A Few-Shot Wi-Fi Spoofing Attack Detection Method and System Based on Meta-Learning
Through the small sample Wi-Fi camouflage attack detection method based on meta-learning, the convolutional neural network and multiple auxiliary networks are used to learn meta-knowledge from historical tasks, solving the problem of insufficient sample size and achieving fast and accurate Wi-Fi camouflage attack detection in the Internet of Things environment.
Patent Information
- Application Number
- CN202111148387.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-09-27
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2041-09-27
AI Technical Summary
The existing Wi-Fi camouflage attack detection methods are difficult to effectively detect unknown attack behaviors in the case of insufficient sample size, and require a large amount of data and long-term training to adapt to new tasks, which cannot meet the resource constraints and real-time requirements of the Internet of Things.
Using a small sample Wi-Fi camouflage attack detection method based on meta-learning, we learn meta knowledge from historical tasks by building multiple auxiliary networks and migrating them to a new Wi-Fi camouflage attack detection task. The spatial structural features of the protocol are extracted using convolutional neural networks and quickly adapt to new tasks with few samples.
In the case of shortage of data in new tasks, 98% accuracy can be achieved through only 50 samples training, meeting the resource constraints and real-time requirements of the Internet of Things, and quickly adapting to new tasks.
Smart Images

Figure CN113938889B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of Internet of Things security, and relates to a few-shot learning detection method and system based on meta-learning. Background Art
[0002] In recent years, the number of Internet of Things (IoT) intelligent devices has increased sharply, resulting in a significant increase in wireless network traffic. By 2021, wireless network traffic has accounted for two-thirds of the global network traffic, of which 66% is generated by Wi-Fi (such as IEEE802.11 networks) and cellular networks. By 2023, there will be nearly 628 million public Wi-Fi hotspots globally, up from 169 million in 2018, a four-fold increase. The widely deployed Wi-Fi network provides convenient and high-speed local area network communication, but at the same time is accompanied by privacy and security issues such as Wi-Fi spoofing, injection, and flood attacks.
[0003] For the purpose of Wi-Fi impersonation attack detection (WAID), intrusion detection (IDS) is an important part of network security. IDS includes three main categories: specification-based, anomaly-based, and misbehavior-based IDS. Specification-based SNORT (using rule-based technology) can only identify known anomalies and lacks the ability to detect unknown behaviors. Anomaly-based intrusion detection systems learn known behavioral characteristics through deep learning (DL) technology and can detect unknown attacks. In addition, in misbehavior-based technologies, K. Kim et al. proposed a deep feature extraction and selection (D-FES) IDS using stacked autoencoders (SAE), manually selected deep compressed features based on SAE weights, and input them into a deep neural network (DNN) to achieve the WAID task. Y. Zhou et al. used heuristic algorithms such as particle swarm optimization (PSO) and bat algorithm (BA) for feature weighting selection and model weighting aggregation respectively. Although their work has improved the automation level and the performance of the WAID task, the proposed methods rely on a large amount of data and samples and do not work well in the case of scarce sample sizes. Therefore, in order to overcome the situation of insufficient data volume and small samples, network traffic sample increment algorithms based on generative adversarial network (GAN) and conditional generative adversarial network (CGAN) have been proposed. However, as is well known, GAN has problems such as mode collapse and sample retraining and is difficult to apply to actual environments.
[0004] Therefore, to address the above problems, the present invention designs a small-sample Wi-Fi impersonation attack detection method applicable to insufficient data and meeting the resource constraints and real-time requirements of the Internet of Things. Summary of the Invention
[0005] To overcome the above deficiencies of existing detection methods, the present invention proposes a Wi-Fi impersonation attack detection method based on meta-learning (hereinafter referred to as Meta-WF), which is applicable to the few-shot scenario and meets the resource constraints and real-time requirements of the Internet of Things.
[0006] The technical solution adopted by the present invention to solve its technical problems is as follows:
[0007] A small-sample Wi-Fi impersonation attack detection method based on meta-learning, characterized in that the method comprises the following steps:
[0008] 1) Data preprocessing: The data comes from the publicly available AWID dataset, which contains a large amount of Wi-Fi network impersonation attack traffic data collected from real network environments. First, convert the network traffic features into images, and the number of image channels is consistent with the number of layers of the network protocol layering framework. Secondly, perform one-hot encoding processing on the data labels;
[0009] 2) Deep feature extraction: Use a convolutional neural network (CNN) to process the data and extract protocol space structure features; to improve the feature learning performance, input the original features and the extracted features into multiple fully connected layers together;
[0010] 3) Meta-knowledge transfer of multiple auxiliary networks: Construct multiple auxiliary networks to learn meta-knowledge from different historical Wi-Fi impersonation attack detection (WAID) tasks respectively and transfer the knowledge to a new WAID task with a few-shot problem, so as to quickly adapt to the new task and solve the few-shot problem;
[0011] 4) Method evaluation: Use 3 types of forgery attack types as historical data, and the remaining types as new task data; in the training stage, randomly select 2 types from the 3 types to form a historical WAID task; in the test stage, select normal samples and the remaining new attack types to construct a new WAID task; use accuracy, precision, recall, and F1_score to evaluate the performance of the proposed method.
[0012] Preferably, in the step 1), the data preprocessing includes the following process:
[0013] Step 101, data preprocessing stage. The AWID dataset consists of the IEEE 802.11 network protocol architecture, mainly including WLAN control frames (Wlan), WLAN management frames (Wlan_mgt), and WLAN physical status frames (Radiotap), etc. First, make into a network traffic dataset, where represents M-dimensional features, represents the N-dimensional label after one-hot encoding.
[0014] Step 102, in order to extract more features, in addition to the original feature X i , considering the spatial structure information of the protocol frames. Input the original feature X i into c convolutional (conv) layer channels, and obtain
[0015]
[0016] where, h and w represent the length and width of the convolutional channels respectively.
[0017] Through the above formula, each traffic X i can be converted into an image of c×h×w, which is consistent with the hierarchy of the protocol frames and can further improve the representation of features. It should be noted that different protocol frames have different h and w. If where H and W represent the uniform length and width of each image channel, multiple "0"s need to be added to keep H and W consistent.
[0018] Preferably, the deep feature extraction in step 2) includes the following process:
[0019] Step 201, input the processed data into a convolutional neural network (CNN), and the spatial structure features can be extracted through the following formula
[0020]
[0021] where, w' and b represent the weights and biases of the CNN parameter θ.
[0022] Here, in order to obtain multi-dimensional the original features should be considered to further improve the performance of feature learning. Embed X i as auxiliary features and together they are converted into fully connected layer (FC) features F(X i ; θ) through the following formula:
[0023]
[0024] Finally, by using multi-layer convolution, the attack prediction label for the WAID task can be obtained.
[0025]
[0026] Preferably, in step 3), the meta-knowledge transfer of multiple auxiliary networks includes the following process:
[0027] Step 301, construct the WAID task: For different WAID tasks Construct several auxiliary networks Train them separately. Then define the WAID task as where T, N, K, Q represent the number of tasks, the number of categories, the number of support sets the number of query sets A WAID task can be considered to identify unknown Wi-Fi attacks through a small number of support set samples
[0028] Step 302, the specific training process is as follows: First, train Obtain the classification loss L(θ t ) through the binary cross-entropy loss function,
[0029]
[0030] It should be noted that for multi-classification problems, multi-classification cross-entropy is used. Then update the parameters θ′ t in the auxiliary network G(θ aux ) according to the gradient descent method t :
[0031]
[0032] where α and respectively represent the meta-learning rate and the gradient of
[0033] Note that formula (6) only includes one-step gradient update, and it can be directly extended to multi-step gradient update. Use the updated gradient for query set testing, and obtain the meta-knowledge of by calculating the loss The optimization goal of the present invention is to learn a self-learning model G(θ * ) that can quickly adapt to different past In this way, when facing new , the model G(θ * ) can achieve fast knowledge transfer. More specifically, the meta-objective function is defined as:
[0034]
[0035] Formally, the gradient descent method is used to obtain a self-learning model G(θ * ) * :
[0036]
[0037] where β is the meta-step size. Then G(θ * ) * is used to perform few-shot fine-tuning on the new WAID task :
[0038]
[0039] where θ′ new represents the parameters of the updated network G(θ′ new ), denotes loss. Finally, predictions can be made on the new task:
[0040]
[0041] Preferably, the method evaluation in step 4) includes the following process:
[0042] Step 401, method evaluation: The data comes from the publicly available AWID dataset, which contains the largest number of Wi-Fi network data collected from real network environments. It includes four types: normal instances, spoofing attacks, flooding attacks, and injection attacks, and the ratio of normal instances to attack instances in the training set is 33:1:1:1.35. To verify the performance of the proposed method in identifying new tasks, 3 of these types are used as historical data, and the remaining type is used as new task data. Since the success of meta-learning depends on large and diverse historical classification tasks, 2 types are randomly selected from the 3 types to form a historical WAID task. In the test phase, new WAID tasks are formed using normal samples and new attack types. Therefore, for the purpose of testing, each WAID task is defined as a binary classification task, that is, classifying normal and new anomalies.
[0043] Step 402, evaluation metrics: To quantitatively evaluate the performance of the WAID task, accuracy (Acc), precision (Prec i ), recall (Rc i) and F1_score as the measurement criteria:
[0044]
[0045]
[0046] Among them, TP i , TN i , FP i , FN i respectively represent the true positive, true negative, false positive, and false negative of the i-th label in the label set.
[0047] A system for implementing the small-sample Wi-Fi impersonation attack detection method based on meta-learning of the present invention includes a data preprocessing module, a deep feature extraction module, a meta-knowledge transfer module of multiple auxiliary networks, and a method evaluation module that are connected in sequence. Among them,
[0048] Data preprocessing module: The data comes from the publicly available AWID dataset, which contains a large amount of Wi-Fi network impersonation attack traffic data collected from real network environments; first, convert the network traffic characteristics into images, and the number of image channels is consistent with the number of layers of the network protocol layering framework. Secondly, perform one-hot encoding processing on the data labels;
[0049] Deep feature extraction module: Use a convolutional neural network (CNN) to process the data and extract protocol space structure features; in order to improve the feature learning performance, input the original features and the extracted features into multiple fully connected layers together;
[0050] Meta-knowledge transfer module of multiple auxiliary networks: Construct multiple auxiliary networks to learn meta-knowledge from different historical Wi-Fi impersonation attack detection (WAID) tasks respectively and transfer the knowledge to a new WAID task with a small-sample problem, so as to quickly adapt to the new task and solve the small-sample problem;
[0051] Method evaluation module: Use 3 types of forgery attack types as historical data, and the remaining types as new task data; in the training stage, randomly select 2 types from the 3 types to form a historical WAID task; in the test stage, select normal samples and the remaining new attack types to construct a new WAID task; use accuracy (Accuracy), precision (Precision), recall (Recall), and F1_score to evaluate the performance of the proposed method.
[0052] Advantages and positive effects of the present invention:
[0053] In view of the problem that the existing Wi-Fi camouflage attack detection method needs to retrain the learning network through a large number of samples and for a long time to adapt to the new WAID task, a few-shot Wi-Fi camouflage attack detection method based on meta-learning is proposed. This method learns knowledge from multiple historical WAID scenarios and quickly adapts to new WAID scenarios with few samples. After testing, in the case of a shortage of new task data, training with 50 samples achieved an accuracy of 98% with a single-step fine-tuning operation. The present invention is applicable to the few-shot scenario and meets the resource constraints and real-time requirements of the Internet of Things. Description of the Drawings
[0054] Figure 1 It is the overall flowchart of the method of the present invention.
[0055] Figure 2 (a) to Figure 2 (b) are the experimental result diagrams of the method of the present invention, where Figure 2 (a) is the precision performance of Meta-WF and DNN under different fine-tuning steps, Figure 2 (b) is the precision performance of Meta-WF under different WIAD tasks and different fine-tuning steps. Detailed Embodiments
[0056] In order to make the technical solutions and design ideas of the present invention clearer, the present invention will be described in further detail below with reference to the drawings.
[0057] A few-shot Wi-Fi forgery attack detection method based on meta-learning, by constructing multiple auxiliary networks, respectively learning meta-knowledge from different historical WAID tasks, and can quickly transfer the meta-knowledge to new WAID tasks.
[0058] The backbone network in the present invention is composed of a CNN with 4 Blocks and 3 FC layers. Among them, we define a convolutional block as Block = {Conv2d, Relu, BN, Max_pool}.
[0059] Referring to Figure 1 、 Figure 2 , a few-shot Wi-Fi forgery attack detection method based on meta-learning includes the following steps:
[0060] 1) Data preprocessing: The data comes from the publicly available AWID dataset, which contains the largest number of Wi-Fi network traffic data collected from real network environments. First, the network traffic features are converted into images, and the number of channels of the images is consistent with the hierarchical features of the protocol framework. Secondly, the data labels are processed by one-hot encoding.
[0061] 2) Deep feature extraction: Use a convolutional neural network (CNN) to process the data and extract spatial structure features; to improve the feature learning performance, input the original features and the extracted features into multiple fully connected layers together.
[0062] 3) Meta-knowledge transfer of multiple auxiliary networks: Construct multiple auxiliary networks to learn meta-knowledge from historical WAID tasks respectively to quickly adapt to new tasks; among them, the meta-task construction adopts the few-shot learning strategy.
[0063] 4) Method evaluation: Use 3 types as historical data and the remaining types as new task data; in the training stage, randomly select 2 types from the 3 types to form a historical WAID task; in the test stage, select normal samples and the remaining new attack types to construct a new WAID task; use accuracy, precision, recall, and F1_score to evaluate the performance of the method.
[0064] The step 1) includes the following processes:
[0065] Step 101, data preprocessing stage, the AWID dataset is composed of the IEEE 802.11 network protocol architecture, mainly including WLAN control (Wlan), WLAN management (Wlan_mgt), and WLAN physical state (Radiotap), etc. First, make be a network traffic dataset, where represents M-dimensional features, represents the N-dimensional label after one-hot encoding.
[0066] Step 102, to extract more features, in addition to the original feature X i , considering the spatial structure information of the protocol frame. Pass the original feature X i through the C convolutional (conv) layer channels and obtain
[0067]
[0068] where, h and w represent the length and width of the convolutional channels respectively.
[0069] Through the above formula, each traffic X i can be converted into an image of c×h×w, which is consistent with the hierarchy of the protocol frame and can further improve the representation of features. It should be noted that different protocol frames have different h and w. If Among them, H and W represent the uniform length and width of each image channel, and multiple "0"s need to be added to keep H and W consistent.
[0070] The step 2) includes the following process:
[0071] Step 201, input the processed into the convolutional neural network (CNN), and the spatial structure features can be extracted through the following formula
[0072]
[0073] where, w' and b represent the weights and biases of the CNN parameter θ.
[0074] Here, in order to obtain multi-dimensional the original features should be considered to further improve the performance of feature learning. Embed X i as the auxiliary feature and are together converted into the fully connected layer (FC) feature F(X i ; θ) through the following formula:
[0075]
[0076] Finally, using the multi-layer FC s , the predicted label of the WAID task can be obtained
[0077]
[0078] The step 3) includes the following process:
[0079] In order to be able to solve the tasks of data shortage and rapid deployment of new WAID, multiple auxiliary networks are constructed to learn knowledge from different historical WAID tasks respectively and quickly transfer the knowledge to assist the network to adapt to the new task.
[0080] Step 301, construct the WAID task: for different WAID tasks construct several auxiliary networks and train them separately. Then define the WAID task as where T, N, K, Q represent the number of tasks, the number of categories, the number of support sets , the number of query sets . A WAID task can be considered to identify unknown Wi-Fi attacks through a small number of support set samples
[0081] Step 302, the specific training process is as follows: First, train to obtain the classification loss L(θ t ) through the binary cross-entropy loss function.
[0082]
[0083] It should be noted that for multi-classification problems, multi-classification cross-entropy is used. Then, update the parameters θ′ t in the auxiliary network G(θ aux ) according to the gradient descent method: t :
[0084]
[0085] where α and represent the meta-learning rate and gradient respectively. Note that formula (6) only contains one-step gradient update, and it can be directly extended to multi-step gradient updates.
[0086] Apply the updated gradient to the query set for testing, and obtain the meta-knowledge of t by calculating the loss L(θ′ ). For different The optimization objective of the present invention is to learn a self-learning model G(θ * ) that can quickly adapt to different past . In this way, when facing new , the model G(θ * ) can achieve fast knowledge transfer. More specifically, the meta-objective function is defined as:
[0087]
[0088] Formally, use the gradient descent method to obtain a self-learning model G(θ * ): * :
[0089]
[0090] where β is the meta-step size. Then use G(θ * ) * to perform few-shot fine-tuning on the new WAID task :
[0091]
[0092] where θ′ new represents the parameters of the updated network G(θ′ new ). representation loss. Finally, predictions can be made for the new task:
[0093]
[0094] The step 4) includes the following process:
[0095] Step 401, method evaluation: The data comes from the publicly available AWID dataset, which contains the largest number of Wi-Fi network data collected from real network environments. It contains four types: normal instances, fakes, floods, and injections, and the ratio of normal instances to attack instances in the training set is 33:1:1:1.35. To verify the performance of Meta-WF in identifying new tasks, 3 of these types are used as historical data, and the remaining type is used as new task data. Since the success of meta-learning depends on large and diverse historical classification tasks, 2 types are randomly selected from the 3 types to form the historical WAID tasks. In the test phase, new WAID tasks are formed using normal samples and new attack types. Therefore, for the purpose of testing, each WAID task is defined as a binary classification task, that is, classifying normal and new anomalies.
[0096] Step 402, evaluation metrics: To quantitatively evaluate the performance of the WAID task, accuracy (Acc), precision (Prec i ), recall (Rc i ) and F1_score are used as the measurement criteria:
[0097]
[0098]
[0099] where TP i , TN i , FP i , FN i respectively represent the true positive, true negative, false positive, and false negative of the i-th label in the label set.
[0100] Experiment description: Figure 2 a shows the results of fine-tuning a new WAID task (such as IM) using 50 samples from the training set. The results show that the proposed Meta-WF in the present invention can improve the accuracy of the initial network from 50% to 98% with only one-step fine-tuning. However, the traditional DNN algorithm is difficult to improve the performance of new tasks due to insufficient data and requires longer fine-tuning steps, which indicates that the proposed method has a fast adaptation speed and can solve the problem of insufficient data for new tasks. Figure 2The results of b show the fast adaptation performance of Meta_WF under different WAID task requirements and different fine-tuning steps, demonstrating the applicability of Meta_WF.
[0101] The system implementing the few-shot Wi-Fi spoofing attack detection method based on meta-learning of the present invention includes a data preprocessing module, a deep feature extraction module, a meta-knowledge transfer module of multiple auxiliary networks, and a method evaluation module that are connected in sequence; the data preprocessing module, the deep feature extraction module, the meta-knowledge transfer module of multiple auxiliary networks, and the method evaluation module respectively correspond to the contents of steps 1) to 4) of the method of the present invention.
[0102] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than limiting it. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art can still make other modifications or changes in different forms according to the foregoing embodiments or the accompanying drawings. It is impossible to enumerate all implementation manners or technical solutions here. All modifications, replacements, etc. within the principles of the present invention should be included within the scope of protection required by the present invention.
Claims
1. A few-shot Wi-Fi spoofing attack detection method based on meta-learning, characterized in that It includes the following steps: 1) Data preprocessing: The data comes from the publicly available AWID dataset, which contains a large amount of Wi-Fi impersonation attack traffic data collected from real network environments; First, convert the network traffic features into images, and the number of image channels is consistent with the number of layers of the network protocol hierarchical framework. Second, perform one-hot encoding on the data labels; 2) Deep feature extraction: Use a convolutional neural network (CNN) to process the data and extract protocol space structure features; To improve the feature learning performance, input the original features and the extracted features into multiple fully connected layers together; 3) Meta-knowledge transfer of multiple auxiliary networks: Construct multiple auxiliary networks to learn meta-knowledge from different historical Wi-Fi impersonation attack detection (WAID) tasks respectively and transfer the knowledge to the new WAID task with few-shot problems; Specifically, it includes the following processes: Step 301, constructing WAID tasks: for different WAID tasks T t , build several auxiliary networks Train separately, where θ t represents the model parameters of the t-th WAID task; then the WAID task is defined as Where T, N, K, Q represent the number of tasks, the number of categories, and the support set S respectively. t Quantity, query set Q t quantity, and Y i t denote the data samples and labels of the t-th WAID task respectively; a WAID task can be considered as a small number of support set samples Identify unknown Wi-Fi spoofing attacks in and Represent data samples and labels respectively; Step 302, the specific training process is as follows: First, train S t , and obtain the classification loss L(θ t ) through the binary cross-entropy loss function Then update the parameters θ t ) aux in the auxiliary network G(θ t ′: where α and represent the meta-learning rate and the gradient of T t respectively; Update the gradient for the query set Q t Test by calculating the loss L(θ t ′) to obtain T t of the meta-knowledge; For different Ts t , the meta-objective function is defined as: Formally, the gradient descent method is used to obtain a self - learning model G(θ * ) * : where β is the meta-step size; then use G(θ * ) * to perform few-shot fine-tuning on the new WAID task T new : Among them, θ′ new represents the parameters of the updated network G(θ′ new ); denotes the loss of T new ={X new , Y new}, where X new and Y new represent the new test sample and label respectively; finally, predictions can be made for the new task: Among them, F(X new ; θ′ new ) is the fully connected layer feature; FC s () is the fully connected layer mapping function; 4) Method evaluation: Use Accuracy, Precision, Recall, and F1_score to evaluate the performance of the small-sample Wi-Fi impersonation attack detection method based on meta-learning; Specifically, it includes the following steps: Step 401, Method evaluation: The data comes from the publicly available AWID dataset, which contains the largest number of Wi-Fi network data collected from real network environments; It includes four types: normal instances, impersonation attacks, flood attacks, and injection attacks, and the ratio of normal instances to attack instances in the training set is 33:1:1:1.35; In the training stage, randomly select 2 attack types and normal instances from 3 attack types to form a historical WAID task; In the test stage, use normal samples and new attack types to form a new WAID task; Define each WAID task as a binary classification task, that is, classify normal and new anomalies; Step 402, Evaluation Metrics: To quantitatively evaluate the performance of the WAID task, the accuracy Acc, precision Prec i , recall Rc i and F1_score are used as the measurement criteria: Among them, TP i , TN i , FP i , FN i respectively represent the true positive, true negative, false positive, and false negative of the i-th label in the label set.
2. The small-sample Wi-Fi camouflage attack detection method based on meta-learning according to claim 1, wherein The data preprocessing in step 1) includes: Step 101, data preprocessing phase. The AWID dataset is a network traffic dataset based on the IEEE 802.11 network protocol. First, make be the network traffic dataset, where represents the M-dimensional original features, represents the N-dimensional labels after one-hot encoding, represents the real number space; Step 102: Input the original feature X i into c convolutional (conv) layer channels to obtain spatial structure information through protocol frames Among them, h and w represent the length and width of the convolutional channels respectively; Each traffic volume X can be converted into an image of c×h×w through the above formula. Different protocol frames have different h and w. If i where H and W represent the uniform length and width of each image channel, multiple "0"s need to be added to keep H and W consistent. 3. The method for detecting small-sample Wi-Fi camouflage attacks based on meta-learning according to claim 2, wherein The deep feature extraction in step 2) includes the following processes: Step 201, input the processed data into a Convolutional Neural Network (CNN), and the spatial structure feature f can be extracted by the following formula i S : Among them, w' and b represent the weights and biases of the CNN parameter θ; To obtain d-dimensional features The original features should be considered to further improve the performance of feature learning; the embedding X i is used as an auxiliary feature and is converted together with i to the fully-connected layer feature F(X ; θ): Finally, using multi-layer convolution and the fully connected layer mapping function FC s , the attack prediction label for the WAID task can be obtained 。 4. A system for implementing the few-shot Wi-Fi camouflage attack detection method based on meta-learning according to claim 1, characterized in that, It includes a data preprocessing module, a deep feature extraction module, a meta-knowledge transfer module of multiple auxiliary networks, and a method evaluation module connected in sequence. Among them, The data preprocessing module is used to preprocess the data; The data comes from the publicly available AWID dataset, which contains a large amount of Wi-Fi impersonation attack traffic data collected from real network environments; First, convert the network traffic features into images, and the number of image channels is consistent with the number of layers of the network protocol hierarchical framework. Second, perform one-hot encoding on the data labels; The deep feature extraction module is used to process the data using a convolutional neural network (CNN) and extract protocol space structure features; To improve the feature learning performance, input the original features and the extracted features into multiple fully connected layers together; A meta-knowledge transfer module for multiple auxiliary networks, which is used to construct multiple auxiliary networks to learn meta-knowledge from different historical Wi-Fi impersonation attack detection (WAID) tasks respectively and transfer the knowledge to a new WAID task with few-shot problems; specifically including the following process: Step 301, constructing WAID tasks: for different WAID tasks T t , construct several auxiliary networks G(θ t ) aux = {G(θ t ) aux |t∈T} are trained separately, where θ t represents the model parameters of the t-th WAID task; then the WAID task is defined as Where T, N, K, Q represent the number of tasks, the number of categories, and the support set S respectively. t Quantity, query set Q t quantity, and Y i t denote the data samples and labels of the t-th WAID task respectively; a WAID task can be considered as a small number of support set samples Identify unknown Wi-Fi spoofing attacks in and Y i n Represent data samples and labels respectively; Step 302, the specific training process is as follows: First, train S t , and obtain the classification loss L(θ t ) through the binary cross-entropy loss function Then update the parameters θ t ) aux in the auxiliary network G(θ t ′: Among them, α and represent the meta learning rate and the t gradient of T, respectively; Update the gradients for query set Q t Test by calculating the loss L(θ t ′) to obtain T t of the meta-knowledge; for different T t , the meta-objective function is defined as: Formally, the gradient descent method is used to obtain a self - learning model G(θ * ) * : where β is the meta-step size; then use G(θ * ) * to perform few-shot fine-tuning on the new WAID task T new as follows: Among them, θ′ new represents the parameters of the updated network G(θ′ new ), denotes the loss of T new ={X new , Y new}, where X new and Y new represent the new test sample and label respectively; finally, predictions can be made for the new task: Among them, F(X new ; θ′ new ) is the fully connected layer feature; FC s () is the fully connected layer mapping function; A method evaluation module, which is used to evaluate the performance of a few-shot Wi-Fi impersonation attack detection method based on meta-learning; use Accuracy, Precision, Recall, and F1_score to evaluate the performance of the few-shot Wi-Fi impersonation attack detection method based on meta-learning; specifically including the following steps: Step 401, method evaluation: The data comes from the publicly available AWID dataset, which contains the largest number of Wi-Fi network data collected from real network environments; it contains four types: normal instances, impersonation attacks, flooding attacks, and injection attacks, and the ratio of normal instances to attack instances in the training set is 33:1:1:1.35; in the training phase, randomly select 2 attack types and normal instances from 3 attack types to form a historical WAID task; in the test phase, use normal samples and new attack types to form a new WAID task; define each WAID task as a binary classification task, that is, classify normal and new anomalies; Step 402, Evaluation Metrics: To quantitatively evaluate the performance of the WAID task, the accuracy Acc, precision Prec i , recall Rc i and F1_score are used as the measurement criteria: Among them, TP i , TN i , FP i , FN i respectively represent the true positive, true negative, false positive, and false negative of the i-th label in the label set.
Citation Information
Patent Citations
Network traffic protocol recognition method based on deep learning
CN107682216A
Method and system for constructing network intrusion detection model based on transfer learning
CN110224987A