, if the comprehensive anomaly score is lower than or equal to the threshold, the terminal's current behavior is considered normal, and no detectable vulnerability exists. The determination of this pre-set threshold is crucial; it is not arbitrarily set but determined during the model training and validation phases through in-depth analysis of the anomaly score distribution of a large amount of normal traffic and known vulnerability traffic. Typically, this threshold is optimized by evaluating the false positive rate (misclassifying normal traffic as anomaly) and the false negative rate (failing to detect actual vulnerabilities) at different thresholds to find an optimal balance between the two that meets the security requirements of the actual application scenario. For example, in critical IoT infrastructures with extremely high security requirements, a relatively low threshold might be chosen to reduce the false negative rate, even if this may lead to some false positives; while in scenarios with higher system stability requirements, a higher threshold might be chosen to reduce false positives, thereby avoiding unnecessary interference. Once a vulnerability is identified, the system can immediately trigger a series of pre-defined security responses, such as sending alerts to the security operations center, isolating affected terminals, logging abnormal events, or initiating further forensic analysis. This explicit judgment mechanism greatly improves the efficiency and response speed of IoT terminal vulnerability detection, enabling security teams to quickly identify and address potential threats, thereby effectively protecting the security of IoT devices and networks and avoiding serious consequences such as data breaches, service interruptions, or loss of system control due to vulnerability exploitation.
[0082] In summary, the AI-based IoT terminal vulnerability detection method according to the embodiments of this application is explained. It uses an autoencoder as a generator and combines it with a discriminator to form a generative adversarial network (GAN) framework. Through adversarial training, the model is forced to deeply learn and accurately grasp the inherent distribution patterns and essential characteristics of normal network traffic. Therefore, during the detection phase, when abnormal traffic containing vulnerability exploitation behavior is input, because its pattern deviates from the learned normal paradigm, the trained generator will be unable to effectively reconstruct the traffic, resulting in significant reconstruction errors. Simultaneously, the discriminator can also keenly identify the difference between it and the normal pattern. Ultimately, by comprehensively considering the reconstruction performance of the generator and the discrimination results of the discriminator, it is possible to achieve sensitive and accurate detection of unknown vulnerabilities without relying on any prior attack knowledge, effectively overcoming the limitations of existing technologies.
[0083] As described above, the data collaboration management platform according to the embodiments of this application can be implemented in various wireless terminals, such as servers with AI-based IoT terminal vulnerability detection algorithms. In one possible implementation, the data collaboration management platform according to the embodiments of this application can be integrated into the wireless terminal as a software module and / or hardware module. For example, the data collaboration management platform can be a software module in the operating system of the wireless terminal, or it can be an application developed for the wireless terminal; of course, the data collaboration management platform can also be one of many hardware modules of the wireless terminal.
[0084] The various embodiments of this disclosure have been described above. These descriptions are exemplary and not exhaustive, nor are they limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terminology used herein is chosen to best explain the principles, practical application, or improvement of the technology in the market, or to enable others skilled in the art to understand the embodiments disclosed herein.
Claims
1. A method for detecting vulnerabilities in IoT terminals based on artificial intelligence, characterized in that, include: Model training phase and vulnerability detection phase; The model training phase includes: S1: Obtain training data, which is a set of network traffic sessions labeled as normal traffic; S2: Extract traffic features from each network traffic session labeled as normal traffic to obtain a set of normal traffic feature vectors; S3: Fixed generator, the discriminator is trained based on the set of normal traffic feature vectors to obtain an updated discriminator; S4: Fix the update discriminator, and train the generator based on the set of normal traffic feature vectors to obtain the update generator; S5: Repeat steps S3 and S4 until the reconstruction error and discrimination score meet the preset conditions to obtain the trained generator and the trained discriminator; The vulnerability detection phase includes: S6: Obtain the traffic feature vector of the IoT terminal to be detected; S7: Input the feature vector of the traffic to be detected into the trained generator and the trained discriminator to obtain a comprehensive anomaly score; S8: Based on the comparison between the comprehensive anomaly score and the preset threshold, determine whether the IoT terminal to be detected has vulnerabilities.
2. The IoT terminal vulnerability detection method based on artificial intelligence according to claim 1, characterized in that, include: The generator is an autoencoder, which includes an encoder and a decoder.
3. The IoT terminal vulnerability detection method based on artificial intelligence according to claim 2, characterized in that, Step S2 includes: Extract time features, packet features, and byte features from each network traffic session labeled as normal traffic; After combining time features, data packet features, and byte features into a feature vector, normalization is performed to obtain the normal traffic feature vector.
4. The IoT terminal vulnerability detection method based on artificial intelligence according to claim 2, characterized in that, Step S3 includes: The first batch of normal flow feature vectors is extracted from the set of normal flow feature vectors; The first batch of normal flow feature vectors are input into the discriminator to obtain the genuine product loss; The first batch of normal traffic feature vectors are input into a fixed generator to obtain the first batch of reconstructed traffic feature vectors; The first batch of reconstructed traffic feature vectors are input into the discriminator to obtain the counterfeit loss; Based on the losses from counterfeit goods and genuine goods, the internal parameters of the discriminator are updated through backpropagation to obtain the updated discriminator.
5. The IoT terminal vulnerability detection method based on artificial intelligence according to claim 2, characterized in that, Step S4 includes: Take a second batch of normal flow feature vectors from the set of normal flow feature vectors; The second batch of normal traffic feature vectors are input into the generator to obtain the second batch of reconstructed traffic feature vectors. The second batch of reconstructed traffic feature vectors are input into the update discriminator to obtain adversarial loss; Calculate the reconstruction loss between the second batch of normal traffic feature vectors and the second batch of reconstructed traffic feature vectors; Based on the reconstruction loss and the adversarial loss, the internal parameters of the generator are updated through backpropagation to obtain the updated generator.
6. The IoT terminal vulnerability detection method based on artificial intelligence according to claim 5, characterized in that, The second batch of normal traffic feature vectors is input into the generator to obtain the second batch of reconstructed traffic feature vectors, including: The normal traffic feature vector is input into the encoder of the generator to obtain the hidden encoded vector of normal traffic pattern features; The normal traffic pattern feature latent encoding vector is subjected to pattern feature sparsification to obtain a sparse normal traffic pattern feature latent encoding vector; The sparse normal traffic pattern feature latent encoding vector is input into the decoder of the generator to obtain the reconstructed traffic feature vector.
7. The IoT terminal vulnerability detection method based on artificial intelligence according to claim 6, characterized in that, Performing pattern feature sparsification on the normal traffic pattern feature latent encoding vector to obtain a sparse normal traffic pattern feature latent encoding vector includes: The feature optimization representation of the implicit coding vector of the normal traffic pattern is performed to obtain the refined feature vector of the implicit coding of the normal traffic pattern; Calculate the feature distribution redundancy of the refined feature vector of the normal traffic pattern implicit coding relative to the feature implicit coding vector of the normal traffic pattern; In response to the feature distribution redundancy meeting the preset condition, the refined feature vector of the normal traffic pattern implicit coding is set as the sparse normal traffic pattern feature implicit coding vector.
8. The IoT terminal vulnerability detection method based on artificial intelligence according to claim 7, characterized in that, In response to the feature distribution redundancy meeting a preset condition, the refined feature vector of the normal traffic pattern implicit coding is set as the sparse normal traffic pattern feature implicit coding vector, including: in response to the distance between the feature distribution redundancy and the target redundancy meeting a preset tolerance, the refined feature vector of the normal traffic pattern implicit coding is set as the sparse normal traffic pattern feature implicit coding vector.
9. The IoT terminal vulnerability detection method based on artificial intelligence according to claim 1, characterized in that, Step S7 includes: The feature vector of the traffic to be detected is input into the trained generator to obtain the generator anomaly score; The feature vector of the traffic to be detected is input into the trained discriminator to obtain the discriminator anomaly score; The weighted sum between the generator anomaly score and the discriminator anomaly score is calculated to obtain the comprehensive anomaly score.
Citation Information
Cited By
Intelligent explanation method for inspection result of mart based on AI algorithm
CN120600198A