Sub-graph reasoning method fusing logic rule learning and attack semantic enhancement

By combining the SecGIRF model with logical rule learning and attack semantic enhancement, the problem of insufficient inductive ability and neglect of semantic characteristics in subgraph reasoning methods in the field of network security is solved, and the reasoning ability and accuracy for complex attack scenarios are improved.

CN120975216AActive Publication Date: 2025-11-18CHENGDU UNIV OF INFORMATION TECH

Patent Information

Application Number
CN202511493846.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-20
Publication Date
2025-11-18
Estimated Expiration
2045-10-20

AI Technical Summary

Technical Problem

Existing subgraph reasoning methods in the field of cybersecurity have failed to effectively incorporate the logical rules and paths in the attack chain, resulting in insufficient inductive ability and neglecting the semantic characteristics of attack behavior, which affects the accuracy of reasoning.

Method used

We construct a SecGIRF model, combining logical rule learning and attack semantic enhancement. We model multi-hop paths using Horn rules, introduce an information entropy negative sampling strategy, and employ a path-weighted multi-head attention mechanism and a semantic-aware encoding network to optimize triplet scoring and the training process.

Benefits of technology

It improves the model's reasoning ability for complex attack scenarios, alleviates the structural sparsity problem, enhances the modeling accuracy for heterogeneous attack paths, and achieves zero-sample generalization reasoning for new threat relationships.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120975216A_ABST
    Figure CN120975216A_ABST
Patent Text Reader

Abstract

The invention discloses a sub-graph reasoning method fusing logic rule learning and attack semantic enhancement. The method comprises the steps that an input layer dynamically integrates knowledge graph topology and an AMIE rule base, an initial k-hop sub-graph is generated, and structured input is provided for attack chain mining; the sub-graph extraction module is used for executing double confidence filtering, screening high-value attack chains and applying dictionary filtering to enhance semantic reliability; the sub-graph coding module adopts an entity perception update layer and a relationship aggregation evolution layer of a dual-channel mechanism to collaboratively model the spatial-temporal characteristics of an attack chain; the relation reasoning optimization module is used for dynamically injecting high confidence rules and optimizing triple scores; and the training optimization module is used for implementing task perception negative sampling. According to the subgraph reasoning method fusing logic rule learning and attack semantic enhancement, based on inductive reasoning and semantic perception modeling, by taking subgraph modeling guided by a logic path as a core, attack chain rules with high confidence in a training graph are mined, and the understanding ability of a model structure is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a subgraph reasoning method that integrates logical rule learning and attack semantic enhancement. Background Technology

[0002] In the field of cybersecurity, knowledge graphs (KGs) provide fundamental support for automated reasoning in complex domains by structurally modeling entities and their relationships. However, due to the highly dynamic nature of cyberattacks (such as zero-day vulnerabilities and new types of malicious traffic) and the diversity of behaviors (such as DDoS, phishing, and APTs), cybersecurity knowledge graphs generally suffer from problems such as sparse structure and heterogeneous relationships. These issues make it difficult for traditional graph neural networks (GNNs) to effectively propagate graph signals on such graphs, limiting their performance in critical tasks such as link prediction.

[0003] In the face of constantly changing graph environments, subgraph reasoning methods are widely used in dynamic knowledge graph modeling due to their good inductive and scalable properties. They can make predictions based solely on query-related local structures without requiring global model updates, thus overcoming the cost problem caused by frequent updates in traditional inductive methods (such as TransE and RotatE).

[0004] However, existing subgraph reasoning methods still have significant limitations in the application of cybersecurity: on the one hand, they do not introduce logical rules and paths in the attack chain to guide subgraph construction, resulting in insufficient inductive ability; on the other hand, they ignore the semantic characteristics of attack behavior, making it difficult for the model to focus on the critical path and affecting the accuracy of reasoning. Summary of the Invention

[0005] The purpose of this invention is to provide a subgraph reasoning method that integrates logical rule learning and attack semantic enhancement. By constructing a security-aware Graph Inductive Reasoning Framework (SecGIRF), it innovatively combines domain knowledge-driven inductive reasoning with semantic-aware modeling. With logical path-guided subgraph modeling as its core, it mines high-confidence attack chain rules in the training graph, improving the model's structural understanding ability. Simultaneously, it introduces an attack type priority-driven information entropy negative sampling strategy to enhance the correlation between the training graph and attack semantics, thereby alleviating the sparsity problem. In terms of model design, the SecGIRF model combines a path-weighted multi-head attention mechanism with a semantic-aware encoding network to further strengthen the modeling ability and semantic expression of key attack chains.

[0006] To achieve the above objectives, this invention provides a subgraph reasoning method that integrates logical rule learning and attack semantic enhancement. The SecGIRF model consists of five modules: an input layer, a subgraph extraction module, a subgraph encoding module, a relation reasoning optimization module, and a training optimization module. The input layer dynamically integrates the knowledge graph topology and the AMIE rule base to generate an initial k-hop subgraph, providing structured input for attack chain mining. The subgraph extraction module performs double reset letter filtering to screen high-value attack chains and applies dictionary filtering to enhance semantic reliability; The subgraph encoding module adopts a dual-path mechanism. The entity perception update layer iteratively optimizes the node representation through path perception attention and target relationship perception attention. The relationship aggregation and evolution layer generates a high-order semantic representation by fusing multi-source relationships through the φ function, and collaboratively models the spatiotemporal features of the attack chain. The relational reasoning optimization module dynamically injects high-confidence rules to optimize triple scoring; The training optimization module implements task-aware negative sampling.

[0007] Preferably, in the subgraph extraction module, multi-hop paths are modeled using the Horn rule form in first-order logic (FOL), where the Horn rule is as follows: ; in, This is the first relationship in the rule body that initiates the attack chain, describing the initial actions of the attack. The second relationship in the rule body describes how, after the first step, the attacker or the exploited entity propagates the attack to the next intermediate entity; As the final step of the attack, the last item in the rule body connects the last intermediate entity and the final attack target; For target relationships; the rule body represents the relationship from the entity. To the entity The rule header represents the target relationship in the multi-hop path between them. ; In the rule generation phase, rules are generated based on the classic logical induction method AMIE through frequent relation path mining and confidence calculation; each rule is represented by a triple path pattern, as shown below: ; in, and Describe the reasoning path for the relationship; The predicates in the rule header describe the entities. Target relationship; This is the identifier for the entire rule, used to uniquely identify a logical rule; The generated rules are filtered, and the confidence threshold is retained. Frequent relationship paths.

[0008] Preferably, after selecting the confidence rules, these rules are weighted; for each path Count the number of times it appears in the positive sample. Number of occurrences in the entire sample Define attack probability As shown below: ; in, This is a smoothing factor used to mitigate statistical bias in low-frequency paths; the path is calculated based on its frequency and attack probability. weight As shown below: ; in, For path The frequency of occurrence in the training set reflects the importance of the path.

[0009] Preferably, a subgraph is constructed based on the filtered rules and calculated weights, centered around the target triplet. , with head entity Tail-end entity Extract k-hop subgraphs centered on; from and Starting from there, they expanded outwards respectively. Step 1, obtain the set of adjacent nodes of the entity. and As shown below: ; ; in, This represents the shortest path distance. This represents the number of hops extracted from the subgraph. Candidate relationship; Through the and The intersection operation of adjacency sets yields the common set of nodes. and build with and Subgraph with core As shown below: ; ; ; in, A set of nodes; Let it be the set of edges; , Let be any two nodes in the subgraph; After the subgraph is constructed, the selected rule paths are injected into the edge set to form the final subgraph, as shown below: ; ; in, The basic topological edge set; This is the set of filtered rule paths; This is the weight threshold; This is the final set of edges; This is the final weighted subgraph constructed around the target node; A weight mapping function or set of weights that applies to the entire final subgraph. .

[0010] Preferably, the SecGIRF model introduces a dual-pathway mechanism for subgraph encoding during the subgraph encoding stage, including an entity perception update layer and a relation aggregation evolution layer; The entity perception update layer updates entity representations by fusing rule-based paths and task semantics through path perception attention and target relationship perception attention; The relation aggregation and evolution layer integrates multi-hop relations through the φ function and merges the states of neighboring entities. It then outputs evolution nodes through gating to form a closed-loop collaboration.

[0011] Preferably, during initial encoding, a dual-radius node labeling DRNL strategy is adopted, which calculates the relationship between nodes and head entities. Tail-end entity The shortest path distance is used to label nodes, so that the label value of each node reflects its relative position in the subgraph, providing structural information for model learning; the node labeling formula is as follows: ; in, For nodes The double radius marker value; Let be any node in the subgraph; To further capture the higher-order semantic context of the target triples in the graph, a context graph is constructed, whose nodes include entities, relations, and connections. and Confidence rule path; After the context graph is constructed, a graph convolutional network is used to embed and update the nodes, modeling their higher-order interactions; a multidimensional interaction encoding function is introduced for any pair of context nodes. The features are combined and modeled as follows: ; in, For node pairs The interactive feature vector; , This is a vector representation of a node in the context graph; This is a vector concatenation operation; and These represent modeling differences and similarities, respectively.

[0012] Preferably, during the structural encoding process, an attention mechanism based on target relations is introduced; the attention weight of each edge in the subgraph... As shown below: ; in, , The initial feature vector; Embed vectors for the target relation; , The vector representation of the point features after linear transformation; The linear transformation vector representing the target relation features; and These are trainable parameters; for Transpose of; For activation functions; Further capture potential path dependencies in the subgraph, based on the relationship between each node and the entity. and The nodes are sorted by distance, and a node sequence is constructed. Only the selected rule path nodes are sorted according to the attack chain order. Temporal features are extracted by BiGRU to supplement the sequence information that is difficult to model explicitly in the static structure.

[0013] Preferably, in the feature fusion stage, the spliced ​​features are processed through an MLP network to fuse multi-source information, including node-initialized labeled features, relationship-aware attention embeddings, and path-level BiGRU sequence features; the feature fusion is as follows: ; in, For nodes The final feature representation; This represents the nodes in the context graph; This represents a sequence of nodes. It is a multilayer perceptron; In the design of the feedforward network after feature fusion, a three-layer expansion-contraction structure is adopted to capture the nonlinear structural features in the subgraph, as shown below: ; in, For nodes The update indicates; Represents a non-linear activation function; For nodes The set of adjacent nodes; The index for traversing all neighbors of node i; In the graph aggregation phase, a target relation-based approach is adopted. The attention mechanism, for each edge The aggregation weights are adjusted as follows: ; in, The normalized attention weights represent the neighbors. For nodes The intensity of the impact; For activation functions; For target relationship A linear mapping vector; For nodes Any neighboring node; The final node is represented as: ; in, For nodes The final aggregate representation; For neighboring nodes The representation after processing by the MLP network; It is a multilayer perceptron used for feature transformation.

[0014] Preferably, in the relational reasoning optimization module, the SecGIRF model introduces a multi-granularity semantic fusion mechanism during the reasoning phase, combining structural context, rule paths, and task semantic information to achieve model-based optimization of reasoning performance. The specific process is as follows: First, at the structural level, obtain the node representation { }, and combined with rule path embedding , to obtain fusion representation As shown below: ; Through aggregate functions The node features are summarized to construct a subgraph structure representation, as shown below: ; in, Represented as a subgraph structure; Then, at the semantic level, a context graph is introduced to model the rule path semantics and relational context of the target triples in the knowledge graph; the target entity... Candidate Relationship and its semantic interaction feature input feature combination function As shown below: ; in, Represents candidate relation; function The impact of candidate relations on semantic interaction is clearly expressed; This is a vector concatenation operation; Finally, a dual-pathway relationship scoring function is used to achieve joint structure-semantic optimization, as shown below: ; in, The final predicted score for the target triplet; This is the learnable weight matrix used for subgraph structure representation; This is a learnable weight matrix used for semantic features; and All are learnable parameters; It is a non-linear activation function used to fuse the matching strength of structural context and semantic path to the target relation; Furthermore, at the logical level, the SecGIRF model introduces a rule consistency optimization mechanism; this is applied to the confidence Horn rules automatically mined from the training set. If a path matches a rule body, then the scoring of the corresponding relationship is enhanced by the rule, as shown below: ; in, Score the relationships adjusted under logical constraints; To control the degree of influence of rule paths on inference results; Indicates whether a rule path match exists, with a value of 0 or 1. A value of 1 indicates that a match occurs if and only if the entity pairs... There exists a path that completely matches a certain rule body; a value of 0 indicates that there is no path that satisfies the matching condition. This indicates assignment; During the training phase, the multi-objective loss function is jointly optimized. This includes relation classification loss and logical consistency constraints, as shown below: ; in, Cross-entropy loss; For logical consistency loss, it is used to encourage the model to maintain consistent reasoning under the constraints of logical rules, and to encourage the model to make consistent reasoning judgments under logical rules. For weight hyperparameters.

[0015] Preferably, the training optimization module is designed around three aspects: negative sampling mechanism, loss function construction and optimization strategy. The specific implementation process is as follows: First, regarding the negative sampling strategy, the task-aware negative sampling method based on attack semantic categories enhances the relevance of negative samples in the semantic space and improves the ability to distinguish attack types by assigning different sampling weights to different attack types; whereby the sampling probability is defined as: ; in, The frequency of occurrence of attack types; For attack category label space; For the sample The attack type; The sampling probability is set; a filtering mechanism based on the head and tail entity relationship dictionary is introduced to avoid potential positive examples and improve the quality of negative samples. Then, in constructing the loss function, a multi-task joint loss function is adopted; where the main task loss is a binary cross-entropy based on negative sampling, used to supervise triplet relation classification; the auxiliary task loss is based on pseudo-labels generated by logical rule paths, which imposes consistency constraints on subgraphs that satisfy high-confidence paths; the two are combined in a weighted form to construct the overall loss function. As shown below: ; in, This represents the main task loss based on the structure score; This represents the consistency loss based on the rule path score; These are the weighting coefficients; Finally, in terms of training scheduling and parameter optimization, the AdamW optimizer is adopted, combined with a weight decay mechanism to suppress overfitting; gradient clipping and L2 regularization control are introduced to prevent gradient explosion.

[0016] Therefore, this invention employs a subgraph reasoning method that integrates logical rule learning and attack semantic enhancement, thereby improving the reasoning ability of network security knowledge graphs in complex attack scenarios. A rule path injection mechanism based on attack probability weighting is introduced to effectively alleviate the structural sparsity problem; a task-aware negative sampling strategy and a multi-head attention mechanism are designed to improve the model's accuracy in modeling heterogeneous attack paths; and a logical consistency optimization method is combined to achieve zero-sample generalization reasoning for novel threat relationships.

[0017] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description

[0018] Figure 1This is a diagram of the SecGIRF model architecture constructed by a subgraph reasoning method that integrates logical rule learning and attack semantic enhancement according to the present invention. Figure 2 This is a diagram of a dual-path spatiotemporal collaborative coding architecture; Figure 3 This is a flowchart of the subgraph (SG) and context graph (CG) processing of the present invention; Figure 4 This is a diagram showing the interpretability verification results of the rule header-rule body embedding space of this invention. Detailed Implementation

[0019] The technical solution of the present invention will be further described below with reference to the accompanying drawings and embodiments.

[0020] Example 1 like Figure 1 As shown, this invention presents a subgraph reasoning method that integrates logical rule learning and attack semantic enhancement to construct a security-aware inductive graph reasoning model—SecGIRF (Security-aware Graph Inductive Reasoning Framework), which includes five modules: input layer, subgraph extraction module, subgraph encoding module, relation reasoning optimization module, and training optimization module.

[0021] The input layer dynamically integrates the knowledge graph topology and the AMIE rule base to generate an initial k-hop subgraph, providing structured input for attack chain mining.

[0022] The subgraph extraction module performs double-reset confidence filtering (rule path confidence). And attack probability ), screen high-value attack chains and apply dictionary filtering to enhance semantic reliability.

[0023] The subgraph encoding module adopts a dual-path mechanism. The entity perception update layer iteratively optimizes the node representation through path perception attention and target relationship perception attention, while the relationship aggregation and evolution layer generates a high-order semantic representation by fusing multi-source relationships through the φ function. The two work together to model the spatiotemporal features of the attack chain.

[0024] The relational reasoning optimization module dynamically injects high-confidence rules to optimize triple scoring.

[0025] The training optimization module implements task-aware negative sampling to improve noise robustness.

[0026] The five modules form a closed-loop architecture of rule-driven → spatiotemporal coding → dynamic feedback, which improves the real-time threat identification capability.

[0027] I. Subgraph Extraction Module.

[0028] In inductive knowledge graph reasoning, local subgraphs are widely used to characterize the contextual relationships between entities. To improve the model's ability to logically model structural relationships, multi-hop paths are modeled using the Horn Rule from First-order Logic (FOL). The Horn Rule is as follows: ; in, This is the first relationship in the rule body that initiates the attack chain, describing the initial actions of the attack. The second relationship in the rule body describes how, after the first step, the attacker or the exploited entity propagates the attack to the next intermediate entity; This is the final step in the attack, the last item in the rule body, connecting the last intermediate entity and the final attack target; For target relationships; the rule body represents the relationship from the entity. To the entity The rule header represents the target relationship in the multi-hop path between them. .

[0029] This structure can be transformed into a relational path consisting only of relation sequences in a knowledge graph, exhibiting good interpretability and generalization ability. Compared to directly embedding and modeling entity pairs, the relational path-based representation can more accurately capture the underlying semantic logic between entities.

[0030] In the rule generation phase, high-quality rules are generated based on the classic logical induction method (Association Rule Mining Inference Engine, AMIE) through frequent relation path mining and confidence calculation. Each rule is represented by a triplet path pattern, as shown below: ; in, and Describe the reasoning path for the relationship; The predicates in the rule header describe the entities. Target relationship (e.g., " "has a certain attribute / state" or " (Able to reach a certain inference conclusion); in knowledge graph reasoning... It typically represents the target relationship pattern derived from the rule body; An identifier for the entire rule, used to uniquely identify a logical rule; different Different rule instances correspond to different rules.

[0031] The generated rules are filtered, retaining those with high confidence (threshold). The frequent relationship paths are identified. Only high-confidence rules that pass the screening are used in subsequent subgraph construction. This screening process ensures the reliability of the rules and provides a valid reasoning basis for the subsequent model.

[0032] After selecting high-confidence rules, these rules are weighted. The weight of each path reflects its correlation with the attack behavior. For each path... Count the number of times it appears in the positive sample. Number of occurrences in the entire sample Define attack probability As shown below: ; in, This is a smoothing factor used to mitigate statistical bias in low-frequency paths. If a path never appears, a default probability is assigned. As a cold start mechanism; only retain The path, where the attack probability threshold .

[0033] Based on the aforementioned frequency and attack probability, calculate the path. weight As shown below: ; in, Representing a path The frequency of occurrence of a path in the training set reflects its importance within the overall data. The resulting path weights will play a crucial role in subgraph construction and inference, enhancing the model's ability to focus on critical paths.

[0034] Based on the filtered rules and calculated weights, the subgraph is constructed. This involves building around the target triplet. , with head entity Tail-end entity K-hop subgraph extraction is performed centered on [the target element]. and Starting from there, they expanded outwards respectively. Step 1, obtain the set of adjacent nodes of the entity. and As shown below: ; ; in, This represents the shortest path distance. This represents the number of hops extracted from the subgraph. This is a candidate relationship.

[0035] By performing an intersection operation on these two adjacency sets, we obtain a common set of nodes. and build with and Subgraph with core As shown below: ; ; ; in, A set of nodes; Let it be the set of edges; , For any two nodes (entities) in the subgraph.

[0036] At this point, a system was constructed based on and The core of the basic topology.

[0037] After the subgraph is constructed, the selected rule paths are injected into the edge set to form the final subgraph, as shown below: ;

[0038] in, The basic topological edge set; This is the set of filtered rule paths; This is the weight threshold; This is the final set of edges; This is the final weighted subgraph constructed around the target node; A weight mapping function or set of weights that applies to the entire final subgraph. The final subgraph contains the basic topology and rule paths with high attack relevance, providing high-quality input for subsequent encoding.

[0039] II. Subgraph Encoding Module.

[0040] To enhance the model's ability to discriminate local structures, the SecGIRF model introduces multiple mechanisms—structure awareness, semantic awareness, and task awareness—in the subgraph encoding stage. Its core dual-pathway architecture is as follows: Figure 2 As shown: The entity perception update module on the left uses path perception attention (to generate weights) Relationship between the target and the perceived attention (generation) By integrating rule paths and task semantics, entity representations are updated. .

[0041] The right-side relation aggregation and evolution module, through Integrating multi-hop relationships It also integrates the states of neighboring entities and outputs the evolution node through gating. The two modules form a closed-loop collaboration.

[0042] When initializing and encoding its nodes, a double-radius node labeling (DRNL) strategy is employed. This strategy calculates the relationship between nodes and the head entity. Tail-end entity The shortest path distance is used to label nodes, so that each node's label value reflects its relative position in the subgraph, thus providing structural information that helps the model learn. The node labeling formula is as follows: ; in, For nodes The double radius marker value; Let be any node in the subgraph.

[0043] To further capture the higher-order semantic context of the target triples in the graph, a context graph is constructed. The nodes of the context graph include entities, relations, and connections. and The high-confidence rule path; where edges represent semantic associations, such as co-occurrence frequency, path inclusion relationship, etc.

[0044] After the context graph is constructed, a Graph Convolutional Network (GCN) is used to update the node embeddings and model their high-order interactions. To enhance the expressive power of context modeling, a multi-dimensional interaction encoding function is further introduced for any pair of context nodes. The features are combined and modeled as follows: ; in, For node pairs The interactive feature vector; , This is a vector representation of a node in the context graph; This is a vector concatenation operation; and Modeling differences and similarities respectively helps to enhance the ability to discriminate relational semantics.

[0045] In the structural encoding process, an attention mechanism based on target relations is introduced. The attention weight of each edge in the subgraph depends not only on the features of its two endpoints but also on the embedding vector of the target relation, emphasizing the structural pattern relevant to the current inference task. Attention Weights As shown below: ; in, , The initial feature vector; Embed vectors for the target relation; , The vector representation of the point features after linear transformation; The linear transformation vector representing the target relation features; and These are trainable parameters; for Transpose of; This is the activation function.

[0046] Further capture potential path dependencies in the subgraph, based on the relationship between each node and the entity. and The nodes are sorted by distance, and a node sequence is constructed. Only the selected rule path nodes are sorted according to the attack chain order. Temporal features are extracted by BiGRU to supplement the sequence information that is difficult to model explicitly in the static structure.

[0047] In the feature fusion stage, the spliced ​​features are processed through an MLP network to fuse multi-source information, including node-initialized label features, relationship-aware attention embeddings, and path-level BiGRU sequence features. Feature fusion is as follows: ; in, For nodes The final feature representation; This represents the nodes in the context graph; This represents a sequence of nodes. It is a multilayer perceptron.

[0048] In the design of the feedforward network after feature fusion, a three-layer expansion-contraction structure feedforward network is adopted. This is to capture the nonlinear structural features in the subgraph; where, This represents the dimension of the input node features. This structure helps improve the model's ability to model complex local relationships, thereby effectively handling multi-hop paths and higher-order semantic information, as shown below: ; in, For nodes The update indicates; Represents a non-linear activation function; For nodes The set of adjacent nodes; This is the index for traversing all neighbors of node i.

[0049] To incorporate task information, an attention mechanism based on target relations is used in the graph aggregation stage, which is applied to each edge. The aggregation weights are adjusted as follows: ; in, The normalized attention weights represent the neighbors. For nodes The intensity of the impact; For activation functions; A linear mapping vector for embedding vectors of the target relation; For nodes Any neighboring node.

[0050] The final node is represented as: ; in, For nodes The final aggregate representation; For neighboring nodes The representation after processing by the MLP network; It is a multilayer perceptron used for feature transformation.

[0051] Finally, the node representation integrates three types of information: structural labels, relation-aware attention embeddings, contextual semantic features, and path features, thereby generating a discriminative representation of the triple structure context, providing stronger representational support for relation prediction tasks. Figure 3 As shown.

[0052] III. Relational Reasoning Optimization Module.

[0053] To improve the model's accuracy on the target triplet To enhance its relation discrimination capabilities, the SecGIRF model introduces a multi-granular semantic fusion mechanism during the inference phase, combining structural context, rule paths, and task semantic information to achieve model-based optimization of inference performance.

[0054] First, at the structural level, based on the envelope subgraph described above, the node representation is obtained { }, and combined with rule path embedding , to obtain fusion representation As shown below: ; Through aggregate functions The node features are summarized to construct a subgraph structure representation, as shown below: ; in, This is a subgraph structure representation.

[0055] Then, at the semantic level, a context graph model is further introduced to model the rule path semantics and relational context of the target triples in the knowledge graph. This involves the target entity... Candidate Relationship and its semantic interaction feature input feature combination function As shown below: ; in, Represents candidate relation; function The impact of candidate relations on semantic interaction is clearly expressed; This function performs vector concatenation operations. It takes into account both the differences and similarities between entity pairs, enhancing the ability to discriminate relational semantics.

[0056] Finally, to achieve joint structure-semantic optimization, a two-pathway relation scoring function is adopted, as shown below: ; in, The final predicted score for the target triplet; A learnable weight matrix (used for subgraph structure representation); This is a learnable weight matrix (used for semantic features); and All are learnable parameters; It is a non-linear activation function used to fuse the matching strength of structural context and semantic path to the target relationship.

[0057] Furthermore, at the logical level, the SecGIRF model introduces a rule consistency optimization mechanism. This mechanism targets high-confidence Horn rules automatically mined from the training set. If a path matches a rule body, then the scoring of the corresponding relationship is enhanced by the rule, as shown below: ; in, Score the relationships adjusted under logical constraints; To control the degree of influence of rule paths on inference results; Indicates whether a rule path match exists, with a value of 0 or 1. A value of 1 indicates that a match occurs if and only if the entity pairs... There exists a path that completely matches a certain rule body; when the value is 0, there is no path that satisfies the matching condition. This indicates assignment.

[0058] During the training phase, the multi-objective loss function is jointly optimized. This includes relation classification loss and logical consistency constraints, as shown below: ; in, Cross-entropy loss; For logical consistency loss, it is used to encourage the model to maintain consistent reasoning under the constraints of logical rules, and to encourage the model to make consistent reasoning judgments under logical rules. represents the weight hyperparameter. Through structural representation enhancement, context path modeling, and rule consistency guidance, the SecGIRF model significantly improves the model's ability to generalize and summarize complex relationships, making it particularly suitable for sparse, heterogeneous, and rule-driven knowledge graph scenarios in cybersecurity tasks.

[0059] IV. Training Optimization Module.

[0060] During the training process, the task characteristics and logical induction requirements in the cybersecurity graph were fully integrated, and the design was carried out around three aspects: negative sampling mechanism, loss function construction and optimization strategy, in order to improve training efficiency and model generalization ability.

[0061] Firstly, regarding the negative sampling strategy, to address the issues of uneven distribution and significant long-tail phenomenon of attack entities in the security graph, a task-aware negative sampling method based on attack semantic categories enhances the relevance of negative samples in the semantic space by assigning different sampling weights to different attack types. This improves the ability to distinguish attack types and helps enhance the discriminative power of the training signal. Specifically, the sampling probability is defined as: ; in, Indicates the frequency of occurrence of attack types; For attack category label space; For the sample The attack type; The sampling probability is denoted as .

[0062] In addition, a filtering mechanism based on the head-and-tail entity relation dictionary is introduced (i.e. and This effectively avoids potential positive examples and improves the quality of negative samples.

[0063] Then, in constructing the loss function, a multi-task joint loss function is adopted to balance structural accuracy and rule consistency. The main task loss is a binary cross-entropy based on negative sampling, used to supervise triplet relation classification. The auxiliary task loss is based on pseudo-labels generated by logical rule paths, imposing consistency constraints on subgraphs that satisfy high-confidence paths. The two are combined in a weighted manner to construct the overall loss function. As shown below: ; in, This represents the main task loss based on the structure score; This represents the consistency loss based on the rule path score; These are the weighting coefficients.

[0064] Finally, regarding training scheduling and parameter optimization, this model employs the AdamW optimizer, combined with a weight decay mechanism to effectively suppress overfitting. The learning rate scheduling strategy, ReduceLROnPlateau, dynamically adjusts the learning rate according to the training progress to ensure model convergence. By introducing gradient clipping and L2 regularization control, gradient explosion is prevented, further improving generalization ability. Furthermore, all parameters are initialized using Xavier to ensure stability in the early stages of training.

[0065] Example 2 1. Data set and evaluation metrics.

[0066] Predicting cyber threats from security-related public data is an emerging research field, and currently there are no publicly available datasets to evaluate the model proposed in this invention. Therefore, this embodiment constructs the AttackKG dataset to provide a comprehensive and structured knowledge graph for cyber threat prediction tasks. This dataset collects over 5800 cyber threat data entries, containing a total of 19410 structured triples, expressing various related information in security events in the form of "head entity-relationship-tail entity". The main sources of this dataset can be divided into the following two categories: [The dataset is divided into two main parts:] (1) Network Data Collection: A large amount of vulnerability description text was extracted from the CNNVD (China National Information Security Vulnerability Sharing Platform) website using an automated web crawler system, and 5015 sentences involving attacks and vulnerabilities were randomly selected to construct the initial corpus. This data covers various security threat scenarios, such as attack descriptions of buffer overflows, remote execution, and privilege escalation. Subsequently, the corpus was manually annotated according to a predefined annotation strategy to ensure the accuracy and semantic consistency of the data.

[0067] (2) Security Information Integration: Structured vulnerability and attack information from multiple mainstream security databases (including CVE, NVD, CWE, CPAEC, and the ATT&CK framework) is further integrated and added as supplementary fields to the triples corresponding to the labeled text. This integration process enhances the professionalism and information density of the dataset, making it not only cover attack techniques and tools, but also contextual information such as attack targets and path relationships.

[0068] This dataset contains 6 main entity categories (attack type, domain name, host, IP address, tool, vulnerability) and 7 relation types (such as exploits, uses_tool, resolves_to, etc.), with a total of over 2,000 entities and over 600 relation types. It comprehensively covers the key elements and causal chains commonly encountered in network attack activities. The entity types and their number statistics are shown in Table 1.

[0069] Table 1. Statistics on entity types and their quantity in the AttackKG dataset. ;

[0070] To ensure the accuracy of model training and evaluation, this dataset is divided into three versions (V1, V2, and V3) using GraiL's temporal principle. Each version contains independent training, validation, and test sets in a 6:2:2 ratio. The data distribution and entity relationships differ for each version to evaluate the model's generalization ability in different scenarios, especially its adaptability to unknown data and new attack types, as shown in Table 2.

[0071] Table 2. Statistics on the partitioning of AttackKG multi-version benchmark sets ;

[0072] In this embodiment, in order to comprehensively and objectively evaluate the performance of the model in knowledge graph reasoning and relation prediction tasks, two mainstream evaluation metrics were adopted: AUC (Area Under Curve) and Ranking metrics.

[0073] AUC (Area Under the ROC Curve) is an important metric for measuring the discriminative ability of binary classification models, widely used in tasks such as link prediction and anomaly detection in knowledge graphs. The AUC value ranges from [0, 1], and its physical meaning is: the probability that the model will rank the predicted score of the positive sample before the negative sample when randomly selecting a positive sample and a negative sample. The closer the AUC value is to 1, the stronger the model's ability to distinguish between positive and negative samples; when the AUC value is 0.5, it indicates that the model's performance is comparable to random guessing.

[0074] Ranking metrics are primarily used to evaluate a model's ranking ability in knowledge graph completion tasks. Common metrics include Mean Rank (MR), Mean Reciprocal Rank (MRR), and Hits@K.

[0075] MR represents the average rank of the correct entity among all candidate entities; a smaller value is better.

[0076] MRR is the average of the reciprocals of the correct entity rankings. A higher value is better, indicating that the model tends to rank correct entities higher, as shown below: ; Where Rank represents the ranking of each sample; N is the number of samples in the test set.

[0077] Hits@K is another commonly used evaluation metric, mainly used to evaluate the model's ranking ability in knowledge graph completion tasks, as shown below: ; in, This is an indicator function that takes the value 1 when the condition is true and 0 otherwise. This is the hit threshold.

[0078] This metric represents the proportion of correct entities ranked in the top K positions. Common K values ​​include 1, 3, and 10. The higher the Hits@K value, the stronger the model's ability to rank correct entities in the top K positions, thus indicating that the model has higher ranking accuracy.

[0079] 2. Baseline model and parameter settings.

[0080] To evaluate the performance of the proposed model in cybersecurity knowledge graph reasoning tasks, it was compared with several state-of-the-art benchmark models. These benchmark models cover two main categories: rule-based methods and graph neural network (GNN) based methods.

[0081] Rule-based approaches: These models extract logical rules from knowledge graphs and perform reasoning based on these rules, including NeuralLP [Yang et al., 2015], DRUM [Sadeghian et al., 2019], and RuleN [Yang et al., 2017].

[0082] GNN-based methods: These methods learn entity-independent features for knowledge graphs using graph neural networks (GNNs) and utilize graph structures for reasoning. Specific examples include GraIL [Teru et al., 2020], CoMPILE [Mai et al., 2021], SNRI [Yao et al., 2020], and SASILP [Li et al., 2020].

[0083] These benchmark models cover a variety of approaches, from rule-based reasoning to graph neural networks, providing a strong basis for comparison with the model proposed in this invention. By comparing with these benchmark models, the advantages and disadvantages of this model in complex cybersecurity data and unseen relation reasoning tasks can be comprehensively evaluated.

[0084] The SecGIRF model constructed in this invention is implemented based on the PyTorch and DGL frameworks, and all experiments were conducted in an environment equipped with an NVIDIA GeForce RTX 3090 GPU. To ensure the effectiveness and stability of the model, key hyperparameters were optimized in multiple experiments, and the specific parameter settings are shown in Table 3. During training, these settings were used to optimize the training stability of the model, while avoiding overfitting and improving efficiency.

[0085] Table 3 Parameter Settings ;

[0086] During the hyperparameter selection process, key parameters such as batch size, learning rate, and number of GCN layers were optimized using a grid search method. The specific search space included batch size {2, 4, 8}, learning rate {0.001, 0.005, 0.01}, and number of GCN layers {2, 3, 4}. After multiple rounds of experiments, the optimal configuration was finally selected as batch size 2, learning rate 0.01, and number of GCN layers 3. This choice ensured model accuracy while also optimizing computational efficiency, thus achieving a balance between the two.

[0087] 3. Experimental results.

[0088] Experimental results demonstrate the effectiveness of the SecGIRF model in cybersecurity knowledge graph reasoning tasks, and are compared with several state-of-the-art benchmark models on the AttackKG dataset.

[0089] As shown in Table 4, the SecGIRF model achieved the best AUC values ​​on all three dataset versions (V1, V2, and V3). Version V2 significantly outperformed V1 / V3 (+2.0% / 2.5%), which is attributed to its more balanced data distribution and richer attack chain patterns (7 relation types, covering more complex semantic associations), providing the model with more comprehensive structure-semantic learning signals. These results demonstrate that the SecGIRF model has a strong ability to distinguish between positive and negative samples.

[0090] Compared to models such as Neural-LP, DRUM, RuleN, and GraIL, the SecGIRF model demonstrates significant advantages across all three versions. Compared to GraIL, SecGIRF achieves substantial improvements across all versions, particularly a 6.3% AUC improvement in version V2. This validates that SecGIRF's rule enhancement mechanism effectively compensates for the limitations of pure structural models, especially in modeling multi-hop attack paths, where injecting high-confidence rules enhances its ability to capture sparse attack chains. The advantages over CoMPILE and SNRI demonstrate the synergistic effect of the context graph and attention mechanism. The context graph models global semantic dependencies, while relation-aware attention strengthens the weight allocation of local critical paths, jointly optimizing the discrimination accuracy in complex attack scenarios. This also indicates that the SecGIRF model has stronger discriminative capabilities in complex cybersecurity inference tasks.

[0091] Table 4 Comparison of AUC performance of SecGIRF models ;

[0092] As shown in Table 5, the SecGIRF model also demonstrated strong capabilities in the MRR evaluation, indicating that the present invention can more consistently rank the correct answers at the top in multi-hop reasoning tasks. The MRR evaluation results also show the better performance of the SecGIRF model, further validating its powerful ability to accurately rank correct entities.

[0093] In the evaluation of Hits@K ranking ability, the SecGIRF model also achieved the best results, with Hits@1 values ​​higher than all benchmark models. Particularly noteworthy is its performance on the V2 dataset, where it outperformed all benchmark models by 76.9%. Compared to GraIL, the SecGIRF model showed improvements of 4%, 4.8%, and 1.9% in Hits@10. These improvements demonstrate the significant advantage of the SecGIRF model in accurately ranking the correct triples at the top.

[0094] Table 5. Results of fine-grained metrics for link prediction in the SecGIRF model. ;

[0095] Compared with several strong benchmark models, the model of this invention has made significant progress in AUC and Hits@K metrics, indicating that the SecGIRF model achieves stronger adaptability and higher inference accuracy to dynamic attack chains by introducing rule-enhanced subgraphs (based on attack probability weighting), context graphs and attention mechanisms to fuse global semantic and local structural information, and task-aware negative sampling to alleviate long-tail bias.

[0096] 4. Ablation experiment.

[0097] Ablation experiments were conducted to evaluate the effectiveness of each module in cybersecurity knowledge graph reasoning. The experiments included the ablation of four key modules: rule-guided mechanism, context graph modeling, relation-aware attention, and task-aware negative sampling. The results in Tables 6 and 7 show that removing any module leads to varying degrees of performance degradation, demonstrating the significant contribution of each module to the modeling of dynamic attack chains.

[0098] Specifically, the removal of the rule-guided mechanism resulted in the greatest performance degradation (average AUC decreased by 3.78%, Hits@10 decreased by 4.48%), as this module directly impacts the integrity of multi-hop attack paths. The removal of context graph modeling followed closely (average AUC decreased by 2.59%, Hits@10 decreased by 2.79%), as this module plays a crucial role in capturing cross-domain threat associations. Relationship-aware attention and task-aware negative sampling had relatively smaller impacts, but still led to performance degradation of 1.19% / 1.21% and 0.89% / 1.26%, respectively.

[0099] Table 6. Analysis of the impact of module ablation on AUC ;

[0100] Table 7 Results of Hits@10 Ablation Experiment ;

[0101] The dominant role of the rules module stems from its logical constraints on attack paths. This structured constraint is particularly important in cybersecurity scenarios, especially when facing sparse attack chains (such as APT attacks). The role of the context graph lies in its ability to simultaneously integrate global semantic features and local rule reasoning, providing complementary information for complex attack graphs. Notably, in the data-balanced V2 version, the impact of the rules and context modules is further amplified (Hits@10 decreased by 4.92% and 3.77%, respectively), indicating that the module design has strong robustness to dynamic threat environments.

[0102] In summary, the ablation experiments verified the necessity of rule-guided mechanisms and contextual modeling as the core "two pillars" and further supported the rationality of the SecGIRF model.

[0103] 5. Application verification.

[0104] To visually demonstrate the reasoning mechanism of the SecGIRF model in the cybersecurity knowledge graph, Table 8 lists examples of attack rules learned in the three versions of AttackKG. Two rules with the highest confidence were selected for each dataset version. For example, rule (3) learned in version V2 describes how an attacker, after lateral movement through a compromised device, will inevitably gain control of critical nodes, consistent with the "breakthrough-expansion-control" behavioral logic in APT attacks. All rules embody interpretable security semantics; for example, rule (5) in version V3 associates malicious code injection with C2 channel activation (…). (This corresponds to MITRE ATT&CK tactics T1055→T1071.) These discrete rules, in synergy with neural computation, drive the threat reasoning capabilities of the SecGIRF model.

[0105] Table 8 Examples of AttackKG Multi-Version High-Confidence Attack Rules ;

[0106] like Figure 4 As shown, this scatter plot reveals the distribution relationship between rule paths and target rule heads in the topological space composed of "rule path density" and "node centrality". In the figure, blue dots represent rule paths (ε) with different confidence levels, and their color intensity corresponds to the confidence values ​​(0.55 to 0.90) of the color bar on the right; orange triangles represent target rule heads (r). As can be seen from the figure, high-confidence (dark blue) rule paths are significantly clustered in the upper left area of ​​the graph, exhibiting characteristics of high node centrality and medium-to-low rule path density. This indicates that the most valuable rules are often associated with core nodes in the network, and their path structures are not overly complex. In contrast, the distribution of target rule heads is more dispersed.

[0107] This distribution pattern provides an intuitive basis for the rule selection mechanism of the SecGIRF model: prioritizing high-confidence rules located in this region (high centrality, moderate density) can effectively capture key attack patterns, thereby enhancing the model's inference performance.

[0108] Therefore, this invention employs a subgraph reasoning method that integrates logical rule learning and attack semantic enhancement, thereby improving the reasoning ability of network security knowledge graphs in complex attack scenarios. By introducing a rule path injection mechanism based on attack probability weighting, the structural sparsity problem is effectively alleviated; a task-aware negative sampling strategy and a multi-head attention mechanism are designed to improve the model's accuracy in modeling heterogeneous attack paths; and a logical consistency optimization method is combined to achieve zero-sample generalization reasoning for novel threat relationships.

[0109] Experiments on the self-built dataset AttackKG demonstrate that the SecGIRF model outperforms existing mainstream methods in key metrics such as AUC, MRR, and Hits@10. It also exhibits good interpretability and generalization ability, showcasing the effectiveness of logical induction and task semantic fusion in subgraph reasoning and improving the generalization prediction ability against novel attacks. This provides a feasible path for the application of graph neural reasoning technology in cybersecurity scenarios.

[0110] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the technical solutions of the present invention, and these modifications or equivalent substitutions cannot cause the modified technical solutions to deviate from the spirit and scope of the technical solutions of the present invention.

Claims

1. A subgraph reasoning method that integrates logical rule learning and attack semantic enhancement, characterized in that, The construction of the SecGIRF model consists of five modules: input layer, subgraph extraction module, subgraph encoding module, relation reasoning optimization module, and training optimization module; The input layer dynamically integrates the knowledge graph topology and the AMIE rule base to generate an initial k-hop subgraph, providing structured input for attack chain mining. The subgraph extraction module performs double reset letter filtering to screen high-value attack chains and applies dictionary filtering to enhance semantic reliability; The subgraph encoding module adopts a dual-path mechanism. The entity perception update layer iteratively optimizes the node representation through path perception attention and target relationship perception attention. The relationship aggregation and evolution layer generates a high-order semantic representation by fusing multi-source relationships through the φ function, and collaboratively models the spatiotemporal features of the attack chain. The relational reasoning optimization module dynamically injects high-confidence rules to optimize triple scoring; The training optimization module implements task-aware negative sampling.

2. The subgraph reasoning method that integrates logical rule learning and attack semantic enhancement according to claim 1, characterized in that, In the subgraph extraction module, multi-hop paths are modeled using the Horn rule form from first-order logic (FOL), where the Horn rule is as follows: ; in, This is the first relationship in the rule body that initiates the attack chain, describing the initial actions of the attack. The second relationship in the rule body describes how, after the first step, the attacker or the exploited entity propagates the attack to the next intermediate entity; As the final step of the attack, the last item in the rule body connects the last intermediate entity and the final attack target; For target relationships; the rule body represents the relationship from the entity. To the entity The rule header represents the target relationship in the multi-hop path between them. ; In the rule generation phase, rules are generated based on the classic logical induction method AMIE through frequent relation path mining and confidence calculation; each rule is represented by a triple path pattern, as shown below: ; in, and For relationships, describe the reasoning path; The predicates in the rule header describe the entities. Target relationship; This is the identifier for the entire rule, used to uniquely identify a logical rule; The generated rules are filtered, and the confidence threshold is retained. Frequent relationship paths.

3. The subgraph reasoning method integrating logical rule learning and attack semantic enhancement according to claim 2, characterized in that, After selecting the confidence rules, these rules are weighted; for each path Count the number of times it appears in the positive sample. Number of occurrences in the entire sample Define attack probability As shown below: ; in, This is a smoothing factor used to mitigate statistical bias in low-frequency paths; the path is calculated based on its frequency and attack probability. weight As shown below: ; in, For path The frequency of occurrence in the training set reflects the importance of the path.

4. The subgraph reasoning method integrating logical rule learning and attack semantic enhancement according to claim 3, characterized in that, A subgraph is constructed based on the filtered rules and calculated weights, centered around the target triplet. , with head entity Tail-end entity Extract k-hop subgraphs centered on the target; from and Starting from there, they expanded outwards respectively. Step 1, obtain the set of adjacent nodes of the entity. and As shown below: ; ; in, This represents the shortest path distance. This represents the number of hops extracted from the subgraph. Candidate relationship; Through the and The intersection operation of adjacency sets yields the common set of nodes. and build with and Subgraph with core As shown below: ; ; ; in, A set of nodes; Let it be the set of edges; , Let be any two nodes in the subgraph; After the subgraph is constructed, the selected rule paths are injected into the edge set to form the final subgraph, as shown below: ; ; in, The basic topological edge set; This is the set of filtered rule paths; This is the weight threshold; This is the final set of edges; This is the final weighted subgraph constructed around the target node; A weight mapping function or set of weights that applies to the entire final subgraph. .

5. The subgraph reasoning method integrating logical rule learning and attack semantic enhancement according to claim 1, characterized in that, The SecGIRF model introduces a dual-pathway mechanism for subgraph encoding during the subgraph encoding stage, including an entity perception update layer and a relation aggregation evolution layer; The entity perception update layer updates entity representations by fusing rule-based paths and task semantics through path perception attention and target relationship perception attention; The relation aggregation and evolution layer integrates multi-hop relations through the φ function and merges the states of neighboring entities. It then outputs evolution nodes through gating to form a closed-loop collaboration.

6. The subgraph reasoning method integrating logical rule learning and attack semantic enhancement according to claim 5, characterized in that, During initial encoding, a dual-radius node labeling DRNL strategy is adopted, which calculates the relationship between nodes and the head entity. Tail-end entity The shortest path distance is used to label nodes, so that the label value of each node reflects its relative position in the subgraph, providing structural information for model learning; the node labeling formula is as follows: ; in, For nodes The double radius marker value; Let be any node in the subgraph; To further capture the higher-order semantic context of the target triples in the graph, a context graph is constructed, whose nodes include entities, relations, and connections. and Confidence rule path; After the context graph is constructed, a graph convolutional network is used to embed and update the nodes, modeling their higher-order interactions; a multidimensional interaction encoding function is introduced for any pair of context nodes. The features are combined and modeled as follows: ; in, For node pairs Interactive feature vectors; , This is a vector representation of a node in the context graph; This is a vector concatenation operation; and These represent modeling differences and similarities, respectively.

7. The subgraph reasoning method integrating logical rule learning and attack semantic enhancement according to claim 6, characterized in that, In the structural encoding process, an attention mechanism based on target relations is introduced; the attention weight of each edge in the subgraph is... As shown below: ; in, , The initial feature vector; Embed vectors for the target relation; , The vector representation of the point features after linear transformation; The linear transformation vector representing the target relation features; and These are trainable parameters; for transpose; For activation functions; Further capture potential path dependencies in the subgraph, based on the relationship between each node and the entity. and The nodes are sorted by distance, and a node sequence is constructed. Only the selected rule path nodes are sorted according to the attack chain order. Temporal features are extracted by BiGRU to supplement the sequence information that is difficult to be explicitly modeled in the static structure.

8. The subgraph reasoning method integrating logical rule learning and attack semantic enhancement according to claim 7, characterized in that, In the feature fusion stage, spliced ​​features are processed through an MLP network to fuse multi-source information, including node-initialized labeled features, relationship-aware attention embeddings, and path-level BiGRU sequence features; The fusion is as follows: ; in, For nodes The final feature representation; This represents the nodes in the context graph. This represents a sequence of nodes; It is a multilayer perceptron; In the design of the feedforward network after feature fusion, a three-layer expansion-contraction structure is adopted to capture the nonlinear structural features in the subgraph, as shown below: ; in, For nodes The update indicates; Represents a non-linear activation function; For nodes The set of adjacent nodes; The index for traversing all neighbors of node i; In the graph aggregation phase, a target relation-based approach is adopted. The attention mechanism, for each edge The aggregation weights are adjusted as follows: ; in, The normalized attention weights represent the neighbors. For nodes The intensity of the impact; For activation functions; For target relationship A linear mapping vector; For nodes Any neighboring node; The final node is represented as: ; in, For nodes The final aggregate representation; Neighboring nodes The representation after processing by the MLP network; It is a multilayer perceptron used for feature transformation.

9. The subgraph reasoning method integrating logical rule learning and attack semantic enhancement according to claim 1, characterized in that, In the relational reasoning optimization module, the SecGIRF model introduces a multi-granularity semantic fusion mechanism during the inference phase. By combining structural context, rule paths, and task semantic information, it achieves model-based optimization of inference performance. The specific process is as follows: First, at the structural level, obtain the node representation { }, and combined with rule path embedding , to obtain fusion representation As shown below: ; Through aggregate functions The node features are summarized to construct a subgraph structure representation, as shown below: ; in, Represented as a subgraph structure; Then, at the semantic level, a context graph is introduced to model the rule path semantics and relational context of the target triples in the knowledge graph; the target entity... Candidate Relationship and its semantic interaction feature input feature combination function As shown below: ; in, Represents candidate relation; function The impact of candidate relations on semantic interaction is clearly expressed; This is a vector concatenation operation; Finally, a dual-pathway relationship scoring function is used to achieve joint structure-semantic optimization, as shown below: ; in, The final predicted score for the target triplet; This is the learnable weight matrix used for subgraph structure representation; This is a learnable weight matrix used for semantic features; and All are learnable parameters; It is a non-linear activation function used to fuse the matching strength of structural context and semantic path to the target relation; Furthermore, at the logical level, the SecGIRF model introduces a rule consistency optimization mechanism; this is applied to the confidence Horn rules automatically mined from the training set. If a path matches a rule body, then the scoring of the corresponding relationship is enhanced by the rule, as shown below: ; in, Score the relationships adjusted under logical constraints; To control the degree of influence of rule paths on inference results; Indicates whether a rule path match exists, with a value of 0 or 1. A value of 1 indicates that a match occurs if and only if the entity pairs... There exists a path that completely matches a certain rule body; a value of 0 indicates that there is no path that satisfies the matching condition. This indicates assignment; During the training phase, the multi-objective loss function is jointly optimized. This includes relation classification loss and logical consistency constraints, as shown below: ; in, Cross-entropy loss; For logical consistency loss, it is used to encourage the model to maintain consistent reasoning under the constraints of logical rules, and to encourage the model to make consistent reasoning judgments under logical rules. For weight hyperparameters.

10. The subgraph reasoning method integrating logical rule learning and attack semantic enhancement according to claim 1, characterized in that, The training optimization module is designed around three aspects: negative sampling mechanism, loss function construction, and optimization strategy. The specific implementation process is as follows: First, regarding the negative sampling strategy, the task-aware negative sampling method based on attack semantic categories enhances the relevance of negative samples in the semantic space and improves the ability to distinguish attack types by assigning different sampling weights to different attack types; whereby the sampling probability is defined as: ; in, The frequency of occurrence of attack types; For attack category label space; The type of attack in the sample; The sampling probability is set; a filtering mechanism based on the head and tail entity relationship dictionary is introduced to avoid potential positive examples and improve the quality of negative samples. Then, in constructing the loss function, a multi-task joint loss function is adopted; where the main task loss is a binary cross-entropy based on negative sampling, used to supervise triplet relation classification; the auxiliary task loss is based on pseudo-labels generated by logical rule paths, which imposes consistency constraints on subgraphs that satisfy high-confidence paths; the two are combined in a weighted form to construct the overall loss function. As shown below: ; in, This represents the main task loss based on the structure score; This represents the consistency loss based on the rule path score; These are the weighting coefficients; Finally, in terms of training scheduling and parameter optimization, the AdamW optimizer is adopted, combined with a weight decay mechanism to suppress overfitting; gradient clipping and L2 regularization control are introduced to prevent gradient explosion.

Citation Information

Patent Citations

  • Hidden attack tracing method based on dynamic and static behavior mapping and graph neural network

    CN119961929A

  • Network security script arrangement method based on LLM enhanced RL

    CN120710773A

  • Method and apparatus for automatically generating inference questions and answers

    WO2021184311A1

Cited By

  • A multimodal knowledge post-editing model reasoning ability strengthening method and system

    CN122414411A