A Network Attack Processing Method and System Based on Zero-Sum Game
The zero-sum game approach with integrated classifiers and GANs addresses data imbalance in network attack detection, enhancing detection accuracy by optimizing weights and generating diverse, realistic samples for improved classification.
Patent Information
- Application Number
- CN202510245633.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-04
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2045-03-04
AI Technical Summary
When the existing network attack detection methods process unbalanced data, the generative adversarial network lacks effective conditional constraints, resulting in imbalance in the generation results. The single classification algorithm has strong limitations in multi-classification tasks, resulting in low accuracy in handling network attacks.
The zero-sum game-based network attack processing method is adopted, and the combination strategy of multiple classifiers is optimized through integrated learning, combined with the generated adversarial network GAN model for sample expansion, and the Nash equilibrium idea and the various loss function models are used to generate expanded samples of authenticity and diversity.
Improve the accuracy of handling network attacks, enhance the robustness and performance of classifiers under unbalanced data, and generate an augmented sample with authenticity and diversity by generating an adversarial network GAN model to find hidden network intrusion attack behaviors.
Smart Images

Figure CN119788413B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to data processing, and specifically to a network attack processing method and system based on zero-sum game. Background Art
[0002] With the rapid development of technology, especially the wide application of technologies such as cloud computing, big data, Internet of Things, and artificial intelligence, the means and tools of network attacks are also constantly evolving, leading to an increasing number of network security threats.
[0003] In the prior art, researchers have proposed using the method based on Generative Adversarial Network (GAN) to enhance the performance of Network Intrusion Detection System (NIDS). For example, in Lee G C, Li J H, Li Z Y. A Wasserstein Generative Adversarial Network–Gradient Penalty-Based Model with Imbalanced Data Enhancement for Network Intrusion Detection[J]. Applied Sciences, 2023, 13(14): 8132., Gwo-Chuan Lee et al. proposed a model based on Wasserstein Generative Adversarial Network - Gradient Penalty, which solves the data imbalance problem in the network intrusion detection system through data enhancement and improves the recognition accuracy of rare attack types. The proposed gradient penalty method makes the model training more stable and easier to converge. However, the subsequent two-stage fine-tuning algorithm increases the complexity and computational cost of the system and has a high dependence on data quality.
[0004] In Li Z, Chen S, Dai H, et al. Abnormal traffic detection: Traffic feature extraction and DAE-GAN with efficient data augmentation[J]. IEEE Transactions on Reliability, 2022, 72(2): 498-510., Zecheng Li et al. proposed a denoising autoencoder model based on Generative Adversarial Network, which uses an abnormal traffic detection method. Through an efficient data enhancement and feature extraction framework, the semi-supervised anomaly detection model is improved by using the generated pseudo-abnormal data, and the accuracy and efficiency of network intrusion detection are enhanced. Due to the inclusion of multiple denoising autoencoders and adversarial training processes, it has high requirements for computing resources and implementation; the computational cost for processing high-dimensional data is relatively high.
[0005] In the implementation process of the above-mentioned prior art, it is found that the existing data augmentation algorithms mainly rely on generative adversarial networks. However, these algorithms lack effective conditional constraints during the training process, resulting in unbalanced generation results, which instead exacerbate the imbalance problem of data augmentation. Moreover, the existing classification algorithms are all single algorithms, which have limitations in multi-classification tasks. When the data distribution is unbalanced, the overall classification metrics are good, but their minority components cannot be effectively detected, and the metrics are not good, resulting in low accuracy in dealing with network attacks. Summary of the Invention
[0006] In view of the problems existing in the prior art, the present invention provides a method and system for processing network attacks based on zero-sum game.
[0007] The present invention is implemented through the following technical solutions:
[0008] The present invention provides a method for processing network attacks based on zero-sum game, including:
[0009] Determine the target samples in the samples according to the optimal weights of each classifier in the classification system and the predicted values of each classifier for the samples. Each classifier at least includes a random forest classifier, an extremely randomized trees classifier, and a gradient boosting classifier. The samples include network attack information. The optimal weights of each classifier include the values obtained after iterative processing of the samples by each classifier until Nash equilibrium;
[0010] Perform quantity augmentation processing on the target class samples through a generative adversarial network GAN model to obtain augmented samples;
[0011] Perform network attack detection according to the augmented samples and the samples to determine whether there is a network intrusion attack behavior.
[0012] Further, the determining the target samples in the samples according to the optimal weights of each classifier in the classification system and the predicted values of each classifier for the samples includes:
[0013] Process the samples through a random forest classifier to obtain predicted values ;
[0014] Process the samples through an extremely randomized trees classifier to obtain predicted values ;
[0015] Process the samples through a gradient boosting classifier to obtain predicted values ;
[0016] According to determine the processing result of the classification system for the samplesY , where is the optimal weight of the random forest classifier, is the optimal weight of the extra trees classifier, is the optimal weight of the gradient boosting classifier.
[0017] Further, determining the target sample in the sample according to the optimal weights of the classifiers in the classification system and the predicted values of the classifiers for the sample further includes:
[0018] The weight of the th classifier in the (t + 1)-th iteration and the weight of the th classifier in the t-th iteration subtracted, when the absolute value reaches the Nash equilibrium, determine the weight as the optimal weight of the th classifier, where , represents the profit of the th classifier in the th iteration, the profit , the error rate , represents the feature vector of the th sample, represents the true label of the th sample, is an indicator function. When the predicted value of the th classifier for the sample is different from the true label , the value is 1, otherwise it is 0. The first classifier is a random forest classifier, the second classifier is an extra trees classifier, and the third classifier is a gradient boosting classifier.
[0019] Further, the generative adversarial network GAN model includes: a decoder, an encoder, a generator, and a discriminator;
[0020] The decoder is connected to the encoder. The encoder is responsible for dimensionality reduction processing of the target sample, and the decoder is responsible for remapping the target sample with reduced dimensions by the encoder back to the high-dimensional data space;
[0021] The generator is connected to the decoder and is used to generate augmented samples from the target samples sent by the decoder;
[0022] The discriminator is connected to the generator and is used to determine whether the augmented samples generated by the generator meet the conditions;
[0023] The generative adversarial network (GAN) model includes an adversarial loss sub-model, a reconstruction loss sub-model, a diversity loss sub-model, and a temporal loss sub-model; among them,
[0024] The adversarial loss sub-model:
[0025] ;
[0026] is used to improve the authenticity of the samples generated by the generator, where represents the target sample, represents the random noise vector, represents the condition, represents the generator, represents the discriminator, represents the expected value of and under the data distribution , and the data distribution represents the distribution law of the samples in the original data set, and data represents the original data set;
[0027] The reconstruction loss sub-model is used to increase the distribution gap between samples during the dimensionality reduction process by the encoder, represents the result after the target sample and the condition are input into the encoder and then passed through the decoder, and the double absolute value is the norm;
[0028] The diversity loss sub-model is used to ensure the diversity of the generated samples, where represents the sample and The Euclidean distance between them, represents the minimum distance between each sample and other samples ;
[0029] The temporal loss sub-model used to ensure that the generated samples are similar to the samples in the low-dimensional space , where E is the encoder, x is the target sample, c is the condition, G is the generator, z is the random noise vector, G(z, c) is the output result of the generator, and E(x, c) is the output result of the target sample through the encoder.
[0030] Furthermore, the generative adversarial network (GAN) model further includes: a function for measuring the similarity between the generated samples and the samples in terms of feature distribution where represents the target sample, represents the augmented sample, is the number of samples.
[0031] The present invention also provides a processing system for network attacks, including:
[0032] A classification module, configured to determine a target sample in the sample according to the optimal weights of each classifier in the classification system and the prediction values of each classifier for the sample. The number of samples not classified as the target sample is greater than the number of target samples. Each classifier at least includes a random forest classifier, an extremely randomized trees classifier, and a gradient boosting classifier. The sample includes network attack information. The optimal weights of each classifier include the values obtained after iteratively processing the sample to Nash equilibrium;
[0033] An expansion module, configured to perform quantity expansion processing on the target class samples through a generative adversarial network (GAN) model to obtain expanded samples;
[0034] A determination module, configured to perform network attack detection based on the expanded samples and the samples to determine whether there is a network intrusion attack behavior.
[0035] Further, the classification module is further configured to process the sample through a random forest classifier to obtain a prediction value ; process the sample through an extremely randomized trees classifier to obtain a prediction value ; process the sample through a gradient boosting classifier to obtain a prediction value ; and determine the processing result of the classification system for the sample according to where, Y is the optimal weight of the random forest classifier, is the optimal weight of the extremely randomized trees classifier, is the optimal weight of the gradient boosting classifier, is the optimal weight of the gradient boosting classifier.
[0036] Further, the classification module is further configured to determine that the weight of the i-th classifier in the (t + 1)-th iteration, when the absolute value of the subtraction from the weight of the j-th classifier in the t-th iteration reaches Nash equilibrium, is the optimal weight of the i-th classifier, where represents the benefit of the i-th classifier in the k-th iteration. In each iteration, the benefit is, the error rate is the optimal weight of the i-th classifier where, represents the i-th classifier in the k-th iteration, and in each iteration, the benefit is, the error rate represents The feature vector of a sample, denotes the true label of the th sample, is an indicator function. When the th classifier's predicted value for the sample differs from the true label , the value is 1; otherwise, it is 0. The first classifier is a random forest classifier, the second classifier is an extremely randomized trees classifier, and the third classifier is a gradient boosting classifier.
[0037] Furthermore, the generative adversarial network GAN model includes: a decoder, an encoder, a generator, and a discriminator;
[0038] The decoder is connected to the encoder. The encoder is responsible for dimensionality reduction processing of the target sample, and the decoder is responsible for remapping the target sample with reduced dimensions by the encoder back to the high-dimensional data space;
[0039] The generator is connected to the decoder and is used to generate augmented samples from the target samples sent by the generator through the decoder;
[0040] The discriminator is connected to the generator and is used to determine whether the augmented samples generated by the generator meet the conditions;
[0041] The generative adversarial network GAN model includes an adversarial loss sub-model, a reconstruction loss sub-model, a difference loss sub-model, and a temporal loss sub-model; among them,
[0042] The adversarial loss sub-model:
[0043] ;
[0044] is used to improve the authenticity of the samples generated by the generator. Among them, represents the target sample, represents the random noise vector, represents the condition, represents the generator, represents the discriminator, represents the expected value of and under the data distribution . The data distribution represents the distribution law of the samples in the original dataset, and data represents the original data represents the expected value under the noise distribution and the conditional distribution ;
[0045] The reconstruction loss sub-model It is used to increase the distribution gap between samples during the dimensionality reduction process of the encoder. It represents the result after the target sample and the conditional input are input into the encoder and then passed through the decoder, with double absolute values. is the norm.
[0046] Differential loss sub-model It is used to ensure the diversity of generated samples. Among them, represents the sample and the Euclidean distance between them, represents for each sample and other samples the minimum distance between them;
[0047] Temporal loss sub-model for ensuring that the generated samples are similar to the samples in the low-dimensional space:
[0048] ;
[0049] E is the encoder, where x is the target sample, c is the condition, G is the generator, z is the random noise vector, G(z, c) is the output result of the generator, and E(x, c) is the output result of the target sample after passing through the encoder.
[0050] Furthermore, the generative adversarial network GAN model further includes: a function for measuring the similarity of the generated samples and the samples in the feature distribution Among them, represents the target sample, represents the augmented sample, is the number of samples.
[0051] Compared with the prior art, the present invention has the following beneficial technical effects:
[0052] The idea of Nash equilibrium in game theory is introduced. Through the ensemble learning method, the combined strategies of multiple classifiers are optimized to improve the robustness and performance of the classifiers when dealing with imbalanced data. Furthermore, multiple loss function models are introduced, which can constrain the training effect of the model in multiple aspects, accelerate the model convergence speed, and ensure the authenticity and diversity of the generated samples. At the same time, the Transformer architecture is used for the model, enabling the model to have consistent feature extraction and representation capabilities when processing complex data, that is, target samples. Through the multi-head attention mechanism, the model can simultaneously focus on different parts of the target sample and find hidden attack features in a wider feature space. Thereby improving the processing accuracy of network attacks.
[0053] The network attack processing method and system based on zero-sum game provided by the present invention. According to the optimal weights of each classifier in the classification system and the predicted values of each classifier for the sample, the target samples in the sample are determined. The number of samples not classified as target samples is greater than the number of target samples. Each classifier at least includes a random forest classifier, an extremely randomized tree classifier, and a gradient boosting classifier. The sample includes network attack information. The optimal weights of each classifier include the values obtained after iteratively processing the sample to Nash equilibrium. Then, the target class samples are processed by a generative adversarial network (GAN) model for quantity expansion to obtain expanded samples. Then, based on the expanded samples and the sample, network attack detection is performed to determine whether there is a network intrusion attack behavior. By using the GAN model to generate expanded samples with authenticity and diversity, it is beneficial to find hidden network intrusion attack behaviors. Thus, the accuracy of network attack processing is improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] Figure 1 is a schematic flowchart of the network attack processing method based on zero-sum game according to an embodiment of the present invention;
[0055] Figure 2 is a schematic structural diagram of an ensemble learning classifier under the game theory strategy according to an embodiment of the present invention;
[0056] Figure 3 is a schematic overall structural diagram of a generative adversarial network (GAN) model according to an embodiment of the present invention;
[0057] Figure 4 is a schematic specific structural diagram of a generative adversarial network (GAN) model according to an embodiment of the present invention;
[0058] Figure 5 is a multi-loss curve diagram of a generative adversarial network (GAN) model according to an embodiment of the present invention.
[0059] Figure 6 is a schematic structural diagram of the network attack processing system based on zero-sum game according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0060] The present invention will be further described in detail below with reference to specific embodiments, which are explanations of the present invention rather than limitations.
[0061] A network attack processing system based on zero-sum game provided by an embodiment of the present invention is applicable to actual network traffic, where legitimate communication data is much more than malicious attack data. This imbalance leads to bias in the training of attack detection models, making existing models tend to ignore those few but critical malicious attack scenarios. Further, the network attack processing system based on zero-sum game provided by an embodiment of the present invention can be set inside the network attack detection or outside the network attack detector. When set outside the network attack detector, it can be an independently set system or a system set together with the network attack detector, which is not limited herein. An embodiment of the present invention solves the data imbalance problem in the network intrusion detection system by generating augmented samples through a generative adversarial network (GAN) model, improving the recognition accuracy of rare attack types.
[0062] The network attack processing method based on zero-sum game provided by an embodiment of the present invention is mainly implemented through a classifier and a generative adversarial network (GAN). Among them, the classifier is based on zero-sum game, and the generative adversarial network (GAN) is also based on zero-sum game. The specific description is as follows:
[0063] Figure 1 It is a flowchart of the network attack processing method based on zero-sum game according to an embodiment of the present invention; as Figure 1 shown, the network attack processing method based on zero-sum game includes the following steps:
[0064] Step 101: Determine the target samples in the samples according to the optimal weights of each classifier in the classification system and the prediction values of each classifier for the samples.
[0065] In this embodiment, the number of samples not classified as target samples is greater than the number of target samples. Each classifier at least includes a random forest classifier, an extra trees classifier, and a gradient boosting classifier. The samples include network attack information. The optimal weights of each classifier include the values obtained after iterative processing of the samples by each classifier until Nash equilibrium;
[0066] Specifically, this embodiment introduces the Nash equilibrium idea in game theory and optimizes the combined strategies of multiple classifiers through an ensemble learning method to improve the robustness and performance of the classifier in processing imbalanced data. The ensemble learning classifier under the game theory strategy is as Figure 2 shown.
[0067] At the beginning of training, three classifiers are initialized, namely a random forest classifier (RandomForestClassifier), an extra trees classifier (ExtraTreesClassifier), and a gradient boosting classifier (GradientBoostingClassifier). The initial weight of each classifier , satisfy . For each classifier, calculate its error rate. Suppose the error rates are , , and the error rate formula is as shown in (1):
[0068] (1);
[0069] Among them, represents the feature vector of the -th sample, represents the true label of the -th sample. is an indicator function. When the prediction value of classifier for sample is different from the true label , has a value of 1, otherwise 0.
[0070] Calculate the gain of each classifier based on the error rate. The lower the error rate, the higher the gain. In each iteration, the gain The gain formula is as shown in (2):
[0071] (2);
[0072] Define the weights of the three classifiers. And adjust the weights according to the gain. The update formula is as shown in (3):
[0073] (3);
[0074] represents the weight of the -th classifier in the -th iteration, represents the gain of the -th classifier in the -th iteration.
[0075] Repeat the steps of calculating the error rate, gain, and update strategy until the change in the weights is less than a small threshold , that is, reaching the Nash equilibrium, as shown in equation (4):
[0076] (4);
[0077] After reaching the Nash equilibrium, the final prediction result is the weighted average of the prediction results of each classifier, as shown in equation (5):
[0078] (5);
[0079] Represents the final predicted probability obtained based on the weighted average of the prediction results of each classifier. Among them, through continuous iteration, when the returns of each classifier reach the Nash equilibrium state, the optimal weights of each classifier are determined according to the return value and the total return , for example, through a random forest classifier for the sample to obtain a predicted value ;
[0080] through an extremely randomized tree classifier for the sample to obtain a predicted value ;
[0081] through a gradient boosting classifier for the sample to obtain a predicted value ;
[0082] According to , determine the processing result of the classification system for the sample Y , where is the optimal weight of the random forest classifier, the optimal weight of the extremely randomized tree classifier, is the optimal weight of the gradient boosting classifier. The first classifier is the random forest classifier, the second classifier is the extremely randomized tree classifier, and the third classifier is the gradient boosting classifier.
[0083] To better demonstrate the performance advantages of the classifiers we proposed, we compared the performance of the classifiers on the KDDTrain+ and KDDTest+ datasets. The results are shown in the table. Our optimization strategy outperforms traditional single classifiers in classification tasks, especially in the identification of scarce samples, showing significant performance improvement. This further proves the effectiveness and practicality of optimizing classifier combinations through game theory strategies.
[0084] Table 1: Comparison of classifier accuracy performance
[0085]
[0086] Furthermore, we list the various metrics in the multi-classification task of ensemble learning as shown in the table. The overall accuracy of the model reaches 99.62%, which is excellent in the same field. However, when writing out the specific classification of each small class, the classification performance of the small classes is extremely low. For categories such as rootkit, bufferoverflow, imap, land, loadmodule, perl, etc., due to the extremely limited records in the dataset, the classification metrics are extremely low or even completely undetectable. And in network attack simulations, the failure to detect any type may bring serious consequences.
[0087] Table 2: Multi-class Classification Performance Table of Classifiers
[0088]
[0089] At the same time, due to the influence brought about by the extremely small number of some types, the volatility of such indicators is extremely high. Taking loadmodule as an example, there is only one record in the dataset. At this time, there are only two possibilities for the test accuracy, that is, 0% or 100%. When macroscopically describing the classification model, the results of loadmodule can only be described as extremely good and extremely poor in terms of classification effect. And there are not a few such types of data. It is often not appropriate to use the existing classification evaluation indicators.
[0090] Therefore, when using the dataset to evaluate the classification model, the overall evaluation indicators are not suitable for describing rare samples. Instead, data augmentation algorithms are needed to expand rare samples, and evaluate all aspects of the model's performance based on a relatively large balanced quantity scale. At this time, the generative adversarial network has become the best data augmentation tool. Through the adversarial training of the generative network and the discriminative network, the generative network can generate realistic data samples, thus effectively making up for the shortage of rare category samples in the dataset. This method not only increases the number of rare samples, but also retains the diversity of samples, making the performance of the classification model more stable and reliable when facing minority categories. By introducing the generative adversarial network, we can effectively expand the number of rare samples without changing the structure of the original dataset, making the performance indicators obtained more representative when evaluating the classification model. At the same time, the data samples of the generative adversarial network can retain the key features of the original data, avoiding the problem of model overfitting caused by simple replication or excessive enhancement. Therefore, the application of the generative adversarial network not only solves the limitations of traditional data augmentation methods, but also lays a solid foundation for further improving the generalization ability of the classification model.
[0091] Step 102: Perform quantity expansion processing on the target class samples through the generative adversarial network GAN model to obtain expanded samples;
[0092] Figure 3 It is the overall structural schematic diagram of the generative adversarial network GAN model in an embodiment of the present invention. As Figure 3As shown in the figure, the generative adversarial network GAN model in this embodiment includes: a decoder Decoder, an encoder Encoder, a generator Generator, and a discriminator Discriminator; the decoder is connected to the encoder, and the encoder is responsible for the dimensionality reduction processing of the target samples, and the decoder is responsible for remapping the target samples with reduced dimensions by the encoder back to the high-dimensional data space; the Encoder and Decoder are responsible for the conversion of high- and low-dimensional feature data, and at the same time, the data condition type is used to further distinguish normal samples from abnormal samples, so as to further reduce the potential impact brought by data imbalance from the data input level. The generator is connected to the decoder and is used to generate augmented samples that meet the conditions from the target samples sent by the decoder; the discriminator is connected to the generator and is used to judge whether the augmented samples generated by the generator meet the conditions, that is, to judge the authenticity of the generated data and whether it meets the condition constraints. By adding this process that combines dimensionality reduction and restoration using conditions, the key features of the data can be effectively retained, and the interference of the information imbalance problem on model training can be reduced.
[0093] After receiving the low-dimensional features and conditional information processed by the encoder Encoder, the generator Generator generates new data samples that meet the conditions. To ensure the diversity and authenticity of the generated samples, the Generator adopts an adversarial training method to continuously optimize its own generation ability. The Discriminator is used to distinguish the authenticity of the input samples and at the same time judge whether the samples meet the given conditions. In this way, the Discriminator not only improves the discrimination ability of the generated samples, but also ensures the consistency of the feature distribution between the generated samples and the real data.
[0094] In the data augmentation task, enhancing the diversity of the data should be the main goal. Therefore, we comprehensively compare and analyze the improvement of the classification task metrics and the similarity between the generated samples and the original samples. The improvement of the metrics of the classification model proves the effectiveness of the data augmentation algorithm. At the same time, we select three evaluation metrics for data augmentation: PRD, RMSE, and MAE to corroborate and quantify the data augmentation effect of CE-GAN from the side. These generated metrics should be kept within a reasonable range, neither too high to lose authenticity nor too low to lose diversity, to ensure that the generated samples achieve the best balance between diversity and authenticity.
[0095] In model training, we introduce a variety of loss functions to constrain the model training effect, namely adversarial loss, reconstruction loss, difference loss, and moment loss, etc. Each loss function plays a key role in different parts of the model.
[0096] The adversarial loss is the core of the generative adversarial network. Through the game between the Generator and the Discriminator, the Generator continuously improves the authenticity of the generated samples, while the Discriminator enhances its ability to distinguish true from false and match conditions. Specifically, the conditional adversarial loss can be described as shown in Equation (6):
[0097] (6);
[0098] where, represents the real data, i.e., the target samples, represents the random noise vector, represents the conditional information, represents the generator, represents the discriminator, represents the expected value of and under the given data distribution . The lower the expected value, the better the samples generated by the generator. The data distribution represents the distribution law of the samples in the original dataset, and data represents the original data. is an abstract representation used to refer to the distribution law of the target samples in the dataset. This law cannot be simply described and represented by functions, etc., so a representative pdata is used.
[0099] The reconstruction loss can ensure the effective data dimensionality reduction and restoration between the Encoder and the Decoder. By combining data with conditional information, the distribution gap between normal samples and abnormal samples is widened during the dimensionality reduction process. The reconstruction loss is described as shown in Equation (7):
[0100] (7);
[0101] represents the result after the target samples and conditional inputs are fed into the encoder and then passed through the decoder; The diversity loss is used to ensure the diversity of the generated samples, prevent overfitting from occurring, and thus lose the meaning of the generative adversarial network. At the same time, it makes the generated samples as realistic as possible. Its form is shown in Equation (8):
[0102] (8);
[0103] where, represents the Euclidean distance between the sample and . represents calculating the minimum distance between each sample and other samples . It exists in the form of a small negative mean during the overall training process, thus avoiding the loss of authenticity in generation for the sake of model diversity.
[0104] The temporal loss is used to ensure that the generated samples are overall similar to the original data in the low-dimensional space, improving the reliability of the generated data. Its form is shown in Equation (9):
[0105] (9);
[0106] E is the encoder, where x is the target sample, c is the condition, G is the generator, z is the random noise vector, G(z, c) is the output result of the generator, and E(x, c) is the output result of the target sample through the encoder. The whole process describes and calculates the size of the distribution difference between the target sample and the generated sample.
[0107] By combining four loss functions, the training effect of the model can be constrained in multiple aspects, the convergence speed of the model can be accelerated, the authenticity and diversity of the generated samples can be ensured, and a more appropriate trade-off can be made between the two to improve the quality of the generated samples of CE-GAN.
[0108] As Figure 4 shown, we list the model architectures used by each network in CE-GAN. For the high complexity and high diversity characteristics attached to network attacks, the multi-head attention mechanism of Transformer can flexibly extract rich feature representations of signals from the input data. To ensure the equal capabilities of the Generator and Discriminator in the CE-GAN model, we use the Transformer architecture for both of them, enabling them to have consistent feature extraction and representation capabilities when processing complex data. Through the multi-head attention mechanism, the model can simultaneously focus on different parts of the data and find hidden attack features in a wider feature space, which is crucial for identifying complex network attack behaviors.
[0109] To evaluate the quality of the samples generated by CE-GAN, we selected three commonly used metrics in the field of data augmentation, namely PRD, RMSE, and MAE, which can quantify the results of CE-GAN with formulas, thereby indirectly reflecting the authenticity and diversity of the generated samples.
[0110] 1. PRD
[0111] PRD is used to measure the similarity between the generated samples and the real samples in terms of feature distribution. By calculating the percentage root mean square difference between the generated samples and the real samples, it can be evaluated whether the generated samples maintain authenticity while maintaining diversity. The calculation formula is shown in (10):
[0112] (10);
[0113] Among them, represents the real sample, represents the generated sample, is the number of samples. PRD is more sensitive to the deviation of the overall distribution of the generated samples and can reflect the accuracy of the generated samples in the overall distribution. The smaller the value, the higher the authenticity and the lower the diversity.
[0114] 2. RMSE
[0115] RMSE represents the root mean square error between the generated sample and the real sample, which can reflect the numerical difference between the generated sample and the real sample. Its calculation formula is as shown in (11):
[0116] (11);
[0117] The smaller the RMSE value, the higher the similarity between the generated sample and the real sample. RMSE is more sensitive to the larger error values in the generated samples and can effectively capture the larger error values in the generated samples.
[0118] 3. MAE
[0119] MAE usually represents the absolute error between the generated sample and the real sample, intuitively reflecting the quality of the generated sample. The formula is as shown in (12):
[0120] (12);
[0121] The smaller the MAE value, the higher the quality of the generated sample and the lower the diversity. MAE is equally sensitive to all error values and is a relatively stable and direct error measure.
[0122] The K-fold validation experiment first verifies the effectiveness of the model. The effectiveness of the model is verified using three metrics: PRD, RMSE, and MAE. The experiments are all carried out with the expansion of single-class scarce attack samples. As shown in Table 3, we combine buffer_overflow with normal samples to form new samples. These are divided into K parts, where K - 1 parts are used as the training set and 1 part is used as the test set, thereby cross-verifying the effectiveness and generality of the model. From the metrics, the average PRD of the attack samples generated by the CE-GAN generation network is 64.3868, the average RMSE is 0.1964, and the average MAE is 0.1264. The overall performance is relatively good, which verifies the effectiveness of the CE-GAN model from the generation metrics.
[0123] Table 3 K-fold experiment verification table for NSL-KDD dataset
[0124]
[0125] Such as Figure 5As shown, we plotted the loss curves of the various loss values of the Generator and the Discriminator loss value. The adversarial loss of the Generator increased rapidly in the initial stage of training, and the Discriminator loss decreased rapidly. When reaching about 400 iterations, the two reached a balanced state. The Moment loss and the Constrastive loss showed a weak adversarial situation throughout the process. One was responsible for enhancing data diversity, and the other was responsible for enhancing data authenticity. When the curves of the two reached equilibrium and stability, the model was in a state of retaining diversity on the basis of being relatively real. At this time, the Generator could generate diverse samples that met the authenticity, thus effectively expanding the dataset.
[0126] In the experiment, we conducted multiple trials on the composition of the Generator loss value. The composition of the Generator loss value is shown in Equation (13), where and both are used to control the loss value coefficients, generally taking , at this time, the two are relatively stable and do not have too much impact on the entire training process. When takes a larger value, the model stability is lower, and the mode collapse problem will occur multiple times. Therefore, the diversity size needs to be controlled within a smaller range, so as to have a smaller impact on the model training process and enhance the diversity.
[0127] (13);
[0128] Step 103: Detect network attacks based on the expanded samples and the samples, and determine whether there is a network intrusion attack behavior.
[0129] The present invention implementation introduces the Nash equilibrium idea in game theory. Through the ensemble learning method, the combined strategies of multiple classifiers are optimized to improve the robustness and performance of the classifier when dealing with imbalanced data. Further, multiple loss function models are introduced, which can constrain the training effect of the model in multiple aspects, accelerate the model convergence speed, and ensure the authenticity and diversity of the generated samples. At the same time, the Transformer architecture is used for the model, enabling the model to have consistent feature extraction and representation capabilities when processing complex data, that is, target samples. Through the multi-head attention mechanism, the model can simultaneously pay attention to different parts of the target sample and find hidden attack features in a wider feature space. Thus, the processing accuracy of network attacks is improved.
[0130] In this embodiment, according to the optimal weights of each classifier in the classification system and the predicted values of each classifier for the samples, the target samples in the samples are determined. The number of samples not classified as target samples is greater than the number of target samples. The classification system includes at least a random forest classifier, an extremely randomized tree classifier, and a gradient boosting classifier. The samples include network attack information. Then, the target class samples are processed by a generative adversarial network (GAN) model for quantity expansion to obtain expanded samples. Then, network attack detection is performed based on the expanded samples and the samples to determine whether there is a network intrusion attack behavior. By using the GAN model to generate expanded samples with authenticity and diversity, it is beneficial to find hidden network intrusion attack behaviors, thereby improving the processing accuracy of network attacks.
[0131] Figure 6 FIG. is a schematic structural diagram of an unbalanced electrocardiogram data determination system based on an adaptive generative adversarial network according to an embodiment of the present invention. As Figure 6 shown, the unbalanced electrocardiogram data determination system based on an adaptive generative adversarial network according to an embodiment of the present invention includes: a classification module 61, an expansion module 62, and a determination module 63, where
[0132] The classification module 61 is configured to determine the target samples in the samples according to the optimal weights of each classifier in the classification system and the predicted values of each classifier for the samples. The number of samples not classified as target samples is greater than the number of target samples. The classification system includes at least a random forest classifier, an extremely randomized tree classifier, and a gradient boosting classifier. The samples include network attack information;
[0133] The expansion module 62 is configured to perform quantity expansion processing on the target class samples through a generative adversarial network (GAN) model to obtain expanded samples;
[0134] The determination module 63 is configured to perform network attack detection based on the expanded samples and the samples to determine whether there is a network intrusion attack behavior.
[0135] In this embodiment, according to the optimal weights of each classifier in the classification system and the predicted values of each classifier for the samples, the target samples in the samples are determined. The number of samples not classified as target samples is greater than the number of target samples. The classification system includes at least a random forest classifier, an extreme random tree classifier, and a gradient boosting classifier. The samples include network attack information. Then, the target class samples are processed through a generative adversarial network (GAN) model for quantity expansion to obtain expanded samples. Then, network attack detection is performed based on the expanded samples and the samples to determine whether there is a network intrusion attack behavior. By generating expanded samples with authenticity and diversity through the GAN model, it is beneficial to find hidden network intrusion attack behaviors. Thus, the processing accuracy of network attacks is improved.
[0136] In the embodiment of the present invention, the classification module 61 is further configured to process the samples through a random forest classifier to obtain predicted values ; process the samples through an extreme random tree classifier to obtain predicted values ; process the samples through a gradient boosting classifier to obtain predicted values ; according to , determine the processing result of the classification system for the samples Y , where is the optimal weight of the random forest classifier, is the optimal weight of the extreme random tree classifier, is the optimal weight of the gradient boosting classifier.
[0137] Furthermore, the classification module 61 is further configured to determine the weight of the th classifier in the (t + 1)-th iteration, when the absolute value of the subtraction between the weight of the th classifier in the t-th iteration reaches the Nash equilibrium, as the optimal weight of the th classifier, where , the benefit in each iteration, the error rate , , represents the feature vector of the th sample, represents the true label of the th sample, is an indicator function. When the predicted value of the th classifier for the sample is the same as the true label At different times, the value is 1, otherwise it is 0. The first classifier is a random forest classifier, the second classifier is an extremely randomized tree classifier, and the third classifier is a gradient boosting classifier.
[0138] Based on the above embodiments, the generative adversarial network GAN model includes: a decoder, an encoder, a generator, and a discriminator;
[0139] The decoder is connected to the encoder. The encoder is responsible for dimensionality reduction processing of the target samples, and the decoder is responsible for remapping the target samples dimensionally reduced by the encoder back to the high-dimensional data space;
[0140] The generator is connected to the decoder and is used to generate augmented samples from the target samples sent by the decoder;
[0141] The discriminator is connected to the generator and is used to determine whether the augmented samples generated by the generator meet the conditions;
[0142] The generative adversarial network GAN model includes an adversarial loss sub-model, a reconstruction loss sub-model, a diversity loss sub-model, and a temporal loss sub-model; among them,
[0143] The adversarial loss sub-model:
[0144] ;
[0145] is used to improve the authenticity of the samples generated by the generator, where represents the target sample, represents the random noise vector, represents the condition, represents the generator, represents the discriminator, represents the expectation of and under the data distribution The data distribution represents the distribution law of the samples in the original data set, and data represents the original data;
[0146] The reconstruction loss sub-model is used to increase the distribution gap between samples during the dimensionality reduction process by the encoder, represents the result after the target sample and the condition are input into the encoder and then passed through the decoder;
[0147] The diversity loss sub-model is used to ensure the diversity of the generated samples, where represents the sample and The Euclidean distance between, Indicates for each sample The minimum distance from other samples ;
[0148] The temporal loss sub-model used to ensure that the generated samples are similar to the samples in the low-dimensional space , where E is the encoder, x is the target sample, c is the condition, G is the generator, z is the random noise vector, G(z, c) is the output result of the generator, and E(x, c) is the output result of the target sample after passing through the encoder.
[0149] Furthermore, based on the above embodiments, the generative adversarial network GAN model further includes: a function for measuring the similarity between the generated samples and the samples in terms of feature distribution , where represents the target sample, represents the augmented sample, is the number of samples.
[0150] The implementation principle and technical effect of this embodiment are similar to Figures 1-5 the implementation principle and technical effect shown, and will not be elaborated here.
[0151] The above is only a relatively preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention should be covered within the protection scope of the present invention.
Claims
1. A network attack processing method based on zero-sum game, characterized in that, Including: Determine the target samples in the samples according to the optimal weights of each classifier in the classification system and the predicted values of each classifier for the samples. The classifiers at least include a random forest classifier, an extremely randomized trees classifier, and a gradient boosting classifier. The samples include network attack information. The optimal weights of each classifier include the values obtained after iteratively processing the samples to Nash equilibrium by each classifier. Perform quantity augmentation processing on the target class samples through a generative adversarial network (GAN) model to obtain augmented samples. Perform network attack detection based on the augmented samples and the samples to determine whether there is a network intrusion attack behavior. The step of determining the target samples in the samples according to the optimal weights of each classifier in the classification system and the predicted values of each classifier for the samples includes: Process the samples through a random forest classifier to obtain predicted values ; Process the samples through an extremely randomized tree classifier to obtain predicted values ; Process the samples through a gradient boosting classifier to obtain predicted values ; According to , determine the processing result of the classification system for the sample Y , where is the optimal weight of the random forest classifier, is the optimal weight of the extremely randomized trees classifier, is the optimal weight of the gradient boosting classifier; The step of determining the target samples in the samples according to the optimal weights of each classifier in the classification system and the predicted values of each classifier for the samples further includes: The weight of the th classifier in the (t + 1)-th iteration is subtracted from the weight of the th classifier in the t-th iteration, and when the absolute value of the subtraction reaches the Nash equilibrium, the weight is determined to be the optimal weight of the th classifier , where and represents the profit of the th classifier in the th iteration. In each iteration, the profit , the error rate , and represents the feature vector of the th sample, represents the true label of the th sample, is an indicator function. When the predicted value of the th classifier for the sample is different from the true label , the value of is 1, otherwise it is 0. The first classifier is a random forest classifier, the second classifier is an extra tree classifier, and the third classifier is a gradient boosting classifier.
2. The network attack processing method based on zero-sum game according to claim 1, characterized in that, The generative adversarial network (GAN) model includes: a decoder, an encoder, a generator, and a discriminator. The decoder is connected to the encoder. The encoder is responsible for dimensionality reduction processing of the target samples, and the decoder is responsible for remapping the target samples dimensionally reduced by the encoder back to the high-dimensional data space. The generator is connected to the decoder and is used to generate augmented samples from the target samples sent by the decoder. The discriminator is connected to the generator and is used to determine whether the augmented samples generated by the generator meet the conditions. The generative adversarial network (GAN) model includes an adversarial loss sub-model, a reconstruction loss sub-model, a difference loss sub-model, and a temporal loss sub-model. Among them, The adversarial loss sub-model: ; For improving the authenticity of samples generated by a generator, where, represents the target sample, represents the random noise vector, represents the condition, represents the generator, represents the discriminator, represents the expected value of under the data distribution and , and the data distribution represents the distribution law of samples in the original dataset, and data represents the original data, represents the expected value under the noise distribution and under the conditional distribution ; The reconstructed loss sub-model is used to increase the distribution gap between samples during the dimensionality reduction process of the encoder, represents the result after the target sample and the conditional input are input into the encoder and then passed through the decoder, and the double absolute value is the norm; Diversity loss sub-model used to ensure the diversity of generated samples, where represents the sample and the Euclidean distance between represents the minimum distance between each sample and other samples ; Temporal loss sub-model for ensuring that the generated samples are similar to the samples in the low-dimensional space , is the encoder, where is the target sample, is the condition, is the generator, is the random noise vector, is the output result of the generator, is the output result of the target sample through the encoder.
3. The network attack processing method based on zero-sum game according to claim 2, wherein The generative adversarial network GAN model further includes a function for measuring the similarity between the generated samples and the samples in terms of feature distribution , where represents the target sample, represents the augmented sample, is the number of samples.
4. A network attack processing system based on zero-sum game, characterized in that, Including: A classification module, which is used to determine the target samples in the samples according to the optimal weights of each classifier in the classification system and the predicted values of each classifier for the samples. The number of samples not classified as target samples is greater than the number of target samples. The classifiers at least include a random forest classifier, an extremely randomized trees classifier, and a gradient boosting classifier. The samples include network attack information. The optimal weights of each classifier include the values obtained after iteratively processing the samples to Nash equilibrium by each classifier. An augmentation module, which is used to perform quantity augmentation processing on the target class samples through a generative adversarial network (GAN) model to obtain augmented samples. A determination module, which is used to perform network attack detection based on the augmented samples and the samples to determine whether there is a network intrusion attack behavior. The classification module is further configured to process the sample through a random forest classifier to obtain a predicted value ; process the sample through an extra trees classifier to obtain a predicted value ; process the sample through a gradient boosting classifier to obtain a predicted value ; determine the processing result of the classification system on the sample according to , where Y is the optimal weight of the random forest classifier, is the optimal weight of the extra trees classifier, is the optimal weight of the gradient boosting classifier; The classification module is also used for the weight of the th classifier in the (t + 1)-th iteration subtracted from the weight of the th classifier in the t-th iteration, and when the absolute value of the subtraction reaches the Nash equilibrium, it determines that the weight is the optimal weight of the th classifier, where , , represents the return of the th classifier in the -th iteration, the return in each iteration is , the error rate is , represents the feature vector of the th sample, represents the true label of the th sample, is an indicator function. When the predicted value of the th classifier for the sample is different from the true label , the value is 1, otherwise it is 0. The first classifier is a random forest classifier, the second classifier is an extra trees classifier, and the third classifier is a gradient boosting classifier.
5. The network attack processing system based on zero-sum game according to claim 4, characterized in that The generative adversarial network (GAN) model includes: a decoder, an encoder, a generator, and a discriminator. The decoder is connected to the encoder. The encoder is responsible for dimensionality reduction processing of the target samples, and the decoder is responsible for remapping the target samples dimensionally reduced by the encoder back to the high-dimensional data space. The generator is connected to the decoder and is used to generate augmented samples from the target samples sent by the decoder. The discriminator is connected to the generator and is used to determine whether the augmented samples generated by the generator meet the conditions. The generative adversarial network (GAN) model includes an adversarial loss sub-model, a reconstruction loss sub-model, a difference loss sub-model, and a temporal loss sub-model. Among them, The adversarial loss sub-model: For improving the authenticity of samples generated by a generator, where, represents the target sample, represents the random noise vector, represents the condition, represents the generator, represents the discriminator, represents the expected value of under the data distribution and , and the data distribution represents the distribution law of samples in the original dataset, and data represents the original data; represents the expected value under the noise distribution and under the conditional distribution ; The reconstruction loss sub-model is used to increase the distribution gap between samples during the dimensionality reduction process by the encoder, represents the result after the target sample and the conditional input are input into the encoder and then passed through the decoder, with double absolute value being the norm; Diversity Loss Sub - model used to ensure the diversity of generated samples, where represents the sample and the Euclidean distance between represents the minimum distance for each sample and other samples therebetween; Temporal loss sub-model for ensuring that the generated sample is similar to the sample in the low-dimensional space , is the encoder, where is the target sample, is the condition, is the generator, is the random noise vector, is the output result of the generator, is the output result of the target sample through the encoder.
6. The network attack processing system based on zero-sum game according to claim 5, characterized in that, The generative adversarial network GAN model further includes a function for measuring the similarity between the generated samples and the samples in terms of feature distribution , where represents the target sample, represents the augmented sample, is the number of samples.
Citation Information
Patent Citations
Integrated learning method and device based on interval optimization
CN108090510A
Multi-sample AutoMix data enhancement method and system based on adversarial learning
CN117876813A
Network intrusion detection method, device and system based on federated learning
CN118400118A