An Internet of Things intrusion detection method, device, equipment, and storage medium

By applying a transfer learning-based intrusion detection method on IoT devices, using recommendation systems and neural network classifiers to migrate knowledge from the field of Internet intrusion detection, the problem of intrusion detection of IoT devices is solved, and efficient and accurate intrusion detection is achieved.

CN115955336BActive Publication Date: 2025-06-10SHENZHEN INST OF ADVANCED TECH CHINESE ACAD OF SCI

Patent Information

Application Number
CN202211561759.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-07
Publication Date
2025-06-10
Estimated Expiration
2042-12-07

AI Technical Summary

Technical Problem

Due to limited computing and storage capabilities and insufficient energy supply, IoT devices are difficult to deploy strong intrusion detection mechanisms, resulting in devices being susceptible to malicious intrusion and impaired security.

Method used

Using a transfer learning-based method, we enhance knowledge migration through recommendation systems, transfer rich in intrusion detection knowledge from the field of Internet intrusion detection to the field of Internet of Things, and use neural network classifiers to perform intrusion detection.

Benefits of technology

Effective intrusion detection is achieved in an Internet of Things environment with scarce data, overcome the problems of scarcity and characteristic heterogeneity of IoT data, and improve the accuracy and efficiency of intrusion detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115955336B_ABST
    Figure CN115955336B_ABST
Patent Text Reader

Abstract

The present application relates to an Internet of Things intrusion detection method, device, equipment, and storage medium. The method includes: inputting Internet source domain intrusion detection data into a source domain feature mapper, and inputting Internet of Things target domain intrusion detection data into a target domain feature mapper; constructing a recommendation system trained based on the source domain; recommending a most similar Internet source domain intrusion detection data for each Internet of Things target domain intrusion detection data; constructing a recommendation system trained based on the target domain; recommending the top N similar Internet of Things target domain intrusion detection data for the mean vector of each Internet source domain intrusion detection data; calculating the Euclidean distance between the recommendation result of the recommendation system trained based on the source domain and the recommendation result of the recommendation system trained based on the target domain to obtain a recommendation system matching loss; calculating a supervised loss; updating the parameters of the neural network; and performing Internet of Things intrusion detection. The present application can perform Internet of Things intrusion detection more effectively.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of network communication technology, and particularly relates to an Internet of Things intrusion detection method, device, equipment, and storage medium. Background Art

[0002] With the rapid progress and development of Internet of Things devices, more and more Internet of Things devices are being applied in daily production and life, making more and more applications more intelligent, such as Internet of Things-driven smart cities, Internet of Things-driven smart medical care and elderly care, etc. However, Internet of Things devices themselves have some defects. For example, most Internet of Things devices have extremely limited computing and storage capabilities, and their energy supply is also very limited. Therefore, it becomes relatively infeasible to deploy a relatively powerful intrusion detection mechanism on Internet of Things devices, which makes Internet of Things devices more vulnerable to malicious intrusion attacks, thus damaging the security of Internet of Things devices themselves, and it is difficult to guarantee the security of their applications and users.

[0003] To ensure the security of Internet of Things devices, their running applications, and users, an effective intrusion detection mechanism is needed to detect possible intrusion behaviors and thus ensure the security of Internet of Things devices. There are mainly two traditional intrusion detection mechanisms: one is the rule-based intrusion detection method; the other is the machine learning-based intrusion detection method. The rule-based intrusion detection method relies on a pre-established intrusion rule library. When it is detected that a certain communication conforms to a certain rule in the intrusion rule library, this communication is determined to be an illegal intrusion. The machine learning-based intrusion detection method, on the other hand, needs to pre-train a machine learning model with a complete labeled dataset and perform intrusion detection through the trained machine learning model.

[0004] However, both of the two traditional intrusion detection methods have strong data dependencies. The rule-based intrusion detection method relies on a complete knowledge base, but constructing and frequently updating this knowledge base requires strong expert knowledge. The machine learning-based intrusion detection method relies on a complete labeled training dataset, but constructing this dataset requires a lot of time and manpower and is costly. In addition, some self-limitations of Internet of Things devices, such as weak storage and communication capabilities, and some considerations of user privacy information make Internet of Things communication data less likely to be collected and obtained, which further greatly impairs the effectiveness of the above two traditional intrusion detection methods with strong data dependencies when facing Internet of Things intrusion detection. Summary of the Invention

[0005] This application provides an Internet of Things intrusion detection method, device, equipment, and storage medium, aiming to at least to some extent solve one of the above technical problems in the prior art.

[0006] To solve the above problems, the present application provides the following technical solutions:

[0007] An Internet of Things intrusion detection method, comprising:

[0008] Step S1: Input the Internet source domain intrusion detection data into the source domain feature mapper, and input the Internet of Things target domain intrusion detection data into the target domain feature mapper;

[0009] Step S2: Using the Internet source domain intrusion detection data as input, construct a recommendation system trained based on the source domain;

[0010] Step S3: Employ the recommendation system trained based on the source domain to recommend a most similar Internet source domain intrusion detection data for each Internet of Things target domain intrusion detection data;

[0011] Step S4: Using the Internet of Things target domain intrusion detection data as input, construct a recommendation system trained based on the target domain;

[0012] Step S5: Employ the recommendation system trained based on the target domain to recommend the top N similar Internet of Things target domain intrusion detection data for the mean vector of each Internet source domain intrusion detection data;

[0013] Step S6: Calculate the Euclidean distance between the recommendation results of the recommendation system trained based on the source domain and the recommendation results of the recommendation system trained based on the target domain for each communication category to obtain the recommendation system matching loss;

[0014] Step S7: Calculate the supervised loss according to the Internet source domain intrusion detection data;

[0015] Step S8: Optimize the supervised loss and the recommendation system matching loss, and update the parameters of the neural network;

[0016] Step S9: If the cosine similarity of the Internet source domain intrusion detection data recommended by the recommendation system for the Internet of Things target domain is greater than the set threshold, then use the intrusion type of the Internet source domain intrusion detection data recommended by the recommendation system as the final intrusion type; if the set threshold is not reached, then use the neural network classifier to perform intrusion detection on the Internet of Things target domain intrusion detection data.

[0017] The technical solution adopted in the embodiment of the present application further includes: Step S2 includes:

[0018] Using the Latent Semantic Indexing algorithm, with the Internet source domain intrusion detection data as input, construct a recommendation system trained based on the source domain; its mathematical expression is:

[0019]

[0020] Among them, the M matrix is the source domain feature matrix, U is the feature-latent space matrix, T is the latent space transformation matrix, V is the communication data-latent space matrix, and R is the dimension parameter. is the i-th communication data in the Internet source domain. is the j-th communication data in the Internet of Things target domain. ‘ is the data representation of the j-th communication data in the Internet of Things target domain after being processed by the recommendation system.

[0021] The technical solution adopted in the embodiment of this application further includes: The step S3 includes:

[0022] Using the recommendation system trained based on the source domain, recommend a most similar Internet source domain intrusion detection data for each Internet of Things target domain intrusion detection data, and use the intrusion category label of the recommended Internet source domain intrusion detection data as the recommendation system label of the Internet of Things target domain intrusion detection data. Its mathematical expression is as follows:

[0023]

[0024] Among them, RS S (x T j ) represents the Internet source domain data recommended for the j-th communication data in the Internet of Things target domain, and PL is the recommendation system label of the j-th communication data in the Internet of Things target domain.

[0025] After that, for all Internet of Things target domain intrusion detection data, take the mean vector by category according to its recommendation system label.

[0026] The technical solution adopted in the embodiment of this application further includes: The step S5 includes:

[0027] Take the average by category for all Internet source domain intrusion detection data, and use the recommendation system trained based on the target domain to recommend the top N similar Internet of Things target domain intrusion detection data for the mean vector of each Internet source domain intrusion detection data, and take the mean vector of the N similar Internet of Things target domain intrusion detection data.

[0028] The technical solution adopted in the embodiment of this application further includes: The step S6 includes:

[0029] Minimize the Euclidean distance between the recommendation results of the recommendation system trained based on the source domain and the recommendation results of the recommendation system trained based on the target domain for each communication category. Its mathematical expression is as follows:

[0030]

[0031] Among them, L ABR is the recommendation system matching loss. and They are respectively the recommendations of the recommendation system trained based on the source domain for the Internet of Things target domain, and the recommendations of the recommendation system trained based on the target domain for the Internet source domain.

[0032] The technical solution adopted in the embodiment of the present application further includes: The step S7 includes:

[0033] Calculate the supervised loss of the intrusion detection data in the Internet source domain, and its mathematical expression is as follows:

[0034]

[0035] where: L SUP is the supervised loss of the intrusion detection data in the Internet source domain; n S is the amount of intrusion detection data in the Internet source domain; L CE is the cross-entropy loss function; C is the common classifier, which is a one-layer neural network; f is the feature mapper; x and y are respectively the features and their corresponding labels of the intrusion detection data in the Internet source domain.

[0036] The technical solution adopted in the embodiment of the present application further includes: The step S8 includes:

[0037] Use the gradient descent optimization algorithm to optimize the supervised loss and the matching loss of the recommendation system, and update the network parameters; Determine whether the model converges: If the model converges, execute step S9; Otherwise, return to step S1.

[0038] Another technical solution adopted in the embodiment of the present application is: An Internet of Things intrusion detection device, including:

[0039] Input module: Used to input the intrusion detection data in the Internet source domain into the source domain feature mapper, and input the intrusion detection data in the Internet of Things target domain into the target domain feature mapper;

[0040] Construction module: Used to use the intrusion detection data in the Internet source domain as input to construct a recommendation system trained based on the source domain;

[0041] Recommendation module: Used to use the recommendation system trained based on the source domain to recommend a most similar Internet source domain intrusion detection data for each Internet of Things target domain intrusion detection data;

[0042] Construction module: Also used to use the intrusion detection data in the Internet of Things target domain as input to construct a recommendation system trained based on the target domain;

[0043] Recommendation module: Also used to use the recommendation system trained based on the target domain to recommend the top N similar Internet of Things target domain intrusion detection data for the mean vector of each Internet source domain intrusion detection data;

[0044] Matching loss calculation module: used to calculate the Euclidean distance between the recommendation results of the recommendation system trained based on the source domain and the recommendation results of the recommendation system trained based on the target domain for each communication category, and obtain the recommendation system matching loss;

[0045] Supervision loss calculation module: used to calculate the supervision loss according to the Internet source domain intrusion detection data;

[0046] Update module: used to optimize the supervision loss and the recommendation system matching loss, and update the parameters of the neural network;

[0047] Intrusion detection module: when the cosine similarity of the Internet source domain intrusion detection data recommended by the recommendation system for the Internet of Things target domain is greater than the set threshold, use the intrusion type of the Internet source domain intrusion detection data recommended by the recommendation system as the final intrusion type; when the set threshold is not reached, use the neural network classifier to perform intrusion detection on the Internet of Things target domain intrusion detection data.

[0048] Another technical solution adopted in the embodiments of the present application is: a device, the device includes a processor and a memory coupled to the processor, wherein,

[0049] The memory stores program instructions for implementing the Internet of Things intrusion detection method;

[0050] The processor is used to execute the program instructions stored in the memory to control Internet of Things intrusion detection.

[0051] Another technical solution adopted in the embodiments of the present application is: a storage medium, storing program instructions that can be run by a processor, and the program instructions are used to execute the Internet of Things intrusion detection method.

[0052] Compared with the prior art, the beneficial effects produced by the present application are as follows: it relates to an Internet intrusion data field, which includes intrusion detection data collected from the Internet field, such as intrusion detection data collected from a network center server, and an Internet of Things field that is completely unlabeled. By migrating rich intrusion detection knowledge from the Internet intrusion field to the Internet of Things intrusion field with scarce data, and enhancing the accuracy of knowledge migration through a recommendation system, the Internet of Things field with scarce data can perform more effective intrusion detection, overcoming the difficulty of scarce Internet of Things data. Compared with the prior art, the present application has at least the following beneficial effects:

[0053] 1. This application uses a transfer learning - based approach for intrusion detection of Internet of Things (IoT) devices. Its advantages are that, compared with traditional intrusion detection methods, this application can perform effective IoT intrusion detection in unsupervised scenarios with scarce data and can overcome the feature heterogeneity between the Internet intrusion data source domain and the IoT intrusion data target domain.

[0054] 2. This application adopts a method of matching the recommendation results of a recommendation system, enabling the transfer learning method to be more refined when transferring intrusion detection knowledge. The recommendation result matching mechanism of the recommendation system can promote a more refined matching of intrusion data between the two data domains, and the more refined feature matching can further enable the recommendation system to better mine intrusion information and knowledge, thus forming a virtuous cycle between the recommendation system matching and the feature space matching.

[0055] 3. This application uses a combination of a recommendation system and a neural network classifier to make decisions on intrusion detection. As a tool that can effectively mine category interests, the recommendation system can, when well - trained, fully mine and learn the features of different intrusion categories, and thus make a more accurate intrusion detection judgment compared with the neural network. BRIEF DESCRIPTION OF THE DRAWINGS

[0056] Figure 1 is a flowchart of the IoT intrusion detection method according to an embodiment of this application;

[0057] Figure 2 is a schematic structural diagram of the IoT intrusion detection device according to an embodiment of this application;

[0058] Figure 3 is a schematic structural diagram of the device according to an embodiment of this application;

[0059] Figure 4 is a schematic structural diagram of the storage medium according to an embodiment of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0060] In order to make the objectives, technical solutions, and advantages of this application clearer, the following further elaborates on this application with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not used to limit this application.

[0061] Please refer to Figure 1 , which is a flowchart of the IoT intrusion detection method according to an embodiment of this application. The IoT intrusion detection method according to an embodiment of this application includes the following steps:

[0062] Step S1: Input the Internet source - domain intrusion detection data into the source - domain feature mapper, and input the IoT target - domain intrusion detection data into the target - domain feature mapper. Specifically:

[0063] Input the Internet source domain intrusion detection data into the source domain feature mapper, and input the Internet of Things target domain intrusion detection data into the target domain feature mapper. Both the source domain feature mapper and the target domain feature mapper are two-layer fully connected neural networks, with LeakyRelu as the activation function. The source domain feature mapper and the target domain feature mapper map the Internet source domain intrusion detection data and the Internet of Things target domain intrusion detection data into a common feature space.

[0064] Step S2: Use the Internet source domain intrusion detection data as input to construct a recommendation system trained based on the source domain. Specifically:

[0065] Adopt the Latent Semantic Indexing (LSI) algorithm, use the Internet source domain intrusion detection data as input, and construct a recommendation system trained based on the source domain. Its mathematical expression is as follows:

[0066]

[0067] Among them, the M matrix is the source domain feature matrix, U is the feature-latent space matrix, T is the latent space transformation matrix, V is the communication data-latent space matrix, R is the dimension parameter, is the i-th communication data in the Internet source domain, is the j-th communication data in the Internet of Things target domain, ‘ is the data representation of the j-th communication data in the Internet of Things target domain after being processed by the recommendation system.

[0068] Step S3: Use the recommendation system trained based on the source domain to recommend a most similar Internet source domain intrusion detection data for each Internet of Things target domain intrusion detection data. Specifically:

[0069] Use the recommendation system trained based on the source domain to recommend a most similar Internet source domain intrusion detection data for each Internet of Things target domain intrusion detection data. The intrusion category label of the recommended Internet source domain intrusion detection data is used as the recommendation system label of the Internet of Things target domain intrusion detection data. Its mathematical expression is as follows:

[0070]

[0071] Among them, RS S (x T j ) represents the Internet source domain data recommended for the j-th Internet of Things target domain communication data, and PL is the recommendation system label of the j-th Internet of Things target domain communication data.

[0072] The recommendation rule is based on the maximization of cosine distance. Then, for all the intrusion detection data in the IoT target domain, the mean vectors are taken by class according to their recommendation system tags.

[0073] Step S4: Use the intrusion detection data in the IoT target domain as input to construct a recommendation system trained based on the target domain. Specifically:

[0074] Adopt the Latent Semantic Indexing (LSI) algorithm, use the intrusion detection data in the IoT target domain as input, and construct a recommendation system trained based on the target domain.

[0075] The specific construction process is similar to that in Step S2 and will not be elaborated here.

[0076] Step S5: Use the recommendation system trained based on the target domain to recommend the top N similar intrusion detection data in the IoT target domain for the mean vector of each intrusion detection data in the Internet source domain. Specifically, it includes:

[0077] Take the average of all the intrusion detection data in the Internet source domain by class, and use the recommendation system trained based on the target domain to recommend the top N similar intrusion detection data in the IoT target domain for the mean vector of each intrusion detection data in the Internet source domain, and take the mean vector of the N similar intrusion detection data in the IoT target domain.

[0078] Step S6: Calculate the Euclidean distance between the recommendation results of the recommendation system trained based on the source domain and the recommendation results of the recommendation system trained based on the target domain for each communication category to obtain the recommendation system matching loss. Specifically:

[0079] Minimize the Euclidean distance between the recommendation results of the recommendation system trained based on the source domain and the recommendation results of the recommendation system trained based on the target domain for each communication category. Its mathematical expression is as follows:

[0080]

[0081] where L ABR is the recommendation system matching loss, and are the recommendations of the recommendation system trained based on the source domain for the IoT target domain and the recommendations of the recommendation system trained based on the target domain for the Internet source domain respectively.

[0082] Step S7: Calculate the supervision loss according to the intrusion detection data in the Internet source domain. Specifically:

[0083] Calculate the supervision loss of the intrusion detection data in the Internet source domain. Its mathematical expression is as follows:

[0084]

[0085] Wherein: L SUP is the supervision loss of Internet source domain intrusion detection data; n S is the amount of Internet source domain intrusion detection data; L CE is the cross-entropy loss function; C is a common classifier, which is a one-layer neural network; f is a feature mapper; x and y are the features and their corresponding labels of Internet source domain intrusion detection data respectively.

[0086] Step S8: Optimize the supervision loss and the matching loss of the recommendation system, and update the parameters of the neural network. Specifically:

[0087] Use the gradient descent optimization algorithm to optimize the supervision loss and the matching loss of the recommendation system, and update the network parameters. Determine whether the model converges: If the model converges, execute step S9; otherwise, return to step S1.

[0088] Step S9: Perform Internet of Things intrusion detection. Specifically:

[0089] Perform intrusion detection: If the cosine similarity when the recommendation system recommends Internet source domain intrusion detection data for the Internet of Things target domain is greater than the set threshold, such as 0.6, then use the intrusion type of the Internet source domain intrusion detection data recommended by the recommendation system as the final intrusion type judgment; if the set threshold is not reached, then use the neural network classifier to perform intrusion detection judgment on the Internet of Things target domain intrusion detection data.

[0090] Please refer to Figure 2 , which is a schematic structural diagram of the Internet of Things intrusion detection device according to an embodiment of the present application. The Internet of Things intrusion detection device 10 according to an embodiment of the present application includes: an input module 101, a construction module 102, a recommendation module 103, a matching loss calculation module 104, a supervision loss calculation module 105, an update module 106, and an intrusion detection module 107. Wherein:

[0091] The input module 101 is used to input Internet source domain intrusion detection data into the source domain feature mapper, and input Internet of Things target domain intrusion detection data into the target domain feature mapper. Specifically:

[0092] The input module 101 inputs Internet source domain intrusion detection data into the source domain feature mapper, and inputs Internet of Things target domain intrusion detection data into the target domain feature mapper. Both the source domain feature mapper and the target domain feature mapper are two-layer fully connected neural networks, with LeakyRelu as the activation function. The source domain feature mapper and the target domain feature mapper map the Internet source domain intrusion detection data and the Internet of Things target domain intrusion detection data into a common feature space.

[0093] The building module 102 is used to construct a recommendation system trained based on the source domain by using the Internet source domain intrusion detection data as input. Specifically:

[0094] The building module 102 uses the Latent Semantic Indexing (LSI) algorithm to construct a recommendation system trained based on the source domain by using the Internet source domain intrusion detection data as input. Its mathematical expression is as follows:

[0095]

[0096] Where the M matrix is the source domain feature matrix, U is the feature-latent space matrix, T is the latent space transformation matrix, V is the communication data-latent space matrix, and R is the dimension parameter. is the i-th communication data of the Internet source domain. is the j-th communication data of the Internet of Things target domain. ‘ is the data representation of the j-th communication data of the Internet of Things target domain after being processed by the recommendation system.

[0097] The recommendation module 103 is used to recommend a most similar Internet source domain intrusion detection data for each Internet of Things target domain intrusion detection data by using the recommendation system trained based on the source domain.

[0098] Specifically:

[0099] The recommendation module 103 uses the recommendation system trained based on the source domain to recommend a most similar Internet source domain intrusion detection data for each Internet of Things target domain intrusion detection data. The intrusion category label of the recommended Internet source domain intrusion detection data is used as the recommendation system label of the Internet of Things target domain intrusion detection data. Its mathematical expression is as follows:

[0100]

[0101] Where RS S (x T j ) represents the Internet source domain data recommended for the j-th Internet of Things target domain communication data, and PL is the recommendation system label of the j-th Internet of Things target domain communication data.

[0102] The recommendation rule is based on the maximization of the cosine distance. Then, for all Internet of Things target domain intrusion detection data, the mean vector is taken by class according to its recommendation system label.

[0103] The building module 102 is also used to construct a recommendation system trained based on the target domain by using the Internet of Things target domain intrusion detection data as input. Specifically:

[0104] The building block 102 adopts the Latent Semantic Indexing (LSI) algorithm, takes the intrusion detection data of the Internet of Things target domain as input, and constructs a recommendation system trained based on the target domain.

[0105] The recommendation module 103 is further configured to use the recommendation system trained based on the target domain to recommend the top N similar intrusion detection data of the Internet of Things target domain for the mean vector of each intrusion detection data of the Internet source domain. Specifically, it includes:

[0106] The recommendation module 103 takes the average of all intrusion detection data of the Internet source domain by category, uses the recommendation system trained based on the target domain to recommend the top N similar intrusion detection data of the Internet of Things target domain for the mean vector of each intrusion detection data of the Internet source domain, and takes the mean vector of the N similar intrusion detection data of the Internet of Things target domain.

[0107] The matching loss calculation module 104 is used to calculate the Euclidean distance between the recommendation results of the recommendation system trained based on the source domain and the recommendation results of the recommendation system trained based on the target domain for each communication category, and obtain the recommendation system matching loss. Specifically:

[0108] The matching loss calculation module 104 minimizes the Euclidean distance between the recommendation results of the recommendation system trained based on the source domain and the recommendation results of the recommendation system trained based on the target domain for each communication category. Its mathematical expression is as follows:

[0109]

[0110] Among them, L ABR is the recommendation system matching loss, and are respectively the recommendation for the Internet of Things target domain by the recommendation system trained based on the source domain, and the recommendation for the Internet source domain by the recommendation system trained based on the target domain.

[0111] The supervised loss calculation module 105 is used to calculate the supervised loss according to the intrusion detection data of the Internet source domain. Specifically:

[0112] The supervised loss calculation module 105 calculates the supervised loss of the intrusion detection data of the Internet source domain. Its mathematical expression is as follows:

[0113]

[0114] Among them: L SUP is the supervised loss of the intrusion detection data of the Internet source domain; n S is the amount of intrusion detection data of the Internet source domain; L CEis the cross-entropy loss function; C is a common classifier, which is a one-layer neural network; f is a feature mapper; x and y are the features of the Internet source domain intrusion detection data and their corresponding labels respectively.

[0115] The update module 106 is used to optimize the supervision loss and the recommendation system matching loss, and update the parameters of the neural network. Specifically:

[0116] The update module 106 uses the gradient descent optimization algorithm to optimize the supervision loss and the recommendation system matching loss, and update the network parameters.

[0117] The intrusion detection module 107 is used to perform Internet of Things intrusion detection. Specifically:

[0118] The intrusion detection module 107 performs intrusion detection: if the cosine similarity when the recommendation system recommends Internet source domain intrusion detection data for the Internet of Things target domain is greater than the set threshold, such as 0.6, then use the intrusion type of the Internet source domain intrusion detection data recommended by the recommendation system as the final intrusion type judgment; if the set threshold is not reached, then use the neural network classifier to perform intrusion detection judgment on the Internet of Things target domain intrusion detection data.

[0119] Please refer to Figure 3 , which is a schematic structural diagram of the device according to an embodiment of the present application. The device 50 includes a processor 51 and a memory 52 coupled to the processor 51.

[0120] The memory 52 stores program instructions for implementing the above-mentioned Internet of Things intrusion detection method.

[0121] The processor 51 is used to execute the program instructions stored in the memory 52 to control Internet of Things intrusion detection.

[0122] Among them, the processor 51 can also be called a CPU (Central Processing Unit, central processing unit). The processor 51 may be an integrated circuit chip with signal processing capabilities. The processor 51 may also be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0123] Please refer to Figure 4, which is a schematic structural diagram of the storage medium according to an embodiment of the present application. The storage medium according to the embodiment of the present application stores a program file 61 that can implement all the above methods. Among them, the program file 61 can be stored in the above storage medium in the form of a software product, including several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to execute all or part of the steps of the methods according to various embodiments of the present invention. The foregoing storage medium includes: various media that can store program codes such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs, or devices such as computers, servers, mobile phones, and tablets.

[0124] It should be noted that: The present application has general applicability and can be used for various communication detections, such as intrusion detection, security detection, task detection, etc. The present application is robust to the characteristics and distributions of source domain data and target domain data. The present application can act on homogeneous or heterogeneous source domain data and target domain data. The present application can act on the Internet of Things data to be measured without any supervision information.

[0125] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined in the present application can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to these embodiments shown in the present application, but will conform to the widest scope consistent with the principles and novel features disclosed in the present application.

Claims

1. An Internet of Things intrusion detection method, characterized in that, it includes: Step S1: Input the Internet source domain intrusion detection data into the source domain feature mapper, and input the Internet of Things target domain intrusion detection data into the target domain feature mapper; Step S2: Use the Internet source domain intrusion detection data as input to construct a recommendation system trained based on the source domain; Step S3: Use the recommendation system trained based on the source domain to recommend a most similar Internet source domain intrusion detection data for each Internet of Things target domain intrusion detection data; Step S4: Use the Internet of Things target domain intrusion detection data as input to construct a recommendation system trained based on the target domain; Step S5: Use the recommendation system trained based on the target domain to recommend the top N similar Internet of Things target domain intrusion detection data for the mean vector of each Internet source domain intrusion detection data; Step S6: Calculate the Euclidean distance between the recommendation results of the recommendation system trained based on the source domain and the recommendation results of the recommendation system trained based on the target domain for each communication category to obtain the recommendation system matching loss; Step S7: Calculate the supervision loss based on the Internet source domain intrusion detection data; Step S8: Optimize the supervision loss and the recommendation system matching loss, and update the parameters of the neural network; Step S9: If the cosine similarity of the Internet source domain intrusion detection data recommended by the recommendation system for the Internet of Things target domain is greater than the set threshold, use the intrusion type of the Internet source domain intrusion detection data recommended by the recommendation system as the final intrusion type; If the set threshold is not reached, use the neural network classifier to perform intrusion detection on the Internet of Things target domain intrusion detection data.

2. The Internet of Things intrusion detection method according to claim 1, characterized in that, the step S2 includes: Using the Latent Semantic Indexing algorithm, use the Internet source domain intrusion detection data as input to construct a recommendation system trained based on the source domain; its mathematical expression is: Among them, the M matrix is the source domain feature matrix, U is the feature-hidden space matrix, T is the hidden space transformation matrix, V is the communication data-hidden space matrix, and R is the dimension parameter. is the i-th communication data of the Internet source domain. is the j-th communication data of the Internet of Things target domain. ‘ is the data representation of the j-th communication data of the Internet of Things target domain after being processed by the recommendation system.

3. The Internet of Things intrusion detection method according to claim 2, characterized in that, the step S3 includes: Using the recommendation system trained based on the source domain, recommend a most similar Internet source domain intrusion detection data for each Internet of Things target domain intrusion detection data, and use the intrusion category label of the recommended Internet source domain intrusion detection data as the recommendation system label of the Internet of Things target domain intrusion detection data, and its mathematical expression is as follows: Among them, RS S (x T j ) represents the Internet source domain data recommended for the communication data of the j-th Internet of Things target domain, and PL is the recommendation system label of the communication data of the j-th Internet of Things target domain; After that, for all Internet of Things target domain intrusion detection data, take the mean vector according to their recommendation system labels by category.

4. The Internet of Things intrusion detection method according to claim 3, characterized in that, the step S5 includes: Take the average of all Internet source domain intrusion detection data by category, and use the recommendation system trained based on the target domain to recommend the top N similar Internet of Things target domain intrusion detection data for the mean vector of each Internet source domain intrusion detection data, and take the mean vector of the N similar Internet of Things target domain intrusion detection data.

5. The Internet of Things intrusion detection method according to claim 4, characterized in that, the step S6 includes: Minimize the Euclidean distance between the recommendation results of the recommendation system trained based on the source domain and the recommendation results of the recommendation system trained based on the target domain for each communication category. The mathematical expression is as follows: Among them, L ABR is the matching loss of the recommendation system, and are the recommendations of the recommendation system trained based on the source domain for the IoT target domain and the recommendations of the recommendation system trained based on the target domain for the Internet source domain, respectively.

6. The Internet of Things intrusion detection method according to claim 5, wherein, the step S7 includes: Calculate the supervised loss of the Internet source domain intrusion detection data. The mathematical expression is as follows: Where: L SUP is the supervision loss of Internet source domain intrusion detection data; n S is the amount of Internet source domain intrusion detection data; L CE is the cross-entropy loss function; C is the common classifier, which is a one-layer neural network; f is the feature mapper; x and y are the features of the Internet source domain intrusion detection data and their corresponding labels respectively.

7. The Internet of Things intrusion detection method according to claim 6, wherein, the step S8 includes: Adopt the gradient descent optimization algorithm to optimize the supervised loss and the matching loss of the recommendation system, and update the network parameters; determine whether the model converges: if the model converges, execute step S9; otherwise, return to step S1.

8. An Internet of Things intrusion detection device, wherein, it includes: Input module: used to input the Internet source domain intrusion detection data into the source domain feature mapper, and input the Internet of Things target domain intrusion detection data into the target domain feature mapper; Construction module: used to construct a recommendation system trained based on the source domain with the Internet source domain intrusion detection data as the input; Recommendation module: used to adopt the recommendation system trained based on the source domain to recommend a most similar Internet source domain intrusion detection data for each Internet of Things target domain intrusion detection data; Construction module: also used to construct a recommendation system trained based on the target domain with the Internet of Things target domain intrusion detection data as the input; Recommendation module: also used to adopt the recommendation system trained based on the target domain to recommend the top N similar Internet of Things target domain intrusion detection data for the mean vector of each Internet source domain intrusion detection data; Matching loss calculation module: used to calculate the Euclidean distance between the recommendation results of the recommendation system trained based on the source domain and the recommendation results of the recommendation system trained based on the target domain for each communication category, and obtain the matching loss of the recommendation system; Supervised loss calculation module: used to calculate the supervised loss according to the Internet source domain intrusion detection data; Update module: used to optimize the supervised loss and the matching loss of the recommendation system, and update the parameters of the neural network; Intrusion detection module: used to use the intrusion type of the Internet source domain intrusion detection data recommended by the recommendation system as the final intrusion type when the cosine similarity of the Internet source domain intrusion detection data recommended by the recommendation system for the Internet of Things target domain is greater than the set threshold; when the set threshold is not reached, the neural network classifier is used to perform intrusion detection on the Internet of Things target domain intrusion detection data.

9. A device, wherein, the device includes a processor and a memory coupled to the processor, wherein, the memory stores program instructions for implementing the Internet of Things intrusion detection method according to any one of claims 1-7; the processor is used to execute the program instructions stored in the memory to control Internet of Things intrusion detection.

10. A storage medium, wherein, it stores program instructions that can be run by a processor, and the program instructions are used to execute the Internet of Things intrusion detection method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Method and system for constructing network intrusion detection model based on transfer learning

    CN110224987A

  • Industrial control system intrusion detection method based on time convolutional network and transfer learning

    CN113132399A

Cited By

  • Internet of Things intrusion detection method and device based on artificial intelligence, and electronic equipment

    CN116962027A