An update anomaly detection method

By receiving updated data from IoT devices and extracting abnormal feature values, and utilizing a multi-round trained anomaly detection model and the Isolation Forest algorithm, the security threats during the OTA update process of IoT devices are solved, achieving more efficient anomaly detection and security protection.

CN119603015BActive Publication Date: 2025-11-18CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411676445.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-21
Publication Date
2025-11-18
Estimated Expiration
2044-11-21

AI Technical Summary

Technical Problem

IoT devices are vulnerable to malicious attacks, data tampering, and man-in-the-middle attacks during OTA updates, leading to security issues.

Method used

By receiving updated data from the first time window, multiple abnormal feature values ​​are extracted and processed using an anomaly detection model trained multiple times on the training sample set to determine whether the updated data is abnormal. The isolated forest algorithm is used to adjust the maximum number of samples to improve the robustness and detection efficiency of the model.

Benefits of technology

It improves the security of OTA updates for IoT devices, effectively detecting and preventing malicious attacks and data tampering.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119603015B_ABST
    Figure CN119603015B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of network security, in particular to an updating anomaly detection method. Embodiments of the application receive updating data of a first time window; determine a plurality of abnormal feature values of the updating data of the first time window, the plurality of abnormal feature values being respectively used to represent data transmission states of the updating data in a plurality of dimensions; process the plurality of abnormal feature values based on an anomaly detection model to determine whether the updating data of the first time window is abnormal; wherein the anomaly detection model is obtained through multiple rounds of training based on a training sample set, in each round of training, training samples are obtained from the training sample set based on a maximum sample number, each training sample includes a feature sample of training data corresponding to a preset time length and an abnormal label; and the maximum sample number used in each round of training is determined based on training samples used in a previous round of training or an error rate of a model after the previous round of training.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular to an update anomaly detection method. Background Technology

[0002] OTA updates are typically used for devices such as smartphones and smart cars that require regular feature updates, security patches, or configuration changes. This technology allows device manufacturers or service providers to remotely update devices without physical contact, thus simplifying device maintenance and management.

[0003] When IoT devices undergo OTA updates, they need to receive a large amount of data, making them vulnerable to security threats such as malicious attacks, data tampering, and man-in-the-middle attacks during the upgrade process.

[0004] Therefore, improving the security of IoT device update processes has become an urgent technical problem to be solved. Summary of the Invention

[0005] This application provides an update anomaly detection method to improve the security of IoT device update processes.

[0006] Firstly, this application provides an update anomaly detection method, the method comprising:

[0007] Receive updated data for the first time window; the duration of the first time window is a preset duration;

[0008] Determine multiple abnormal feature values ​​for the updated data in the first time window, wherein the multiple abnormal feature values ​​are used to characterize the data transmission status of the updated data in multiple dimensions.

[0009] The multiple abnormal feature values ​​are processed based on the anomaly detection model to determine whether the updated data in the first time window is abnormal.

[0010] The anomaly detection model is obtained through multiple rounds of training based on the training sample set. In each round of training, training samples are obtained from the training sample set based on the maximum number of samples. Each training sample includes a feature sample of the training data corresponding to a preset duration and an anomaly label. The maximum number of samples used in each round of training is determined based on the training samples used in the previous round of training or the model error rate after the previous round of training.

[0011] The above scheme extracts multiple abnormal feature values ​​from the updated data to detect unique network traffic characteristics during OTA updates, and combines this with an anomaly detection model to identify anomalies in the update process. This anomaly detection model is obtained through a dynamic strategy that adaptively adjusts the maximum sample size to improve the model's robustness and detection efficiency.

[0012] In some optional implementations, the plurality of abnormal feature values ​​include some or all of the expected offset feature value, response duration feature value, rate change feature value, and integrity feature value;

[0013] The expected offset feature value is determined based on the integrity detection result of the data packets contained in the updated data of the first time window, the data volume of the updated data of the first time window, and the expected data volume.

[0014] The response duration feature value is determined based on the amount of updated data in the first time window and the data transmission duration of the updated data in the first time window;

[0015] The rate change characteristic value is determined based on the data transmission rate of the updated data in the first time window and the data transmission rate of the updated data in the second time window; the reception time of the updated data in the second time window is earlier than the reception time of the updated data in the first time window.

[0016] The integrity feature value is the product of the integrity detection result of the data packets included in the updated data of the first time window and the amount of data in the first time window.

[0017] In some alternative implementations, the maximum number of samples used in each round of training is determined in the following way:

[0018] Based on the amount of training samples used in the previous training round and / or the model error rate after the previous training round, the target abnormal state is determined among multiple abnormal states;

[0019] Adjust the maximum number of samples used in the previous training round based on the adjustment method corresponding to the target abnormal state, and obtain the maximum number of samples used in the current training round.

[0020] In some optional implementations, the multiple abnormal states include abnormal data volume, abnormal data complexity, abnormal data change, and abnormal model detection; the determination of the target abnormal state among the multiple abnormal states based on the data volume of the training samples used in the previous training round and / or the model error rate after the previous training round includes:

[0021] According to the priority order of various abnormal states, it is determined whether the training samples used in the previous round of training meet the above-mentioned abnormal data volume, abnormal data complexity, and abnormal data change; when it is determined that any abnormal state is met, the above-mentioned abnormal state is taken as the target abnormal state.

[0022] If the abnormality in data volume, data complexity, and data change does not meet the criteria, then determine whether the model error rate after the previous training round meets the criteria for model detection anomaly.

[0023] If the model detects an anomaly, then the model detects the anomaly as the target anomaly state.

[0024] In some alternative implementations, the determination of whether the data volume is abnormal is made in the following ways:

[0025] The amount of training sample data used in the previous training round is compared with a preset data amount threshold; if it is greater than the first data amount threshold or less than the second data amount threshold, it is determined that the data amount is abnormal, and the first data amount threshold is not less than the second data amount threshold.

[0026] In some alternative implementations, the determination of whether the data complexity anomaly is met is made in the following ways:

[0027] The complexity of the training samples used in the previous training round is compared with a complexity threshold; if it is greater than the first complexity threshold or less than the second complexity threshold, it is determined that the data complexity is abnormal, and the first complexity threshold is not less than the second complexity threshold; the complexity of the training samples is determined based on the amount of data in the corresponding training samples.

[0028] In some alternative implementations, the determination of whether data changes are abnormal is made in the following ways:

[0029] Compare the amount of data from the training samples used in the first two rounds of training, or compare the amount of data from the training samples used in every two adjacent orders in the previous round of training; if they are different, then it is determined that the data change is abnormal.

[0030] In some alternative implementations, the determination of whether the model detects anomalies is made in the following ways:

[0031] The error rate of the model after the previous training round is compared with the preset error tolerance rate. If it is greater than the first error tolerance rate or less than the second error tolerance rate, it is determined that the model detects an anomaly. The first error tolerance rate is not less than the second error tolerance rate.

[0032] In some optional implementations, adjusting the maximum number of samples used in the previous training round based on the adjustment method corresponding to the target abnormal state includes:

[0033] When the target abnormal state is an abnormal data volume, a first adjustment weight is determined based on the difference between the data volume of the training samples used in the first two rounds of training; the maximum number of samples used in the previous round of training is adjusted based on the first adjustment weight; or...

[0034] When the target anomalous state is an anomalous data complexity, a second adjustment weight is determined based on the difference between the complexity of the training samples used in the previous training round and a complexity threshold; the maximum number of samples used in the previous training round is adjusted based on the second adjustment weight; or...

[0035] When the target abnormal state is an abnormal data change, the data volume change is determined by comparing the data volume of the training samples used in the previous two rounds of training, or by comparing the data volume of every two adjacent training samples used in the previous round of training, wherein the data volume change is either an increase or no increase; based on the third adjustment weight corresponding to the data volume change, the maximum number of samples used in the previous round of training is adjusted; or...

[0036] When the target abnormal state is a model detection abnormality, the ratio of the model error rate after the previous training round to the preset error tolerance rate is used as the fourth adjustment weight, and the maximum number of samples used in the previous training round is adjusted based on the fourth adjustment weight.

[0037] In some optional implementations, if the data volume change refers to the data volume change between every two adjacent training samples, then adjusting the maximum number of samples used in the previous training round based on the third adjustment weight corresponding to the data volume change includes:

[0038] Following the order of the training samples used in the previous training round, perform the following operations for each training sample used in the previous training round:

[0039] Based on the changes in the amount of data between the training samples and the reference training samples, a third adjustment weight corresponding to the changes in the amount of data is determined; the reference training sample is the training sample that is in the next adjacent order of the training samples in the previous training round.

[0040] The current maximum number of samples is adjusted based on the third adjustment weight. The current maximum number of samples is the maximum number of samples used in the previous training round, or the current maximum number of samples is the maximum number of samples adjusted based on the changes in the data volume of at least two training samples used in the previous training round.

[0041] Secondly, embodiments of this application provide an updated anomaly detection device, the device comprising:

[0042] The receiving module is used to receive update data of the first time window; the duration of the first time window is a preset duration.

[0043] The determination module is used to determine multiple abnormal feature values ​​of the updated data in the first time window, wherein the multiple abnormal feature values ​​are used to characterize the data transmission status of the updated data in multiple dimensions.

[0044] The processing module is used to process the multiple abnormal feature values ​​based on the anomaly detection model to determine whether the updated data in the first time window is abnormal. The anomaly detection model is obtained by training multiple times based on the training sample set. In each training round, training samples are obtained from the training sample set based on the maximum number of samples. Each training sample includes a feature sample of the training data corresponding to a preset duration and an anomaly label. The maximum number of samples used in each training round is determined based on the training samples used in the previous training round or the model error rate after the previous training round.

[0045] Thirdly, embodiments of this application provide an electronic device including at least one processor and at least one memory, wherein the memory stores a computer program that, when executed by the processor, causes the processor to perform the steps of any of the methods described in the first aspect.

[0046] Fourthly, embodiments of this application provide a computer-readable storage medium storing a computer program executable by a processor, which, when run on the processor, causes the processor to perform the steps of any of the methods described in the first aspect.

[0047] Fifthly, embodiments of this application provide a computer program product comprising a computer program stored in a computer-readable storage medium; when a processor of an electronic device reads the computer program from the computer-readable storage medium, the processor executes the computer program, causing the electronic device to perform the steps of any of the methods described in the first aspect. Attached Figure Description

[0048] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0049] Figure 1 This is a schematic diagram illustrating an application scenario of an update anomaly detection method provided in an embodiment of this application;

[0050] Figure 2 A flowchart of an update anomaly detection method provided in this application embodiment;

[0051] Figure 3A schematic diagram illustrating the relationship between training samples and training data provided in this application embodiment;

[0052] Figure 4 A flowchart for determining the maximum number of samples used in each round of training, provided as an embodiment of this application;

[0053] Figure 5 A flowchart for determining a target abnormal state is provided in an embodiment of this application;

[0054] Figure 6 A flowchart for adjusting the maximum number of samples provided in this application embodiment;

[0055] Figure 7 An overall flowchart provided for an embodiment of this application;

[0056] Figure 8 This is a schematic diagram of an update anomaly detection device provided in an embodiment of this application;

[0057] Figure 9 An electronic device provided in an embodiment of this application;

[0058] Figure 10 An electronic device provided in the embodiments of this application. Detailed Implementation

[0059] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. The described embodiments are only some, not all, of the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0060] Furthermore, in the description of the embodiments of this application, unless otherwise stated, "and" means "or", for example, A / B can mean A or B; "and / or" in the text is merely a description of the relationship between related objects, indicating that there can be three relationships, for example, A and / or B can mean: A exists alone, A and B exist simultaneously, and B exists alone.

[0061] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the stated features. In the description of this application, "a plurality of" means two or more, unless otherwise explicitly specified.

[0062] In the description of this application, it should be noted that, unless otherwise expressly specified and limited, the term "connection" should be interpreted broadly. For example, it can refer to a direct connection, an indirect connection through an intermediate medium, or a connection within two devices. Those skilled in the art can understand the specific meaning of the above term in this application based on the specific circumstances.

[0063] To facilitate understanding of the method, apparatus, and electronic device for obtaining user information via microservices provided in the embodiments of this application, some terms used in the embodiments of this application will be explained below so that those skilled in the art can understand them.

[0064] OTA (Over-the-Air) refers to the technology of remotely updating, configuring, or managing the software, firmware, or configuration information of a device via a wireless communication network. OTA updates are commonly used in devices such as smartphones and smart cars that require regular feature updates, security patches, or configuration changes. This technology allows device manufacturers or service providers to perform remote updates without physical contact with the device, thus simplifying the device maintenance and management process.

[0065] Isolation Forest is a highly efficient unsupervised anomaly detection algorithm that determines whether a data point is an anomaly by recursively splitting the data and calculating the path length of the data points. Due to its high computational efficiency, applicability to high-dimensional data, and the fact that it does not require predefined normal behavior, Isolation Forest has wide applications in fields such as cybersecurity, financial fraud, and industrial monitoring.

[0066] max_samples: This parameter controls the maximum number of samples used per tree in an isolated forest, which determines the tree construction speed and the model's detection accuracy.

[0067] Reference Figure 1 This application illustrates an application scenario of an updated anomaly detection method. For example... Figure 1 As shown, the scenario includes a target IoT device 10 and a server 11.

[0068] Among them, IoT devices refer to computer devices with certain computing capabilities and communication functions, such as personal computers, smartphones, tablets, laptops, e-book readers, intelligent voice interaction devices, smart homes, smart cars, and in-vehicle terminals. Target IoT device 10 refers to IoT devices that need to receive function updates, security patches, or configuration changes. Server 11 can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud storage, cloud functions, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms.

[0069] It should be noted that, Figure 1 The examples shown are merely illustrative; in reality, the number of target IoT devices and servers is unlimited and is not specifically limited in this application embodiment.

[0070] The following describes the update anomaly detection method provided by the exemplary embodiments of this application in conjunction with the application scenarios described above and with reference to the accompanying drawings. It should be noted that the above application scenarios are only shown to facilitate understanding of the spirit and principles of this application, and the embodiments of this application are not limited in any way in this respect.

[0071] See Figure 2 The diagram shown is a flowchart of an update anomaly detection method according to an embodiment of this application. The specific steps are as follows:

[0072] Step S201: Receive the update data of the first time window; the duration of the first time window is a preset duration.

[0073] It should be noted that during the update process of the target IoT device, it receives update data transmitted from the server and updates the target IoT device accordingly. When receiving update data, the target IoT device divides the received update data into different time windows based on a preset time interval. The first time window is the latest time window.

[0074] The updated data received by the target IoT is divided into different time windows based on the reception time of the updated data received by the target IoT. The first time window includes the latest received updated data.

[0075] Step S202: Determine multiple abnormal feature values ​​of the updated data in the first time window. The multiple abnormal feature values ​​are used to characterize the data transmission status of the updated data in multiple dimensions.

[0076] Optionally, the multiple abnormal feature values ​​in the embodiments of this application include some or all of the expected offset feature value, response duration feature value, rate change feature value, and integrity feature value.

[0077] The following embodiments of this application describe each abnormal feature value separately:

[0078] 1. Expected offset eigenvalue.

[0079] Optionally, the expected offset feature value in this embodiment is determined based on the integrity detection result of the data packets included in the updated data of the first time window, the data volume of the updated data of the first time window, and the expected data volume.

[0080] It should be noted that the update data for each time window contains at least one data packet.

[0081] In one optional implementation, the present application embodiment determines the expected offset feature value of the updated data in the first time window based on the integrity detection result of the data packets contained in the updated data of the first time window and the difference between the data volume of the updated data in the first time window and the expected data volume.

[0082] It should be noted that the integrity check results are used to characterize whether the data packets contained in the updated data of the first time window are complete.

[0083] For example, in this application embodiment, the integrity of each data packet is checked using packet_integrity_check to ensure that the data has not been tampered with.

[0084] Optionally, in this embodiment of the application, the expected offset feature value is obtained by weighting the weight and the difference between the data volume of the updated data in the first time window and the expected data volume based on the integrity detection result of the data packets contained in the updated data of the first time window.

[0085] In this embodiment, the expected offset feature value is used as an anomaly marker value to characterize the degree of anomaly of the updated data in the first time window during transmission in the expected offset dimension.

[0086] For example, the formula for calculating the expected offset feature value in this application embodiment is: Expected offset feature value = integrity detection result * (1 - first transmission data amount / expected transmission data amount).

[0087] The integrity check result indicates the outcome of the data packet integrity check, signifying whether the data packet passed the check. For example, 1 indicates a passed check, and 0 indicates a failed check. In other words, 1 indicates that all data packets in the updated data of the first time window are complete, and 0 indicates that at least one data packet in the updated data of the first time window is incomplete. The first transmitted data volume represents the actual data volume of the updated data in the first time window. The expected transmitted data volume represents the expected data volume, which is based on a preset fixed value.

[0088] This application provides an example of the process for calculating the expected offset feature value using the parameters shown in Table 1:

[0089]

[0090] Table 1

[0091] 2. Response time characteristic value.

[0092] Response time characteristic (also known as unit traffic response time characteristic) measures the time required to transmit each byte and evaluates transmission efficiency. It is obtained by calculating the ratio of the total data transmission time to the amount of data transmitted, thus determining the average response time per byte.

[0093] The response time feature value in this embodiment is used to characterize the degree of anomaly in the network latency or transmission efficiency of the updated data in the first time window during transmission. When this value is large, it may indicate the presence of network latency or low transmission efficiency.

[0094] Optionally, the response duration feature value in this embodiment is determined based on the amount of updated data in the first time window and the data transmission duration of the updated data in the first time window.

[0095] In one optional implementation, the ratio of the amount of updated data in the first time window to the data transmission duration of the updated data in the first time window is used as the response duration feature value of the updated data in the first time window.

[0096] For example, the formula for calculating the expected offset feature value in this application embodiment is: response duration feature value = first data transmission duration / first data transmission amount.

[0097] Here, the response duration characteristic value represents the response time per unit of traffic, the first data transmission duration represents the duration of transmitting updated data within the first time window, and the first transmitted data volume represents the amount of updated data within the first time window.

[0098] It should be noted that, since updated data may be received intermittently within the preset duration of the first time window, the first data transmission duration is the duration of transmitting updated data within the first time window.

[0099] This application uses the parameters shown in Table 2 to illustrate the process of determining the response duration feature value:

[0100]

[0101] Table 2

[0102] 3. Characteristic values ​​of rate change.

[0103] Rate variation characteristic (also known as rate fluctuation characteristic) reflects the rate change between two consecutive transmissions. The rate difference between the two transmissions is calculated by comparing the amount of data and the data transmission duration of the two transmissions.

[0104] The rate change characteristic value in this application embodiment is used to characterize the degree of abnormality in the data transmission rate fluctuation during the first time window. When the rate fluctuation is large, it may indicate an OTA update network anomaly or the presence of a traffic attack.

[0105] Optionally, the rate change characteristic value in this embodiment is determined based on the data transmission rate of the updated data in the first time window and the data transmission rate of the updated data in the second time window.

[0106] It should be noted that the update data in the second time window is received earlier than the update data in the first time window.

[0107] For example, if the first time window is the latest time window, then the second time window is the previous time window of the first time window.

[0108] For example, if the first time window is the current M-th time window, then the second time window is the M-1-th time window.

[0109] In one optional implementation, the difference between the data transmission rate of the updated data in the first time window and the data transmission rate of the updated data in the second time window is used as the rate change characteristic value of the updated data in the first time window.

[0110] The data transmission rate for each time window is determined based on the amount of data to be updated and the data transmission duration for that time window.

[0111] For example, the calculation formula for determining the rate change characteristic value in this application embodiment is: Rate change characteristic value = ABS(Second transmitted data amount / Second data transmission duration - First transmitted data amount / First data transmission duration).

[0112] Where ABS represents absolute value operation. The second transmitted data volume represents the amount of updated data in the second time window. The second data transmission duration represents the data transmission duration of the updated data in the second time window, that is, the duration of transmitting updated data within the second time window. The first transmitted data volume represents the amount of updated data in the first time window. The first data transmission duration represents the duration of transmitting updated data within the first time window.

[0113] This application provides an example of the process for determining the characteristic values ​​of rate change using the parameters shown in Table 3:

[0114]

[0115] Table 3

[0116] 4. Integrity characteristic value.

[0117] Integrity feature values ​​(also known as data integrity score features) are used to characterize the integrity of transmitted updated data. When a data packet passes the integrity check, the integrity feature value equals the actual amount of data transmitted; if the check fails, the integrity score is 0. Integrity feature values ​​are used to indicate potential data tampering or transmission failure.

[0118] Optionally, in this embodiment, the integrity feature value is the product of the integrity detection result of the data packets included in the updated data of the first time window and the amount of data in the first time window.

[0119] It should be noted that the process of determining the integrity detection results of the data packets included in the updated data of the first time window can be found in section 1, Expected Offset Feature Values, and will not be repeated here.

[0120] For example, the formula for calculating the expected offset feature value in this application embodiment is: Integrity feature value = Integrity detection result * First transmission data volume.

[0121] The integrity check result indicates the outcome of the data packet integrity check, signifying whether the data packet passed the check. For example, 1 indicates a passed check, and 0 indicates a failed check. In other words, 1 indicates that all data packets in the updated data of the first time window are complete, and 0 indicates that at least one data packet in the updated data of the first time window is incomplete. The first transmitted data volume represents the actual data volume of the updated data in the first time window.

[0122] This application provides an example of the process for setting integrity feature values ​​using the parameters shown in Table 4:

[0123]

[0124] Table 4

[0125] Based on the above process, multiple abnormal feature values ​​of the updated data in the first time window are generated.

[0126] Step S203: Process multiple abnormal feature values ​​based on the anomaly detection model to determine whether the updated data in the first time window is abnormal.

[0127] Optionally, in the embodiments of this application, before processing multiple abnormal feature values ​​through the anomaly detection model, the multiple abnormal feature values ​​may also be standardized.

[0128] In one optional implementation, the determined multiple abnormal feature values ​​are combined into a feature matrix, and the combined feature matrix is ​​standardized to obtain multiple abnormal feature values ​​after standardization.

[0129] The embodiments of this application can scale multiple abnormal feature values ​​to a normal distribution with a mean of 0 and a variance of 1, which is suitable for situations where the data presents a normal distribution and the scale differences of different features are large.

[0130] For example, the obtained multiple abnormal feature values ​​can be shown in Table 5:

[0131]

[0132]

[0133] Table 5

[0134] After standardization, the standardized abnormal feature values ​​are shown in Table 6:

[0135] Expected offset eigenvalues Response time feature value rate change characteristic value Integrity eigenvalues 0.75877241 0.03983137 -0.88285461 0.03314477 1.18686861 0.03983137 -0.69644115 -0.07331907 0.33067621 1.67921145 -0.17972765 0.13960861 -0.39152019 -1.19494116 1.75707847 -1.7865081 -1.88479705 0.03983137 -0.00194594 1.68707379

[0136] Table 6

[0137] In this embodiment, multiple abnormal feature values ​​after standardization are input into an anomaly detection model. The anomaly detection model detects the multiple abnormal feature values ​​and outputs the detection results. The detection results indicate whether the updated data in the first time window is abnormal.

[0138] In this embodiment, the anomaly detection model is obtained by training multiple rounds of training based on the training sample set. In each round of training, training samples are obtained from the training sample set based on the maximum number of samples. Each training sample includes a feature sample of the training data corresponding to a preset duration and an anomaly label. The maximum number of samples used in each round of training is determined based on the training samples used in the previous round of training or the model error rate after the previous round of training.

[0139] like Figure 3The diagram illustrates the relationship between training samples and training data in an embodiment of this application. Taking a preset duration of 5 seconds as an example, training sample 1 contains feature samples of the training data corresponding to 0 to 5 seconds, training sample 2 contains feature samples of the training data corresponding to 1 to 6 seconds, training sample 3 contains feature samples of the training data corresponding to 2 to 7 seconds, and so on.

[0140] It should be noted that the anomaly detection model in this application embodiment can be trained on the target IoT device or on other devices, and the trained anomaly detection model can be deployed on the target IoT device. This application does not impose any restrictions on this.

[0141] Before training the anomaly detection model, this application embodiment first collects training data. The training data consists of network traffic data and data information during the update process of the target IoT device. The data information includes all network activity records within a preset time period, such as packet size, protocol type, packet interval, connection duration, number of authentication failures, etc.

[0142] Secondly, after obtaining the training data, the embodiments of this application can also clean and organize the collected training data, remove noisy data and invalid records, correct outliers in the data, and handle missing values ​​(such as using interpolation or mean filling).

[0143] Optionally, in this embodiment of the application, feature samples of training data corresponding to each preset duration are determined based on the processed training data.

[0144] It should be noted that, in this embodiment, the feature samples of the training data corresponding to each preset duration are composed of the expected offset feature value, response duration feature value, rate change feature value, and integrity feature value of the training data corresponding to the corresponding preset duration. The feature samples of the training data corresponding to each preset duration can be a feature matrix.

[0145] In this embodiment, the expected offset feature value, response duration feature value, rate change feature value, and integrity feature value of the training data are combined as unique anomaly markers to obtain feature samples.

[0146] Each preset duration is a time window. The process of determining the expected offset feature value, response duration feature value, rate change feature value and integrity feature value of the training data corresponding to each preset duration can refer to the process of determining the expected offset feature value, response duration feature value, rate change feature value and integrity feature value of the updated data for each time window described in step S202 above. This application will not repeat it here.

[0147] For example, the anomaly detection model used in this application embodiment can be an isolation forest model. When training the isolation forest model, standardized feature samples are used to train the model based on the feature samples of the training sample set. Isolation forests identify anomalies by constructing multiple decision trees to segment the data space. The core of the model is to use path length to measure the degree of "isolation" of data points; points that are more easily isolated are more likely to be anomalies.

[0148] Optionally, in the embodiments of this application, training samples are obtained from the training sample set according to the maximum number of samples in each round of training for the anomaly detection model. The maximum number of samples used in each round of training is determined based on the training samples used in the previous round of training or the model error rate after the previous round of training.

[0149] It should be noted that the maximum number of samples used in the first round of training in this application embodiment is preset. The model is trained based on this maximum number of samples in the first round of training, and the features of the input training samples and the performance of the model are monitored during the training process.

[0150] For example, the characteristics of the monitored training samples may include the amount and complexity of the data corresponding to the training samples, and the performance of the model may be the model error rate, such as the false positive rate and the false negative rate.

[0151] Optional, such as Figure 4 As shown in the flowchart of an embodiment of this application for determining the maximum number of samples used in each round of training, the specific steps are as follows:

[0152] Step S401: Based on the amount of training samples used in the previous training round and / or the model error rate after the previous training round, determine the target abnormal state among multiple abnormal states.

[0153] Optionally, the various abnormal states in the embodiments of this application include abnormal data volume, abnormal data complexity, abnormal data change, and abnormal model detection.

[0154] like Figure 5 As shown in the figure, this application embodiment provides a flowchart for determining a target abnormal state, and the specific steps are as follows:

[0155] Step S501: According to the priority order of various abnormal states, determine whether the training samples used in the previous round of training meet the criteria of abnormal data volume, abnormal data complexity, and abnormal data change; when it is determined that any abnormal state is met, take that abnormal state as the target abnormal state.

[0156] For example, the priority order of various abnormal states can be: abnormal data volume, abnormal data complexity, abnormal data change, and abnormal model detection. Then, it is determined whether the data volume, data complexity, data change, and model detection conditions are met in that order. When any one of these abnormal states is determined to be met, that state is taken as the target abnormal state.

[0157] In this embodiment, the system determines whether the data volume, data complexity, and data change are abnormal based on the amount of training samples used in the previous training round; and determines whether the model detection is abnormal based on the model error rate after the previous training round.

[0158] Optionally, embodiments of this application may determine whether the data volume, data complexity, and data change are abnormal by means of the following methods respectively.

[0159] For example, in this application embodiment, the following method is used to determine whether the data volume is abnormal: the data volume of the training samples used in the previous training round is compared with a preset data volume threshold, which includes a first data volume threshold and a second data volume threshold; if it is greater than the first data volume threshold or less than the second data volume threshold, it is determined that the data volume is abnormal.

[0160] The first data volume threshold is not less than the second data volume threshold, and the first data volume threshold and the second data volume threshold can be preset values ​​based on experience.

[0161] For example, in this application embodiment, the following method is used to determine whether the data complexity is abnormal: the complexity of the training samples used in the previous training round is compared with a complexity threshold, which includes a first complexity threshold and a second complexity threshold; if it is greater than the first complexity threshold or less than the second complexity threshold, then it is determined that the data complexity is abnormal.

[0162] The first complexity threshold is not less than the second complexity threshold. The first and second complexity thresholds can be preset values ​​based on experience, or values ​​determined based on the complexity of the training samples used in the previous round of training. The complexity of each training sample is determined based on the amount of data in that training sample.

[0163] For example, the first complexity threshold and the second complexity threshold can be the complexity of the training samples used in the previous round of training.

[0164] In this embodiment of the application, the complexity of the training samples can be the variance or entropy of the data volume of the corresponding training samples.

[0165] For example, embodiments of this application determine whether data changes are abnormal by comparing the amount of data in the training samples used in the first two rounds of training, or by comparing the amount of data in every two adjacent training samples used in the previous round of training; if they are not the same, then it is determined that data changes are abnormal.

[0166] For example, if a fourth round of training is performed, the amount of training data used in the second round of training is compared with the amount of training data used in the third round of training.

[0167] It should be noted that if the amount of data in every two adjacent training samples used in the previous training round is not the same, then it is determined to be an abnormal data change.

[0168] The order of the training samples is determined by the time they are received, and they are arranged in order from earliest to latest.

[0169] The reception time of a training sample can be the reception time of the latest received training data within a preset time period corresponding to a training sample.

[0170] Step S502: If the abnormality of data volume, data complexity, and data change is not met, then determine whether the model error rate after the previous training round meets the requirements for model detection anomalies.

[0171] For example, in this application embodiment, the model error rate after the previous training round is compared with a preset error tolerance rate, which includes a first error tolerance rate and a second error tolerance rate. If the error rate is greater than the first error tolerance rate or less than the second error tolerance rate, the model error rate is determined to be in accordance with the model error detection.

[0172] The first fault tolerance rate is not less than the second fault tolerance rate, and the first and second fault tolerance rates can be preset values ​​based on experience.

[0173] Optionally, in this embodiment, the model error rate includes the false positive rate and the false negative rate; the first fault tolerance rate includes a first false positive fault tolerance rate and a second false negative fault tolerance rate; the second fault tolerance rate includes a first false negative fault tolerance rate and a second false negative fault tolerance rate; and model detection anomalies include false positive rate anomalies and false negative rate anomalies. Judgment is made according to the priority order between false positive rate anomalies and false negative rate anomalies. When it is determined that either a false positive rate anomaly or a false negative rate anomaly is met, it is determined that the model detection anomaly is met.

[0174] For example, taking the priority of false positive rate anomalies as higher than false negative rate anomalies as an example, the process is as follows: First, determine if the false positive rate is greater than the first false positive tolerance rate or less than the second false positive tolerance rate. If it is greater than the first false positive tolerance rate or less than the second false positive tolerance rate, it is determined to meet the criteria for a false positive rate anomaly. If it is less than or equal to the first false positive tolerance rate and greater than or equal to the second false positive tolerance rate, it is determined not to meet the criteria for a false positive rate anomaly. If it does not meet the criteria for a false positive rate anomaly, the process is as follows: Second, determine if the false negative rate is greater than the first false negative tolerance rate or less than the second false negative tolerance rate. If it is greater than the first false negative tolerance rate or less than the second false negative tolerance rate, it is determined to meet the criteria for a false negative rate anomaly. If it is less than or equal to the first false negative tolerance rate and greater than or equal to the second false negative tolerance rate, it is determined not to meet the criteria for a false negative rate anomaly.

[0175] Specifically, when the first false positive tolerance rate and the second false positive tolerance rate are the same in this embodiment, it is determined that the false positive rate does not meet the abnormality when the false positive rate is equal to the first false positive tolerance rate. When the first false negative tolerance rate and the second false negative tolerance rate are the same in this embodiment, it is determined that the false negative rate does not meet the abnormality when the false negative rate is equal to the first false negative tolerance rate.

[0176] Step S503: If the model detection is abnormal, then the model detection is abnormal as the target abnormal state.

[0177] For example, the priority order of various abnormal states can also be: model detection abnormality, data volume abnormality, data complexity abnormality, and data change abnormality.

[0178] Then, it is determined whether the data meets the model's anomaly detection criteria, namely, abnormal data volume, abnormal data complexity, and abnormal data change. If any of these anomalies is found, that anomaly is taken as the target anomaly.

[0179] The target abnormal state is determined based on the above process.

[0180] Step S402: Adjust the maximum number of samples used in the previous training round based on the adjustment method corresponding to the target abnormal state to obtain the maximum number of samples used in the current training round.

[0181] Different adjustment methods are implemented for different target abnormal states. The embodiments of this application are described as follows:

[0182] 1. When the target abnormal state is abnormal data volume.

[0183] During OTA updates, the size of transmitted data packets and the update frequency may fluctuate depending on device status or network conditions. When the data volume is small, reduce max_samples (maximum number of samples) to improve computational efficiency. When the data volume is large, increase max_samples to fully utilize more samples to build the tree and improve the model's detection accuracy.

[0184] Optionally, in this embodiment of the application, a first adjustment weight is determined based on the difference between the amount of training samples used in the first two rounds of training; and the maximum number of samples used in the previous round of training is adjusted based on the first adjustment weight.

[0185] For example, in this application embodiment, the adjusted maximum number of samples is obtained using Formula 1:

[0186]

[0187] Among them, max_samples new `max_samples_current` represents the maximum number of samples after adjustment, which is the maximum number of samples used in the current training round, such as the Nth round, where N is a positive integer; `max_samples_current` represents the current maximum number of samples, which is the maximum number of samples used in the previous training round, such as the (N-1)th round.

[0188] This is the first adjustment weight. Here, α represents the adjustment coefficient, which can be set based on empirical values ​​to control the magnitude of change in the maximum sample size. This indicates the amount of training data used in the previous training round, such as the (N-1)th round. This indicates the amount of training data used in the (N-2)th round of training.

[0189] It should be noted that if at least one training sample was used in the previous training round, the data volume of the training samples used in the previous training round can be the sum of the data volumes of the at least one training sample used in the previous training round, or it can be the average of the data volumes of the at least one training sample used in the previous training round. This application does not impose any restrictions on this. The calculation method for the data volume of the training samples used in the first two training rounds is the same.

[0190] 2. When the target abnormal state is abnormal data complexity.

[0191] OTA (Over-The-Air) updates sometimes involve complex data packets, and sometimes relatively simple ones. When the data is complex, increase `max_samples` to ensure the model can capture the diversity and complex patterns of the data; when the data is simple, decrease `max_samples` to avoid overfitting and improve training speed.

[0192] Optionally, in this embodiment of the application, the second adjustment weight is determined based on the difference between the complexity of the training samples used in the previous training round and the complexity threshold; the maximum number of samples used in the previous training round is adjusted based on the second adjustment weight.

[0193] For example, in this application embodiment, the adjusted maximum number of samples is obtained through Formula 2:

[0194]

[0195] Among them, max_samples new `max_samples_current` represents the maximum number of samples after adjustment, which is the maximum number of samples used in the current training round, such as the Nth round, where N is a positive integer; `max_samples_current` represents the current maximum number of samples, which is the maximum number of samples used in the previous training round, such as the (N-1)th round.

[0196] This is the second adjustment weight. Here, k represents a coefficient controlling the adjustment magnitude; the larger the value, the more sensitive the adjustment. This indicates the complexity of the training samples used in the previous training round, such as the (N-1)th round. This represents the complexity threshold.

[0197] It should be noted that if at least one training sample was used in the previous training round, the complexity of the training samples used in the previous training round can be the sum of the complexities of at least one training sample used in the previous training round, or it can be the average complexity of at least one training sample used in the previous training round. This application does not impose any restrictions on this. The complexity threshold is then set based on the complexity calculation method.

[0198] 3. When the target abnormal state is abnormal data change.

[0199] This application's embodiments detect abnormal data changes based on a sliding window mechanism. If the data volume in the current window increases compared to the previous window, then `max_samples` is increased; if it decreases, then `max_samples` is decreased. This is suitable for making simple rule adjustments when the amount of data in the window changes drastically.

[0200] In one optional implementation, the data volume used in one round of training can be considered as the data volume of a window. If the current training round is N, the data volume of the training samples used in the (N-1)th round (the previous round) is compared with the data volume of the training samples used in the (N-2)th round to determine the change in data volume. That is, the change in data volume is determined by comparing the data volume of the training samples used in the previous two rounds of training. The change in data volume is defined as either an increase or no increase.

[0201] Then, based on the third adjustment weight corresponding to the change in data volume, the maximum number of samples used in the previous training round is adjusted.

[0202] For example, in this application embodiment, the adjusted maximum number of samples is obtained through Formula 3:

[0203]

[0204] Among them, max_samples new `max_samples_current` represents the maximum number of samples after adjustment, which is the maximum number of samples used in the current training round, such as the Nth round, where N is a positive integer; `max_samples_current` represents the current maximum number of samples, which is the maximum number of samples used in the previous training round, such as the (N-1)th round.

[0205] The current_window_size represents the amount of training data used in the previous training round, such as the N-1th round; the previous_window_size represents the amount of training data used in the N-2th round.

[0206] Where current_window_size>previous_window_size means that the amount of training samples used in the (N-1)th round of training is greater than the amount of training samples used in the (N-2)th round of training. If the amount of data increases, the third adjustment weight corresponding to the increase in the amount of data is 1.2, which adjusts the maximum number of samples used in the previous round of training.

[0207] If current_window_size ≤ previous_window_size, it means that the amount of training samples used in the (N-1)th round of training is less than or equal to the amount of training samples used in the (N-2)th round of training. If the amount of data does not increase, the third adjustment weight of 0.8 is used to adjust the maximum number of samples used in the previous round of training.

[0208] In another optional implementation, this embodiment of the application can consider the nth training sample used in the previous training round as the data volume of a time window. The data volume of the nth training sample is then compared with the data volume of the (n+1)th training sample to determine the change in data volume. That is, by comparing the data volume of every two adjacent training samples used in the previous training round, the change in data volume between every two adjacent training samples is determined, indicating whether the data volume has increased or not.

[0209] Then, based on the third adjustment weight corresponding to the change in data volume, the maximum number of samples used in the previous training round is adjusted.

[0210] Optionally, for the implementation of adjusting the maximum number of samples based on the amount of training samples in every two adjacent orders used in the previous training round, this application embodiment adjusts the maximum number of samples used in the previous training round through steps A1-A2, including:

[0211] Following the order of the training samples used in the previous training round, perform the following operations for each training sample used in the previous training round:

[0212] Step A1: Based on the changes in the amount of data between the training samples and the reference training samples, determine the third adjustment weight corresponding to the changes in the amount of data.

[0213] The reference training sample is the training sample that is in the next adjacent order of the training samples in the previous training round.

[0214] For example, if the training sample is the nth training sample used in the previous training round, then the reference training sample is the (n+1)th training sample used in the previous training round.

[0215] Step A2: Adjust the current maximum number of samples based on the third adjustment weight.

[0216] The current maximum number of samples is either the maximum number of samples used in the previous training round, or the current maximum number of samples is the maximum number of samples adjusted based on the changes in the data volume of at least two training samples used in the previous training round.

[0217] For example, if n is 1, the third adjustment weight is determined based on the change in data volume between the first and second training samples used in the previous training round, and the current maximum number of samples is adjusted based on the third adjustment weight. The current maximum number of samples is the maximum number of samples used in the previous training round. For example, if the current round is N, the maximum number of samples used in the (N-1)th round of training is adjusted based on the third adjustment weight.

[0218] If n is 2, the third adjustment weight is determined based on the change in data volume between the second and third training samples used in the previous training round, and the current maximum number of samples is adjusted based on the third adjustment weight. The current maximum number of samples is the maximum number of samples after adjustment based on the change in data volume between the first and second training samples.

[0219] If n is 3, the third adjustment weight is determined based on the change in data volume between the 3rd and 4th training samples used in the previous training round, and the current maximum number of samples is adjusted based on the third adjustment weight. The current maximum number of samples is the maximum number of samples after adjustment based on the change in data volume between the 2nd and 3rd training samples.

[0220] In this implementation method, the adjusted maximum number of samples can also be obtained using Formula 3. Here, current_window_size represents the data size of the (n+1)th training sample used in the previous training round; previous_window_size represents the data size of the nth training sample used in the previous training round.

[0221] Where current_window_size>previous_window_size means that the data size of the (n+1)th training sample is greater than the data size of the nth training sample. If the data size increases, the third adjustment weight 1.2 corresponding to the increase in data size is used to adjust the current maximum number of samples.

[0222] If current_window_size ≤ previous_window_size, it means that the data size of the (n+1)th training sample is less than or equal to the data size of the nth training sample. If the data size has not increased, the third adjustment weight of 0.8 corresponding to the case where the data size has not increased is used to adjust the current maximum number of samples.

[0223] 4. When the target abnormal state is detected as abnormal by the model.

[0224] Model performance can fluctuate over time. For example, in OTA updates, malicious data injection detection can occur. If the model's error rate increases, `max_samples` can be increased to improve the model's robustness. Conversely, if the model's error rate is low and detection efficiency can be improved, `max_samples` can be decreased to reduce computational resource consumption.

[0225] Optionally, in the embodiments of this application, the model error rate includes the false positive rate and the false negative rate.

[0226] Optionally, in this embodiment of the application, the ratio of the model error rate after the previous training round to the preset error tolerance rate is used as the fourth adjustment weight, and the maximum number of samples used in the previous training round is adjusted based on the fourth adjustment weight.

[0227] For example, in this application embodiment, the adjusted maximum number of samples is obtained through Formula 4:

[0228]

[0229] Among them, max_samples new `max_samples_current` represents the maximum number of samples after adjustment, which is the maximum number of samples used in the current training round, such as the Nth round, where N is a positive integer; `max_samples_current` represents the current maximum number of samples, which is the maximum number of samples used in the previous training round, such as the (N-1)th round.

[0230] The fourth adjustment is the weighting. Among them, error_rate_current represents the current model error rate, which is the model error rate after the previous training round, such as the false positive rate or the false negative rate; error_rate_target represents the preset error tolerance rate, which can be preset based on empirical values, such as the preset false positive error tolerance rate or the preset false negative error tolerance rate.

[0231] When the model error rate is the false positive rate, the preset fault tolerance rate is the preset false positive fault tolerance rate; when the model error rate is the false negative rate, the preset fault tolerance rate is the preset false negative fault tolerance rate.

[0232] Based on the above process, the maximum number of samples used in the current round of training is obtained, and training samples are then obtained from the training sample set based on this maximum number of samples for the current round of training.

[0233] Meanwhile, this embodiment continuously monitors changes in training samples and model performance during training, iteratively optimizing the `max_samples` parameter through multiple rounds of training to finally obtain a trained anomaly detection model. The application process of the anomaly detection model can be found in [reference needed]. Figure 2 The flowchart shown.

[0234] like Figure 6 As shown in the flowchart of an embodiment of this application for adjusting the maximum number of samples, the specific steps are as follows:

[0235] Step S601: Start model training.

[0236] Step S602: Monitor the amount of data in the input training samples and the model error rate.

[0237] It should be noted that the amount of data in the training samples is calculated by the model based on the feature samples of the input training samples.

[0238] Step S603: Determine whether the data changes are abnormal based on the amount of data in the input training samples. If yes, proceed to step S604; otherwise, proceed to step S605.

[0239] Step S604: Adjust the maximum number of samples used in the previous round using the adjustment method corresponding to abnormal data changes.

[0240] Step S605: Determine whether the data complexity is abnormal based on the amount of data in the input training samples; if yes, proceed to step S606; if no, proceed to step S607.

[0241] Step S606: Adjust the maximum number of samples used in the previous round using the adjustment method corresponding to the abnormal data complexity.

[0242] Step S607: Determine whether the data changes are abnormal based on the amount of data in the input training samples; if yes, proceed to step S608; if no, proceed to step S609.

[0243] Step S608: Adjust the maximum number of samples used in the previous round using the adjustment method corresponding to abnormal data changes.

[0244] Step S609: Determine whether the model error rate of the current model meets the criteria for model detection anomaly; if yes, proceed to step S6010; if no, proceed to step S6011.

[0245] It should be noted that the current model error rate is the model error rate after the previous training round.

[0246] Step S6010: Adjust the maximum number of samples used in the previous round using the adjustment method corresponding to the anomaly detected by the model.

[0247] Step S6011: Use the maximum number of samples used in the previous round as the maximum number of samples used in the current round.

[0248] like Figure 7 As shown in the figure, an overall flowchart of an embodiment of this application is presented, and the specific steps are as follows:

[0249] Step S701: Collect training data.

[0250] This application embodiment collects training data based on network traffic during the update process of the target IoT device.

[0251] Step S702, data preprocessing.

[0252] For example, the collected training data will be cleaned and organized to remove noisy data and invalid records, correct outliers in the data, and handle missing values ​​(such as by using interpolation or mean imputation).

[0253] Step S703: Extract features from the training data to obtain feature samples.

[0254] Step S704: Perform data standardization processing on the feature samples.

[0255] Step S705: Use the dynamic strategy of adjusting the maximum number of samples in the isolated forest to train the isolated forest model.

[0256] Step S706: Deploy the trained Isolation Forest model.

[0257] After successful validation, the isolated forest model will be deployed to the production environment (target IoT devices). The deployed model will then perform anomaly detection on real-time traffic data, ensuring timely identification of potential network threats or security risks.

[0258] The following is the process of applying the Isolation Forest model:

[0259] Step S707: Collect update data in real time for updating the target IoT device.

[0260] The target IoT device continuously collects network traffic data (update data) during OTA updates in real time. This data will be used to extract features within a fixed time window and then fed into a deployed Isolation Forest model for detection.

[0261] Step S708: Extract features from the real-time collected updated data to obtain multiple abnormal feature values.

[0262] Step S709: Perform data standardization processing on the obtained multiple abnormal feature values.

[0263] Standardize the real-time feature data to make it conform to the feature distribution during model training, so that the model can correctly process and detect anomalies.

[0264] Step S7010: Input the standardized multiple outlier feature values ​​into the isolated forest model.

[0265] Anomaly detection using the Isolation Forest model: This method uses an isolation forest model to detect anomalies in standardized real-time feature data. The model calculates an anomaly score for each sample and classifies the samples based on the score and a set threshold; samples with higher scores are considered anomalies.

[0266] Step S7011: The isolated forest model outputs the detection results.

[0267] Optionally, in this embodiment of the application, the detection results may be used to determine whether a security threat pattern is met. If so, an alarm may be triggered, and a predefined response mechanism may be activated, such as notifying the security operations center, isolating the infected processor, or automatically performing further security scans.

[0268] If the target IoT device is a smart car, the security operations center can be notified, the infected on-board card can be isolated, or further security scanning can be performed automatically.

[0269] Anomaly Detection Result Analysis: Analyze detected anomaly data to determine whether these anomalies conform to expected security threat patterns or whether further investigation and response are required. Alarms can be generated based on anomaly detection results, triggering predefined response mechanisms. Response measures may include notifying the security operations center, isolating infected onboard cards, or automatically performing further security scans.

[0270] It should be noted that `max_samples` controls the maximum number of samples used per tree, directly affecting the model's training time, memory usage, and detection performance.

[0271] Small sample size: Training is faster, but it may affect the accuracy of the model, especially when the dataset is large and contains complex patterns.

[0272] Large sample size: The model usually performs better and can capture complex data patterns more accurately, but training time and resource consumption will also increase.

[0273] The model iterative update in this embodiment refers to the dynamic adjustment of the max_samples parameter based on the characteristics of the data (such as data volume, abnormal distribution, data complexity, etc.) when new data arrives, and the model is retrained or updated to maintain its detection capability. This is especially important in environments with large data volume changes or real-time data streams.

[0274] Advantages include: 1. High adaptability: By iteratively updating and dynamically adjusting max_samples, the model can adapt to changes in data, improving detection accuracy on datasets of different sizes. 2. Resource optimization: When computational resources are limited, reducing max_samples can improve running efficiency; when higher accuracy is required, increasing the number of samples can improve detection accuracy.

[0275] `max_samples` determines the maximum number of samples used by each isolated tree, which is crucial for large-scale datasets and high-frequency data flow environments (such as OTA update scenarios). By dynamically adjusting `max_samples`, isolated forests can adaptively optimize based on changes in data volume and complexity, improving the accuracy and computational efficiency of anomaly detection.

[0276] This application proposes a method for anomaly detection of OTA updates of target IoT devices based on network traffic characteristics and combined with the isolated forest algorithm. This application has the following advantages and effects over the prior art:

[0277] 1. Abnormal Traffic Marking Features: During OTA updates, the integrity of data packets is first checked (using `packet_integrity_check`) to ensure the data has not been tampered with. Then, the difference between the actual amount of data transmitted and the expected amount is calculated as an anomaly marker. Specifically, `packet_integrity_check` is used as a weight, combined with the difference between the actual and expected amounts of data transmitted to obtain the anomaly marker value for each transmission. Finally, this anomaly marker value is used as a unique combined input feature to represent the degree of anomaly that may exist during transmission.

[0278] 2. Unit Traffic Response Time Feature: Unit traffic response time measures the time required to transmit each byte, evaluating transmission efficiency. It is obtained by calculating the ratio of total transmission time to the amount of data transmitted, providing the average response time per byte as a unique combined input feature. A large value may indicate network latency or low transmission efficiency.

[0279] 3. Rate Fluctuation Characteristics: Reflects the rate change between two consecutive transmissions. By comparing the data volume and transmission time of two transmissions, the rate difference between the two transmissions is calculated as a unique combined input characteristic. Large rate fluctuations may indicate OTA update network anomalies or DDoS attacks.

[0280] 4. Data Integrity Scoring Feature: Used to assess the integrity of transmitted data. This feature combines the packet integrity check result with the product of the actual transmitted data volume as a unique combined input feature. If the packet passes the integrity check, the integrity score equals the actual transmitted data volume; if it fails the check, the integrity score is 0. This feature is used to identify potential data tampering or transmission failure.

[0281] 5. A unique dynamic strategy model is proposed to adjust the max_samples parameter value of the Isolation Forest, thereby improving the robustness and detection efficiency of the model. In different scenarios, the appropriate dynamic adjustment strategy can effectively improve the performance and efficiency of the Isolation Forest model based on data characteristics, business needs and real-time changes.

[0282] Technical effects in OTA update scenarios:

[0283] 1. Responding to dynamic changes in data streams

[0284] During OTA updates, network traffic, the size and frequency of transmitted data packets may fluctuate over time. A fixed `max_samples` parameter may not be able to adapt to these dynamic changes. However, through iterative model updates, `max_samples` can be dynamically adjusted based on the amount of data in each time window. This allows the model to use more samples when the amount of data is large and reduce the number of samples when the amount of data is small, thus ensuring computational efficiency.

[0285] Technical Benefits: Real-time Adaptation to Data Changes: During OTA updates, the model can flexibly adjust to changes in device and network conditions, avoiding resource waste or accuracy degradation. Reduced Computational Overhead: When the data volume is small, reducing max_samples can lower computational costs and improve system response speed.

[0286] 2. Improve the accuracy of anomaly detection

[0287] By iteratively updating max_samples based on the complexity of OTA transmission data, the characteristics of abnormal behavior, and historical data, isolated forests can better capture abnormal behavior in different time periods. In particular, when data transmission fluctuates greatly or anomalies occur in a short period of time, they can quickly detect potential attacks or abnormal transmissions.

[0288] Technical Benefits: Enhanced Anomaly Detection Capabilities: During OTA updates, the model can improve anomaly detection accuracy and reduce false negatives and missed positives through more refined sample selection and updates. Flexible Adaptation to Complex Data Patterns: Dynamically adjusting `max_samples` helps to better capture potential anomaly patterns in complex scenarios as the complexity of OTA update data changes.

[0289] 3. Real-time response to security threats

[0290] In OTA updates, security threats (such as malware injection and packet tampering) require rapid response. By iteratively updating the max_samples parameter, the Isolation Forest model can monitor and adjust for abnormal behavior in network traffic in real time, ensuring a rapid response to sudden anomalies.

[0291] Technical Benefits: Timely Anomaly Detection and Response: Through iterative updates, isolated forests can quickly capture potential security threats in real-time traffic monitoring, issuing timely alerts and preventing the spread of security risks. Improved Security and Stability: Real-time monitoring and dynamic adjustments to OTA updates help ensure the security of the software update process for vehicles or devices, improving system stability.

[0292] 4. Optimize the resource utilization rate of the model.

[0293] For large-scale OTA update scenarios, dynamically adjusting `max_samples` can avoid overusing computing resources. Through iterative updates, the number of samples can be adjusted in real time based on traffic or packet size, optimizing the system's resource utilization efficiency.

[0294] Technical Benefits: Saves computational resources: Adjusting the number of samples based on data volume and anomaly detection requirements effectively reduces wasted computational resources, especially during large-scale updates or when data transfer loads are high. Improves model efficiency: By rationally adjusting `max_samples`, unnecessary computational consumption is reduced, making system resource allocation more efficient.

[0295] 5. Enhanced model adaptability

[0296] Through a sliding window mechanism or iterative updates based on real-time performance feedback, the Isolation Forest model can continuously adapt to new data features during OTA updates. By monitoring metrics such as network traffic and transmission rate, and dynamically adjusting max_samples, the model ensures efficient and stable performance under different environments.

[0297] Technical benefits: Strong adaptability: The model can automatically optimize according to data changes, improving the continuous performance of detection. Reduced model overfitting: Dynamic adjustment avoids the overfitting problem caused by fixed parameters, ensuring that the model is suitable for constantly changing data environments.

[0298] like Figure 8 As shown in the figure, an embodiment of this application provides an update anomaly detection device, comprising:

[0299] The receiving module 801 is used to receive update data of the first time window; the duration of the first time window is a preset duration.

[0300] The determining module 802 is used to determine multiple abnormal feature values ​​of the updated data in the first time window, wherein the multiple abnormal feature values ​​are used to characterize the data transmission status of the updated data in multiple dimensions.

[0301] The processing module 803 is used to process the multiple abnormal feature values ​​based on the anomaly detection model to determine whether the updated data in the first time window is abnormal; wherein, the anomaly detection model is obtained by multiple rounds of training based on the training sample set, and in each round of training, training samples are obtained from the training sample set based on the maximum number of samples, and each training sample includes a feature sample of training data corresponding to a preset duration and an anomaly label; the maximum number of samples used in each round of training is determined based on the training samples used in the previous round of training or the model error rate after the previous round of training.

[0302] Based on the same inventive concept as the above method embodiments, this application also provides an electronic device. The principle of the electronic device in solving the problem is similar to that of the method in the above embodiments. Therefore, the implementation of the electronic device can refer to the implementation of the above method, and the repeated parts will not be described again.

[0303] See Figure 9 As shown, the electronic device 90 may include at least a processor 91 and a memory 92. The memory 92 stores program code, which, when executed by the processor 91, causes the processor 91 to perform the steps of the update anomaly detection method described in the above embodiments of this application.

[0304] The following reference Figure 10 To describe an electronic device 100 according to this embodiment of the present application. Figure 10 The electronic device 100 is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.

[0305] like Figure 10 The electronic device 100 is manifested in the form of a general electronic device. The components of the electronic device 100 may include, but are not limited to: at least one processing unit 101, at least one storage unit 102, and a bus 103 connecting different system components (including storage unit 102 and processing unit 101).

[0306] Bus 103 represents one or more of several bus structures, including a memory bus or memory controller, peripheral bus, processor, or local bus using any of the various bus structures.

[0307] Storage unit 102 may include a readable medium in the form of volatile memory, such as random access memory (RAM) 1021 and / or cache memory 1022, and may further include read-only memory (ROM) 1010.

[0308] Storage unit 102 may also include a program / utility 1010 having a set (at least one) program module 1024, such program module 1024 including but not limited to: operating system, one or more application programs, other program modules and program data, each of these examples or some combination of these may include an implementation of a network environment.

[0309] Electronic device 100 can also communicate with one or more external devices 104 (e.g., keyboard, pointing device, etc.), and with one or more devices that enable objects to interact with electronic device 100, and / or with any device that enables electronic device 100 to communicate with one or more other electronic devices (e.g., router, modem, etc.). This communication can be performed via input / output (I / O) interface 105. Furthermore, electronic device 100 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 106. As shown, network adapter 106 communicates with other modules used in electronic device 100 via bus 103. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with electronic device 100, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0310] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0311] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0312] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0313] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0314] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. An update anomaly detection method, characterized in that, include: Receive updated data in the first real-time window; The duration of the first time window is a preset duration; Determine multiple abnormal feature values ​​for the updated data in the first time window, wherein the multiple abnormal feature values ​​are used to characterize the data transmission status of the updated data in multiple dimensions. The multiple abnormal feature values ​​are processed based on the anomaly detection model to determine whether the updated data in the first time window is abnormal. The anomaly detection model is obtained by training the training sample set in multiple rounds. In each round of training, training samples are obtained from the training sample set based on the maximum number of samples. Each training sample includes a feature sample and anomaly label of the training data corresponding to a preset duration. The maximum number of samples used in each round of training is determined in the following way: Based on the amount of training samples used in the previous training round and / or the model error rate after the previous training round, the target abnormal state is determined among multiple abnormal states; Adjust the maximum number of samples used in the previous training round based on the adjustment method corresponding to the target abnormal state, and obtain the maximum number of samples used in the current training round.

2. The method according to claim 1, characterized in that, The plurality of abnormal feature values ​​include some or all of the expected offset feature value, response duration feature value, rate change feature value, and integrity feature value; The expected offset feature value is determined based on the integrity detection result of the data packets contained in the updated data of the first time window, the data volume of the updated data of the first time window, and the expected data volume. The response duration feature value is determined based on the amount of updated data in the first time window and the data transmission duration of the updated data in the first time window; The rate change characteristic value is determined based on the data transmission rate of the updated data in the first time window and the data transmission rate of the updated data in the second time window; the reception time of the updated data in the second time window is earlier than the reception time of the updated data in the first time window. The integrity feature value is the product of the integrity detection result of the data packets included in the updated data of the first time window and the amount of data in the first time window.

3. The method according to claim 1, characterized in that, The various abnormal states include abnormal data volume, abnormal data complexity, abnormal data change, and abnormal model detection; the determination of the target abnormal state among the various abnormal states based on the data volume of the training samples used in the previous training round and / or the model error rate after the previous training round includes: According to the priority order of various abnormal states, it is determined whether the training samples used in the previous round of training meet the above-mentioned abnormal data volume, abnormal data complexity, and abnormal data change; when it is determined that any abnormal state is met, the above-mentioned abnormal state is taken as the target abnormal state. If the abnormality in data volume, data complexity, and data change does not meet the criteria, then determine whether the model error rate after the previous training round meets the criteria for model detection anomaly. If the model detects an anomaly, then the model detects the anomaly as the target anomaly state.

4. The method according to claim 3, characterized in that, Determine whether the data volume is abnormal using the following methods: The amount of training sample data used in the previous training round is compared with a preset data amount threshold; if it is greater than the first data amount threshold or less than the second data amount threshold, it is determined that the data amount is abnormal, and the first data amount threshold is not less than the second data amount threshold.

5. The method according to claim 3, characterized in that, Determine whether the data complexity anomaly is met using the following methods: The complexity of the training samples used in the previous training round is compared with a complexity threshold; if it is greater than the first complexity threshold or less than the second complexity threshold, it is determined that the data complexity is abnormal, and the first complexity threshold is not less than the second complexity threshold; the complexity of the training samples is determined based on the amount of data in the corresponding training samples.

6. The method according to claim 3, characterized in that, Determine whether the data change is abnormal using the following methods: Compare the amount of data from the training samples used in the first two rounds of training, or compare the amount of data from the training samples used in every two adjacent orders in the previous round of training; if they are different, then it is determined that the data change is abnormal.

7. The method according to claim 3, characterized in that, Determine whether the model detects anomalies using the following methods: The error rate of the model after the previous training round is compared with the preset error tolerance rate. If it is greater than the first error tolerance rate or less than the second error tolerance rate, it is determined that the model detects an anomaly. The first error tolerance rate is not less than the second error tolerance rate.

8. The method according to claim 3, characterized in that, The adjustment of the maximum number of samples used in the previous training round based on the adjustment method corresponding to the target abnormal state includes: When the target abnormal state is an abnormal data volume, a first adjustment weight is determined based on the difference between the data volume of the training samples used in the first two rounds of training; the maximum number of samples used in the previous round of training is adjusted based on the first adjustment weight; or... When the target anomalous state is an anomalous data complexity, a second adjustment weight is determined based on the difference between the complexity of the training samples used in the previous training round and a complexity threshold; the maximum number of samples used in the previous training round is adjusted based on the second adjustment weight; or... When the target abnormal state is an abnormal data change, the data volume change is determined by comparing the data volume of the training samples used in the previous two rounds of training, or by comparing the data volume of every two adjacent training samples used in the previous round of training, wherein the data volume change is either an increase or no increase; based on the third adjustment weight corresponding to the data volume change, the maximum number of samples used in the previous round of training is adjusted; or... When the target abnormal state is a model detection abnormality, the ratio of the model error rate after the previous training round to the preset error tolerance rate is used as the fourth adjustment weight, and the maximum number of samples used in the previous training round is adjusted based on the fourth adjustment weight.

9. The method according to claim 8, characterized in that, If the data volume change refers to the data volume change between every two adjacent training samples, then adjusting the maximum number of samples used in the previous training round based on the third adjustment weight corresponding to the data volume change includes: Following the order of the training samples used in the previous training round, perform the following operations for each training sample used in the previous training round: Based on the changes in the amount of data between the training samples and the reference training samples, a third adjustment weight corresponding to the changes in the amount of data is determined; the reference training sample is the training sample that is in the next adjacent order of the training samples in the previous training round. The current maximum number of samples is adjusted based on the third adjustment weight. The current maximum number of samples is the maximum number of samples used in the previous training round, or the current maximum number of samples is the maximum number of samples adjusted based on the changes in the data volume of at least two training samples used in the previous training round.

Citation Information

Patent Citations

  • Training method of abnormal data detection model, electronic equipment and storage medium

    CN113033639A

  • Training method, anomaly detection method and device, equipment and storage medium

    CN113537337A