A Method, System, Device and Medium for Predicting Power 5G Network Traffic Attacks
By weighting One-hot encoding standardized processing of multi-dimensional traffic data of power 5G networks, and feature extraction is performed in combination with multi-scale convolutional neural networks and long-term memory networks of attention mechanisms, and high-order modeling is used for advanced modeling, the problem of low prediction accuracy in the existing technology is solved, and higher prediction accuracy and generalization capabilities are achieved.
Patent Information
- Application Number
- CN202510387709.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2045-03-31
AI Technical Summary
In the prior art, deep learning network models are used to predict abnormalities in 5G networks, but the model construction process is complex and the computing resources are high, resulting in low prediction accuracy.
Weighted One-hot encoding is used to standardize multi-dimensional traffic data, combine multi-scale convolutional neural networks and long-term memory networks with attention mechanisms for feature extraction, use the improved deep neural network model for advanced modeling, and use the activation function to predict traffic attacks.
It improves the prediction accuracy of power 5G network traffic attacks, enhances the model's ability to identify and generalize complex network attack behaviors, and reduces the risk of overfitting.
Smart Images

Figure CN119907003B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information technology, and in particular to a method, system, device and medium for predicting power 5G network traffic attacks. Background Art
[0002] At present, 5G networks have been widely used in the power industry due to their technical advantages such as high bandwidth and low latency. However, due to the openness of the channel and the diversity of users, they face multiple security risks. Therefore, the abnormal prediction of 5G networks has become increasingly important.
[0003] In the prior art, deep learning network models are usually used to predict the anomalies of 5G networks. However, the process of building the model is complex, and the demand for computing resources is relatively high, which limits its practical application to a certain extent and results in a low prediction accuracy.
[0004] It can be seen that how to improve the prediction accuracy of power 5G network traffic attacks has become a technical problem that needs to be urgently solved by those skilled in the art. Summary of the Invention
[0005] The present invention provides a method, system, device and medium for predicting power 5G network traffic attacks, and solves the problem of how to improve the prediction accuracy of power 5G network traffic attacks.
[0006] To solve the above technical problem, in the first aspect of the present invention, a method for predicting power 5G network traffic attacks is provided, including:
[0007] Obtain multi-dimensional traffic data of the power 5G network, and perform standardization processing on the multi-dimensional traffic data through weighted One-hot encoding to obtain a standardized traffic matrix;
[0008] Based on a multi-scale convolutional neural network model and a long short-term memory network model introducing an attention mechanism, extract features from the standardized traffic matrix to obtain comprehensive traffic features;
[0009] Process the comprehensive traffic features according to the improved deep neural network model to obtain high-dimensional traffic features; the improved deep neural network model is a deep neural network integrating a residual network and adaptive dynamic Dropout;
[0010] Perform probability mapping on the high-dimensional traffic features through an activation function to obtain a prediction result of the traffic attack on the power 5G network.
[0011] As a preferred solution, the performing standardization processing on the multi-dimensional traffic data through weighted One-hot encoding to obtain a standardized traffic matrix includes:
[0012] Encode the multi-dimensional traffic data to obtain an encoded traffic matrix, and use a standardization model based on mean absolute deviation to standardize the encoded traffic matrix to obtain a standard encoded traffic matrix;
[0013] Encode the standard encoded traffic matrix through the weighted One-hot encoding to obtain a standardized traffic matrix.
[0014] As one of the preferred solutions, the standardization model is represented by the following formula:
[0015]
[0016]
[0017]
[0018] In the formula, and are the values of the i-th feature before and after standardization in the j-th record of the standard encoded traffic matrix, respectively; is the mean of the i-th feature; is the mean absolute deviation of the i-th feature; n is the total number of features;
[0019] The weighted One-hot encoding is represented by the following formula:
[0020]
[0021]
[0022]
[0023]
[0024] In the formula, Y is the weighted One-hot encoding matrix; is the weight corresponding to the i-th attack type; and are the weight adjustment factors; is the frequency of the i-th attack type in the historical multi-dimensional traffic data; and are the new and old severities of the i-th attack type, respectively; is the learning rate; is the real-time impact evaluation value of the i-th attack type.
[0025] As one of the preferred solutions, use the multi-scale convolutional neural network model and the long short-term memory network model with attention mechanism to extract features from the standardized traffic matrix to obtain comprehensive traffic features, including:
[0026] Feature extraction is performed on the standardized traffic matrix through the convolutional kernels of the multi-scale convolutional neural network model to obtain key features, and the key features are processed through an activation function, and global average pooling operation is used to reduce the dimension of the processing result to generate a preliminary feature matrix;
[0027] A long short-term memory network model with attention weights introduced is used to perform time series modeling on the preliminary feature matrix to obtain a time series feature matrix;
[0028] The preliminary feature matrix and the time series feature matrix are concatenated and fused to obtain a comprehensive traffic feature.
[0029] As one of the preferred solutions, the improved deep neural network model includes a first fully connected layer, a second fully connected layer, a third fully connected layer, a residual layer, a first hidden layer, a second hidden layer, and a third hidden layer; among them,
[0030] Processing the comprehensive traffic feature according to the improved deep neural network model to obtain a high-dimensional traffic feature, including:
[0031] Taking the comprehensive traffic feature as the input feature, after being connected by the residual layer, the comprehensive traffic feature is weighted calculated and mapped through the first fully connected layer to obtain the first layer feature to apply adaptive dynamic Dropout, generate the first traffic feature and output it through the first hidden layer;
[0032] Taking the first traffic feature as the input feature, after being connected by the residual layer, the first traffic feature is weighted calculated and mapped through the second fully connected layer to obtain the second layer feature to apply adaptive dynamic Dropout, generate the second traffic feature and output it through the second hidden layer;
[0033] Taking the second traffic feature as the input feature, after being connected by the residual layer, the second traffic feature is weighted calculated and mapped through the third fully connected layer to obtain the third layer feature to apply adaptive dynamic Dropout, generate the high-dimensional traffic feature and output it through the third hidden layer.
[0034] As one of the preferred solutions, the output results of each hidden layer are represented by the following formula:
[0035]
[0036]
[0037]
[0038] In the formula, is the output feature of the u-th hidden layer; is a random mask matrix; is the feature of the u-th layer; is the output probability of the u-th fully connected layer; a1 and a2 are hyperparameters; 、 are the overfitting prevention feature probability and the sparse prevention feature probability of the u-th fully connected layer respectively; is the weight gradient of the u-th fully connected layer; Var() is the variance of the gradient change; Mean() is the gradient mean; is the smoothing factor; is the i-th feature of the u-th fully connected layer; is the indicator function; N is the total number of features.
[0039] As one of the preferred solutions, the probability mapping of the high-dimensional traffic feature by the activation function to obtain the traffic attack prediction result for the power 5G network includes:
[0040] Using the Softmax function to perform probability mapping on the high-dimensional traffic feature to obtain the classification probability;
[0041] Comparing the preset classification threshold with the classification probability, and determining the traffic attack prediction result for the power 5G network according to the comparison result;
[0042] Among them, the preset classification threshold is represented by the following formula:
[0043]
[0044] In the formula, K is the preset classification threshold; E is the classification weight factor; Precision and Recall are the first and second prediction accuracies respectively.
[0045] The second aspect of the present invention provides a power 5G network traffic attack prediction system, including:
[0046] A data preprocessing module, configured to obtain multi-dimensional traffic data of the power 5G network, and perform standardization processing on the multi-dimensional traffic data through weighted One-hot encoding to obtain a standardized traffic matrix;
[0047] A feature extraction module, configured to extract features from the standardized traffic matrix based on a multi-scale convolutional neural network model and a long short-term memory network model introducing an attention mechanism to obtain comprehensive traffic features;
[0048] A feature processing module, configured to process the comprehensive traffic features according to the improved deep neural network model to obtain high-dimensional traffic features; the improved deep neural network model is a deep neural network integrating a residual network and adaptive dynamic Dropout;
[0049] A classification prediction module, configured to perform probability mapping on the high-dimensional traffic features through an activation function to obtain a prediction result of traffic attacks on the power 5G network.
[0050] A third aspect of the present invention provides an electronic device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, the power 5G network traffic attack prediction method as described above is implemented.
[0051] A fourth aspect of the present invention provides a computer-readable storage medium. The computer-readable storage medium includes a stored computer program. When the device where the computer-readable storage medium is located executes the computer program, the power 5G network traffic attack prediction method as described above is implemented.
[0052] Compared with the prior art, the beneficial effects of the embodiments of the present invention are at least one of the following:
[0053] (1) By fully collecting multi-dimensional traffic data of the power 5G network, adopting data preprocessing techniques based on standardization and normalization to improve the quality and consistency of the original data. At the same time, combining the weighted One-hot encoding technique to convert various types of network attack behaviors in the original data into vector expressions, which improves the model's attention to different attack types and avoids rare attacks being ignored, providing efficient data support for subsequent feature extraction and classification models;
[0054] (2) Utilizing the characteristics of a multi-scale convolutional neural network model and a long short-term memory network model with an attention mechanism jointly for feature extraction, which improves the model's recognition accuracy of complex network attack behaviors and generalization ability and robustness in time series scenarios;
[0055] (3) Through a deep neural network that combines a residual network and adaptive dynamic Dropout for high-order modeling of the extracted feature data, using a multi-layer structure to gradually capture complex relationships in the data, introducing an adaptive dynamic Dropout mechanism between each hidden layer to randomly mask some neurons, reducing the model's over-reliance on a single feature, thereby reducing the risk of overfitting. Combining with an activation function, smoothing the data distribution, optimizing the classification ability for multiple types of attack behaviors, and improving the generalization effect for unknown attacks;
[0056] (4) Mapping high-dimensional features to classification probabilities through the classification mechanism of the activation function, thereby improving the accurate prediction of traffic attack behaviors on the power 5G network. Description of the Drawings
[0057] To more clearly illustrate the technical solutions of the present invention, the accompanying drawings required for the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.
[0058] Figure 1 is a flowchart of a method for predicting power 5G network traffic attacks provided by an embodiment of the present invention;
[0059] Figure 2 is a flowchart of feature extraction in step S2 provided by an embodiment of the present invention;
[0060] Figure 3 is a flowchart of feature processing in step S3 provided by an embodiment of the present invention;
[0061] Figure 4 is a structural diagram of a power 5G network traffic attack prediction system provided by an embodiment of the present invention;
[0062] Figure 5 is a structural diagram of an electronic device provided by an embodiment of the present invention. Detailed Embodiments
[0063] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings and embodiments. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of them. The purpose of providing these embodiments is to make the disclosure of the present invention more thorough and comprehensive. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.
[0064] In the description of this application, the terms "first", "second", "third", etc. are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first", "second", "third", etc. may explicitly or implicitly include one or more of such features. In the description of this application, unless otherwise stated, the meaning of "a plurality" is two or more.
[0065] In the description of the present application, it should be noted that, unless otherwise clearly specified and defined, the terms "installed", "connected", and "connected" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected, or indirectly connected through an intermediate medium, and it can be the communication inside two components. The terms "vertical", "horizontal", "left", "right", "upper", "lower" and similar expressions used herein are only for the purpose of illustration, rather than indicating or implying that the system or component referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation of the present invention. The term "and / or" used herein includes any and all combinations of one or more of the related listed items. For those of ordinary skill in the art, the specific meanings of the above terms in the present application can be understood according to specific circumstances.
[0066] In the description of the present application, it should be noted that, unless otherwise defined, all technical and scientific terms used in the present invention have the same meanings as those commonly understood by those skilled in the technical field to which the present invention belongs. The terms used in the specification of the present invention are only for the purpose of describing specific embodiments, and are not intended to limit the present invention. For those of ordinary skill in the art, the specific meanings of the above terms in the present application can be understood according to specific circumstances.
[0067] In one embodiment, as Figure 1 shown, the first aspect of the present invention provides a method for predicting power 5G network traffic attacks, including:
[0068] S1. Obtain multi-dimensional traffic data of the power 5G network, and perform normalization processing on the multi-dimensional traffic data through weighted One-hot encoding to obtain a normalized traffic matrix;
[0069] S2. Based on a multi-scale convolutional neural network model and a long short-term memory network model with an attention mechanism, extract features from the normalized traffic matrix to obtain comprehensive traffic features;
[0070] S3. Process the comprehensive traffic features according to the improved deep neural network model to obtain high-dimensional traffic features; the improved deep neural network model is a deep neural network that integrates a residual network and adaptive dynamic Dropout;
[0071] S4. Perform probability mapping on the high-dimensional traffic features through an activation function to obtain a prediction result of the traffic attack on the power 5G network.
[0072] The present invention collects multi-dimensional traffic data in real time from various base stations, user equipment and other sources of the power 5G network, such as traffic volume and direction, timestamp and time interval, location information, user identity, type and quality of services, network load and quality, security events and traffic characteristics, etc., from multiple dimensions to comprehensively reflect the situation of network traffic, and cleans and transforms these multi-dimensional traffic data, removes duplicate and invalid data items, standardizes the data format and data item definition, and performs standardization processing on the multi-dimensional traffic data using weighted One-hot encoding; among them, the weighted One-hot encoding is based on the traditional One-hot encoding, and different weights are assigned according to the severity and real-time impact assessment of the attack data in each dimension, so as to obtain a standardized traffic matrix, so as to solve the problem that the traditional collection method has significant deficiencies in data consistency and analysis performance due to the diverse and inconsistent original data formats, and the presence of noise data and unrecognizable fields.
[0073] Then, based on the multi-scale convolutional neural network model (MSCNN), by constructing multiple parallel convolutional paths, each path using different convolutional kernel sizes and strides, to capture feature information of different scales that can reflect the details and global characteristics of traffic data, and combining with the long short-term memory network model with attention mechanism (Attention-LSTM), through its internal gate mechanism and state update mechanism, which can process long sequence data and capture the long-distance dependencies therein to obtain time features, to obtain comprehensive traffic features to comprehensively reflect the traffic situation of the power 5G network, providing strong support for subsequent attack prediction, and further solving the problem that traditional feature extraction methods are difficult to capture the non-linear features in complex network attack patterns.
[0074] Then, a deep neural network model that combines the residual network (ResNet) and Adaptive Dynamic Dropout (ADD) is used to process the comprehensive traffic features extracted by MSCNN; among them, the residual network helps to alleviate the problem of gradient disappearance in deep neural networks by introducing skip connections; Adaptive Dynamic Dropout can dynamically adjust the Dropout rate according to the data distribution and training process to reduce overfitting; the comprehensive traffic features are input into the improved deep neural network model, and through multi-layer non-linear transformation and feature extraction, high-dimensional traffic features are obtained to more deeply reflect the internal laws and potential risks of traffic data, and further solve the problems that traditional prediction methods rely on rule bases, fixed thresholds or dynamic models, are difficult to adapt to new attacks, are prone to false alarms and missed reports, and have high computational complexity and limited effects.
[0075] Finally, select an appropriate activation function (such as the Softmax function or the Swish function, etc.) to perform probability mapping on the high-dimensional traffic features, and obtain the traffic attack prediction results of the power 5G network. These results can be presented in the form of a probability distribution, which is convenient for subsequent security protection and decision support.
[0076] In one embodiment, the standardizing the multi-dimensional traffic data through weighted One-hot encoding to obtain a standardized traffic matrix includes:
[0077] Performing encoding processing on the multi-dimensional traffic data to obtain an encoded traffic matrix, and using a standardization model based on the mean absolute deviation to perform standardization processing on the encoded traffic matrix to obtain a standard encoded traffic matrix;
[0078] Performing encoding processing on the standard encoded traffic matrix through the weighted One-hot encoding to obtain a standardized traffic matrix.
[0079] Specifically, for the prediction of network attacks, it is necessary to observe feature information such as the type, quantity, and dimension of network attacks. The present invention uses a data preprocessing technology based on standardization in a data collector in the power monitoring network to clean and normalize the collected original network traffic data, eliminate noise data and invalid fields, and output high-quality standardized input data.
[0080] In the data preprocessing stage, non-numerical information needs to be replaced with numerical index values for analysis. After encoding, each attack type will be represented by an integer value, which is convenient for subsequent calculation and classification; among them, the encoded traffic matrix is defined as , where represents the encoding result of the i-th record. In this way, the formatting process of the data is completed. Next, the encoded data is processed using a standardization model based on the mean and mean absolute deviation to eliminate the influence of the dimension between different features, ensure the robustness of the algorithm on the input data, thereby improving the stability of data analysis and the training effect of the model. The standardization model is represented by the following formula:
[0081]
[0082]
[0083]
[0084] In the formula, , are the values of the i-th feature before and after standardization in the j-th record of the standard encoded traffic matrix, respectively; is the mean of the i-th feature; is the mean absolute deviation of the i-th feature; n is the total number of features;
[0085] Compared with the standardization based on standard deviation, the standardization model based on mean absolute deviation is more robust to outliers. At the same time, the standard deviation will be significantly amplified by a few extreme values, while the mean absolute deviation is less affected by extreme values. Therefore, it is more suitable for dealing with the abnormal data that may exist in network traffic.
[0086] After the standardization process is completed, the attack types need to be encoded. For the encoding of attack types, the present invention adopts weighted One-hot encoding, where the weighted One-hot encoding is represented by the following formula:
[0087]
[0088]
[0089]
[0090]
[0091] In the formula, Y is the weighted One-hot encoding matrix; is the weight corresponding to the i-th attack type, and its value can be dynamically generated according to the characteristics of the attack; n is the vector dimension; 、 are weight adjustment factors, used to control the influence ratio of frequency and severity; is the frequency of the i-th attack type in the historical multi-dimensional traffic data; 、 are the new and old severities (such as service interruption impact, economic loss, etc.) of the i-th attack type respectively; is the learning rate; is the real-time impact evaluation value of the i-th attack type.
[0092] The weighted One-hot encoding model can be trained according to historical traffic data. At the same time, when the model is running, it will update the weights according to the actual impact of the attack (such as user feedback, economic loss, etc.). In the data preprocessing stage of the present invention, not only the standardization of the data is completed, but also the importance of the attack types is embedded in the feature vector matrix through dynamic weighted One-hot encoding. To enhance the consistency and analyzability of the data, the standardization operation is completed using the mean and absolute difference, solving the problems that may exist in the original data and cannot be recognized or processed, and providing more accurate input for subsequent feature extraction and classification modeling.
[0093] In one embodiment, step S2 includes:
[0094] Feature extraction is performed on the standardized traffic matrix through the convolution kernels of the multi-scale convolutional neural network model to obtain key features, and the key features are processed through an activation function, and global average pooling operation is used to reduce the dimension of the processing result to generate a preliminary feature matrix;
[0095] The long short-term memory network model with attention weights introduced is used to perform time series modeling on the preliminary feature matrix to obtain a time series feature matrix;
[0096] The preliminary feature matrix and the time series feature matrix are concatenated and fused to obtain comprehensive traffic features.
[0097] Specifically, since the deficiency of the traditional CNN lies in that its convolution kernel has a fixed size, resulting in the ability to capture only single-scale features, it is difficult to balance local and global information, and it is usually limited to shallow feature extraction, with insufficient ability to model non-linear relationships in complex patterns or high-dimensional data, prone to missing potential important features, and lacking the ability to model the context relevance and global dependence between features, being highly sensitive to noise and redundant information in high-dimensional data, resulting in a decline in model performance and poor robustness to interference data. Based on this, in the feature extraction stage of the present invention, a multi-scale convolutional neural network is used to perform feature extraction on the preprocessed data. By introducing convolution kernels of various sizes, multi-scale feature extraction is achieved, which can capture local and global information simultaneously, improve the adaptability to complex patterns, and at the same time, combined with the global average pooling operation, Attention-LSTM is proposed to further enhance the ability of MSCNN to extract time series network traffic features, effectively reducing interference in the data and improving the robustness of the model to interference data. The specific feature extraction process is as Figure 2 shown.
[0098] The input of the multi-scale convolutional neural network is a set of continuous sliding window representations, enabling the standardized traffic matrix to be input into the sliding window. In order to extract local features within the sliding window, convolution kernels are used to perform feature transformation on the input; among them, convolution kernels of various sizes are used to extract local features of different scales. Let the convolution kernel be J c , and the formula for the convolution operation is:
[0099]
[0100] In the formula, is the key feature extracted by the c-th convolution kernel; is the Sigmoid activation function; w is the window size; t is the time; is the bias term of the c-th channel, used to enhance the non-linear expression ability of the feature;
[0101] The output of the convolution operation is non-linearly transformed through the Sigmoid activation function to effectively enhance the network's ability to express complex features and avoid feature loss. All convolution results are concatenated and fused to form a higher-dimensional feature matrix. 。
[0102] Finally, the global average pooling method is adopted for the fused feature matrix F to further extract the most significant features, thereby achieving feature dimensionality reduction and spatial invariance. The formula for global average pooling is as follows:
[0103]
[0104] In the formula, is the global average pooling result of the c-th channel; is the i-th value of the c-th channel of the fused feature matrix, and n is the total number of elements of the feature in this channel.
[0105] The pooling operation selects the maximum value within the local window, retains the most important features, reduces the data complexity, solves the problem of over-reliance on local maxima in max pooling, and enhances information retention, model stability, and spatial invariance.
[0106] After convolution and pooling operations, the preliminary feature matrix P is obtained. Based on the MSCNN architecture, the present invention proposes an Attention-LSTM unit to perform time series modeling on the pooled preliminary feature matrix to further enhance the ability to capture context relevance and non-linear relationships in dynamic network traffic features. The input of the traditional LSTM is P, and the output is the feature representation after time series modeling :
[0107]
[0108] In the formula, 、 、 are the input gate, forget gate, and output gate respectively; is the memory unit; is the hidden state of the LSTM (the final output feature - time series feature matrix); W and U are network weights, which can be obtained through training with historical data and can also be updated in real time according to the data effect when processing real-time data; tanh is the hyperbolic tangent activation function.
[0109] However, in traditional LSTM, the memory gate, input gate, and output gate are calculated through static weight matrices and bias parameters, and cannot dynamically adjust the weights at each time step according to the global context information of the sequence. Based on this, the present invention uses an attention mechanism to dynamically optimize the gating calculation process inside LSTM, enabling the gating unit to explicitly perceive global context features, enhancing the ability of dynamic weight allocation, and the introduction of the attention mechanism enables the gating unit to better capture complex time series non-linear features. That is, based on the traditional memory gate formula, attention weights are added to enable the memory gate to dynamically perceive global context information, as follows:
[0110]
[0111] By introducing attention weights , the dynamic ratio of the memory gate's retention of past information is adjusted, enabling the memory of past time steps to be dynamically adjusted in combination with the current context. Similarly, the attention mechanism is also introduced into the input gate , enabling the input update at the current time step to be combined with the global context, as shown in the following formula:
[0112]
[0113] For the update of the candidate memory unit, the proportion of the input is dynamically adjusted based on the context features:
[0114]
[0115] The update of the output gate controlling the hidden state also needs to add dynamic attention weights :
[0116]
[0117] The update of the final hidden state combines the gating results optimized by attention:
[0118]
[0119] Among them, is the memory update with the attention mechanism.
[0120] Finally, the output features of Attention-LSTM and the feature matrix extracted by MSCNN are concatenated and fused to form comprehensive traffic features , where, represents the feature concatenation operation. The final comprehensive traffic features contain both static features extracted by multi-scale convolution and dynamic time series features modeled by LSTM, providing richer input information for the subsequent classification stage, and the obtained feature extraction results provide high-quality feature representations for the input of the subsequent deep neural network.
[0121] In the feature extraction stage of the present invention, a multi-scale convolutional neural network is used to extract features from the standardized data. The MSCNN scans the local area of the data through a convolutional kernel, extracts key features and generates a feature map. In order to enhance the non-linear expression ability of the model, the Sigmoid activation function is used to process the result after the convolutional operation; the last step of feature extraction is to extract the most significant feature values through global average pooling operation, thereby effectively reducing the redundant information of the data, while retaining the spatial invariance and importance of the feature data; the Attention-LSTM unit is used to perform sequence modeling on the features extracted by the MSCNN to capture the context relevance between different time steps; at the same time, the features extracted by the MSCNN and the Attention-LSTM are fused to generate a comprehensive feature matrix, thereby significantly improving the model's recognition ability for complex network attack behaviors, especially the generalization ability and robustness in the time series scenario, effectively extracting the key patterns in the data, reducing the interference of redundant information, and providing a basis for subsequent feature processing and classification.
[0122] In one embodiment, the improved deep neural network model includes a first fully connected layer, a second fully connected layer, a third fully connected layer, a residual layer, a first hidden layer, a second hidden layer, and a third hidden layer; wherein, step S3 includes:
[0123] Taking the comprehensive traffic feature as the input feature, after being connected by the residual layer, the first fully connected layer performs weighted calculation and mapping processing on the comprehensive traffic feature to obtain the first-layer feature, applies adaptive dynamic Dropout, generates the first traffic feature and outputs it through the first hidden layer;
[0124] Taking the first traffic feature as the input feature, after being connected by the residual layer, the second fully connected layer performs weighted calculation and mapping processing on the first traffic feature to obtain the second-layer feature, applies adaptive dynamic Dropout, generates the second traffic feature and outputs it through the second hidden layer;
[0125] Taking the second traffic feature as the input feature, after being connected by the residual layer, the third fully connected layer performs weighted calculation and mapping processing on the second traffic feature to obtain the third-layer feature, applies adaptive dynamic Dropout, generates a high-dimensional traffic feature and outputs it through the third hidden layer.
[0126] Specifically, the feature processing flow is as Figure 3As shown, at this stage, the present invention is based on a DNN that fuses ResNet and adaptive dynamic Dropout to further process the high-dimensional feature data generated in the feature extraction stage. The improved deep neural network model DNN extracts high-order features layer by layer through its multi-layer structure and learns the complex relationships between features. Among them, the DNN includes three hidden layers, and each layer performs a non-linear mapping on the input features through weights, biases, and activation functions. The input features are directly added to the output features through residual connections, allowing information to jump and transmit along the network levels, retaining low-order features in each layer, while enhancing the deep network's learning ability for high-order features, alleviating the vanishing gradient problem in the deep model, and retaining both low-order and high-order features in each layer. At the same time, adaptive dynamic Dropout is introduced between each hidden layer to randomly mask some neurons, reducing the model's over-reliance on single features, thereby reducing the risk of overfitting. At this stage, the present invention uses the Sigmoid activation function to enhance the model's non-linear modeling ability, ensuring that the model can accurately capture the potential features in the data. Finally, the DNN generates deep feature representations, providing a clear feature basis for the classification stage. In addition, it should be noted that the parameters in the model adopted in the solution can be obtained through training and summarization of historical data, and then the trained model is used to process real-time data.
[0127] The improved deep neural network model takes the comprehensive traffic features as input. After being connected through the residual layer, the fully connected layer and the hidden layer are used to process and extract high-order features layer by layer. Among them, the calculation formula for each fully connected layer is:
[0128]
[0129] In the formula, 、 are the input and output of the u-th fully connected layer respectively; is the Sigmoid activation function. Selecting the Sigmoid activation function as the non-linear transformation can effectively handle the non-linear relationships between complex features and provide stronger expression ability for the model; is the weight matrix of the u-th fully connected layer; is the bias vector of the u-th fully connected layer. In this formula, when u = 1, the input and output of the first fully connected layer are the comprehensive traffic features and the first-layer features respectively; when u = 2, the input and output of the second fully connected layer are the first-layer features and the second-layer features respectively; then when u = 3, the input and output of the third fully connected layer are the second-layer features and the third-layer features respectively.
[0130] After being processed by the fully connected layer, adaptive dynamic Dropout is applied to each level of features obtained. That is, the activation values of neurons are mapped to the relative linear range of a certain function (such as the sigmoid function) for probability calculation. Then, according to the mapped activation values or other relevant metrics, the inactivation probability of each neuron is calculated. This probability can be dynamic, that is, it changes according to the current state of the neuron or the characteristics of the input data. And in each forward propagation, some neurons are randomly inactivated according to the calculated inactivation probability. At the same time, in the backpropagation process, parameter updates are performed according to the inactivated network structure to randomly mask some neurons, reduce the over-reliance of the model on a single feature, thereby reducing the risk of overfitting, and combining with the activation function to smooth the data distribution, optimize the classification ability for multiple types of attack behaviors, and improve the generalization effect for unknown attacks.
[0131] After applying adaptive dynamic Dropout to the hierarchical features, traffic features are generated and output through the hidden layer. Then, the output results of each hidden layer are represented by the following formula:
[0132]
[0133]
[0134]
[0135] In the formula, is the output feature of the u-th hidden layer; is the random mask matrix; is the feature of the u-th layer; is the output probability of the u-th fully connected layer; a1 and a2 are hyperparameters used to adjust the influence weights of gradient change and feature sparsity on the Dropout probability; 、 are the overfitting prevention feature probability and the sparsity prevention feature probability of the u-th fully connected layer respectively. Among them, the overfitting prevention feature probability is used to characterize the sensitivity of gradient change: if the gradient change amplitude of a certain layer is large, the Dropout probability should be low to avoid excessive weakening of feature learning. If the gradient change is small, the Dropout probability can be high to increase randomness to prevent overfitting; the sparsity prevention feature probability is used to characterize the sensitivity of feature sparsity: if the feature sparsity is high, it means that the feature representation ability of this layer is weak, then the Dropout probability needs to be reduced to retain more neurons; if the feature sparsity is low, the Dropout probability can be increased to enhance the regularization effect; is the weight gradient of the u-th fully connected layer; Var() is the variance of gradient change; Mean() is the gradient mean; is the smoothing factor; is the i-th feature of the u-th fully connected layer; is an indicator function; N is the total number of features. In this formula, when u = 1, the output of the first hidden layer is the first traffic feature; when u = 2, the output of the second hidden layer is the first traffic feature; then when u = 3, the output of the third hidden layer is the high-dimensional traffic feature. The high-dimensional traffic feature generated after multi-layer mapping represents the high-order modeling result of the improved deep neural network for feature data. This result not only contains the local feature information of the original input, but also captures the complex relationships between features through non-linear mapping.
[0136] In the feature processing stage of the present invention, a DNN integrating a residual network and adaptive dynamic Dropout is used to perform further high-order feature modeling and semantic representation on the feature data extracted from the MSCNN. The residual connection allows information to skip along the network hierarchy by directly adding the input to the output, which can retain low-order features in each layer, while enhancing the deep network's learning ability for high-order features, alleviating the vanishing gradient problem, reducing information loss, capturing the complex relationships between features, and generating high-dimensional semantic features through multi-layer non-linear mapping, providing more discriminative inputs for classification. And ADD regularization is introduced between each hidden layer to avoid the problem of excessive information loss or insufficient feature learning during the training process caused by a fixed Dropout probability, improving the training robustness and generalization ability of the deep neural network, enabling the model to better adapt to complex network attack patterns, reducing the excessive dependence between neurons, and effectively alleviating the overfitting of the model. The present invention uses the improved deep neural network to abstract and optimize the input features layer by layer, transforming the original local features into high-dimensional feature vectors with global semantic information as the input for the next classification stage, providing support for the accurate identification of network attacks.
[0137] In one embodiment, step S4 includes:
[0138] Using the Softmax function to perform probability mapping on the high-dimensional traffic feature to obtain classification probabilities;
[0139] Comparing the preset classification threshold with the classification probability, and determining the traffic attack prediction result for the power 5G network according to the comparison result;
[0140] Among them, the preset classification threshold is represented by the following formula:
[0141]
[0142] Wherein, K is a preset classification threshold; E is a classification weight factor that determines the relative importance of Precision and Recall (usually E = 1, i.e., the F1 score); Precision and Recall are the first and second prediction accuracies respectively, that is, among the predictions classified as attacks, the proportion of actual attacks, and among the data that are actually attacks, the proportion of those successfully predicted as attacks.
[0143] Specifically, the present invention uses the Softmax function to map high-dimensional traffic features into class probabilities and completes the classification decision based on the preset classification threshold: first, the Softmax function is used to normalize the high-dimensional traffic features to convert the output of the model into probability values within the range of [0, 1] and ensure that the sum of all class probabilities is 1, so as to facilitate threshold judgment; then, according to the probability values output by Softmax, it is judged whether there is an abnormal behavior or an attack. If the output result exceeds the preset classification threshold, it is determined that the original input data has an attack behavior of this category; otherwise, it is determined that there is no abnormal behavior.
[0144] The present invention maps the deep features into a probability distribution by introducing the Softmax function and combines threshold judgment to achieve accurate classification and prediction of network attack behaviors, ensuring the efficiency and reliability of the model in a complex network environment and meeting the requirements of efficient and accurate network attack prediction in a complex dynamic environment.
[0145] In the embodiments of the present application, based on the problem of how to improve the prediction accuracy of power 5G network traffic attacks, a power 5G network traffic attack prediction method is designed. By combining standardization processing with dynamic weighted One-hot coding technology, it converts network attack types into high-quality vector representations, significantly improving the model's ability to focus on different types of attack behaviors, avoiding rare attack behaviors being ignored, and providing more accurate input data for subsequent feature extraction and classification; uses a multi-scale convolutional neural network to extract local and global features, and proposes an attention-optimized LSTM model to capture context associations and dynamic non-linear features in time series, greatly enhancing the feature modeling ability and recognition accuracy for complex network traffic data; in the feature processing stage, a deep neural network integrating a residual network and an adaptive dynamic Dropout mechanism is proposed. By optimizing the high-order feature modeling process, it reduces the risk of overfitting and enhances the classification and generalization ability for new network attack behaviors; combining the Softmax classification mechanism and the dynamic threshold adjustment strategy, the present invention realizes the probability distribution mapping and real-time classification determination of network attack behaviors, meeting the requirements of efficient and accurate network attack prediction in a complex dynamic environment.
[0146] It should be noted that although the steps in the above flowcharts are shown sequentially according to the arrows, these steps are not necessarily executed sequentially in the order indicated by the arrows. Unless otherwise specified in this article, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders.
[0147] In another embodiment, as Figure 4 shown, the second aspect of the present invention provides a power 5G network traffic attack prediction system, including:
[0148] A data preprocessing module 10, configured to obtain multi-dimensional traffic data of the power 5G network, and perform normalization processing on the multi-dimensional traffic data through weighted One-hot encoding to obtain a normalized traffic matrix;
[0149] A feature extraction module 20, configured to extract features from the normalized traffic matrix based on a multi-scale convolutional neural network model and a long short-term memory network model introducing an attention mechanism to obtain comprehensive traffic features;
[0150] A feature processing module 30, configured to process the comprehensive traffic features according to an improved deep neural network model to obtain high-dimensional traffic features; the improved deep neural network model is a deep neural network integrating a residual network and adaptive dynamic Dropout;
[0151] A classification and prediction module 40, configured to perform probability mapping on the high-dimensional traffic features through an activation function to obtain a traffic attack prediction result for the power 5G network.
[0152] It should be noted that each module in the above power 5G network traffic attack prediction system can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor of the computer device in hardware form or be independent of it, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each of the above modules. For the specific limitations of a power 5G network traffic attack prediction system, refer to the limitations on a power 5G network traffic attack prediction method in the above text. The two have the same functions and effects, and will not be elaborated here.
[0153] The third aspect of the present invention provides an electronic device, which includes:
[0154] A processor, a memory, and a bus;
[0155] The bus is used to connect the processor and the memory;
[0156] The memory is used to store operation instructions;
[0157] The processor is configured to execute operations corresponding to a method for predicting power 5G network traffic attacks as shown in the first aspect of this application by calling the operation instructions and executable instructions to cause the processor to execute.
[0158] In an alternative embodiment, an electronic device is provided, as Figure 5 shown. Figure 5 The electronic device 5000 shown includes: a processor 5001 and a memory 5003. Among them, the processor 5001 and the memory 5003 are connected, such as connected through a bus 5002. Optionally, the electronic device 5000 may further include a transceiver 5004. It should be noted that in practical applications, the transceiver 5004 is not limited to one, and the structure of the electronic device 5000 does not constitute a limitation on the embodiments of the present application.
[0159] The processor 5001 may be a CPU, a general-purpose processor, a DSP, an ASIC, an FPGA, or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute various exemplary logic blocks, modules, and circuits described in connection with the disclosure of the present application. The processor 5001 may also be a combination that implements computing functions, such as a combination including one or more microprocessors, a combination of a DSP and a microprocessor, etc.
[0160] The bus 5002 may include a path for transmitting information between the above components. The bus 5002 may be a PCI bus or an EISA bus, etc. The bus 5002 may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 5 only a thick line is shown in, but it does not mean that there is only one bus or one type of bus.
[0161] The memory 5003 may be a ROM or other type of static storage device that can store static information and instructions, a RAM, or other type of dynamic storage device that can store information and instructions, or it may also be an EEPROM, a CD-ROM, or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto.
[0162] The memory 5003 is used to store the application program code for executing the solution of the present application and is controlled by the processor 5001 to execute. The processor 5001 is used to execute the application program code stored in the memory 5003 to implement the content shown in any of the foregoing method embodiments.
[0163] Among them, the electronic devices include but are not limited to: mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Tablet Computers), PMPs (Portable Multimedia Players), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc.
[0164] The fourth aspect of the present invention provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements a method for predicting power 5G network traffic attacks shown in the first aspect of this application.
[0165] Another embodiment of this application provides a computer-readable storage medium, on which a computer program is stored. When it runs on a computer, it enables the computer to execute the corresponding content in the foregoing method embodiments.
[0166] In addition, an embodiment of the present invention also proposes a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the steps of the above method.
[0167] In summary, the present invention relates to the field of information technology, and discloses a method, system, device and medium for predicting power 5G network traffic attacks. The method includes obtaining multi-dimensional traffic data of a power 5G network, and performing standardization processing on the multi-dimensional traffic data through weighted One-hot encoding to obtain a standardized traffic matrix; performing feature extraction on the standardized traffic matrix based on a multi-scale convolutional neural network model and a long short-term memory network model introducing an attention mechanism to obtain comprehensive traffic features; processing the comprehensive traffic features according to an improved deep neural network model to obtain high-dimensional traffic features; the improved deep neural network model is a deep neural network integrating a residual network and adaptive dynamic Dropout; performing probability mapping on the high-dimensional traffic features through an activation function to obtain a prediction result of the traffic attack on the power 5G network, so as to effectively predict the network traffic attack situation and provide more efficient and accurate security protection for the power 5G communication network.
[0168] Each embodiment in this specification is described in a progressive manner. For the parts that are the same or similar in each embodiment, reference can be made to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and reference can be made to the corresponding part of the method embodiment for relevant content. It should be noted that the technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as within the scope described in this specification.
[0169] The above-described embodiments only represent several preferred embodiments of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art in this technical field, without departing from the technical principle of the present invention, several improvements and substitutions can be made, and these improvements and substitutions should also be regarded as within the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the protection scope of the claims.
Claims
1. A method for predicting power 5G network traffic attacks, characterized in that: include: Acquire multidimensional traffic data of the electric power 5G network, and standardize the multidimensional traffic data through weighted one-hot coding to obtain a standardized traffic matrix; Based on a multi-scale convolutional neural network model and a long short-term memory network model with an attention mechanism, feature extraction is performed on the standardized traffic matrix to obtain comprehensive traffic features; The comprehensive traffic features are processed according to the improved deep neural network model to obtain high-dimensional traffic features; The improved deep neural network model is a deep neural network that integrates residual network and adaptive dynamic Dropout; Probability mapping is performed on the high-dimensional traffic features through an activation function to obtain a traffic attack prediction result on the power 5G network; The multi-dimensional traffic data is standardized by weighted One-hot encoding to obtain a standardized traffic matrix, including: The multidimensional traffic data is coded to obtain a coded traffic matrix, and the coded traffic matrix is standardized by using a standardization model based on mean absolute deviation to obtain a standard coded traffic matrix; The standard coded traffic matrix is encoded by the weighted one-hot encoding to obtain a standardized traffic matrix; The standardized model is expressed by the following formula: In the formula, , are the values of the i-th feature in the j-th record in the standard coded traffic matrix before and after normalization, respectively; is the mean of the i-th feature; is the mean absolute deviation of the i-th feature; n is the total number of features; The weighted One-hot encoding is expressed by the following formula: Where Y is the weighted One-hot encoding matrix; is the weight corresponding to the i-th attack type; , is the weight adjustment factor; is the frequency of the i-th attack type in the historical multi-dimensional traffic data; , are the new and old severity of the i-th attack type, respectively; is the learning rate; is the real-time impact assessment value of the i-th attack type; The multi-scale convolutional neural network model and the long short-term memory network model with the attention mechanism are used to extract features from the standardized traffic matrix to obtain comprehensive traffic features, including: The standardized traffic matrix is subjected to feature extraction through the convolution kernel of the multi-scale convolutional neural network model to obtain key features, and the key features are processed through an activation function to reduce the dimension of the processing results by a global average pooling operation to generate a preliminary feature matrix; wherein the multi-scale convolutional neural network model is MSCNN; the input of the multi-scale convolutional neural network is a set of continuous sliding window representations, the standardized traffic matrix is input into the sliding window, and the convolution kernel of the multi-scale convolutional neural network is used to perform feature transformation on the input standardized traffic matrix to obtain key features; The preliminary feature matrix is modeled by a long short-term memory network model that introduces attention weights, so as to obtain a time series feature matrix; wherein the long short-term memory network model that introduces attention weights is Attention-LSTM; Attention-LSTM uses the preliminary feature matrix as input to model the time series, and outputs a time series feature matrix; The preliminary feature matrix and the time series feature matrix are concatenated and fused to obtain comprehensive traffic features; The improved deep neural network model includes a first fully connected layer, a second fully connected layer, a third fully connected layer, a residual layer, a first hidden layer, a second hidden layer and a third hidden layer; wherein, The comprehensive traffic features are processed according to the improved deep neural network model to obtain high-dimensional traffic features, including: Taking the comprehensive flow feature as an input feature, after connection through the residual layer, weighted calculation and mapping processing are performed on the comprehensive flow feature through the first fully connected layer to obtain a first layer feature to apply adaptive dynamic Dropout, generate a first flow feature and output it through the first hidden layer; Taking the first flow feature as an input feature, after being connected through the residual layer, performing weighted calculation and mapping processing on the first flow feature through the second fully connected layer, obtaining a second layer feature to apply adaptive dynamic Dropout, generating a second flow feature and outputting it through the second hidden layer; Taking the second flow feature as an input feature, after connection through the residual layer, performing weighted calculation and mapping processing on the second flow feature through the third fully connected layer, obtaining a third layer feature to apply adaptive dynamic Dropout, generating a high-dimensional flow feature and outputting it through the third hidden layer; The probability mapping of the high-dimensional traffic features by the activation function to obtain the traffic attack prediction result of the power 5G network includes: The Softmax function is used to perform probability mapping on the high-dimensional traffic features to obtain classification probability; Compare the classification probability with a preset classification threshold, and determine a prediction result of a traffic attack on the electric power 5G network according to the comparison result; The preset classification threshold is expressed by the following formula: In the formula, K is the preset classification threshold; E is the classification weight factor; Precision and Recall are the first and second prediction accuracy rates respectively.
2. A method for predicting power 5G network traffic attacks according to claim 1, characterized in that: The output of each hidden layer is expressed as follows: In the formula, is the output feature of the uth hidden layer; is a random mask matrix; is the u-th layer feature; is the output probability of the uth fully connected layer; a1 and a2 are hyperparameters; , are the anti-fitting feature probability and anti-sparse feature probability of the u-th fully connected layer respectively; is the weight gradient of the u-th fully connected layer; Var() is the variance of the gradient change; Mean() is the gradient mean; is the smoothing factor; is the i-th feature of the u-th fully connected layer; is the indicator function; N is the total number of features.
3. A power 5G network traffic attack prediction system, characterized in that: include: A data preprocessing module is used to obtain multi-dimensional flow data of the power 5G network, and standardize the multi-dimensional flow data through weighted one-hot coding to obtain a standardized flow matrix; A feature extraction module, used for extracting features from the standardized traffic matrix based on a multi-scale convolutional neural network model and a long short-term memory network model introducing an attention mechanism, to obtain comprehensive traffic features; A feature processing module, used for processing the comprehensive traffic features according to an improved deep neural network model to obtain high-dimensional traffic features; the improved deep neural network model is a deep neural network that integrates a residual network and an adaptive dynamic Dropout; A classification prediction module, used for performing probability mapping on the high-dimensional traffic features through an activation function to obtain a traffic attack prediction result on the power 5G network; The multi-dimensional traffic data is standardized by weighted One-hot encoding to obtain a standardized traffic matrix, including: The multidimensional traffic data is coded to obtain a coded traffic matrix, and the coded traffic matrix is standardized by using a standardization model based on mean absolute deviation to obtain a standard coded traffic matrix; The standard coded traffic matrix is encoded by the weighted one-hot encoding to obtain a standardized traffic matrix; The standardized model is expressed by the following formula: In the formula, , are the values of the i-th feature in the j-th record in the standard coded traffic matrix before and after normalization, respectively; is the mean of the i-th feature; is the mean absolute deviation of the i-th feature; n is the total number of features; The weighted One-hot encoding is expressed by the following formula: Where Y is the weighted One-hot encoding matrix; is the weight corresponding to the i-th attack type; , is the weight adjustment factor; is the frequency of the i-th attack type in the historical multi-dimensional traffic data; , are the new and old severity of the i-th attack type, respectively; is the learning rate; is the real-time impact assessment value of the i-th attack type; The multi-scale convolutional neural network model and the long short-term memory network model with the attention mechanism are used to extract features from the standardized traffic matrix to obtain comprehensive traffic features, including: The standardized traffic matrix is subjected to feature extraction through the convolution kernel of the multi-scale convolutional neural network model to obtain key features, and the key features are processed through an activation function to reduce the dimension of the processing results by using a global average pooling operation to generate a preliminary feature matrix; wherein the multi-scale convolutional neural network model is MSCNN; the input of the multi-scale convolutional neural network is a set of continuous sliding window representations, the standardized traffic matrix is input into the sliding window, and the convolution kernel of the multi-scale convolutional neural network is used to perform feature transformation on the input standardized traffic matrix to obtain key features; The preliminary feature matrix is modeled by a long short-term memory network model that introduces attention weights, so as to obtain a time series feature matrix; wherein the long short-term memory network model that introduces attention weights is Attention-LSTM; Attention-LSTM uses the preliminary feature matrix as input to model the time series, and outputs a time series feature matrix; The preliminary feature matrix and the time series feature matrix are concatenated and fused to obtain comprehensive traffic features; The improved deep neural network model includes a first fully connected layer, a second fully connected layer, a third fully connected layer, a residual layer, a first hidden layer, a second hidden layer and a third hidden layer; wherein, The comprehensive traffic features are processed according to the improved deep neural network model to obtain high-dimensional traffic features, including: Taking the comprehensive flow feature as an input feature, after connection through the residual layer, weighted calculation and mapping processing are performed on the comprehensive flow feature through the first fully connected layer to obtain a first layer feature to apply adaptive dynamic Dropout, generate a first flow feature and output it through the first hidden layer; Taking the first flow feature as an input feature, after being connected through the residual layer, performing weighted calculation and mapping processing on the first flow feature through the second fully connected layer, obtaining a second layer feature to apply adaptive dynamic Dropout, generating a second flow feature and outputting it through the second hidden layer; Taking the second flow feature as an input feature, after connection through the residual layer, performing weighted calculation and mapping processing on the second flow feature through the third fully connected layer, obtaining a third layer feature to apply adaptive dynamic Dropout, generating a high-dimensional flow feature and outputting it through the third hidden layer; The probability mapping of the high-dimensional traffic features by the activation function to obtain the traffic attack prediction result of the power 5G network includes: The Softmax function is used to perform probability mapping on the high-dimensional traffic features to obtain classification probability; Compare the classification probability with a preset classification threshold, and determine a prediction result of a traffic attack on the electric power 5G network according to the comparison result; The preset classification threshold is expressed by the following formula: In the formula, K is the preset classification threshold; E is the classification weight factor; Precision and Recall are the first and second prediction accuracy rates respectively.
4. An electronic device, characterized in that: It includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, and when the processor executes the computer program, it implements the power 5G network traffic attack prediction method as described in any one of claims 1 to 2.
5. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored computer program, wherein when the device where the computer-readable storage medium is located executes the computer program, the power 5G network traffic attack prediction method as described in any one of claims 1 to 2 is implemented.
Citation Information
Patent Citations
Power network flow anomaly detection method and system based on adversarial convolutional neural network
CN117596011A
Deep learning-oriented network anomaly detection method and device, storage medium and equipment
CN118070107A