An adversarial traffic example generation method, system, and computer device
By obtaining and splicing traffic feature data in the adversarial traffic example generation method, and performing adversarial training and gradient punishment processing, the local lag problem caused by excessive discriminator is solved, which significantly improves the quality of generating adversarial traffic examples and the stability of the model.
Patent Information
- Application Number
- CN202510016821.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-06
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2045-01-06
AI Technical Summary
The existing adversarial traffic example generation method. During the adversarial learning process, the discriminator is too powerful, which quickly recognizes the difference between the generator output and the real sample, which forces the generator to continuously improve the sample quality, causing the discriminator to fall into a local lag, affecting the training effect and convergence speed of the entire model.
By obtaining random noise vectors and real traffic samples, important attack feature data of real traffic samples are extracted, and feature stitching and fusing them with the normal traffic feature data output by the generator to generate fake traffic samples. Then, the forged adversarial traffic samples are trained to obtain adversarial traffic samples, and the gradient of the discriminator is controlled through the gradient penalty term to ensure the adversarial balance between the generator and the discriminator.
It significantly improves the effect of generating adversarial traffic examples in the energy Internet, evaluates attack characteristics through weight value algorithms, retains the core characteristics of the original malicious behavior, enhances the applicability and authenticity of generated examples, inhibits overfitting of discriminators, promotes benign interaction between generators and discriminators, and improves the quality of generated adversarial traffic examples and the stability of the model.
Smart Images

Figure CN119892442B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network traffic, and particularly to a method, system and computer device for generating adversarial traffic examples. Background Art
[0002] The energy Internet is being deployed in many industries in China. The key infrastructure, production equipment, and control systems in important energy fields such as electricity, coal, oil and gas, and petrochemicals will gradually become networked, digital, and intelligent. Once attacked maliciously, it will cause significant economic losses and even threaten personal safety, bringing major security risks to national security. As network traffic becomes increasingly complex, in the field of the energy Internet, attackers use adversarial sample attack techniques to damage key energy equipment and network infrastructure. In order to protect the security of the energy Internet, adversarial traffic examples are generated to retrain the encrypted malicious traffic detection model.
[0003] Currently, there are still deficiencies in the adversarial traffic example generation technology for the energy Internet. In the existing adversarial traffic example generation methods, during the adversarial learning process, due to the discriminator being too powerful, it quickly identifies the differences between the outputs of the generator and real samples, forcing the generator to continuously improve the sample quality. This intense competition causes the discriminator to fall into local lag, thereby affecting the training effect and convergence speed of the entire model. Summary of the Invention
[0004] The main objective of the present invention is to provide a method for generating adversarial traffic examples, aiming to solve the technical problems in the prior art.
[0005] The present invention proposes a method for generating adversarial traffic examples, including:
[0006] Obtain a random noise vector and real traffic samples, and extract important attack feature data of the real traffic samples;
[0007] Input the random noise vector into a generator to obtain normal traffic feature data;
[0008] Perform feature splicing and fusion on the normal traffic feature data and important attack feature data to obtain forged traffic samples;
[0009] Perform adversarial training on the forged adversarial traffic samples to obtain adversarial traffic samples;
[0010] Obtain a gradient penalty term according to the real traffic samples and forged traffic samples;
[0011] Obtain a total loss according to the forged traffic samples, adversarial traffic samples and real traffic samples, and determine whether the total loss is greater than a preset loss;
[0012] If the total loss is greater than the preset loss, it is determined that the forged traffic sample is real traffic;
[0013] If the total loss is not greater than the preset loss, return to the step of inputting the random noise vector into the generator to obtain normal traffic feature data until the total loss is greater than the preset loss.
[0014] Preferably, the step of extracting the important attack features of the network traffic includes:
[0015] Obtain all traffic features of the network traffic, and obtain multiple attack features according to all the traffic features;
[0016] Obtain the corresponding prediction marginal contribution according to each of the attack features and all traffic features;
[0017] Average all traffic features into multiple traffic sample subsets, and obtain the corresponding average marginal contribution according to each of the attack features and traffic sample subsets;
[0018] Obtain the weight value of each attack feature according to multiple average marginal contributions and prediction marginal contributions;
[0019] Sort multiple weight values in descending order to obtain a weight sorting table;
[0020] Set a splitting value, and split the weight values in the weight sorting table that are greater than the splitting value to obtain an important weight value table;
[0021] Mark the attack features corresponding to each weight value in the important weight value table as important attack features.
[0022] Preferably, the step of obtaining the corresponding average marginal contribution according to each of the attack features and traffic sample subsets includes:
[0023] Input each traffic sample subset into the gradient boosting model to obtain a first prediction value;
[0024] Replace the feature data in each traffic sample subset with each of the attack features to obtain a replacement traffic sample;
[0025] Input each replacement traffic sample into the gradient boosting model to obtain a second prediction value;
[0026] Obtain the corresponding marginal contribution according to each of the second prediction values and the first prediction value;
[0027] Calculate the average marginal contribution according to multiple marginal contributions, and the calculation formula is:
[0028]
[0029] Among them, P(G) k represents the k-th average marginal contribution, and J(B) k represents the k-th marginal contribution, k represents the serial number of the marginal contribution, and N represents the number of marginal contributions.
[0030] Preferably, the step of obtaining the gradient penalty term according to the real traffic sample and the forged traffic sample includes:[[]]
[0031] Obtain a random interpolation coefficient table, where the random interpolation coefficient table includes a plurality of interpolation coefficients arranged in ascending order;
[0032] Calculate the corresponding interpolation samples according to each interpolation coefficient, real traffic sample and forged traffic sample, where the calculation formula is:
[0033] C(YB) i =α i *Z(Y)+(1 - α i )W(Y);
[0034] Among them, C(YB) i represents the i-th interpolation sample, α i represents the i-th interpolation coefficient, i represents the serial number of the interpolation coefficient, Z(Y) represents the real traffic sample, and W(Y) represents the forged traffic sample;
[0035] Obtain the interpolation expected value according to the mean value of the plurality of interpolation samples;
[0036] Input each interpolation sample into the discriminator to obtain the corresponding interpolation output, and obtain the gradient of each interpolation output with respect to the corresponding interpolation sample;
[0037] Calculate the L2 norm of each gradient to obtain the sum of squared gradients;
[0038] Calculate the gradient penalty term according to the interpolation expected value and the sum of squared gradients, where the calculation formula is:
[0039]
[0040] Among them, T(C) represents the gradient penalty term, λ represents the weight parameter of the penalty term, C(Q) represents the interpolation expected value, represents the i-th gradient, D(C(YB) i ) represents the i-th interpolation output, and C(YB) i represents the i-th interpolation sample.
[0041] Preferably, the step of obtaining the total loss according to the forged traffic sample, adversarial traffic sample and real traffic sample includes:[[]]
[0042] Obtain the forged sample expected value according to the forged traffic sample, and obtain the forged sample loss according to the forged sample expected value;
[0043] Perform adversarial training on the forged adversarial traffic sample to obtain an adversarial traffic sample;
[0044] Obtain the adversarial sample expected value according to the adversarial traffic sample, and obtain the real sample expected value according to the real traffic sample;
[0045] Obtain the adversarial sample loss according to the adversarial sample expected value, and obtain the real sample loss according to the real sample expected value;
[0046] Obtain the total loss according to the gradient penalty term, the real sample loss, the forged sample loss, and the adversarial sample loss.
[0047] Preferably, the steps of obtaining the adversarial sample loss according to the adversarial sample expected value and obtaining the real sample loss according to the real sample expected value include:
[0048] Obtain an adversarial traffic sample, and input the adversarial traffic sample into a discriminator to obtain the real probability of the adversarial sample;
[0049] Calculate the adversarial sample loss according to the adversarial sample expected value and the real probability of the adversarial sample, where the calculation formula is:
[0050] D(Y) = D(QW) * [log(1 - D(YG))];
[0051] Wherein, D(Y) represents the adversarial sample loss, D(QW) represents the adversarial sample expected value, and D(YG) represents the real probability of the adversarial sample;
[0052] Obtain a real traffic sample, and input the real traffic sample into a discriminator to obtain the real probability of the real sample;
[0053] Calculate the real sample loss according to the real sample expected value and the real probability of the real sample, where the calculation formula is:
[0054] Z(Y) = Z(QW) * logZ(YG);
[0055] Wherein, Z(Y) represents the real sample loss, Z(QW) represents the real sample expected value, and Z(YG) represents the real probability of the real sample.
[0056] This application also provides an adversarial traffic example generation system, including:
[0057] A first acquisition module, configured to acquire a random noise vector and a real traffic sample, and extract important attack feature data of the real traffic sample;
[0058] An input module, configured to input the random noise vector into a generator to obtain normal traffic feature data;
[0059] A splicing module, configured to perform feature splicing and fusion on the normal traffic feature data and important attack feature data to obtain forged traffic samples;
[0060] A training module, configured to perform adversarial training on the forged adversarial traffic samples to obtain adversarial traffic samples;
[0061] A second acquisition module, configured to obtain a gradient penalty term according to the real traffic samples and the forged traffic samples;
[0062] A third acquisition module, configured to obtain a total loss according to the forged traffic samples, the adversarial traffic samples, and the real traffic samples;
[0063] A judgment module, configured to judge whether the total loss is greater than a preset loss;
[0064] If the total loss is greater than the preset loss, it is determined that the forged traffic sample is real traffic;
[0065] If the total loss is not greater than the preset loss, return to the step of inputting the random noise vector into the generator to obtain normal traffic feature data until the total loss is greater than the preset loss.
[0066] Preferably, the first acquisition module includes:
[0067] A first acquisition unit, configured to acquire all traffic features of the network traffic and acquire multiple attack features according to the all traffic features;
[0068] A second acquisition unit, configured to acquire a corresponding prediction marginal contribution according to each of the attack features and the all traffic features;
[0069] A division unit, configured to evenly divide all traffic features into multiple traffic sample subsets and acquire a corresponding average marginal contribution according to each of the attack features and the traffic sample subsets;
[0070] A third acquisition unit, configured to acquire a weight value of each attack feature according to the multiple average marginal contributions and the prediction marginal contributions;
[0071] A sorting unit, configured to sort the multiple weight values in descending order to obtain a weight sorting table;
[0072] A splitting unit, configured to set a splitting value and split the weight values in the weight sorting table that are greater than the splitting value to obtain an important weight value table;
[0073] A marking unit for marking the attack features corresponding to each weight value in the important weight value table as important attack features.
[0074] The present invention also provides a computer device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of the above-mentioned adversarial traffic example generation method are implemented.
[0075] The present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above-mentioned adversarial traffic example generation method are implemented.
[0076] The beneficial effects of the present invention are as follows: Through multiple key optimizations, the present invention significantly improves the effect of generating adversarial traffic examples in the energy Internet. By using the weight value algorithm to evaluate and screen attack features, the core features of the original malicious behavior are retained, enhancing the applicability and authenticity of the generated examples in real energy Internet scenarios. By punishing the gradient, overfitting of the discriminator can be suppressed, maintaining the adversarial balance between the generator and the discriminator, and preventing one side from being too strong or too weak, thereby promoting the positive interaction between the generator and the discriminator. It can effectively capture the key information in the traffic sequence, further improve the quality of generating adversarial traffic examples, accelerate the convergence process of training, and enhance the stability of the model. By continuously adjusting the generator, it is ensured that the difference between the forged traffic samples and the real traffic samples gradually decreases, so that the generated samples are more in line with the characteristics of real network traffic. Such high-fidelity adversarial traffic examples can more realistically reflect the patterns of the original attack behaviors. Through these optimization measures, the generated adversarial traffic examples not only have high camouflage, but also can retain the original attack behaviors, and can effectively improve the adversarial detection performance through retraining, thus providing stronger protection for network security in the energy Internet, making the present invention have high practical application value, and can provide personalized and accurate network security services for the energy Internet, with broad application prospects. BRIEF DESCRIPTION OF THE DRAWINGS
[0077] Figure 1 It is a schematic flowchart of the method according to an embodiment of the present invention.
[0078] Figure 2 It is a schematic structural diagram of the device according to an embodiment of the present invention.
[0079] Figure 3 It is a schematic internal structure diagram of the computer device according to an embodiment of the present application.
[0080] The realization, functional features and advantages of the object of the present invention will be further described with reference to the embodiments and the accompanying drawings. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0081] It should be understood that the specific embodiments described herein are merely for explaining the present invention and are not intended to limit the present invention.
[0082] As Figures 1 - 3 shown, the present application provides a method for generating adversarial traffic examples, including:
[0083] S1. Obtain a random noise vector and a real traffic sample, and extract important attack feature data of the real traffic sample;
[0084] S2. Input the random noise vector into a generator to obtain normal traffic feature data;
[0085] S3. Perform feature splicing and fusion on the normal traffic feature data and the important attack feature data to obtain a forged traffic sample;
[0086] S4. Perform adversarial training on the forged adversarial traffic sample to obtain an adversarial traffic sample;
[0087] S5. Obtain a gradient penalty term according to the real traffic sample and the forged traffic sample;
[0088] S6. Obtain a total loss according to the forged traffic sample, the adversarial traffic sample, and the real traffic sample;
[0089] S7. Determine whether the total loss is greater than a preset loss;
[0090] If the total loss is greater than the preset loss, determine that the forged traffic sample is real traffic;
[0091] If the total loss is not greater than the preset loss, return to the step of inputting the random noise vector into the generator to obtain normal traffic feature data until the total loss is greater than the preset loss.
[0092] As described in the above steps S1-S7, as network traffic becomes increasingly complex, in the field of energy Internet, attackers use adversarial sample attack technology to destroy key energy equipment and network infrastructure. In order to protect the security of energy Internet, adversarial traffic examples are generated to retrain the encrypted malicious traffic detection model. At present, the adversarial traffic example generation technology for energy Internet still has shortcomings. During the training process, the existing adversarial traffic example generation method fails to maintain an effective adversarial balance between the generator and the discriminator, resulting in the generated adversarial examples ignoring the potential contextual dependencies between feature sequences and making it difficult to retain the pattern characteristics of the original traffic sequence, thereby reducing the misleading ability of the generated samples and affecting the success rate of the attack. The present invention obtains random noise vectors and real traffic samples, extracts important attack feature data of the real traffic samples, inputs the random noise vectors into a generator to obtain normal traffic feature data, and performs feature splicing and fusion of the normal traffic feature data and the important attack feature data to obtain forged traffic samples. In traditional adversarial traffic generation methods, the generator and the discriminator may not maintain an effective adversarial balance, resulting in the generated adversarial examples ignoring the potential contextual dependencies in the traffic sequence. Contextual dependencies refer to the mutual relationships and sequential information between various features in the traffic data, which is crucial to the success rate of the attack. By introducing the splicing and fusion of normal traffic and attack features, the new generative model can better capture and retain this contextual information and improve the quality of the generated adversarial examples. By means of feature splicing, the generated forged traffic samples can better retain the pattern characteristics of normal traffic and the key features of the attack. This fusion enables the generator to pay more attention to the patterns and regularities in the original traffic when generating forged traffic samples, avoiding the distortion of the adversarial examples in the traditional methods. The generated forged traffic samples can contain the key information of both real traffic and attack traffic during the feature splicing and fusion process, thereby improving the ability of these samples to mislead traffic classification models or traffic detection systems. Since the forged traffic not only retains the structure of the real traffic, but also enhances the characteristics of the attack, making them more deceptive, they can Effectively bypass the traffic detection system. Since the generated forged traffic samples can more accurately reflect the characteristics of normal traffic and attack traffic, they can break the normal behavior pattern of the traffic detection system when executed, thereby increasing the probability of successful attack. This method can effectively improve the feasibility and success rate of adversarial attacks in real environments. In the adversarial learning process, the existing adversarial traffic example generation method has a too powerful discriminator, which causes it to quickly identify the difference between the generator output and the real sample, thereby forcing the generator to continuously improve the sample quality. This intense competition causes the discriminator to fall into local lag, which in turn affects the training effect and convergence speed of the entire model. The adversarial traffic samples are obtained by adversarial training on the forged adversarial traffic samples, and the gradient penalty items are obtained according to the real traffic samples and the forged traffic samples.By controlling the gradients of the discriminator, it is ensured that it does not overly bias towards certain specific patterns during adversarial training, but rather gives the generator more room to adjust its output, thereby balancing the difficulty of training and the capabilities of the generator. This method helps to avoid the adverse effects of an overly strong discriminator on the training process, provides a more balanced learning motivation. Through adversarial training, the generator and the discriminator are usually in a game relationship. The goal of a typical GAN (Generative Adversarial Network) model is to make the generator generate forged samples that are difficult for the discriminator to distinguish, while the discriminator tries to identify the forged samples. The gradient penalty term is usually used to constrain the gradients of the generator and the discriminator to avoid instability in the training process caused by overly large gradients of the discriminator. By penalizing the gradients, overfitting of the discriminator can be suppressed, maintaining the adversarial balance between the generator and the discriminator, and preventing one side from being too strong or too weak, thus promoting a healthy interaction between the generator and the discriminator. Since the generator and the discriminator are in mutual competition during the training process, an overly strong discriminator may cause the generator to fall into local stagnation, resulting in premature convergence of the training process, or the generator being unable to effectively improve the quality of its samples. Through the constraint of gradient penalty, the discriminator will not over-learn the details of the data or make overly extreme judgments on the samples, which can avoid the discriminator prematurely converging to a local optimum. Gradient penalty can prevent the model from falling into a local optimum, allowing the generator to continue to adjust its generation strategy, thereby improving the robustness and generalization ability of training and increasing the diversity of sample generation. Another significant benefit of introducing the gradient penalty term is that it can accelerate the convergence speed of the model. Since the gradient penalty makes the gradient updates during the training process more stable, the generator and the discriminator can be optimized more smoothly, avoiding overly drastic training fluctuations. This helps to avoid oscillations during the training process, reduce the instability caused by excessive competition between the generator and the discriminator, and thus accelerate the convergence speed of the model. Gradient penalty helps to control the magnitude of the gradients, avoiding the occurrence of gradient explosion (overly large gradients) or gradient vanishing (overly small gradients) problems, thereby enhancing the stability of the training process. By effectively balancing the training processes of the generator and the discriminator, the gradient penalty term helps to improve the quality and diversity of forged adversarial traffic samples. Existing methods for generating adversarial traffic examples ignore the fidelity of the original malicious behavior, resulting in the generated samples being difficult to reflect the characteristics of the original attack behavior in real scenarios, reducing their research value for attack strategies and detection mechanisms in real environments. Obtain the total loss through forged traffic samples, adversarial traffic samples, and real traffic samples, and determine whether the total loss is greater than a preset loss. If it is greater than the preset loss, then determine that the forged traffic sample is a real traffic. If it is not greater than, then return to the step of inputting a random noise vector into the generator to obtain normal traffic feature data until the total loss is greater than the preset loss. By continuously adjusting the generator, ensure that the difference between the forged traffic sample and the real traffic sample gradually decreases, so that the generated samples are more in line with the characteristics of real network traffic.This example of high-fidelity adversarial traffic can more realistically reflect the patterns of original attack behaviors, rather than merely "simulating" attacks. Through optimized forged traffic samples, the characteristics of real traffic can be better integrated. Therefore, they can more effectively evaluate the performance of existing detection mechanisms in actual network environments. Detection systems may show different reactions to the generated high-fidelity samples, which can then help researchers more accurately evaluate the robustness of detection mechanisms. By analyzing these adversarial samples, the evolution path of attacks and the behavioral characteristics of attackers can be deeply understood, and on this basis, more effective defense measures can be developed. By continuously optimizing the generator, the generated adversarial traffic samples are not only more realistic but also can cover more types of attack behaviors. This can provide more comprehensive attack data for different types of defense systems to be tested and trained. Through this optimization process, the forged traffic samples can better simulate the original malicious behaviors. For example, attack traffic may contain certain specific network protocol characteristics, traffic patterns, or abnormal behaviors, which are usually not effectively reflected in existing generation methods. By maximizing the similarity between samples and real traffic samples, the characteristics of malicious behaviors can be better retained, improving the effectiveness and credibility of the generated samples, generating more realistic and complex adversarial traffic samples, which helps to apply adversarial training techniques to real environments. This enables security researchers to use these samples to train and test defense systems, promoting research on and response capabilities against adversarial attacks in the field of network security.,
[0093] In one embodiment, step S1 of extracting important attack characteristics of the network traffic includes:
[0094] S11. Obtain all traffic characteristics of the network traffic, and obtain multiple attack characteristics based on all the traffic characteristics;
[0095] S12. Obtain the corresponding prediction marginal contribution according to each attack characteristic and all traffic characteristics;
[0096] S13. Evenly divide all traffic characteristics into multiple traffic sample subsets, and obtain the corresponding average marginal contribution according to each attack characteristic and traffic sample subset;
[0097] S14. Calculate the weight value of each attack characteristic according to multiple average marginal contributions and prediction marginal contributions, where the calculation formula is:
[0098]
[0099] where Q(Z) t represents the t-th weight value, Y(G) t represents the t-th prediction marginal contribution, P(G) tIt represents the average marginal contribution of the t-th one, where t represents the serial number of the attack feature and M represents the number of attack features;
[0100] S15. Sort the multiple weight values in descending order to obtain a weight sorting table;
[0101] S16. Set a segmentation value and segment the weight values in the weight sorting table that are greater than the segmentation value to obtain an important weight value table;
[0102] S17. Mark the attack features corresponding to each weight value in the important weight value table as important attack features.
[0103] As described in the above steps S11 - S17, the present invention obtains all traffic characteristics of network traffic, obtains multiple attack characteristics based on all traffic characteristics, obtains the corresponding predicted marginal contribution according to each attack characteristic and all traffic characteristics, evenly divides all traffic characteristics into multiple traffic sample subsets, and obtains the corresponding average marginal contribution according to each attack characteristic and traffic sample subset. Then, calculates the weight value of each attack characteristic based on multiple average marginal contributions and predicted marginal contributions, sorts the multiple weight values in descending order to obtain a weight ranking table, and divides the weight values greater than the segmentation value in the weight ranking table to obtain an important weight value table. By marking the attack characteristics corresponding to each weight value in the important weight value table as important attack characteristics. Among them, the predicted marginal contribution refers to the incremental contribution of a certain feature or input variable to the final prediction result under a given model. The average marginal contribution is the average of the predicted marginal contributions of all features or input variables. In traditional adversarial traffic generation methods, the generator may ignore the context dependence between traffic characteristics, resulting in the generated adversarial examples not having the pattern characteristics of real traffic. Therefore, the structured information of the traffic sequence may be lost, which in turn affects the effectiveness of adversarial samples. By calculating the marginal contribution of each traffic characteristic and dividing these characteristics into subsets, it can help capture the potential context relationships between traffic characteristics, thereby generating more practically misleading adversarial examples. This method can help the generator avoid overfitting certain features during training and ignore the potential attack effects of other key features by calculating the average marginal contribution and predicted marginal contribution of traffic characteristics. By calculating the weight of each attack characteristic and sorting it according to importance, the generator can more effectively adjust the attack strategy, making the generated adversarial examples more aggressive while maintaining similarity with real traffic, thus increasing the difficulty for the discriminator and enhancing the adversarial ability of the generator. Through weight ranking and segmentation, the most influential attack characteristics in adversarial traffic generation can be identified and marked. This can not only help attackers more precisely understand which traffic characteristics play a key role in the success of the attack, but also help defenders focus on the most important attack paths or characteristics in the defense strategy. Ultimately, this feature selection can improve the generation efficiency of adversarial examples and contribute to building a more robust security protection system. By conducting marginal contribution analysis on multiple traffic sample subsets, it can ensure that the generated adversarial examples can maintain their misleading ability under different traffic patterns. The identification and utilization of important attack characteristics enable adversarial examples to precisely manipulate the key characteristics of traffic while reducing dependence on other unimportant characteristics, thereby achieving a higher success rate when disrupting the defense system. Because adversarial samples can better simulate the structural characteristics of real traffic, and the attack feature selection and weight calculation method help accurately locate the features that have the greatest impact on the system, these adversarial samples will be more misleading in actual attacks, increasing the attack success rate.This means that attackers can more effectively bypass the defense system through these methods, increasing the success probability of attacks. Calculating the average division and marginal contribution of traffic features helps to refine the segmentation of the entire traffic space, thereby reducing the computing resources required in the process of generating adversarial samples, accelerating the generation speed, reducing the computational volume, and improving the efficiency of attacks.
[0104] In one embodiment, step S13 of obtaining the corresponding average marginal contribution according to each of the attack features and traffic sample subsets includes:
[0105] S131: Input each of the traffic sample subsets into the gradient boosting model to obtain a first predicted value;
[0106] S132: Replace the feature data in each of the traffic sample subsets with each of the attack features to obtain replacement traffic samples;
[0107] S133: Input each of the replacement traffic samples into the gradient boosting model to obtain a second predicted value;
[0108] S134: Obtain the corresponding marginal contribution according to each of the second predicted values and the first predicted value;
[0109] S135: Calculate the average marginal contribution according to multiple of the marginal contributions, where the calculation formula is:
[0110]
[0111] where P(G) k represents the kth average marginal contribution, J(B) k represents the kth marginal contribution, k represents the serial number of the marginal contribution, and N represents the number of marginal contributions.
[0112] As described in the above steps S131 - S135, the present invention obtains the first prediction value by inputting each traffic sample subset into the gradient boosting model. By replacing the feature data in each of the traffic sample subsets with each of the attack features, the replaced traffic samples are obtained, and then each replaced traffic sample is input into the gradient boosting model to obtain the second prediction value. Furthermore, the corresponding marginal contribution is obtained according to each second prediction value and the first prediction value, and the average marginal contribution is calculated based on multiple marginal contributions. Traditional adversarial traffic generation methods may ignore the context relationship between features, resulting in the generated traffic examples not having an actual traffic pattern in the sequence structure. By replacing the attack features and calculating the prediction value difference of each traffic sample subset under the original and replaced traffic samples, the specific impact of each feature on the traffic pattern can be effectively captured. The gradient boosting model can evaluate the importance of features according to their contribution degrees, helping the generator consider the dependencies between features when generating adversarial samples, thereby retaining the pattern features of the original traffic sequence. This helps to improve the "naturalness" of the adversarial samples, making them more misleading and increasing the attack success rate. In the traditional training process, the generator may overfit some features and ignore other features, resulting in the generated adversarial samples being difficult to be discriminated by the discriminator.By calculating the marginal contribution of traffic samples based on the gradient boosting model, it is possible to precisely understand the impact of each attack feature on the final judgment result and guide the generator to more precisely adjust the sample generation process. This method helps the generator better balance the adversarial process, avoid "over-adversarializing" a specific feature, enhance the aggressiveness and diversity of the generated adversarial samples. By replacing attack features and calculating the corresponding prediction value differences (i.e., marginal contributions), it is possible to identify which attack features have the greatest impact on the model prediction result. This feature importance-based analysis helps design more effective attack strategies from the attacker's perspective. Important attack features can be highlighted and optimized to increase the misleading ability of the generated samples. For the defense system, this method provides valuable information that can help defenders identify potential weaknesses and improve the robustness of the defense model. The marginal contribution calculated based on the prediction value differences of traffic samples under different feature combinations reflects the importance of each feature for the model's decision-making. The adversarial samples generated in this way can precisely manipulate adversarial features to improve the misleading ability of adversarial samples. This method enables the generated traffic samples to deviate from the normal traffic distribution to the greatest extent while retaining sufficient authenticity and aggressiveness, thereby increasing the attack success rate, especially in complex detection environments. By calculating the marginal contributions of multiple traffic samples and finally obtaining the average marginal contribution of each feature, it is possible to effectively guide the generator to select important features for optimization when generating adversarial samples. Compared with traditional random or heuristic generation methods, this marginal contribution-based optimization method can more quickly find effective attack feature combinations, thereby improving the efficiency of generating adversarial samples and the success rate of attacks. By using the gradient boosting model to calculate marginal contributions, the generation method can adapt to different types of traffic data and attack scenarios and flexibly adjust attack strategies. This enables the generated adversarial samples to achieve good results under different network environments and attack targets. Based on the marginal contribution analysis method of the gradient boosting model, the generated adversarial samples can more realistically reflect the attacker's behavior pattern, making them more confusing and misleading in the actual network. These generated adversarial samples can not only be used for adversarial training but also for evaluating and optimizing existing defense systems, thus providing more practically valuable samples for practical applications in the field of network security.
[0113] In one embodiment, step S5 of obtaining the gradient penalty term according to the real traffic sample and the forged traffic sample includes:
[0114] S51. Obtain a random interpolation coefficient table, where the random interpolation coefficient table includes multiple interpolation coefficients arranged in ascending order of magnitude;
[0115] S52. Calculate corresponding interpolation samples according to each interpolation coefficient, the real traffic sample, and the forged traffic sample, where the calculation formula is:
[0116] C(YB) i = α i *Z(Y)+(1 - α i )W(Y);
[0117] Wherein, C(YB) i represents the i-th interpolation sample, α i represents the i-th interpolation coefficient, i represents the serial number of the interpolation coefficient, Z(Y) represents the true flow sample, and W(Y) represents the forged flow sample;
[0118] S53. Obtain the interpolation expected value according to the mean value of the multiple interpolation samples;
[0119] S54. Input each of the interpolation samples into the discriminator to obtain the corresponding interpolation output, and obtain the gradient of each interpolation output with respect to the corresponding interpolation sample;
[0120] S55. Calculate the L2 norm of each of the gradients to obtain the sum of the squared gradients;
[0121] S56. Calculate the gradient penalty term according to the interpolation expected value and the multiple sums of the squared gradients, and the calculation formula is:
[0122]
[0123] Wherein, T(C) represents the gradient penalty term, λ represents the weight parameter of the penalty term, C(Q) represents the interpolation expected value, represents the i-th gradient, D(C(YB) i ) represents the i-th interpolation output, and C(YB) i represents the i-th interpolation sample.
[0124] As described in the above steps S51 - S56, the present invention obtains a random interpolation coefficient table including a plurality of interpolation coefficients arranged in ascending order of magnitude, calculates corresponding interpolation samples according to each interpolation coefficient, the real traffic sample, and the forged traffic sample, obtains the interpolation expected value through the mean value of multiple interpolation samples, inputs each interpolation sample into the discriminator to obtain the corresponding interpolation output, and obtains the gradient of each interpolation output with respect to the corresponding interpolation sample. By calculating the L2 norm of each gradient, the sum of the squared gradients is obtained. Furthermore, according to the interpolation expected value and the sum of the squared gradients of multiple gradients, the gradient penalty term is calculated. By introducing the interpolation coefficient and performing gradient penalty on the generated interpolation samples, the influence of an overly powerful discriminator can be reduced. Specifically, the gradient penalty term (i.e., the calculation of the sum of the squared gradients) can constrain the learning of the discriminator, preventing it from converging too quickly at the local optimum point. Instead, it prompts the generator to gradually improve the sample quality and stabilize the training process. Due to the adversarial nature of the generator and the discriminator, the training process is often unstable. The samples generated by the generator in the initial stage may have low quality, and the model training is likely to stop at the local optimum solution. By normalizing the gradients (calculating the L2 norm), the gradient penalty can make the training process of the discriminator smoother, thus prompting the generator to explore in a wider sample space and finally generate more real and high-quality traffic examples. This method increases the continuity and consistency of the quality of the samples output by the generator, avoids the fierce competition caused by an overly powerful discriminator, and reduces the instability in training. The calculation of the interpolation expected value and the introduction of the gradient penalty term help to prevent the generator from converging to a single mode, increasing the diversity of the generated samples. During the adversarial training process, an overly powerful discriminator may cause the generator to be fixed too early on a certain fixed mode, resulting in insufficient sample diversity. By processing the mean value of the interpolation samples and smoothing the output of the generator by the gradient penalty, the generator can better learn various possible sample distributions and improve the diversity of the generated samples. A common problem in adversarial training is slow training speed and poor convergence. Especially when there is an imbalance during the confrontation between the generator and the discriminator, the training may be very slow. By using interpolation samples and the gradient penalty term, the learning efficiency of the generator can be effectively improved, avoiding the overlearning of the discriminator and the overly slow optimization of the generator. This can accelerate the overall training process and improve the convergence speed. The gradient penalty term not only helps to counteract the over-optimization of a strong discriminator but also regularizes the training process of the discriminator, thereby preventing it from being overly sensitive to certain minor differences. By calculating the L2 norm of the gradients of multiple interpolation samples, the penalty term constrains the change of the gradients, making the discriminator not respond too violently when facing the generated samples, thus helping the generator to generate high-quality and diverse samples more stably and improving the training efficiency and convergence speed of the entire model, enabling the generator to better generate high-quality traffic samples close to the real samples.
[0125] In one embodiment, step S6 of obtaining the total loss according to the forged traffic sample, adversarial traffic sample, and real traffic sample includes:
[0126] S61. Obtain the expected value of the forged sample according to the forged traffic sample, and obtain the loss of the forged sample according to the expected value of the forged sample;
[0127] S61. Perform adversarial training on the forged adversarial traffic sample to obtain an adversarial traffic sample;
[0128] S63. Obtain the expected value of the adversarial sample according to the adversarial traffic sample, and obtain the expected value of the real sample according to the real traffic sample;
[0129] S64. Obtain the loss of the adversarial sample according to the expected value of the adversarial sample, and obtain the loss of the real sample according to the expected value of the real sample;
[0130] S65. Calculate the total loss according to the gradient penalty term, real sample loss, forged sample loss, and adversarial sample loss, where the calculation formula is:
[0131] Z(S) = Z(Y) + W(Y) + D(Y) + T(C);
[0132] Among them, Z(S) represents the total loss, Z(Y) represents the real sample loss, W(Y) represents the forged sample loss, D(Y) represents the adversarial sample loss, and T(C) represents the gradient penalty term.
[0133] As described in the above steps S61 - S65, the present invention obtains the forged sample expected value by forging traffic samples, obtains the forged sample loss based on the forged sample expected value, obtains the adversarial traffic samples through adversarial training on the forged adversarial traffic samples, obtains the adversarial sample expected value from the adversarial traffic samples, obtains the adversarial sample loss according to the adversarial sample expected value, obtains the real sample expected value from the real traffic samples, obtains the real sample loss according to the real sample expected value, and calculates the total loss through the gradient penalty term, real sample loss, forged sample loss, and adversarial sample loss. Traditional adversarial sample generation methods, especially in the scenarios of network attack detection and defense, often ignore the characteristics of the original malicious traffic, resulting in the generated adversarial samples being difficult to reflect the true characteristics of attack behaviors in the real environment. By introducing the calculation of the expected values of forged traffic samples and real traffic samples, it is ensured that the generated adversarial traffic samples can better match the distribution of the original malicious traffic, thereby improving the authenticity of the generated traffic and the fidelity to attack behaviors. Through the calculation of the forged sample expected value, the distribution of attack traffic can be effectively simulated, making the generated adversarial samples more representative and practical. The adversarial sample expected value obtained through adversarial training enables the adversarial samples to not only confront the detection system but also simulate real attack behaviors. Combining with the expected value of real traffic samples ensures that the generated traffic samples conform to the malicious traffic distribution in the real scenario. By simultaneously optimizing the loss functions of forged samples, adversarial samples, and real samples, the generated adversarial samples can be made more generalizable and robust. Traditional adversarial training often focuses on "deceiving" the detection system while ignoring the relationship between the generated samples and actual attack behaviors, which may lead to the generated samples being ineffective in the actual environment. The optimization method combining the gradient penalty term and multi - sample loss functions enables the training model to generate adversarial samples that not only meet the attack objectives but also have high practical significance. Through the generation of adversarial traffic samples, the intrusion detection system or malicious traffic detection system can be effectively trained to improve its ability to cope with real - world attacks. The generated adversarial samples can not only confront the detection system but also simulate various attack strategies, enabling the system to identify and prevent different types of attack behaviors. By combining the losses of adversarial traffic samples, forged samples, and real samples, the detection system can be trained more meticulously, making it have a higher recognition rate and robustness for different types of attack samples. Generating adversarial samples with real malicious behavior characteristics can help researchers better understand the attack methods of attackers, identify potential vulnerabilities, and design more effective defense strategies. Through the combined training of multiple samples, more diverse attack scenarios can be simulated, improving the adaptability and flexibility of attack detection and defense models. The training method combining forged samples, real samples, and adversarial samples can provide richer training data and enhance the training quality of the model. Different types of samples provide diverse attack manifestations and traffic characteristics, and the model can learn the details of different types of attacks from them.Furthermore, it can improve the recognition ability of the detection system for complex attack patterns. The gradient penalty term can effectively prevent overfitting or poor generation quality problems during the training process by constraining the gradient of the generation model. Gradient penalty can enhance the stability of the generation model, ensuring that the generated adversarial samples can not only successfully "deceive" the detection system, but also maintain the original features of malicious traffic, thus ensuring its effectiveness in the real environment.
[0134] In one embodiment, the step S63 of obtaining the adversarial sample loss according to the adversarial sample expected value and obtaining the real sample loss according to the real sample expected value includes:
[0135] S631. Obtain an adversarial traffic sample, and input the adversarial traffic sample into a discriminator to obtain the real probability of the adversarial sample;
[0136] S632. Calculate the adversarial sample loss according to the adversarial sample expected value and the real probability of the adversarial sample, where the calculation formula is:
[0137] D(Y) = D(QW) * [log(1 - D(YG))];
[0138] where D(Y) represents the adversarial sample loss, D(QW) represents the adversarial sample expected value, and D(YG) represents the real probability of the adversarial sample;
[0139] S633. Obtain a real traffic sample, and input the real traffic sample into a discriminator to obtain the real probability of the real sample;
[0140] S634. Calculate the real sample loss according to the real sample expected value and the real probability of the real sample, where the calculation formula is:
[0141] Z(Y) = Z(QW) * logZ(YG);
[0142] where Z(Y) represents the real sample loss, Z(QW) represents the real sample expected value, and Z(YG) represents the real probability of the real sample.
[0143] As described in the above steps S631 - S634, the present invention obtains the true probability of the adversarial sample by inputting the adversarial traffic sample into the discriminator, calculates the adversarial sample loss based on the expected value of the adversarial sample and the true probability of the adversarial sample, obtains the true probability of the real sample by inputting the real traffic sample into the discriminator, and calculates the real sample loss based on the expected value of the real sample and the true probability of the real sample. By inputting the adversarial traffic sample into the discriminator and calculating its true probability, combined with the expected value of the adversarial sample, the difference between the generated sample and the real malicious traffic can be effectively controlled. This method focuses on the generated sample being able to more realistically reflect the original attack behavior, thus maintaining the characteristics and dynamics of the original malicious behavior. By introducing the true probability and expected value of the real sample, the discriminator can more accurately evaluate the quality of the generated sample, which helps to improve the effectiveness and adaptability of the generated adversarial sample, thereby enhancing the aggressiveness and usability of the adversarial sample. This means that the generated adversarial sample is more aggressive and can pose sufficient challenges to the real detection system, and further helps the detection mechanism better cope with new attack means. If the generated adversarial sample can better retain the characteristics of the original malicious behavior, it can better match the attack strategy, network traffic characteristics and other complex factors in the real environment. This means that researchers can use this adversarial sample to better evaluate the effectiveness of existing defense strategies, especially in complex and dynamic actual network environments. By combining the expected value of the real sample and the true probability of the generated sample, the adversarial sample is made to more conform to the distribution of real attack traffic, thus providing more realistic test data for the research of the detection mechanism. This plays an important role in improving the accuracy of network security protection, reducing the false alarm rate, and enhancing the adaptability of the detection system to new attacks. Using the discriminator to evaluate the sample can serve as an important feedback signal in the training of a generation model (such as Generative Adversarial Networks GANs, etc.). The loss calculation of the adversarial sample and the real sample not only helps to improve the generation quality of the generator, but also helps to improve the discrimination ability of the discriminator, thereby making the generation process more robust and enhancing the generation effect of the adversarial sample in complex environments. The key advantage of this method is that it makes the application of the adversarial sample in the real environment more effective by enhancing the authenticity and fidelity of the adversarial sample. The generated adversarial sample can not only better reflect the characteristics of the original malicious traffic, but also provide more representative and challenging test samples for the research of the detection mechanism and the optimization of network security defense.
[0144] In one embodiment, for the problem of slow convergence rate in generative adversarial training, the main reason is that non-robust distortions tend to move all samples close to the decision boundary. Therefore, even a tiny distortion can move adversarial examples to the decision boundary and lead to misclassification. In contrast, for a robust discriminator, such distortions are expected to be much larger. Based on this, it is proposed to introduce adversarial attacks to make the discriminator more robust, thereby improving the convergence rate and stability in the gradient penalty training process. The PGD (Projected Gradient Descent) projected gradient descent adversarial attack method is selected as the adversarial attack method for the robust training of our discriminator. The principle formula of the PGD attack is as follows:
[0145]
[0146] where x t+1 represents the next traffic sample, and x t represents the current traffic sample. Π x+S is a projection operation used to ensure that the perturbation range of the adversarial sample does not exceed the limit. α is used to control the size of the perturbation in each iteration, and sgn(·) determines the direction of the perturbation. is the gradient of the loss function L(θ, x, y) with respect to the input x. Since PGD is an iterative attack method that generates stronger adversarial samples through multiple gradient updates and projection operations, compared to other methods, PGD can generate stronger perturbations, making the generated adversarial samples more challenging. Therefore, it can effectively test the robustness of the discriminator when facing strong adversarial samples, enabling the discriminator to adapt to stronger adversarial attacks during training and enhancing its robustness. The iterative process of PGD simulates more realistic adversarial attack behaviors, and PGD approximates the optimization objective through multiple update steps, making the adversarial samples it generates more representative and closer to the strategies adopted by adversaries in reality. This step-by-step optimization feature can also enable the model to withstand various attacks of different intensities during training and improve the defense ability of the discriminator. One of the core features of PGD is that it can limit the generated adversarial samples within a predefined constraint space through projection operations. In this way, PGD can generate legal adversarial perturbations and approximate the decision boundary of the model without destroying the original structure of the samples, making PGD an ideal tool in adversarial training because it can help the model maintain strong robustness within a certain perturbation range. By repeatedly updating the adversarial samples, PGD can better capture the vulnerabilities of the network. Compared to other attack methods, PGD is a gradient-based multi-step attack, and each step adjusts the direction and magnitude of the perturbation, making the finally generated adversarial samples better able to force the discriminator to misclassify. This iterative update process can more effectively find the weak points of the model and improve the effect of adversarial training, thereby enhancing robustness. Since PGD is a gradient-based iterative optimization method, the adversarial samples it generates not only depend on the choice of the initial perturbation but can also explore more perturbation spaces through multiple iterations. This diverse perturbation space can help the model better generalize and adapt to different types of adversarial samples, thus improving its robustness in actual deployment.
[0147] This application also provides an adversarial traffic example generation system, including:
[0148] A first acquisition module for acquiring a random noise vector and a real traffic sample and extracting important attack feature data of the real traffic sample;
[0149] An input module for inputting the random noise vector into a generator to obtain normal traffic feature data;
[0150] A splicing module for splicing and fusing the normal traffic feature data and the important attack feature data to obtain a forged traffic sample;
[0151] A training module for performing adversarial training on the forged adversarial traffic sample to obtain an adversarial traffic sample;
[0152] A second acquisition module, configured to obtain a gradient penalty term according to the real traffic sample and the forged traffic sample;
[0153] A third acquisition module, configured to obtain a total loss according to the forged traffic sample, the adversarial traffic sample, and the real traffic sample;
[0154] A judgment module, configured to judge whether the total loss is greater than a preset loss;
[0155] If the total loss is greater than the preset loss, it is determined that the forged traffic sample is real traffic;
[0156] If the total loss is not greater than the preset loss, return to the step of inputting the random noise vector into the generator to obtain normal traffic feature data until the total loss is greater than the preset loss.
[0157] In one embodiment, the first acquisition module includes:
[0158] A first acquisition unit, configured to acquire all traffic features of the network traffic and obtain multiple attack features according to all the traffic features;
[0159] A second acquisition unit, configured to obtain a corresponding predicted marginal contribution according to each of the attack features and all traffic features;
[0160] A partitioning unit, configured to evenly partition all traffic features into multiple traffic sample subsets and obtain a corresponding average marginal contribution according to each of the attack features and the traffic sample subsets;
[0161] A third acquisition unit, configured to obtain a weight value of each attack feature according to multiple average marginal contributions and predicted marginal contributions;
[0162] A sorting unit, configured to sort multiple weight values in descending order to obtain a weight sorting table;
[0163] A splitting unit, configured to set a splitting value and split the weight values in the weight sorting table that are greater than the splitting value to obtain an important weight value table;
[0164] A marking unit, configured to mark the attack features corresponding to each weight value in the important weight value table as important attack features.
[0165] It should be noted that each module and unit in the adversarial traffic example generation system corresponds one-to-one to the steps in the adversarial traffic example generation method.
[0166] As Figure 3 shown, the present application also provides a computer device, which may be a server, and its internal structure may be as Figure 3As shown in the figure. The computer device includes a processor, a memory, a network interface, and a database connected via a system bus. Among them, the processor of the computer design is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store all the data required for the process of the adversarial traffic example generation method. The network interface of the computer device is used to communicate with an external terminal via a network connection. The computer program, when executed by the processor, implements the adversarial traffic example generation method.
[0167] Those skilled in the art can understand that Figure 3 the structure shown in the figure is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied.
[0168] An embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements any one of the above adversarial traffic example generation methods.
[0169] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium provided in the present application and used in the embodiments can include non-volatile and / or volatile memories. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or an external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (SSRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0170] It should be noted that in this text, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, such that a process, apparatus, article or method comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, apparatus, article or method. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, apparatus, article or method comprising such element.
[0171] The above are only the preferred embodiments of this application, and do not limit the patent scope of this application accordingly. Any equivalent structural or equivalent process transformation made by using the content of the specification and drawings of this application, or directly or indirectly applied in other related technical fields, shall be similarly included within the patent protection scope of this application.
[0172] It should be noted that in this text, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, such that a process, apparatus, article or method comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, apparatus, article or method. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, apparatus, article or method comprising such element.
[0173] The above are only the preferred embodiments of this invention, and do not limit the patent scope of this invention accordingly. Any equivalent structural or equivalent process transformation made by using the content of the specification and drawings of this invention, or directly or indirectly applied in other related technical fields, shall be similarly included within the patent protection scope of this invention.
Claims
1. A method for generating adversarial traffic examples, characterized in that: include: Obtaining a random noise vector and a real traffic sample, and extracting important attack features of the real traffic sample; Inputting the random noise vector into a generator to obtain normal traffic characteristic data; The normal traffic feature data and the important attack features are combined to obtain a forged traffic sample; Performing adversarial training on the forged traffic sample to obtain an adversarial traffic sample; Acquire a random interpolation coefficient table, wherein the random interpolation coefficient table includes a plurality of interpolation coefficients arranged in order of magnitude; The corresponding interpolation sample is calculated according to each of the interpolation coefficients, the real traffic sample and the forged traffic sample, wherein the calculation formula is: ; Among them, C(YB) i represents the i-th interpolation sample, α i represents the i-th interpolation coefficient, i represents the serial number of the interpolation coefficient, Z(Y) represents the real traffic sample, and W(Y) represents the forged traffic sample; Obtaining an interpolation expected value according to the average of a plurality of the interpolation samples; Input each of the interpolation samples into the discriminator to obtain a corresponding interpolation output, and obtain the gradient of each of the interpolation outputs relative to the corresponding interpolation sample; Calculate the L2 norm of each gradient to obtain the sum of squared gradients; The gradient penalty term is calculated according to the interpolation expected value and multiple gradient square sums, wherein the calculation formula is: ; Among them, T(C) represents the gradient penalty term, λ represents the weight parameter of the penalty term, C(Q) represents the interpolation expected value, represents the i-th gradient, D(C(YB) i ) represents the i-th interpolation output, C(YB) i represents the i-th interpolation sample; Obtaining a total loss according to the forged traffic sample, the adversarial traffic sample, and the real traffic sample, and determining whether the total loss is greater than a preset loss; If the total loss is greater than the preset loss, the forged traffic sample is determined to be real traffic; If the total loss is not greater than the preset loss, the process returns to the step of inputting the random noise vector into the generator to obtain normal flow characteristic data until the total loss is greater than the preset loss.
2. The method for generating adversarial traffic examples according to claim 1, characterized in that: The step of extracting important attack features of the real traffic sample includes: Acquire all traffic features of the real traffic sample, and acquire multiple attack features based on all traffic features; Obtaining a corresponding predicted marginal contribution according to each of the attack features and all traffic features; Dividing all traffic features evenly into multiple traffic sample subsets, and obtaining a corresponding average marginal contribution according to each of the attack features and traffic sample subsets; Obtaining a weight value of each attack feature according to the plurality of average marginal contributions and predicted marginal contributions; Sorting the plurality of weight values in order of magnitude to obtain a weight sorting table; Setting a split value, and splitting the weight values in the weight ranking table that are greater than the split value, to obtain an important weight value table; The attack feature corresponding to each weight value in the important weight value table is marked as an important attack feature.
3. The method for generating adversarial traffic examples according to claim 2, characterized in that: The step of obtaining the corresponding average marginal contribution according to each of the attack features and the traffic sample subset comprises: Inputting each of the traffic sample subsets into a gradient boosting model to obtain a first prediction value; Replacing the characteristic data in each of the traffic sample subsets with each of the attack characteristics to obtain a replaced traffic sample; Input each replacement traffic sample into the gradient boosting model to obtain a second prediction value; Obtaining a corresponding marginal contribution according to each of the second predicted value and the first predicted value; The average marginal contribution is calculated based on the plurality of marginal contributions, wherein the calculation formula is: ; Among them, P(G) k represents the kth average marginal contribution, J(B) k represents the kth marginal contribution, k represents the ordinal number of the marginal contribution, and N represents the number of marginal contributions.
4. The method for generating adversarial traffic examples according to claim 1, characterized in that: The step of obtaining the total loss according to the forged traffic sample, the adversarial traffic sample and the real traffic sample comprises: Obtaining a forged sample expected value according to the forged traffic sample, and obtaining a forged sample loss according to the forged sample expected value; Performing adversarial training on the forged traffic sample to obtain an adversarial traffic sample; Acquire an adversarial sample expected value according to the adversarial traffic sample, and acquire a real sample expected value according to the real traffic sample; Obtaining adversarial sample loss according to the adversarial sample expected value, and obtaining real sample loss according to the real sample expected value; The total loss is obtained according to the gradient penalty term, the real sample loss, the forged sample loss and the adversarial sample loss.
5. The method for generating adversarial traffic examples according to claim 4, characterized in that: The step of obtaining the adversarial sample loss according to the adversarial sample expected value and obtaining the real sample loss according to the real sample expected value comprises: Obtain an adversarial traffic sample, and input the adversarial traffic sample into the discriminator to obtain the true probability of the adversarial sample; The adversarial sample loss is calculated according to the adversarial sample expected value and the adversarial sample true probability, wherein the calculation formula is: ; Among them, D(Y) represents the adversarial sample loss, D(QW) represents the expected value of the adversarial sample, and D(YG) represents the true probability of the adversarial sample; Obtain a real traffic sample, and input the real traffic sample into the discriminator to obtain a real probability of the real sample; The real sample loss is calculated according to the real sample expected value and the real sample true probability, wherein the calculation formula is: ; Among them, Z(Y) represents the true sample loss, Z(QW) represents the true sample expected value, and Z(YG) represents the true probability of the true sample.
6. A system for generating adversarial traffic examples, characterized in that: include: A first acquisition module is used to acquire a random noise vector and a real traffic sample, and extract important attack features of the real traffic sample; An input module, used for inputting the random noise vector into a generator to obtain normal traffic characteristic data; A splicing module, used for splicing and fusing the normal traffic feature data and the important attack features to obtain a forged traffic sample; A training module, used for performing adversarial training on the forged traffic sample to obtain an adversarial traffic sample; A second acquisition module is used to acquire a random interpolation coefficient table, wherein the random interpolation coefficient table includes a plurality of interpolation coefficients arranged in order of magnitude; The corresponding interpolation sample is calculated according to each of the interpolation coefficients, the real traffic sample and the forged traffic sample, wherein the calculation formula is: ; Among them, C(YB) i represents the i-th interpolation sample, α i represents the i-th interpolation coefficient, i represents the serial number of the interpolation coefficient, Z(Y) represents the real traffic sample, and W(Y) represents the forged traffic sample; Obtaining an interpolation expected value according to the average of a plurality of the interpolation samples; Input each of the interpolation samples into the discriminator to obtain a corresponding interpolation output, and obtain the gradient of each of the interpolation outputs relative to the corresponding interpolation sample; Calculate the L2 norm of each gradient to obtain the sum of squared gradients; The gradient penalty term is calculated according to the interpolation expected value and multiple gradient square sums, wherein the calculation formula is: ; Among them, T(C) represents the gradient penalty term, λ represents the weight parameter of the penalty term, C(Q) represents the interpolation expected value, represents the i-th gradient, D(C(YB) i ) represents the i-th interpolation output, C(YB) i represents the i-th interpolation sample; A third acquisition module is used to obtain a total loss according to the forged traffic sample, the adversarial traffic sample and the real traffic sample; A judgment module, used to judge whether the total loss is greater than a preset loss; If the total loss is greater than the preset loss, the forged traffic sample is determined to be real traffic; If the total loss is not greater than the preset loss, the process returns to the step of inputting the random noise vector into the generator to obtain normal flow characteristic data until the total loss is greater than the preset loss.
7. The adversarial traffic example generation system according to claim 6, characterized in that: The first acquisition module includes: A first acquisition unit, configured to acquire all traffic features of the real traffic sample, and acquire multiple attack features according to all the traffic features; A second acquisition unit, configured to acquire a corresponding predicted marginal contribution according to each of the attack features and all traffic features; A division unit, used to divide all traffic features into multiple traffic sample subsets on average, and obtain a corresponding average marginal contribution according to each of the attack features and traffic sample subsets; A third acquisition unit, configured to acquire a weight value of each attack feature according to the plurality of average marginal contributions and predicted marginal contributions; A sorting unit, used to sort the plurality of weight values in order of magnitude to obtain a weight sorting table; A segmentation unit, used for setting a segmentation value, and segmenting the weight values in the weight ranking table that are greater than the segmentation value to obtain an important weight value table; The marking unit is used to mark the attack feature corresponding to each weight value in the important weight value table as an important attack feature.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 5 are implemented.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
Adversarial sample generation method based on content-aware GAN
CN111881935A
Anti-attack sample generation method
CN118337526A