A method and apparatus for assessing real-time security
By combining drift detection and adaptability, the KernelSHAP method is used to update the weights of safety metrics, addressing the challenge of real-time safety assessment in non-stationary environments and achieving more accurate safety assessment results.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- TSINGHUA UNIVERSITY
- Filing Date
- 2023-07-05
- Publication Date
- 2026-04-14
AI Technical Summary
In non-stationary environments, existing real-time security assessment methods struggle to effectively detect significant changes and provide timely responses. Challenges such as incremental model update strategies, data loss balance properties, limited annotation budgets, and concept drift lead to inaccurate assessment results.
Combining drift detection and adaptation, the weights of security metrics are updated using the KernelSHAP method, the evaluation model is updated incrementally, and the updated model is used to predict security evaluation results. Concept drift is detected and weights are adjusted, an initial labeled dataset and its annotations are constructed, and the evaluation model is updated incrementally.
It reduces the negative impact of approximation errors, improves the accuracy of real-time safety assessments in non-stationary environments, enables timely response to safety hazards, and ensures the effectiveness of assessment results.
Smart Images

Figure CN116821624B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of real-time security assessment technology, and in particular to a real-time security assessment method and apparatus. Background Technology
[0002] Real-time safety assessment is a crucial task in industrial processes. By continuously monitoring and assessing systems in real time, timely alerts and responses can be issued when safety hazards are detected, enabling engineers and maintenance personnel to quickly address safety issues. Traditional safety assessment methods can be divided into two categories: qualitative analysis and quantitative analysis. Qualitative analysis uses qualitative information for safety assessment, utilizing information fusion and fuzzy theory methods to accomplish the task. Quantitative analysis uses performance and status data for safety assessment.
[0003] However, in non-stationary environments, evaluation models need to detect significant changes and provide timely and effective responses; otherwise, irreversible damage may occur. Therefore, further research into the effectiveness of these methods in evaluating system security in non-stationary environments is crucial. While block-level real-time security assessment can maximize the use of statistical information implicit in data, many challenges remain to be addressed in practical block-level real-time security assessment tasks, including incremental model update strategies, the imbalanced nature of data flows, limited annotation budgets, and the detection and adaptation to different concept drifts. Summary of the Invention
[0004] This invention provides a method and apparatus for evaluating real-time security, which reduces the negative impact of approximation errors by combining drift detection and adaptability with the ranking preferences of the generated interpretation, thereby better predicting the results of real-time security evaluation tasks.
[0005] In a first aspect, the present invention provides a method for evaluating real-time security, comprising:
[0006] Acquire the monitoring data stream, and extract the security level information corresponding to each data block at each moment from the monitoring data stream;
[0007] The weight changes of the security indicators are updated based on the security level information using the KernelSHAP method.
[0008] The evaluation model is incrementally updated using the updated security indicators and their weights, and the updated evaluation model is used to predict the security evaluation results.
[0009] The security assessment result is determined based on the pre-set decision threshold and the security assessment result.
[0010] Optionally, the evaluation model is incrementally updated using the updated security metrics and their weights, and the updated evaluation model is used to predict the security evaluation results, including:
[0011] Using the updated security metrics and their weights, an initial labeled dataset and its annotations are constructed, and the mapping relationship between the data and the annotations in the initial labeled dataset is determined.
[0012] The evaluation model is incrementally updated based on the mapping relationship between the initial labeled data and the annotations;
[0013] The predicted security assessment result is determined using the updated assessment model.
[0014] Optionally, the weight changes of the security indicators are updated based on the security level information using the KernelSHAP method, including:
[0015] Based on the data block, an initial interpretation is generated;
[0016] The KernelSHAP method is used to detect the concept drift between the initial interpretation and the corresponding security level information;
[0017] When concept drift is detected, the weight changes of the security metric are updated.
[0018] Optionally, the KernelSHAP method is used to detect the concept drift between the initial interpretation and the corresponding security level information, including:
[0019] The relative performance between the initial interpretation and the security metric is determined using the KernelSHAP method.
[0020] Based on the relative performance, the ranking deviation between the data blocks is determined;
[0021] The concept drift is detected based on the ranking deviation and a pre-set ranking deviation threshold.
[0022] Secondly, the present invention provides a real-time security assessment device, comprising:
[0023] The acquisition module is used to acquire the monitoring data stream and extract the security level information corresponding to each data block at each moment from the monitoring data stream.
[0024] The weight update module is used to update the weight changes of the security indicators based on the security level information using the KernelSHAP method.
[0025] The model update module is used to incrementally update the evaluation model with the updated security indicators and their weights, and use the updated evaluation model to predict the security evaluation results.
[0026] The security assessment result determination module is used to determine the security assessment result based on a pre-set decision threshold and the security assessment result.
[0027] Optionally, the model update module includes:
[0028] The mapping relationship determination submodule is used to construct an initial labeled dataset and its annotations using the updated security metrics and their weights, and to determine the mapping relationship between the data and the annotations in the initial labeled dataset;
[0029] The model update submodule is used to incrementally update the evaluation model based on the mapping relationship between the initial labeled data and the annotations;
[0030] The security assessment result determination submodule is used to determine the predicted security assessment result through the updated assessment model.
[0031] Optionally, the weight update module includes:
[0032] An initial interpretation generation submodule is used to generate an initial interpretation based on the data block;
[0033] The concept drift detection submodule is used to detect the concept drift between the initial interpretation and the corresponding security level information using the KernelSHAP method.
[0034] The weight update submodule is used to update the weight changes of the security metric when concept drift is detected.
[0035] Optionally, the concept drift detection submodule includes:
[0036] The relative performance determination unit is used to determine the relative performance between the initial interpretation and the security index using the KernelSHAP method.
[0037] The ranking deviation determination unit is used to determine the ranking deviation between the data blocks based on the relative performance.
[0038] The drift determination unit is used to detect the concept drift based on the ranking deviation and a pre-set ranking deviation threshold.
[0039] Thirdly, this application provides an electronic device including a processor and a memory, the memory storing computer-readable instructions that, when executed by the processor, perform the steps of the method provided in the first aspect above.
[0040] Fourthly, this application provides a storage medium having a computer program stored thereon, which, when executed by a processor, performs the steps of the method provided in the first aspect above.
[0041] As can be seen from the above technical solutions, the present invention has the following advantages:
[0042] This invention provides a method and apparatus for real-time security assessment. The method includes: acquiring a monitoring data stream and extracting security level information corresponding to each time step of all data blocks from the monitoring data stream; updating the weight changes of the security indicators based on the security level information using the KernelSHAP method; incrementally updating the assessment model with the updated security indicators and their weights, and using the updated assessment model to predict the security assessment result; and determining the security assessment result based on a pre-set decision threshold and the security assessment result. The KernelSHAP method, by extensively learning the system structure, determines the importance of newly collected monitoring data streams, reduces the negative impact of approximation errors, and combines drift detection and adaptability with the ranking preferences of the generated interpretations, thereby better predicting the results of real-time security assessment tasks. Attached Figure Description
[0043] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0044] Figure 1 This is a flowchart illustrating the steps of a real-time security assessment method according to an embodiment of the present invention.
[0045] Figure 2 This is a flowchart illustrating the steps of a second embodiment of the real-time security assessment method of the present invention.
[0046] Figure 3 A schematic diagram illustrating the dynamic model within an online active learning framework;
[0047] Figure 4 A schematic diagram of Jeffrey divergence when η = 0.5;
[0048] Figure 5 A schematic diagram of Jeffrey divergence when η = 1;
[0049] Figure 6 A schematic diagram of the Kullback-Leibler divergence when η = 1;
[0050] Figure 7 This is a structural block diagram of an embodiment of a real-time security assessment device according to the present invention. Detailed Implementation
[0051] This invention provides a method and apparatus for evaluating real-time security, which reduces the negative impact of approximation errors by combining drift detection and adaptability with the ranking preferences of the generated interpretation, thereby better predicting the results of real-time security evaluation tasks.
[0052] To make the objectives, features, and advantages of this invention more apparent and understandable, the technical solutions of the embodiments of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the embodiments described below are only some embodiments of this invention, and not all embodiments. Based on the embodiments of this invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this invention.
[0053] Example 1, please refer to Figure 1 , Figure 1 The flowchart of a real-time security assessment method according to an embodiment of the present invention includes:
[0054] Step S101: Obtain the monitoring data stream and extract the security level information corresponding to each data block at each moment from the monitoring data stream;
[0055] Step S102: Update the weight changes of the security indicators based on the security level information using the KernelSHAP method;
[0056] It should be noted that the KernelSHAP method treats the sampled feature combination as a subset of the model, then calculates the contribution of this subset to the target prediction output, and finally combines each feature to calculate the contribution of the entire prediction output.
[0057] The main idea is to approximate the true Shapley function using weighted linear regression. Typically, the value function v is set as the model prediction f(·). Existing work has proposed the LIME method to provide local interpretation. KernelSHAP is constructed based on LIME and Shapley values. LIME-based interpretive models typically use simplified inputs x', which are mapped through the function x = h. x (x') is mapped onto the original input. Local methods aim to ensure that when z'≈x', g(z')≈f(h) as much as possible. x (z')). Let f t For the original prediction model to be explained at time t, g t To explain the model.
[0058] Step S103: Incrementally update the evaluation model with the updated security indicators and their weights, and use the updated evaluation model to predict the security evaluation results.
[0059] Step S104: Determine the security assessment result based on the preset decision threshold and the security assessment result.
[0060] A real-time security assessment method provided in this embodiment of the invention includes: acquiring a monitoring data stream and extracting security level information corresponding to each time step of all data blocks from the monitoring data stream; updating the weight changes of the security indicators based on the security level information using the KernelSHAP method; incrementally updating the assessment model with the updated security indicators and their weights, and using the updated assessment model to predict the security assessment result; and determining the security assessment result based on a pre-set decision threshold and the security assessment result. The KernelSHAP method determines the importance of newly collected monitoring data streams based on extensive learning of the system structure, reduces the negative impact of approximation errors, and combines drift detection and adaptability with the ranking preferences of the generated interpretations, thereby better predicting the results of real-time security assessment tasks.
[0061] Example 2, please refer to Figure 2 , Figure 2 The flowchart of a second embodiment of the real-time security assessment method of the present invention includes:
[0062] Step S201: Obtain the monitoring data stream and extract the security level information corresponding to each data block at each moment from the monitoring data stream;
[0063] This invention relates to the CRTSA (Crack-Level Real-Time Security Assessment) problem. Assume that this invention collects a monitoring data stream D = {C1, C2, ...} = {x1, x2, ..., x...}. D}, where data blocks Given d safety indicators {S1, S2, ..., S} at time t d}generate.
[0064] It should be noted that there are m security levels in the monitoring data stream. yes The classification labels. In this case, the initial labeled dataset can be obtained. and its annotations (represented as Y using one-hot encoding) L0 ∈R |L0|×m ). Generally, the generated C t∈D is unlabeled. The main purpose is to select a small amount of data for annotation using a well-designed strategy. If It deserves annotation; experts can provide authentic labels. Classifier f t It can be updated incrementally over time. Ideally, with limited annotations, we want the evaluation model (i.e., the classifier) to achieve high safety evaluation accuracy.
[0065] Step S202: Generate an initial interpretation based on the data block;
[0066] Step S203: Detect the concept drift between the initial interpretation and the corresponding security level information using the KernelSHAP method;
[0067] In an optional embodiment, the KernelSHAP method is used to detect the concept drift between the initial interpretation and the corresponding security level information, including:
[0068] The relative performance between the initial interpretation and the security metric is determined using the KernelSHAP method.
[0069] Based on the relative performance, the ranking deviation between the data blocks is determined;
[0070] The concept drift is detected based on the ranking deviation and a pre-set ranking deviation threshold.
[0071] This invention uses a BLS evaluation model, which typically contains two types of neurons: feature nodes (N per group). f (N nodes) and enhancement nodes (N nodes per group) e (a number of nodes). For any... and The i-th group of feature nodes Z0∈R |L0|×Nf The mapping result can be represented as:
[0072]
[0073] Here, μ(·) represents the mapping function. In this case, the initial labeled dataset It can be mapped to a random feature space. W fi and β fi Let N represent the corresponding randomly generated weights and biases, respectively. For any feature group N f 1 node The mapping result can be represented as:
[0074]
[0075] Where Z0 is the initial dataset. The random characteristics. For the j-th augmentation node, we have:
[0076]
[0077] in, This represents the nonlinear mapping result and related operations for the random feature space of the j-th augmentation node. ei and β ei Let W represent the weights and biases of the i-th augmentation node, respectively, and W... ei and β ei They are all randomly generated. ξ j (·) represents the nonlinear mapping function for the j-th group of feature nodes, such as the tanh function or the sigmoid function. ξ for each group of feature nodes... j (·) can remain consistent.
[0078] Based on this, we can conclude that:
[0079]
[0080] Where H0 is the initial dataset. Enhanced features.
[0081] Let A0 represent the series connection of Z0 and H0 (i.e., [Z0|H0]), then and The mapping between them can be represented as:
[0082]
[0083] If random weights and biases (i.e., W) f β f W e and β e ) and the basic mapping functions μ(·) and ξ j (·) is fixed, and any newly acquired data can be projected onto the same random feature space.
[0084] Simultaneously, within the online active learning framework, several valuable samples need to be annotated. (Using C...) t For example, suppose This represents the query batch at time t, where Q t ∈C t Therefore, we can obtain:
[0085]
[0086] In this case, the mapping result at any time t can be expressed as:
[0087]
[0088] Therefore, the new weight vector at time t can be represented as:
[0089]
[0090] Furthermore, to ensure the accuracy of subsequent drift detection results as much as possible, the generalized inverse used in the iterative update rule is solved using the Sherman-Morrison formula. Specifically, for the task query batch Q... t The update rule can be represented as follows:
[0091]
[0092] in,
[0093] Step S204: When concept drift is detected, update the weight changes of the safety indicator;
[0094] In this embodiment of the invention, m security levels need to be considered for the real-time security assessment problem. For the j-th security level and instance... We need to find a solution to the following objective function:
[0095]
[0096]
[0097] Where z'∈{0,1} d , π x' Let L represent the weighting kernel. For KernelSHAP, the loss function L and the weighting kernel can be expressed as:
[0098]
[0099]
[0100] Here, |z'| represents the number of non-zero elements in z'. In this case, when |z'|={0,d}, the solution to the equation is an approximate KernelSHAP value, at which point Ω(g t ) = 0, and π x' (z')=∞.
[0101] In addition, f t and g t Dynamic changes are required. If a significant change is detected in the generated model interpretation, it is assumed that the underlying distributions of the monitored security metrics have also changed accordingly. Please refer to [link / reference]. Figure 3 , Figure 3 This is a schematic diagram illustrating the dynamic model within an online active learning framework. The diagram shows the initial labeled dataset. An initial interpretation φ0 is generated by the interpreter. Then, with each batch of data blocks arriving, the importance of each security metric changes according to the interpretation of the data blocks, thereby detecting concept drift. When drift is detected, contribution metrics can be used to explain these changes, evaluate the value of this batch of data samples, and guide the interpreter's update process.
[0102] However, background data plays a crucial role in controlling sampling variability and directly affects the estimation accuracy of SHAP values. In this case, the obtained KernelSHAP values are not stable enough. Based on this, embodiments of the present invention primarily consider monitoring the ranking preferences of all security metrics to monitor medium to large changes. Furthermore, the imbalanced characteristics of the data stream are also very important. Let N... j Let represent the number of collection instances predicted to have security level j, where j∈{1,2,…,m}. Then the normalized imbalance weights can be expressed as:
[0103]
[0104] For C t any have:
[0105]
[0106] For all security metrics, the feature importance of the t-th data block can be obtained as follows:
[0107]
[0108] Furthermore, safety indicators The relative performance (RP) can be calculated as follows:
[0109]
[0110] Where σ[·] represents the sorting function,
[0111] To obtain the rank deviation (RPD) between the previous data block and the current data block, the following formula can be used:
[0112]
[0113] Where η is a hyperparameter used to control the numerical range. J(·) is the Jeffrey divergence; please refer to [link to relevant documentation]. Figures 4-5 , Figure 4 The diagram shows the Jeffrey divergence when η = 0.5. Figure 5This is a schematic diagram of Jeffrey divergence when η=1. For the same type of divergence, the data range is not the same under different hyperparameters. Jeffrey divergence can be used to measure the relative information loss between two ranking lists when dealing with ranking preferences. Jeffrey divergence can be used to effectively assess and extract the interaction effect between the two, and its formula is expressed as:
[0114]
[0115]
[0116] Where KL(·) represents the Kullback-Leibler divergence, please refer to [link to relevant documentation]. Figure 6 , Figure 6 This is a schematic diagram of the Kullback-Leibler divergence when η=1, compared to... Figure 5 It can be seen that under the same hyperparameters, the data ranges of different types of divergences are not the same. For the RP distribution, the Jeffrey divergence is used to simulate a better bias because it is symmetric and has a lower bound, making J(·) > 0. Let the RPD threshold of the t-th data block be θ. t Drift detection can be described as:
[0117]
[0118] Where δ(t,t-1)>θ t This indicates that a drift has been detected, and when a drift is detected, it is necessary to update the KernelSHAP interpreter accordingly. Generally, if the underlying distribution of the data tends to be stable, then... This is common. In this case, since the model is not updated for long periods, streaming data blocks may not be annotated for a long time (referred to as "cold annotation" in this embodiment). However, in practice, we want the threshold to be dynamically adjusted to accommodate this process. Let ζ t+1 The number of cold annotation samples in the (t+1)th data block can be defined as:
[0119]
[0120] Furthermore, it is reasonable to select multiple instances for annotation. RP can be viewed as C. t The "representative opinion" of all samples in the dataset. Therefore, it is natural to annotate those samples that express more support for this type of opinion (i.e., query batch Q). t For any exist make Indicates all about The one-hot encoded reliability metric for predicting security indicators. In the t-th data block C... t In this context, the evaluation sample values are highly dependent on the evaluation uncertainty, and samples with high uncertainty typically have higher annotation values. Based on this, we can conclude that:
[0121]
[0122] in, The uncertainties in an unbalanced data stream can be defined as:
[0123]
[0124] Therefore, Q t By selecting the one with the smallest |Q t | values are obtained from samples.
[0125] Step S205: Using the updated security metrics and their weights, construct an initial labeled dataset and its annotations, and determine the mapping relationship between the data and the annotations in the initial labeled dataset;
[0126] Step S206: Based on the mapping relationship between the initial labeled data and the annotations, incrementally update the evaluation model;
[0127] Step S207: Determine the predicted security assessment result using the updated assessment model;
[0128] Step S208: Determine the security assessment result based on the preset decision threshold and the security assessment result.
[0129] A real-time security assessment method provided in this embodiment of the invention includes: acquiring a monitoring data stream and extracting security level information corresponding to each time step of all data blocks from the monitoring data stream; updating the weight changes of the security indicators based on the security level information using the KernelSHAP method; incrementally updating the assessment model with the updated security indicators and their weights, and using the updated assessment model to predict the security assessment result; and determining the security assessment result based on a pre-set decision threshold and the security assessment result. The KernelSHAP method determines the importance of newly collected monitoring data streams based on extensive learning of the system structure, reduces the negative impact of approximation errors, and combines drift detection and adaptability with the ranking preferences of the generated interpretations, thereby better predicting the results of real-time security assessment tasks.
[0130] Example 3, please refer to Figure 7 , Figure 7 This is a structural block diagram of an embodiment of a real-time security assessment device according to the present invention, comprising:
[0131] The acquisition module 501 is used to acquire the monitoring data stream and extract the security level information corresponding to each data block at each moment from the monitoring data stream.
[0132] The weight update module 502 is used to update the weight changes of the security indicators based on the security level information using the KernelSHAP method.
[0133] The model update module 503 is used to incrementally update the evaluation model with the updated security indicators and their weights, and use the updated evaluation model to predict the security evaluation results.
[0134] The security assessment result determination module 504 is used to determine the security assessment result based on a pre-set decision threshold and the security assessment result.
[0135] In an optional embodiment, the model update module 503 includes:
[0136] The mapping relationship determination submodule is used to construct an initial labeled dataset and its annotations using the updated security metrics and their weights, and to determine the mapping relationship between the data and the annotations in the initial labeled dataset;
[0137] The model update submodule is used to incrementally update the evaluation model based on the mapping relationship between the initial labeled data and the annotations;
[0138] The security assessment result determination submodule is used to determine the predicted security assessment result through the updated assessment model.
[0139] In an optional embodiment, the weight update module 502 includes:
[0140] An initial interpretation generation submodule is used to generate an initial interpretation based on the data block;
[0141] The concept drift detection submodule is used to detect the concept drift between the initial interpretation and the corresponding security level information using the KernelSHAP method.
[0142] The weight update submodule is used to update the weight changes of the security metric when concept drift is detected.
[0143] In an optional embodiment, the concept drift detection submodule includes:
[0144] The relative performance determination unit is used to determine the relative performance between the initial interpretation and the security index using the KernelSHAP method.
[0145] The ranking deviation determination unit is used to determine the ranking deviation between the data blocks based on the relative performance.
[0146] The drift determination unit is used to detect the concept drift based on the ranking deviation and a pre-set ranking deviation threshold.
[0147] This invention also provides an electronic device, including a memory and a processor. The memory stores a computer program, which, when executed by the processor, causes the processor to perform the steps of a real-time security assessment method as described in any of the above embodiments.
[0148] This invention also provides a computer storage medium storing a computer program thereon, which, when executed by the processor, implements the steps of a real-time security assessment method as described in any of the above embodiments.
[0149] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0150] In the several embodiments provided in this application, it should be understood that the methods, apparatuses, electronic devices, and storage media disclosed in this invention can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual couplings, direct couplings, or communication connections may be through some interfaces; indirect couplings or communication connections between devices or units may be electrical, mechanical, or other forms.
[0151] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0152] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0153] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a readable storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned readable storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0154] The above-described embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for evaluating real-time security, characterized in that, include: Acquire the monitoring data stream, and extract the security level information corresponding to each data block at each moment from the monitoring data stream; The weight changes of security indicators are updated based on the security level information using the KernelSHAP method. The assessment model is incrementally updated with the updated security metrics and their weights, and the updated assessment model is used to predict the security assessment results. The security assessment result is determined based on the pre-set decision threshold and the security assessment result. The weight changes of the security indicators are updated based on the security level information using the KernelSHAP method, including: Based on the data block, an initial interpretation is generated; The KernelSHAP method is used to detect the concept drift between the initial interpretation and the corresponding security level information; When concept drift is detected, the weight changes of the security metric are updated.
2. The real-time security assessment method according to claim 1, characterized in that, The evaluation model is incrementally updated using the updated security metrics and their weights, and the updated evaluation model is used to predict security evaluation results, including: Using the updated security metrics and their weights, an initial labeled dataset and its annotations are constructed, and the mapping relationship between the data and the annotations in the initial labeled dataset is determined. The evaluation model is incrementally updated based on the mapping relationship between the initial labeled data and the annotations; The predicted security assessment result is determined using the updated assessment model.
3. The real-time security assessment method according to claim 1, characterized in that, The KernelSHAP method is used to detect the concept drift between the initial interpretation and the corresponding security level information, including: The relative performance between the initial interpretation and the security metric is determined using the KernelSHAP method. Based on the relative performance, the ranking deviation between the data blocks is determined; The concept drift is detected based on the ranking deviation and a pre-set ranking deviation threshold.
4. A real-time security assessment device, characterized in that, include: The acquisition module is used to acquire the monitoring data stream and extract the security level information corresponding to each data block at each moment from the monitoring data stream. The weight update module is used to update the weight changes of security indicators based on the security level information using the KernelSHAP method. The model update module is used to incrementally update the evaluation model with the updated security indicators and their weights, and to use the updated evaluation model to predict the security evaluation results. The security assessment result determination module is used to determine the security assessment result based on a pre-set decision threshold and the security assessment result. The weight update module includes: An initial interpretation generation submodule is used to generate an initial interpretation based on the data block; The concept drift detection submodule is used to detect the concept drift between the initial interpretation and the corresponding security level information using the KernelSHAP method. The weight update submodule is used to update the weight changes of the security metric when concept drift is detected.
5. The real-time security assessment device according to claim 4, characterized in that, The model update module includes: The mapping relationship determination submodule is used to construct an initial labeled dataset and its annotations using the updated security metrics and their weights, and to determine the mapping relationship between the data and the annotations in the initial labeled dataset; The model update submodule is used to incrementally update the evaluation model based on the mapping relationship between the initial labeled data and the annotations; The security assessment result determination submodule is used to determine the predicted security assessment result through the updated assessment model.
6. The real-time security assessment device according to claim 4, characterized in that, The concept drift detection submodule includes: The relative performance determination unit is used to determine the relative performance between the initial interpretation and the security index using the KernelSHAP method. The ranking deviation determination unit is used to determine the ranking deviation between the data blocks based on the relative performance. The drift determination unit is used to detect the concept drift based on the ranking deviation and a pre-set ranking deviation threshold.
7. An electronic device, characterized in that, It includes a processor and a memory, the memory storing computer-readable instructions, which, when executed by the processor, perform the method as described in any one of claims 1-3.
8. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it performs the method as described in any one of claims 1-3.
Citation Information
Patent Citations
Equipment safety risk assessment method and device based on multiple neural networks
CN114418409A
Power system inertia short-term prediction method based on SHAP-XGBoost algorithm
CN115759380A