Graph Neural Network Anomaly Detection Method and Device Based on Neighborhood Node Structure Encoding
Through the method based on neighboring node structure encoding, node structure features and higher-order neighborhood matrix are calculated, and abnormal detection is performed in combination with semantic features, the transformation invariance and oversmoothing problems of traditional graph neural networks in graph data processing is solved, and adaptive selection and efficient abnormal detection of key nodes are realized.
Patent Information
- Application Number
- CN202211424557.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-14
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2042-11-14
AI Technical Summary
When traditional graph neural networks process graph data, there are transformation invariance and excessive smoothing problems, making it difficult to effectively filter important neighborhood nodes and learn higher-order neighborhood information.
Through a method based on neighboring node structure encoding, node structure features and higher-order neighborhood matrix are calculated, and anomaly detection is performed in combination with semantic features. Anonymous random walk and recursive graph structure statistical features are used to extract structural features, and dynamically weighted through a multi-head attention mechanism. Finally, the graph neural network is trained using the cross entropy loss function.
It realizes adaptive selection of important neighborhood nodes, solves the problem of oversmoothing of graph neural networks, and improves the accuracy of abnormal detection, especially in network defense tasks, which can effectively screen out key nodes.
Smart Images

Figure CN115859143B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of anomaly detection, and particularly relates to a graph neural network anomaly detection method and device based on neighborhood node structure encoding. Background Art
[0002] With the development of deep learning, data-driven methods are used to solve practical problems in different fields, such as image recognition, speech recognition, natural language processing, etc. A graph neural network (GNN) is a model in deep learning for processing data with network topology structures, and its main tasks include node prediction, link prediction, community discovery, etc. On the one hand, the traditional graph convolutional network (GCN) has permutation invariance in the process of aggregating neighborhood information and cannot well screen important neighborhood nodes. On the other hand, there is an over-smoothing problem in the process of deepening the number of layers, and it cannot learn the neighborhood node information of high-order multi-hop distances. Summary of the Invention
[0003] In view of the above research background and technical status quo, in order to screen important neighborhood graph structures and sample important nodes, the present invention provides a graph neural network anomaly detection method and device based on neighborhood node structure encoding. This method is based on the adjacency matrix A of the input graph adjacency to calculate and generate node structure features F structure and role features M role , and further calculate the node structure similarity matrix S and the high-order neighborhood matrix A role . By using the node structure similarity matrix S, the feature contribution of important similar nodes to the target node is improved, and at the same time, the over-smoothing problem caused by the multi-layer graph neural network is reduced by using the high-order neighborhood matrix A role . Finally, the model combines semantic features and structural features to classify abnormal nodes. In addition, the node role feature M role is obtained as an intermediate result during the calculation process of the model, and this intermediate result can be used as the basis for node structure interpretability.
[0004] To achieve the above object, the technical solution of the present invention is as follows: In the first aspect of the embodiments of the present invention, a graph neural network anomaly detection method based on neighborhood node structure encoding is provided, and the method specifically includes the following steps:
[0005] (1) Convert the original data with a topological structure into input data supported by graph neural network encoding, and the input data includes a node attribute matrix and an adjacency matrix;
[0006] (2) Extract structural features from the adjacency matrix using anonymous random walks and / or recursive graph structure statistical features;
[0007] (3) Perform matrix factorization on the structural features to obtain node role features and role structure feature factors;
[0008] (4) Multiply the node role features by their transpose matrix, and set the non - negative values in the resulting matrix to 1 to obtain a high - order adjacency matrix;
[0009] (5) Input the node attribute matrix and the adjacency matrix into the first graph neural network to obtain node neighborhood semantic latent variables;
[0010] (6) Input the node attribute matrix and the high - order adjacency matrix into the second graph neural network to obtain node role semantic latent variables;
[0011] (7) Use the multi - head attention mechanism to dynamically weight the node neighborhood semantic latent variables and the node role semantic latent variables based on similarity to obtain the final node representation;
[0012] (8) Input the final node representation into the activation function, train the graph neural network, use cross - entropy as the loss function to calculate the loss and backpropagate the loss to learn the parameters until the graph neural network converges, and use the label with the highest probability in the output vector of the activation function as the classification result. The classification result is the abnormal category, and the nodes corresponding to the abnormal category are the abnormal targets to be detected.
[0013] In the second aspect of the embodiments of the present invention, there is provided a graph neural network anomaly detection device based on neighborhood node structure encoding, including a memory and a processor, and the memory is coupled to the processor; wherein, the memory is used to store program data, and the processor is used to execute the program data to implement the above - mentioned graph neural network anomaly detection method based on neighborhood node structure encoding.
[0014] In the third aspect of the embodiments of the present invention, there is provided a computer - readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the above - mentioned graph neural network anomaly detection method based on neighborhood node structure encoding.
[0015] Compared with the prior art, the present invention has the following beneficial effects:
[0016] (1) The present invention can adaptively select the contribution of important neighborhood nodes to the target node based on the structural similarity of neighborhood nodes.
[0017] (2) In the process of performing matrix factorization on the structural features, the present invention uses a parameter - free method to calculate and generate each node role feature, providing a structural explanation for nodes with special structures (such as bridging nodes and hub nodes).
[0018] (3) The present invention can obtain the high-order neighborhood information of nodes through node role features and structural features, and address the over-smoothing problem that occurs during the increase in the number of layers of the graph neural network.
[0019] (4) Since the special position and role of nodes in the network structure are crucial, in the network DNS defense task, the important neighborhood graph structure and the important nodes to be sampled can be effectively screened by the method of the present invention. That is, the nodes whose IP addresses of customers, servers, and intermediate routers are attacked, which are the nodes that need to be key-defended, can play a decisive role in the network DNS defense task. Description of the Drawings
[0020] Figure 1 It is a flowchart for generating the node structure features in the method of the present invention;
[0021] Figure 2 It is a flowchart for calculating the high-order neighborhood matrix in the method of the present invention;
[0022] Figure 3 It is a flowchart for calculating the neighborhood node encoding in the method of the present invention;
[0023] Figure 4 It is a flowchart for the method of the present invention;
[0024] Figure 5 It is a schematic diagram of an abnormal detection device for a graph neural network based on neighborhood node structure encoding provided by the present invention. Detailed Embodiment
[0025] To further understand the present invention, the following specifically describes an abnormal detection method for a graph neural network based on neighborhood node structure encoding provided by the present invention in combination with specific implementation methods. However, the present invention is not limited thereto. Non-essential improvements and adjustments made by those skilled in the art under the core guiding ideology of the present invention still fall within the protection scope of the present invention.
[0026] The present invention proposes an abnormal detection method for a graph neural network based on neighborhood node structure encoding. The method includes the following specific steps:
[0027] (1) Convert the original data with a topological structure into input data that supports graph neural network encoding. The input data includes a node attribute matrix X c ∈R n*f1 and an adjacency matrix A adjency ∈ {0, 1} n*n , where n represents the number of nodes in the graph network, and f1 represents the semantic vector dimension corresponding to each node.
[0028] Exemplarily, the original data in the present invention can adopt the data in the network DNS defense scenario, convert the original data in the network DNS defense scenario with a topological structure into input data supporting graph neural network encoding, use the IP addresses of the client, server, and intermediate router as nodes, and their corresponding geographical locations, request headers of network access protocols, etc. as node attributes to construct a node attribute matrix X c , use an access from one IP to another IP as an edge to construct an adjacency matrix A of the network access graph adjency .
[0029] (2) Extract structural features V ∈ R adjency from the adjacency matrix A constructed in step (1) by using anonymous random walk, recursive graph structure statistical features, or a combination thereof n*f2 .
[0030] Among them, the process of generating structural features V by using anonymous random walk includes:
[0031] Anonymous Random Walk anonymizes the sampled nodes during the sampling process of random walk, and only retains the access node category sequence a. Suppose a random walk sequence w = (v1, v2, v3,..., v k ), then its corresponding anonymous random walk sequence is denoted as a = (f(v1), f(v2), f(v3),..., f(v k ), where Sample m anonymous walk paths of length l in the k-hop neighborhood around the node, vectorize the anonymous walk paths to form a d-dimensional vector, and use this d-dimensional vector as the node structural feature V, where d is the number of all unique anonymous random walks of length l
[0032] The specific steps for generating structural features V by using recursive graph structure statistical features are as follows:
[0033] (2.1) Calculate graph structure statistical features (i.e., local features and self-centered network features of nodes). Among them, the local features of nodes include in-degree, out-degree, weighted degree, centrality, betweenness, weight (page rank), and the self-centered network features of nodes include using the k-hop range centered on the node as a subgraph, and counting the number of internal edges in this subgraph and the number of edges adjacent to the boundary nodes of this subgraph
[0034] (2.2) Recursively increase the neighborhood hop count, expand the node neighborhood range to a preset maximum neighborhood hop count K max , and calculate the mean and sum of the local features and self-centered network features of the nodes within this range as the structural features at each hop range
[0035] (2.3) Calculate the null values and variances of the features generated recursively, customize the null value threshold and variance threshold of the features, prune the statistical features of the graph structure where the null values of the features exceed the null value threshold or the variance is less than the variance threshold, and finally retain the remaining statistical feature dimensions of the graph structure as the final structural feature V.
[0036] The specific method of adopting anonymous random walk and recursive graph structure statistical feature combination is as follows: Concatenate the structural feature V generated by the anonymous random walk method and the structural feature V generated by the recursive graph structure statistical feature method to obtain the structural feature V ∈ R n*f2 .
[0037] Exemplarily, the recursive graph structure statistical features may correspond to some statistical features of using a large number of different IPs to attack a website of a certain IP in the network DNS defense scenario.
[0038] (3) For the structural feature V ∈ R generated in step (2) n*f2 Perform matrix decomposition method to decompose it into node role feature M role ∈ R n*r and role structure feature factor F structure ∈ R r*f2 .
[0039] Specifically, perform matrix decomposition on the structural feature V to obtain the node role feature M role and role structure feature factor F structure ; The matrix decomposition methods include but are not limited to Non-Negative Matrix Factorization (NMF), Singular Vector Decomposition (SVD), etc. Preferably, in the embodiments of the present invention, NMF is adopted as the matrix decomposition method because the matrix elements after decomposition are all non-negative values.
[0040] Preferably, step (3) further includes the process of optimizing the obtained node role feature M role ∈ R n*r and role structure feature factor F structure ∈ R r*f2 , which specifically includes the following sub-steps:
[0041] (3.1) Update the node role feature M role and role structure feature factor F structure obtained after decomposing the structural feature V: Use the K-Means clustering method to calculate the K centroids of the matrix elements of the node role feature M role and role structure feature factor F structure respectively, and take the node role feature M roleWith the role structure feature factor F structure The elements in the matrix are updated to the corresponding centroids obtained by the K-Means clustering method, and the updated node role feature is denoted as M′ role , and the updated role structure feature factor is F′ structure .
[0042] (3.2) Use the Minimum Description Length Criterion (MDLC) to evaluate the updated node role feature as M′ role and the updated role structure feature factor as F′ structure of the coding loss. The MDLC loss includes the model coding loss D and the loss ε of lossless coding of data using the model. The model coding loss D = b * r * (n * f2), where b is the updated node role feature as M′ role and the updated role structure feature factor as F′ structure corresponding maximum number of centroids. The loss of lossless coding of data using the model can be ε = ||V - M′ role F′ structure || frobeius or calculate the KL divergence between V and V′ = M′ role F′ structure for the calculation between elements
[0043] (3.3) Pre-define the number of node roles r, and select the role number r corresponding to the minimum value of the model coding loss calculated in step (3.2) based on the grid search method as the optimal role number r opt . Based on the optimal role number r opt perform matrix decomposition on the structure feature V generated in step (2), and decompose it into the optimal node role feature M opt and the optimal role structure feature factor F opt .
[0044] The row of the node role feature M obtained after decomposing the structure feature V role corresponds to the membership degree of a certain node in different roles corresponding to it in the network, that is, the degree of performance of the node as different roles in the subgraph formed with neighborhood nodes. Nodes with similar node role features have similar topological structures in their corresponding neighborhood subgraphs.
[0045] In step (2), use the Minimum Description Length Criterion (MDLC) to find the optimal role number r opt , and actually use a parameter-free method to calculate and generate the node role features of each node, and regard the node role feature node role feature Mrole with the role structure feature factor F structure enables the provision of a structural explanation for nodes with special structures (such as bridging nodes and hub nodes).
[0046] Exemplarily, in the scenario of network DNS defense, some nodes with a bridging role may reflect the topological structure of certain reverse proxies acting as infected hosts and serving as botnet hosts in the IP network. Nodes with certain hub roles may represent the topological structure of the attacked IP during a DNS amplification attack in this network DNS defense scenario.
[0047] (4) Multiply the role feature M' role ∈R n*r obtained in step (3) with its transpose matrix M' role T ∈R r*n and assign the non - negative values in the resulting matrix to 1 to obtain the high - order adjacency matrix A role ∈{0, 1} n*n .
[0048] Traditional graph neural networks often lead to information decay during message aggregation as the number of network layers and the node distance increase. By multiplying M' role with its transpose matrix M' role T nodes with similar roles can be connected, and there is no need for multiple propagations during message dissemination, reducing information decay.
[0049] (5) Input the node attribute matrix X c obtained in step (1) and the adjacency matrix A adjency into the first graph neural network to obtain the node neighborhood semantic latent variable H c ∈R n*h1 , where h1 is the latent variable feature dimension number.
[0050] In the embodiments of the present invention, the first graph neural network includes, but is not limited to, GCN, GraphSAGE, FastGCN, etc.
[0051] In this example, taking GCN as an example: where σ is the activation function (such as: ReLU), is the normalized adjacency matrix, and W is the learning parameter.
[0052] (6) Input the node attribute matrix X c obtained in step (1) and the high - order adjacency matrix A role obtained in step (4) into the second graph neural network to obtain the node role semantic latent variable H r ∈R n*h2。
[0053] In the embodiments of the present invention, the first graph neural network includes, but is not limited to, graph convolutional neural network GCN, deep graph convolutional neural network GraphSAGE, FastGCN, etc.
[0054] (7) Use the multi-head attention mechanism to dynamically weight the node neighborhood semantic latent variable H in step (6) c and the node role semantic latent variable H in step (7) r to obtain the final node representation H node 。
[0055] Specifically, in this example, semantic similarity, structural similarity, and role similarity between nodes are used for dynamic weighting.
[0056] (7.1) Calculate the semantic similarity, structural similarity, and role similarity between nodes respectively;
[0057] The calculation formula of the semantic similarity α context is as follows:
[0058]
[0059] where W1 is the weight parameter of the semantic similarity α context , is the neighborhood semantic latent variable H corresponding to the i-th node c , is the neighborhood semantic latent variable H corresponding to the j-th node c 。
[0060] The calculation formula of the role similarity α role is as follows:
[0061]
[0062] where W2 is the weight parameter of the role similarity α role , is the node role semantic latent variable H corresponding to the i-th node r , is the node role semantic latent variable H corresponding to the j-th node r 。
[0063] The calculation process of the structural similarity matrix S between nodes includes: based on the structural features V ∈ R obtained in step (2) n*f2Calculate the structural similarity between any two nodes in the graph neural network using a similarity kernel function to obtain a node structural similarity matrix S. The similarity kernel function method includes, but is not limited to, Inner Product, Polynomial, Radial Basis Function (RBF), etc.
[0064] (7.2) Use the multi-head attention mechanism to perform weighted summation on the semantic similarity α context , structural similarity S, and role similarity α role , and the formula is as follows:
[0065]
[0066] where coff context is the weight parameter corresponding to the semantic similarity α context , coff structure is the weight parameter corresponding to the structural similarity S, and coff role is the weight parameter corresponding to the role similarity α role .
[0067] (7.3) Calculate the final node representation H node , and the formula is as follows:
[0068] H node = a T * X c .
[0069] (9) Input the final node representation H node obtained in step (8) into the activation function Softmax, train the graph neural network, then use the Cross Entropy Loss as the loss function to calculate the loss, and backpropagate the loss to learn the parameters until the graph neural model converges. In the test phase, fix the model parameters, and use the activation function Softmax to output the label with the highest probability in the vector as the classification result. The node corresponding to the obtained abnormal category is the detected abnormal target. This abnormal target is the node where the IP addresses of the customer, server, and intermediate router in the network DNS defense task are attacked, that is, the node that needs to be key defended.
[0070] Corresponding to the foregoing embodiment of the graph neural network anomaly detection method based on neighborhood node structure encoding, the present invention also provides an embodiment of a graph neural network anomaly detection device based on neighborhood node structure encoding.
[0071] See Figure 5, an anomaly detection device of a graph neural network based on neighborhood node structure encoding provided by an embodiment of the present invention includes one or more processors for implementing the anomaly detection method of the graph neural network based on neighborhood node structure encoding in the above embodiment.
[0072] The embodiment of the anomaly detection device of the graph neural network based on neighborhood node structure encoding of the present invention can be applied to any device with data processing capabilities, and the any device with data processing capabilities can be a device or apparatus such as a computer. The device embodiment can be implemented by software, or by hardware or a combination of software and hardware. Taking software implementation as an example, as a logically meaningful device, it is formed by the processor of any device with data processing capabilities where it is located reading the corresponding computer program instructions in the non-volatile memory into the memory for running. From the hardware level, as Figure 5 shown, it is a hardware structure diagram of any device with data processing capabilities where the anomaly detection device of the graph neural network based on neighborhood node structure encoding of the present invention is located. Except for Figure 5 the shown processor, memory, network interface, and non-volatile memory, usually according to the actual functions of the any device with data processing capabilities where the device in the embodiment is located, other hardware may also be included, which will not be elaborated here.
[0073] The implementation processes of the functions and roles of each unit in the above device are specifically detailed in the implementation processes of the corresponding steps in the above method, which will not be elaborated here.
[0074] For the device embodiment, since it basically corresponds to the method embodiment, the relevant parts can be referred to the partial description of the method embodiment. The device embodiments described above are only illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of the present invention. Those of ordinary skill in the art can understand and implement it without creative efforts.
[0075] The embodiment of the present invention also provides a computer-readable storage medium, on which a program is stored. When the program is executed by a processor, it implements the anomaly detection method of the graph neural network based on neighborhood node structure encoding in the above embodiment.
[0076] The computer-readable storage medium may be an internal storage unit of any data processing capable device described in any of the foregoing embodiments, such as a hard disk or memory. The computer-readable storage medium may also be any data processing capable device, such as a plug-in hard disk, a Smart Media Card (SMC), an SD card, a Flash Card, etc. equipped on the device. Further, the computer-readable storage medium may also include both an internal storage unit of any data processing capable device and an external storage device. The computer-readable storage medium is used to store the computer program and other programs and data required by any data processing capable device, and may also be used to temporarily store data that has been output or is to be output.
[0077] Those skilled in the art will readily conceive of other embodiments of the present application after considering the specification and practicing the content disclosed herein. The present application is intended to cover any variations, uses, or adaptations of the present application that follow the general principles of the present application and include known common knowledge or conventional technical means in the technical field not disclosed in the present application. The specification and examples are only to be considered as exemplary.
[0078] It should be understood that the present application is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope.
Claims
1. A graph neural network anomaly detection method based on neighborhood node structure encoding, characterized in that The method specifically includes the following steps: (1) Convert the original data with a topological structure into input data supported by graph neural network encoding. The input data includes a node attribute matrix and an adjacency matrix. The original data with a topological structure in step (1) is data in a network DNS defense task, including: using the IP addresses of clients, servers, and intermediate routers as nodes of the graph neural network, and using the geographical locations corresponding to the clients, servers, and intermediate routers, and the request headers of network access protocols as node attributes. Using an access from one IP to another as an edge of the graph neural network; (2) Extract structural features from the adjacency matrix using anonymous random walks and / or recursive graph structure statistical features; (3) Perform matrix decomposition on the structural features to obtain node role features and role structure feature factors; (4) Multiply the node role features by their transpose matrix, and set the non-negative values in the resulting matrix to 1 to obtain a high-order adjacency matrix; (5) Input the node attribute matrix and the adjacency matrix into the first graph neural network to obtain node neighborhood semantic latent variables; (6) Input the node attribute matrix and the high-order adjacency matrix into the second graph neural network to obtain node role semantic latent variables; (7) Use a multi-head attention mechanism to dynamically weight the node neighborhood semantic latent variables and the node role semantic latent variables based on similarity to obtain the final node representation; (8) Input the final node representation into an activation function, train the graph neural network, use cross-entropy as the loss function to calculate the loss and backpropagate the loss to learn the parameters until the graph neural network converges. Use the label with the highest probability in the output vector of the activation function as the classification result. The classification result is the abnormal category, and the node corresponding to the abnormal category is the detected abnormal target; The abnormal target is the node where the IP addresses of clients, servers, and intermediate routers in the network DNS defense task are attacked, that is, the node that needs to be key defended.
2. The graph neural network anomaly detection method based on neighborhood node structure encoding according to claim 1, characterized in that The process of generating structural features using recursive graph structure statistical features in step (2) includes: Calculate graph structure statistical features, that is, the local features and self-centered network features of nodes. Among them, the local features of nodes include the in-degree, out-degree, weighted degree, centrality, betweenness, and weight of nodes, and the self-centered network features of nodes include the subgraph with the node as the center within the k-hop range; Recursively increase the neighborhood hop count, expand the node neighborhood range to the preset maximum neighborhood hop count, and calculate the mean and sum of the local features and self-centered network features of nodes within this range as the structural features at each hop range; Calculate the null values and variances of the features generated by recursion, customize the feature null value threshold and variance threshold, and prune the graph structure statistical features whose feature null values exceed the feature null value threshold or whose variances are less than the variance threshold. Finally, retain the remaining graph structure statistical feature dimensions as the structural features.
3. The graph neural network anomaly detection method based on neighborhood node structure encoding according to claim 1, characterized in that, The process of performing matrix decomposition on the structural features in step (3) includes: Selecting the non-negative matrix factorization method to perform matrix decomposition on the structural features.
4. The graph neural network anomaly detection method based on the neighborhood node structure encoding according to claim 1 or 3, characterized in that, Step (3) also includes the process of optimizing the decomposed node role features and role structure feature factors, specifically including the following sub-steps: The node role feature M obtained by decomposing the structural feature V role and the role structure feature factor F structure Update. Use the K-Means clustering method to calculate the K centroids of the matrix elements of the node role feature M role and the role structure feature factor F structure respectively, and update the elements in the matrix of the node role feature M role and the role structure feature factor F structure to the corresponding centroids obtained by the K-Means clustering method. Denote the updated node role feature as M′ role , and the updated role structure feature factor as F′ structure ; The updated node role feature is evaluated using the minimum description length criterion as M′ role and the encoding loss with the updated role structure feature factor being F′ structure ; Predefine the number of node roles \(r\), and select the role number \(r\) corresponding to the minimum model encoding loss based on the grid search method as the optimal role number \(r\). opt ; Based on the optimal role number \(r\) opt Obtain the optimal node role feature \(M\) opt And the optimal role structure feature factor \(F\) opt .
5. The graph neural network anomaly detection method based on the neighborhood node structure encoding according to claim 4, characterized in that, The step (4) is replaced by: multiplying the optimal node role feature M opt by its transpose matrix, and setting the non-negative values in the resulting matrix to 1 to obtain a high-order adjacency matrix.
6. The graph neural network anomaly detection method based on neighborhood node structure encoding according to claim 4, characterized in that The first graph neural network in the step (5) is selected from GCN, GraphSAGE, and FastGCN; the second graph neural network in the step (6) is selected from GCN, GraphSAGE, and FastGCN.
7. The graph neural network anomaly detection method based on the neighborhood node structure encoding according to claim 1, characterized in that The step (7) specifically includes the following sub-steps: (7.1) Calculate the semantic similarity, structural similarity, and role similarity between nodes respectively; The semantic similarity α context is calculated as follows: Among them, W1 is the weight parameter of the semantic similarity α context , is the neighborhood semantic latent variable H corresponding to the i-th node c , is the neighborhood semantic latent variable H corresponding to the j-th node c ; The character similarity α role has the following calculation formula: Among them, W2 is the weight parameter of the role similarity α role , is the node role semantic latent variable H corresponding to the i-th node r , is the node role semantic latent variable H corresponding to the j-th node r ; The calculation process of the structural similarity S between nodes includes: using the similarity kernel function based on the structural feature V obtained in the step (2) to calculate the structural similarity between any two nodes in the graph neural network; (7.2) The multi-head attention mechanism is used to perform weighted summation on the semantic similarity α context , the structural similarity S, and the role similarity α role ; (7.3) Transpose the similarity matrix obtained by weighted summation in the step (7.2) and multiply it with the node attribute matrix to obtain the final node representation.
8. A graph neural network anomaly detection device based on neighborhood node structure encoding, comprising a memory and a processor, characterized in that, The memory is coupled to the processor; wherein, the memory is used to store program data, and the processor is used to execute the program data to implement the graph neural network anomaly detection method based on neighborhood node structure encoding according to any one of the above claims 1-7.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the graph neural network anomaly detection method based on neighborhood node structure encoding according to any one of claims 1-7.
Citation Information
Patent Citations
Distribution network state on-line detection method based on graph neural network
CN115114990A
Internet of vehicles intrusion detection method based on graph neural network
CN115175192A