Anomaly Detection Method and System Based on Large-Scale Graph Neural Network

By converting the target scene into a graph structure, using feature matrix decomposition and multi-layer perceptron, the problems of high time complexity and detection accuracy of abnormality detection in large-scale graph neural networks are solved, and real-time abnormality detection on dynamic graphs is realized.

CN115310540BActive Publication Date: 2025-07-11RENMIN UNIVERSITY OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210950334.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-09
Publication Date
2025-07-11
Estimated Expiration
2042-08-09

AI Technical Summary

Technical Problem

The existing anomaly detection method based on graph neural networks is difficult to effectively expand on large-scale graphs, resulting in high time complexity and inability to meet the requirements of real-time detection. In addition, information loss in dynamic graphs is serious, affecting detection accuracy.

Method used

The object relationship in the target scene is converted into a graph structure, through feature matrix decomposition and information transmission, abnormal detection is performed using multi-layer perceptrons, combined with feature propagation vectors and error vectors, abnormal detection of large-scale graphs is realized, and real-time updates are performed when the graph structure changes.

Benefits of technology

Anomaly detection on large-scale graphs is realized within the effective time, reducing time complexity, meeting real-time detection requirements, and improving detection accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115310540B_ABST
    Figure CN115310540B_ABST
Patent Text Reader

Abstract

The present invention discloses an anomaly detection method based on a large-scale graph neural network, including: converting the relationships between objects in a target scenario into a first graph structure; obtaining a feature matrix based on the first graph structure; the feature matrix includes node features in the first graph structure; obtaining a feature propagation vector and an error vector of the feature matrix during the information transmission process; the feature propagation vector represents the amount of information that has been transmitted between nodes in the feature matrix; the error vector represents the amount of information that has not been transmitted between nodes in the feature matrix; obtaining a final node feature vector of the feature matrix according to the feature propagation vector and the error vector; calculating an identification result of a node according to the final node feature vector to perform anomaly detection. The method of the present invention can achieve anomaly detection on a large-scale graph and obtain the identification results of all nodes on the graph within an effective time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and more particularly to an anomaly detection method and system based on a large-scale graph neural network. Background Art

[0002] An anomaly refers to one that is significantly different from others. In different application fields, an anomaly object is usually considered to have an obvious difference from the standard, normal or expected. In a real scenario, anomalies may manifest as senders of spam, fraudsters or fake users in a social network, network intruders or malware in a computer network, and damaged devices or faulty blocks in an industrial system. Although these anomaly objects may rarely occur in the real world, they usually have real and adverse effects. For example, fake news in social media can cause panic and chaos and may spread misleading beliefs to the public. Unreliable reviews in an online review system can affect customers' shopping choices. Network intrusion may disclose personal privacy data information, and abnormal data may also cause huge economic losses.

[0003] Anomaly detection is a data mining process aimed at identifying abnormal patterns that deviate from the majority in a dataset. To detect anomalies, traditional techniques usually represent real-world objects as feature vectors. For example, the bag-of-words is used to represent news in a social media, and the color histogram is used to represent images in a web page, and then abnormal data points are detected in the vector space. Although these techniques have shown the ability to locate abnormal data points in tabular data format, they do not consider the complex relationships between objects, resulting in low detection accuracy. In a real scenario, there are rich relationships between objects, which can provide valuable supplementary information for anomaly detection. Taking a social network as an example, a fake user can use valid information from normal users to create an account, or can disguise themselves by imitating the attributes of benign users. In this case, the fake user and the benign user will have almost the same features, and traditional anomaly detection techniques may not be able to identify them only using feature information. However, fake users always establish relationships with a large number of benign users to increase their reputation and influence in order to gain benefits from it, while benign users rarely show such activities. Therefore, these dense and unreasonable connections formed by fake users show their deviation from benign users, and a more comprehensive detection technique should take these structural information into consideration to identify abnormal deviation patterns.

[0004] A graph is a data structure frequently used in computer science that can easily model things and their relationships, where nodes represent real objects and edges represent their relationships. As graph data has become ubiquitous in the Web era, graph-structured information plays a crucial role in identifying abnormal data such as fraudulent users or activities. Graph neural networks, as a popular method for mining graph-structured data, can be naturally applied to anomaly detection tasks and can be learned end-to-end without relying on a manually crafted feature process or a statistical model constructed by domain experts. However, since previous graph neural network-based methods require message passing and weight learning to interact in the graph structure, it is difficult to scale to large-scale data, thus affecting the actual application effect of the algorithm. On the other hand, graph neural network-based methods are usually designed based on static graphs. For frequently changing dynamic graphs, they can only be discretized into a sequence of static graph snapshots for processing, but a large amount of dynamic information will be lost after discretization, affecting the accuracy of anomaly detection.

[0005] The information disclosed in this background section is only intended to increase the overall understanding of the present invention and should not be regarded as an admission or any form of suggestion that this information constitutes prior art already known to those of ordinary skill in the art. Summary of the Invention

[0006] The purpose of the present invention is to provide an anomaly detection method and system based on a large-scale graph neural network, which can achieve anomaly detection on a large-scale graph, obtain the recognition results of all nodes on the graph within an effective time, and at the same time meet the accuracy requirements of the calculation results so as to accurately locate abnormal nodes, reduce the time complexity, and meet the requirements of real-time detection.

[0007] To achieve the above object, the present invention provides an anomaly detection method based on a large-scale graph neural network, and the method includes:

[0008] Convert the relationships between objects in the target scenario into a first graph structure; wherein, the objects correspond to the nodes of the first graph structure, and the relationships between the objects correspond to the edges of the first graph structure;

[0009] Obtain a feature matrix based on the first graph structure; the feature matrix includes the node features in the first graph structure, and the node features are the attribute information of the nodes;

[0010] Obtain the feature propagation vector and error vector of the feature matrix during the information transmission process; the feature propagation vector represents the amount of information that has been transmitted between nodes in the feature matrix; the error vector represents the amount of information that has not been transmitted between nodes in the feature matrix;

[0011] Obtain the final node feature vector of the feature matrix according to the feature propagation vector and the error vector;

[0012] Calculate the recognition result of the node based on the final node feature vector for anomaly detection.

[0013] Preferably, the method further includes:

[0014] Decompose the feature matrix into d feature vectors; where d represents the dimension of the node features;

[0015] Obtain the feature propagation vector and error vector of each feature vector respectively;

[0016] Obtain the final node feature vector of the feature matrix based on the feature propagation vector and error vector of each feature vector.

[0017] Preferably, obtaining the feature propagation vector of each feature vector includes:

[0018] Obtain the predicted value and error value of each node in the feature vector;

[0019] Judge whether the error value of each node satisfies the preset condition |r1(s)| < ε;

[0020] If so, take α times of the error value as the updated predicted value, and distribute the remaining 1 - α times to each in - neighbor node to be converted into the error value of the in - neighbor node, where r1(s) is the error value, ε is the error threshold, α is the transfer parameter, and 0 < α < 1;

[0021] If not, obtain the feature propagation vector of the feature vector.

[0022] Preferably, the d feature vectors perform information transfer independently.

[0023] Preferably, calculating the recognition result of the node based on the final node feature vector includes: taking the final node feature vector as the input of the multi - layer perceptron;

[0024] After iteratively updating the parameters of the multi - layer perceptron several times, calculate the recognition result of the node; where: the multi - layer perceptron is a feed - forward neural network with multiple layers, and the feed - forward neural network includes: an input layer, a hidden layer, and an output layer.

[0025] Preferably, the method further includes:

[0026] When the first graph structure changes to the second graph structure, locate the affected changed nodes in the second graph structure;

[0027] Calculate the increment of the changed nodes and superimpose it on the feature propagation vector and error vector of the feature vector to obtain the changed feature propagation vector and error vector.

[0028] Preferably, the change from the first graph structure to the second graph structure includes: inserting directed edges, deleting directed edges, and updating node features.

[0029] Preferably, the method further includes: obtaining the feature propagation vectors in the second graph structure based on the changed feature propagation vectors and error vectors, and forming a feature propagation matrix under the second graph structure;

[0030] Obtaining the feature propagation vectors and error vectors based on the feature propagation matrix.

[0031] In an embodiment of the present invention, an anomaly detection system based on a large-scale graph neural network, the system includes:

[0032] A conversion unit, configured to convert the relationships between objects in a target scenario into a first graph structure; wherein, the objects correspond to the nodes of the first graph structure, and the relationships between the objects correspond to the edges of the first graph structure;

[0033] A first obtaining unit, configured to obtain a feature matrix based on the first graph structure; the feature matrix includes the node features in the first graph structure, and the node features are the attribute information of the nodes;

[0034] A second obtaining unit, configured to obtain the feature propagation vectors and error vectors of the feature matrix during the information transmission process; the feature propagation vectors represent the amount of information that has been transmitted between nodes in the feature matrix; the error vectors represent the amount of information that has not been transmitted between nodes in the feature matrix;

[0035] A third obtaining unit, configured to obtain the final node feature vectors of the feature matrix according to the feature propagation vectors and error vectors;

[0036] A calculation unit, configured to calculate the recognition results of the nodes according to the final node feature vectors for anomaly detection.

[0037] In an embodiment of the present invention, a computer-readable storage medium stores a program, and when the program is executed, it implements the steps of the anomaly detection method based on a large-scale graph neural network as described in any one of the above.

[0038] Compared with the prior art, the anomaly detection method and system based on a large-scale graph neural network according to the present invention can achieve anomaly detection on a large-scale graph, obtain the recognition results of all nodes on the graph within an effective time, and at the same time meet the accuracy requirements of the calculation results, so as to accurately locate the abnormal nodes, reduce the time complexity, and meet the requirements of real-time detection. Description of the Drawings

[0039] Figure 1 It is a flowchart of an anomaly detection method based on a large-scale graph neural network according to an embodiment of the present invention;

[0040] Figure 2 It is a flowchart of an information transmission method according to an embodiment of the present invention;

[0041] Figure 3 It is a structural diagram of an anomaly detection system based on a large-scale graph neural network according to an embodiment of the present invention. Specific embodiments

[0042] Next, with reference to the accompanying drawings, the specific embodiments of the present invention will be described in detail, but it should be understood that the protection scope of the present invention is not limited by the specific embodiments.

[0043] Unless otherwise clearly stated, throughout the specification and claims, the term "comprising" or its variations such as "comprises" or "including" etc. will be understood to include the stated elements or components, without excluding other elements or other components.

[0044] As Figures 1 to 2 shown, an anomaly detection method based on a large-scale graph neural network according to a preferred embodiment of the present invention, the method includes:

[0045] Step S1, converting the relationships between objects in the target scenario into a first graph structure G; wherein, the objects correspond to the nodes of the first graph structure G, and the relationships between the objects correspond to the edges of the first graph structure G. Specifically, the objects in the target scenario can be all registered users of a social platform or a financial system, and the relationships between the objects can be follow relationships or transaction relationships between users.

[0046] Step S2, obtaining a feature matrix based on the first graph structure; the feature matrix includes the node features in the first graph structure, and the node features are the attribute information of the nodes. All node features constitute an n×d-dimensional feature matrix X, where n represents that the first graph structure G contains n nodes, and d represents the number of dimensions of the node features, that is, the number of attribute information attached to the objects in the target scenario. For example, the attribute information of the nodes can be feature identification data such as the identity, gender, age, and region of the user. For example, all registered users and friend relationship networks on Weibo, and all registered accounts and transaction relationship networks on Xianyu.

[0047] Specifically, for social platforms with follow relationships such as Weibo, Xiaohongshu, and Douyin, the registered users on the social platform are mapped to the nodes on the first graph structure, the follow relationships between users are mapped to the edges on the first graph structure, and the attribute information such as the names, locations, and preferences of users can be regarded as the node features attached to the nodes. For example, user A and user B on the social platform are two nodes on the first graph structure. If user A follows user B, then an edge pointing from node B to node A is constructed on the first graph structure, i.e., B—>A. Therefore, node A can be called the out-neighbor node of node B, and node B is the in-neighbor node of node A. For each node v s the number of its out-neighbor nodes is called the out-degree d out (s), and the number of its in-neighbor nodes is called the in-degree d in (s).

[0048] For financial networks with transaction information such as Xianyu and Ethereum, all registered accounts on the financial network can be mapped to the nodes on the first graph structure, the transaction relationships are mapped to the edges on the first graph structure, and the attribute information such as the usernames, locations, and preferences of the accounts can be regarded as the node features attached to the nodes. For example, user A and user B on the financial network are two nodes on the first graph structure. If user A purchases an item from user B, that is, a transaction occurs between the two users, then an edge pointing from node B to node A is constructed on the first graph structure, i.e., B—>A.

[0049] Step S3, obtain the feature propagation vector and error vector of the feature matrix during the information transmission process; the feature propagation vector represents the amount of information that has been transmitted between nodes in the feature matrix; the error vector represents the amount of information that has not been transmitted between nodes in the feature matrix. Specifically, the feature propagation vector is obtained after the information transmission process ends.

[0050] Step S4, obtain the final node feature vector of the feature matrix according to the feature propagation vector and the error vector; the final node feature vector is obtained after the nodes under the first graph structure have undergone feature propagation.

[0051] Step S5, calculate the recognition result of the node according to the final node feature vector for anomaly detection. Specifically, the recognition result of the node v s can be 0 or 1. If the recognition result is 0, it means that the node v s is a normal node, otherwise if the recognition result is 1, it means that the node v s is an abnormal node, that is, the object corresponding to this node is abnormal, and finally anomaly detection is performed according to the recognition result.

[0052] Network data in the target scenario usually contains millions of nodes and edges, which generate extremely high-dimensional and large-scale data. Existing technologies are generally limited by storage space and execution time and are difficult to scale to such data. The method described in the embodiments of the present invention can enable each dimension of features to be propagated independently and then distributed to different CPU cores to further improve the computing efficiency.

[0053] The anomaly detection method based on a large-scale graph neural network according to a specific embodiment of the present invention, preferably, the method further includes:

[0054] Decompose the feature matrix into d feature vectors; where d represents the dimension of the node features.

[0055] Obtain the feature propagation vector and error vector of each feature vector respectively; start with the feature vector x1 to perform information transfer between all nodes in this feature dimension to obtain the feature propagation vector and the error vector r1, where x1 is an n-dimensional feature vector representing the first column of the feature matrix X, and the feature propagation vector is an n-dimensional vector, the number stored in the s-th (1 ≤ s ≤ n) dimension of is the sum of all information obtained by the node v s under the first graph structure, and its value is the predicted value that satisfies the error limit range condition. The information includes the information transferred from other nodes on the dynamic graph to the node v s and the transformation of the node v s 's own information. The error value is expressed as r1(s).

[0056] Obtain the final node feature vector of the feature matrix based on the feature propagation vector and error vector of each feature vector.

[0057] The anomaly detection method based on a large-scale graph neural network according to a specific embodiment of the present invention, preferably, obtaining the feature propagation vector of each feature vector includes:

[0058] Step S21, obtain the predicted value and error value of each node in the feature vector; specifically, the predicted value refers to the amount of information that has been transferred by the node v s and is initialized to 0. The error value r1(s) refers to the amount of information that has been received by the node v s but not yet transferred, and is initialized to x1(s), where x1(s) is the feature value stored in the s-th dimension of the feature vector x1.

[0059] Step S22, determine whether the error value of each node satisfies the preset condition |r1(s)| < ε;

[0060] Step S23, if so, then use α times of the error value as the updated predicted value, and distribute the remaining 1 - α times to each in - neighbor node to convert it into the error value of the in - neighbor node, where r1(s) is the error value, ε is the error threshold, α is the transfer parameter, and 0 ≤ α ≤ 1 is satisfied.

[0061] To reduce the error value of a node, find the node v in the feature matrix whose error value r1(s) does not satisfy the preset condition |r1(s)| < ε s , and convert α times of its error into the predicted value of node v s , and distribute the remaining 1 - α times to each in - neighbor node v t ∈N in (s), and convert it into the error value of the in - neighbor node, where ε is the preset error threshold, α is the transfer parameter, and the user can determine the specific value of α according to the actual situation and 0 ≤ α ≤ 1 is satisfied. N in (s) is the set composed of all in - neighbor nodes of the current node v s ;

[0062] The update formula for the predicted value of the current node v s is:

[0063]

[0064] The update formula for the error value of each in - neighbor node v t ∈N in (s) is:

[0065]

[0066] where, represents the updated predicted value of the current node v s , r'1(t) represents the updated error value of the in - neighbor node v t ∈N in (s), d out (t) is the out - degree of the in - neighbor node v t ;

[0067] Repeat steps S22 and S23. If the error values of all points in the obtained first graph structure satisfy the preset condition |r1(s)| < ε, then end the information transfer process and obtain the feature propagation vector

[0068] Step S24, if not, then obtain the feature propagation vector of the feature vector.

[0069] Specifically, during the execution of steps S22 and S23, each node in the feature vector always maintains the identity on that node

[0070]

[0071] This identity corresponds to the relationship between the predicted value and the error value at this node and its neighbor nodes and features. For example, for any node v s , the predicted value of this node plus α times the error value is always equal to α times the feature value plus the part that will be converted into the error value of node v s after the next information passing, that is, the sum of (1 - α) times the predicted values of all out-neighbor nodes divided by the degree of node v s .

[0072] In the anomaly detection method based on a large-scale graph neural network according to a specific embodiment of the present invention, preferably, the d feature vectors perform information passing independently. Specifically, the n×d-dimensional feature matrix X is decomposed into d independent feature vectors {x1, x2, …, x d}, where d represents the dimension of the node attributes on the first graph structure. The calculation process of the information passing for each dimension is repeatedly executed to obtain the feature propagation vectors on all dimensions in the first structure diagram that form the feature propagation matrix Z under the current first graph structure. The feature propagation matrix Z is an n×d-dimensional matrix, and the s-th row of the matrix represents the final node feature vector z s of node v after feature propagation under the current first graph structure s . The final node feature vector z s is a d-dimensional vector, and the i-th dimension of the final node feature vector z s stores the predicted value at node v i after the information passing is completed s .

[0073] Since the d feature vectors {x1, x2, …, x d} perform information passing independently, the d times of information passing on the first graph structure are parallelizable. That is, when calculating on a multi-core CPU, the information passing for one dimension can be executed on each core of the CPU. If the number of cores of the CPU is d, the information passing for all dimensions can start simultaneously, thereby further shortening the calculation time

[0074] In the anomaly detection method based on a large-scale graph neural network according to a specific embodiment of the present invention, preferably, calculating the recognition result of a node according to the final node feature vector includes:

[0075] Taking the final node feature vector as the input of a multi-layer perceptron

[0076] After iteratively updating the parameters of the multi-layer perceptron E times, the recognition result of the node is calculated; where: the multi-layer perceptron is a feed-forward neural network with L layers, and the feed-forward neural network includes: an input layer, a hidden layer, and an output layer. Wherein, the user can adjust the specific value of L according to actual needs.

[0077] For large-scale graph data, batch processing can be used to input the final node feature vectors into the GPU, and the recognition results of multiple nodes can be calculated simultaneously using the multi-layer perceptron. The user can adjust the batch size according to actual needs. For example, a batch size of 1024 means that 1024 final node feature vectors are input at a time to update the parameters of the multi-layer perceptron.

[0078] In a specific embodiment of the present invention, after the information transmission is completed, the parameter iterative update is performed, avoiding the information transmission and parameter update that are interactively performed in the prior art, enabling the information transmission process to be carried out on the CPU without being restricted by the GPU. Therefore, the scalability of the present invention is improved, and anomaly detection on a large-scale graph can be realized.

[0079] In the anomaly detection method based on a large-scale graph neural network described in a specific embodiment of the present invention, preferably, the method further includes:

[0080] When the first graph structure changes to the second graph structure, locate the affected changed nodes in the second graph structure; specifically, convert the changes that occur over time in the objects and the relationships between objects in the target scenario into changes in the graph structure, that is, change from the first graph structure to the second graph structure. For the change in the graph structure, first locate all the affected nodes directly involved in this change on the second graph structure.

[0081] Calculate the increment of the changed nodes and superimpose it on the feature propagation vector and error vector of the feature vector to obtain the changed feature propagation vector and error vector. According to the identity on the node, quantify the impact of this change on each affected node, and superimpose this part of the increment on the feature propagation vector and the error vector {r1, r2,..., r d}.

[0082] Specifically, for social platforms with follow relationships such as Weibo, Xiaohongshu, and Douyin, over time, new follow relationships will be formed among users. Due to operations such as unfollowing, existing follow relationships will be deleted. There may also be updates to attribute information such as changes in user preferences or frequent activity locations. Among them, the formation and deletion of follow relationships can correspond to changes in the graph structure, and updates to attribute information can correspond to changes in node features.

[0083] In the anomaly detection method based on large-scale graph neural network described in the specific embodiment of the present invention, preferably, the change of the first graph structure to the second graph structure includes: inserting directed edges, deleting directed edges and updating node features. Specifically, if user A newly follows user C, a directed edge from user C to user A is inserted in the graph structure, that is, C—>A. If user A cancels the follow-up to user B, the directed edge from user B to user A is deleted in the graph structure, that is, B—>A. If the hobbies, region, etc. of user A change, the features of the nodes corresponding to user A are updated in the graph structure, that is, {x1(A), x2(A),…, x d (A)}.

[0084] In one implementation, the following steps may be included:

[0085] If a graph structure change occurs, and the change is the insertion of a directed edge, such as v u →v v , then the source node of the directed edge, that is, node v u For the directly affected nodes, calculate the node v u New out-degree, d' out (u) = d out (u)+1, then in each dimension i, node v u The equation changes to:

[0086]

[0087] Calculate the inserted edge v u →v v The resulting increment in dimension i is:

[0088]

[0089] This part of the increment is superimposed on each error vector r i ,have

[0090] If a graph structure change occurs, and the change is the deletion of a directed edge, such as v u →v v , then the source node of the directed edge, that is, node v u For the directly affected nodes, calculate the node v u New out-degree, d' out (u) = d out (u)-1, then in each dimension i, node v u The equation changes to:

[0091]

[0092] It is calculated that the deleted edge is v u →v v The increment on dimension i caused thereby is:

[0093]

[0094] This part of the increment is superimposed on each error vector r i , and there is

[0095] If there is a change in the graph structure and the change is to update the node feature, such as x' i (u) = x i (u) + Δx i (u), where i represents the dimension in which the node feature is updated, and 1 ≤ i ≤ d, then the node where the feature update occurs, that is, node v u is considered as the directly involved affected node, and then the equation change on node v u on dimension i is:

[0096]

[0097] It is calculated that the increment caused by updating the node feature x i (u) is This part of the increment is superimposed on the u-th dimension of the error vector r i , that is

[0098] Large-scale graphs evolve continuously over time, which further exacerbates the difficulty of analysis. Existing technologies cannot output the anomaly detection results on large graphs within the effective time after the graph changes, and cannot meet the requirements of real-time detection. The above embodiments of the present invention can achieve anomaly detection on dynamic graphs, obtain the recognition results of all nodes on the graph within the effective time, and at the same time meet the accuracy requirements of the calculation results so as to accurately locate the anomaly nodes, reduce the time complexity, and meet the requirements of real-time detection.

[0099] For the anomaly detection method based on a large-scale graph neural network described in the specific embodiments of the present invention, preferably, the method further includes: obtaining the feature propagation vector in the second graph structure according to the changed feature propagation vector and error vector and forming the feature propagation matrix under the second graph structure;

[0100] Obtaining the feature propagation vector and error vector based on the feature propagation matrix.

[0101] Specifically, the obtained updated feature propagation vector and error vectors {r1, r2,..., r d}, perform the information transfer calculation process described in steps S22 and S23 again to obtain the feature propagation vectors that meet the error limit range condition in all dimensions of the second graph structure to form the feature propagation matrix Z under the current second graph structure, where the feature propagation matrix Z is an n×d-dimensional matrix, and the s-th row of the matrix represents the node v under the second graph structure s the final node feature vector z after feature propagation s , the final node feature vector z s is a d-dimensional vector, and the i-th dimension of z s stores the predicted value at the node v s after the information transfer is completed on the current graph structure.

[0102] The specific information transfer calculation process includes:

[0103] Maintain the predicted value s and the error values {r1(s), r2(s), …, r (s)} for each node v d on the second graph structure, where the predicted value refers to the s-th dimension of the obtained updated feature propagation vector, and the error values {r1(s), r2(s), …, r d (s)} refer to the s-th dimension of the updated error vector;

[0104] Find the nodes v i in the second graph structure where the error value r i (s) does not meet the preset condition |r s (s)| < ε, and convert α times of its error into the predicted value of the node v s , and distribute the remaining 1 - α times to each in-neighbor node v t ∈N in (s), which is converted into the error value of the in-neighbor node, where ε is the pre-set error threshold, α is the transfer parameter, and the user can determine the specific value of α according to the actual situation and satisfy 0 ≤ α ≤ 1, and N in (s) is the set composed of all in-neighbor nodes of the current node v s ;

[0105] The update formula for the predicted value of the current node v s is:

[0106]

[0107] The update formula for the error value of each in-neighbor node v t ∈N in (s) is:

[0108]

[0109] Among them, represents the current node v s The updated predicted value, r' i (t) represents the in-neighbor node v t ∈N in (s) The updated error value, d out (t) is the in-degree of the in-neighbor node v t ;

[0110] Repeat the above update operation. If the error values of all points in the second graph structure in each dimension satisfy the preset condition |r i (s)| < ε, then end the information propagation process and obtain the feature propagation vector

[0111] For each feature propagation vector The time taken to complete the information propagation process is:

[0112] where ε is a preset error threshold and is usually set α is the transfer parameter, n is the number of nodes in the graph, and π i represents the true value vector corresponding to the feature propagation vector If π i is the one-hot encoded vector e s , that is, only the s-th dimension of the vector is 1 and the remaining dimensions are all 0, and α = 1 is set, then the time complexity of completing the information propagation process is O(1), and the median value in each dimension of the feature propagation vector satisfies the preset condition |r i (s)| < ε. Therefore, the method described in the present invention can immediately obtain the final feature propagation result of the node after the graph changes, thus supporting real-time detection.

[0113] Take the obtained final feature propagation result as the input of the multi-layer perceptron and execute the training process again, so as to obtain the latest recognition result on all nodes. The recognition result value of the node v s is 0 or 1. If the recognition result value is 0, it means that the node v s is a normal node, otherwise the recognition result value is 1, which means that the node v s is an abnormal node, and the real object corresponding to this node is the abnormality to be detected by the present invention.

[0114] In one implementation, this embodiment also provides an incremental calculation method for batch-coming graph structure changes, including:

[0115] Complete the graph structure changes that arrive in batches on the existing graph structure, and store all the affected nodes involved in the set V affected ;

[0116] For each affected node v affected in the set V u , calculate the change Δd out (u) = d' out (u) + d out (u), where d out (u) is the out-degree of the node v u before the graph structure change, and d' out (u) refers to the out-degree of the node v u after the completion of the graph structure changes that arrive in batches. Calculate the new predicted value of this node in each dimension i:

[0117]

[0118] Calculate the increment of the error value of the node v u in each dimension i caused by the updated predicted value:

[0119]

[0120] Update the new error value r' u of the node v i (u) = r i (u) + Δr i (u), where i represents the dimension, and its value is {1, 2,..., d}, and d is the dimension of the node features on the graph structure;

[0121] It should be noted that the calculation processes of the predicted values and error values of all nodes are independent. Therefore, the calculation processes of different nodes can be assigned to different CPU cores to further improve the calculation efficiency.

[0122] Based on the new predicted values and error values of all nodes obtained in the above steps, for each affected node v affected in the set V u , count its new neighbors and store them in the set N add , count its deleted neighbors and store them in the set N delete , and calculate the impacts caused by its new neighbors and deletions in each dimension i:

[0123]

[0124] Update the new error value r″ u of the node v i (u) = r″ i(u) + Δr′ i (u).

[0125] A specific embodiment of the present invention further provides an anomaly detection system based on a large-scale graph neural network, as Figure 3 shown. The system includes:

[0126] A conversion unit 301, configured to convert the relationships between objects in a target scenario into a first graph structure; wherein, the objects correspond to the nodes of the first graph structure, and the relationships between the objects correspond to the edges of the first graph structure;

[0127] A first acquisition unit 302, configured to acquire a feature matrix based on the first graph structure; the feature matrix includes the node features in the first graph structure, and the node features are the attribute information of the nodes;

[0128] A second acquisition unit 303, configured to acquire a feature propagation vector and an error vector of the feature matrix during the information transmission process; the feature propagation vector represents the amount of information that has been transmitted between nodes in the feature matrix; the error vector represents the amount of information that has not been transmitted between nodes in the feature matrix;

[0129] A third acquisition unit 304, configured to acquire a final node feature vector of the feature matrix according to the feature propagation vector and the error vector;

[0130] A calculation unit 305, configured to calculate an identification result of a node according to the final node feature vector for anomaly detection.

[0131] A specific embodiment of the present invention further provides a computer-readable storage medium, on which a program is stored, and when the program is executed, the steps of the anomaly detection method based on a large-scale graph neural network according to any one of the above specific embodiments are implemented.

[0132] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0133] This application is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices to produce a machine, such that the instructions executed by the processors of the computer or other programmable data processing devices produce means for implementing the functions specified in the Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.

[0134] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including instruction means that implement the functions specified in the Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.

[0135] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in the Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.

[0136] The foregoing description of specific exemplary embodiments of the present invention is for purposes of illustration and exemplification. These descriptions are not intended to limit the present invention to the precise forms disclosed, and it is apparent that many changes and variations are possible in light of the above teachings. The purpose of selecting and describing the exemplary embodiments is to explain the specific principles of the present invention and its practical applications, so that those skilled in the art can implement and utilize the various different exemplary embodiments of the present invention, as well as various different selections and changes. The scope of the present invention is intended to be defined by the claims and their equivalents.

Claims

1. An anomaly detection method based on large-scale graph neural networks, characterized in that, The method includes: Converting the relationships between objects in a target scenario into a first graph structure; wherein, the objects correspond to the nodes of the first graph structure, and the relationships between the objects correspond to the edges of the first graph structure; the objects in the target scenario are all registered users of a social platform or a financial system, and the relationships between the objects are following relationships or transaction relationships between users; Obtaining a feature matrix based on the first graph structure; the feature matrix includes node features in the first graph structure, and the node features are attribute information of the nodes; the attribute information of the nodes is user identity, gender, age, and regional feature identification data; Obtaining a feature propagation vector and an error vector of the feature matrix during the information transmission process; the feature propagation vector represents the amount of information that has been transmitted between nodes in the feature matrix; the error vector represents the amount of information that has not been transmitted between nodes in the feature matrix; Obtaining the final node feature vector of the feature matrix according to the feature propagation vector and the error vector; Calculating the recognition result of a node according to the final node feature vector for anomaly detection.

2. The anomaly detection method based on a large-scale graph neural network according to claim 1, wherein The method further includes: Decompose the feature matrix into d feature vectors; where d represents the dimension of the node features. Respectively obtaining the feature propagation vector and the error vector of each feature vector; Obtaining the final node feature vector of the feature matrix based on the feature propagation vector and the error vector of each feature vector.

3. The anomaly detection method based on large-scale graph neural network according to claim 2, characterized in that, Obtaining the feature propagation vector of each feature vector includes: Obtaining the predicted value and the error value of each node in the feature vector; Determine whether the error value of each of the nodes meets a preset condition ; If so, use the times of the error value as the updated predicted value, and distribute the remaining times to each incoming neighbor node to convert it into the error value of the incoming neighbor node, where is the error value, is the error threshold, is the transfer parameter, and satisfies ; If not, then obtaining the feature propagation vector of the feature vector.

4. The anomaly detection method based on large-scale graph neural network according to claim 2, characterized in that, d The information transmission is independently performed for each of the feature vectors.

5. The anomaly detection method based on a large-scale graph neural network according to claim 2, wherein, Calculating the recognition result of a node according to the final node feature vector includes: Using the final node feature vector as the input of a multi-layer perceptron; After iteratively updating the parameters of the multi-layer perceptron several times, calculating the recognition result of the node; wherein: the multi-layer perceptron is a feedforward neural network with multiple layers, and the feedforward neural network includes: an input layer, a hidden layer, and an output layer.

6. The anomaly detection method based on large-scale graph neural network according to claim 2, characterized in that The method further includes: When the first graph structure changes to a second graph structure, locating the affected changed nodes in the second graph structure; Calculating the increment of the changed nodes and superimposing it on the feature propagation vector and the error vector of the feature vector to obtain the changed feature propagation vector and error vector.

7. The anomaly detection method based on large-scale graph neural network according to claim 6, characterized in that The change of the first graph structure to the second graph structure includes: inserting a directed edge, deleting a directed edge, and updating node features.

8. The anomaly detection method based on large-scale graph neural network according to claim 6, wherein, The method further includes: obtaining the feature propagation vector in the second graph structure according to the changed feature propagation vector and error vector and forming a feature propagation matrix under the second graph structure; Obtaining the feature propagation vector and the error vector based on the feature propagation matrix.

9. An anomaly detection system based on a large-scale graph neural network, characterized in that, The system includes: A conversion unit for converting the relationships between objects in a target scenario into a first graph structure; wherein, the objects correspond to the nodes of the first graph structure, and the relationships between the objects correspond to the edges of the first graph structure; A first acquisition unit for obtaining a feature matrix based on the first graph structure; the feature matrix includes node features in the first graph structure, and the node features are attribute information of the nodes; A second acquisition unit, configured to acquire a feature propagation vector and an error vector of the feature matrix during the information transmission process; the feature propagation vector characterizes the amount of information that has been transmitted between nodes in the feature matrix; the error vector characterizes the amount of information that has not been transmitted between nodes in the feature matrix; A third acquisition unit, configured to acquire a final node feature vector of the feature matrix according to the feature propagation vector and the error vector; A calculation unit, configured to calculate an identification result of a node according to the final node feature vector for anomaly detection.

10. A computer-readable storage medium, characterized in that, A program is stored on the computer-readable medium, and when the program is executed, the steps of the anomaly detection method based on a large-scale graph neural network according to any one of claims 1-8 are implemented.

Citation Information

Patent Citations

  • Social network abnormal user detection method and device based on heterogeneous graph neural network

    CN112861967A

  • Anomaly detection with graph adversarial training in computer systems

    US20210067549A1