Electric power communication network security risk identification method based on graph contrast learning
By abstracting the topological structure of the power communication network into a graph model and using graph comparison learning method to identify abnormal optical cables, the problems of insufficient flexibility and insufficient index system in the existing technology are solved, and the security risk identification of power communication network with high accuracy and generalization capabilities is achieved.
Patent Information
- Application Number
- CN202411910869.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-24
- Publication Date
- 2025-05-06
AI Technical Summary
The prior art has problems in the identification of security risks of power communication networks, insufficient flexibility, insufficient indicator system, and difficulty in making full use of network topology information, data integration and feature selection.
The topological structure of the power communication network is abstracted into a graph model by extracting the feature matrix and adjacency matrix of the optical cable, generating attribute network and enhanced attribute graph, using the GNN network for graph representation learning, and identifying abnormal optical cables through comparison loss and reconstruction error.
It significantly improves the accuracy of security risk identification of power communication networks, enhances the generalization ability of the model, can flexibly respond to risk analysis tasks in complex scenarios, and provides solid technical support for the safe and stable operation of power communication networks.
Smart Images

Figure CN119940912A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of smart grids and relates to a technology for identifying security risks in power communication networks, and specifically to a method for identifying security risks in power communication networks based on graph comparative learning. Background Art
[0002] The stable operation of the power communication network is crucial to the protection of the power grid. As the core transmission medium, the risk identification of optical cables has become the key to ensuring the normal operation of power grid services. In order to effectively deal with the risks that may be brought by optical cables and ensure the safe and stable operation of the power grid, it is necessary to identify optical cables that may affect the stability and reliability of the power communication network. The core of the power communication network security risk analysis and identification is to identify and evaluate the optical cables that may affect the stability and reliability of the network, and then take measures such as capacity expansion, expansion or business adjustment for the optical cables with risks to ensure the stable operation of the network. With the continuous growth of business volume, coupled with the strict requirements of power communication on business arrangements and optical cable redundancy, the workload of communication network security risk analysis has increased significantly, and the existing working mode has been unable to cope with this challenge.
[0003] At present, the research work in the field of power communication network security risk identification mainly focuses on three types of methods: rule-based methods, methods based on indicator statistics and quantitative evaluation, and methods based on machine learning. Although these methods have their own characteristics, they still have certain limitations. For example, although the rule-based method has high accuracy, it lacks flexibility and it is difficult to accurately describe the rules in a complex environment; although the method based on indicator statistics and quantitative evaluation is more scientific and objective, the indicator system is often not comprehensive enough and it is difficult to make full use of network topology information; and although the method based on machine learning shows good adaptability and flexibility, it still faces difficulties such as data integration and feature selection in practical applications. Summary of the invention
[0004] Purpose of the invention: In order to overcome the deficiencies in the prior art, a method for identifying security risks in power communication networks based on graph comparative learning is provided.
[0005] Technical solution: To achieve the above purpose, the present invention provides a method for identifying security risks of power communication network based on graph comparative learning, comprising the following steps:
[0006] S1: preprocessing the collected raw data of the power communication network to obtain the characteristic matrix and adjacency matrix of the optical cable;
[0007] S2: Generate attribute network G based on feature matrix and adjacency matrix;
[0008] S3: Introduce prior knowledge into the attribute network G to generate an enhanced attribute graph G ano ;
[0009] S4: Use the GNN network as an encoder to learn the representation of the graph, and combine the attribute network G and the enhanced attribute graph G ano Input to the encoder, use the GNN network to transform the attribute network G and the enhanced attribute graph G ano Encoded into the same latent space, the encoder is guided to distinguish normal and abnormal nodes through contrastive loss;
[0010] S5: Reconstruct the feature matrix and the adjacency matrix using the decoder and calculate the reconstruction error;
[0011] S6: The total loss is obtained based on the comparison loss and the reconstruction error loss, and the security risk identification result of the power communication network is obtained.
[0012] Furthermore, in step S1, a characteristic matrix of the optical cable is constructed by performing table association and selection operations on the complex data in the database; and an adjacency matrix of the optical cable is obtained by matching the sites connected to the A end and the Z end of each optical cable.
[0013] Furthermore, the attribute network G in step S2 is represented as: G = {A, X}, where A∈R n×n represents the adjacency matrix of the optical cable, X∈R n×d represents the characteristic matrix of the optical cable; x u ∈R d represents the attribute of the u-th edge. Each edge has an abnormal label, where y u =0 or y u =1 indicates edge e u Is normal or abnormal; design a detection method f(G): G→{0,1} n , this method associates each edge with a label.
[0014] Furthermore, in step S3, the enhanced attribute graph G ano It not only contains the attribute relationships in the original data, but also incorporates additional information about the anomaly type.
[0015] Furthermore, the encoding method of the encoder in step S4 is: Enc encodes G and G through stacked GAT layers. ano To finally represent Z and Based on the contrast loss function, the comparison is performed on z i and , that is, the representation of each object i in the normal view and the abnormal view.
[0016] Furthermore, the contrast loss function in step S4 is defined as follows:
[0017]
[0018] Where I is the indicator function of the subscript condition. When contrast loss is applied, if y i =1, that is, object i is in G ano is considered abnormal, and its representation in normal view and abnormal view The distance between them will be maximized, where m is a hyperparameter that controls the minimum acceptable value of the distance; if y i =0, that is, node i is in G ano is not considered abnormal, then will be minimized.
[0019] Furthermore, the decoder in step S5 is composed of a GAT layer, and the adjacency and feature matrices are reconstructed from z, and the F-norm of the difference between the input and matrices is the reconstruction error.
[0020] Furthermore, the loss function of the reconstruction error in step S5 is:
[0021]
[0022] Among them, σ(·) is a nonlinear activation function, and λ is a weighting factor that balances the two reconstruction error scales for structure and attributes.
[0023] Furthermore, the total loss L in step S6 is the comparison loss L cl and the reconstruction loss L recon The sum of is as follows:
[0024] L=η·L cl +(1η)L recon (5)
[0025] Here, η is a weighting factor that balances the two loss terms.
[0026] The core highlight of the method of the present invention is that it abstracts the complex topological structure of the power communication network into a graph model for the first time, and under this framework, systematically extracts the characteristic matrix and adjacency matrix of the optical cable based on the power grid data, and comprehensively models and analyzes the abnormal state of the optical cable from the two dimensions of network structure and optical cable attributes (features). Specifically, the present invention defines optical cables with potential safety risks as abnormal optical cables. This definition strategy cleverly transforms the problem of optical cable safety risk identification into a graph anomaly detection problem, opening up a new perspective for solving the problem. More importantly, given that some abnormal information is known, the present invention makes full use of the prior knowledge of these anomalies and innovatively introduces the concept of graph comparison learning. Through the graph comparison learning mechanism, the model can effectively capture the subtle differences between normal optical cables and abnormal optical cables, and then realize the accurate identification of optical cables with potential safety risks, thereby realizing the safety risk identification of the power communication network. The method of the present invention not only significantly improves the accuracy of power communication network security risk identification, but also greatly enhances the generalization ability of the model, enabling it to flexibly cope with optical cable safety risk analysis and identification tasks in various complex scenarios. In general, the power communication network security risk identification method based on graph comparative learning constructed by the present invention is not only innovative in theory, but also shows strong practicality and effectiveness in practical applications, providing solid technical support for the safe and stable operation of the power communication network.
[0027] Beneficial effects: Compared with the prior art, the present invention has the following advantages:
[0028] 1. Construction of power communication network graph model
[0029] This invention abstracts the complex topological structure of the power communication network into a graph model for the first time. This modeling method provides a new perspective and accurate basis for the identification of power communication network security risks. Through the graph model, the structure and connection relationship of the network can be intuitively and accurately reflected, providing a solid foundation for subsequent risk analysis.
[0030] 2. Feature matrix and adjacency matrix extraction
[0031] Based on the graph model, the present invention systematically extracts the characteristic matrix and adjacency matrix of optical cables according to the power grid data. These matrices not only contain the attribute information of optical cables, but also reflect the connection relationship in the network structure, providing comprehensive data support for the identification of optical cable safety risks.
[0032] 3. Abnormal optical cable definition and abnormal detection conversion
[0033] The present invention defines optical cables with potential safety risks as abnormal optical cables, and transforms the optical cable safety risk identification problem into a graph anomaly detection problem. This transformation strategy not only simplifies the complexity of the problem, but also makes full use of the advantages of graph models in anomaly detection, improving the accuracy and efficiency of risk identification in power communication networks.
[0034] 4. Introduction of graph contrast learning mechanism
[0035] This invention innovatively introduces the concept of graph comparison learning, which has more prior knowledge guidance. Through the graph comparison learning mechanism, the model can learn the subtle differences between normal optical cables and abnormal optical cables. The introduction of this mechanism not only improves the accuracy of power communication network security risk identification, but also enhances the generalization ability of the model, enabling it to flexibly respond to risk analysis tasks in various complex scenarios.
[0036] 5. Verification of the practicality and effectiveness of the method
[0037] The power communication network security risk identification method based on graph contrast learning constructed by the present invention is not only innovative in theory, but also verified by practical application for its strong practicality and effectiveness. The proposal of this method provides solid technical support for the safe and stable operation of the power communication network and has important practical application value. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] Figure 1 It is a framework flow chart of the method of the present invention. DETAILED DESCRIPTION
[0039] The present invention is further explained below in conjunction with the accompanying drawings and specific embodiments. It should be understood that these embodiments are only used to illustrate the present invention and are not used to limit the scope of the present invention. After reading the present invention, various equivalent forms of modifications to the present invention by those skilled in the art all fall within the scope defined by the claims attached to this application.
[0040] like Figure 1 As shown, the present invention provides a method for identifying security risks of a power communication network based on graph contrast learning, comprising the following steps:
[0041] S1: preprocessing the collected raw data of the power communication network to obtain the characteristic matrix and adjacency matrix of the optical cable;
[0042] By performing table association and selection operations on the complex data in the database, the characteristic matrix of the optical cable is constructed; by matching the sites connected to the A end and the Z end of each optical cable, the adjacency matrix of the optical cable is obtained.
[0043] S2: Generate attribute network G based on feature matrix and adjacency matrix;
[0044] The attribute network G is represented as: G = {A, X}, where A∈R n×n represents the adjacency matrix of the optical cable, X∈R n×d represents the characteristic matrix of the optical cable; x u ∈R d represents the attribute of the u-th edge. Each edge has an abnormal label, where y u =0 or y u =1 indicates edge e u Is normal or abnormal; design a detection method f(G): G→{0,1} n , this method associates each edge with a label.
[0045] S3: The abnormal type data enhancement module introduces prior knowledge into the attribute network G to generate an enhanced attribute graph G ano ;
[0046] This module uses the experts’ prior knowledge of different anomaly types to enhance the data and generate samples for comparative learning. This prior knowledge covers a wide range of anomaly feature descriptions, behavior pattern analysis, and their complex relationships with other attributes, and is the theoretical basis and source of knowledge for the module’s operation. This type of knowledge is usually acquired through the accumulation of experts’ long-term practical experience and in-depth mining of historical data. This module adopts a novel data enhancement strategy to introduce prior knowledge into the attribute network G. The purpose of this strategy is to generate more diverse data samples by simulating known anomaly types, thereby enhancing the generalization ability of the model. Generated enhanced attribute graph G ano It not only contains the attribute relationships in the original data, but also incorporates additional information about the anomaly type.
[0047] S4: In the GNN-based contrastive learning module, the GNN network is used as an encoder to learn the representation of the graph, and the attribute network G and the enhanced attribute graph G ano Input to the encoder, use the GNN network to transform the attribute network G and the enhanced attribute graph G ano Encoded into the same latent space, G and G ano The representation becomes possible by contrasting, and the encoder is guided to distinguish normal and abnormal nodes through contrast loss, that is, the encoder is guided to represent the normal nodes on the input attribute network and the contrast samples on the enhanced attribute network in different ways, so the abnormal pattern of the enhanced node can be captured;
[0048] The encoding method of the encoder is: Enc encodes G and G through stacked GAT layers ano To finally represent Z and Based on the contrast loss function, the comparison is performed on z i and , that is, the representation of each object i in the normal view and the abnormal view.
[0049] The contrast loss function is defined as follows:
[0050]
[0051] Where I is the indicator function of the subscript condition. When contrast loss is applied, if y i =1, that is, object i is in G ano is considered abnormal, and its representation in normal view and abnormal view The distance between them will be maximized. Here, m is a hyperparameter used to control the minimum acceptable value of the distance. Its function is to prevent the latter term from becoming a negative number. If d is too large, it will affect L cl The proportion of y in the total loss makes the total loss completely dominated by this reconstruction loss and loses its meaning; if y i =0, that is, node i is in G ano is not considered abnormal, then will be minimized.
[0052] S5: In the anomaly detection module, the decoder is used to reconstruct the feature matrix and the adjacency matrix, and the reconstruction error is calculated;
[0053] The decoder consists of a GAT layer to reconstruct the adjacency and feature matrices from z. The F-norm of the difference between the input and the matrix is the reconstruction error; the loss function of the reconstruction error is:
[0054]
[0055] Among them, σ(·) is a nonlinear activation function, and λ is a weighting factor that balances the two reconstruction error scales for structure and attributes.
[0056] S6: According to the contrast loss L cl and the reconstruction loss L recon Get the total loss L, the total loss L is the comparison loss L cl and the reconstruction loss L recon The sum of is as follows:
[0057] L=η·L cl +(1η)L recon (5)
[0058] Among them, η is a weighting factor that balances the two loss terms;
[0059] The anomaly score is calculated based on the total loss L (the two are consistent), and the power communication network security risk identification result is obtained based on the anomaly score.
[0060] The above-mentioned method process of the present invention is summarized here: in the preliminary stage of in-depth analysis and modeling of optical cable network data, data preprocessing is performed, including table association, feature extraction and standardization, and the optical cable feature matrix and adjacency matrix are constructed to accurately reflect the network topology. Subsequently, the abnormal type data enhancement module uses human prior knowledge to enhance the data, generates diversified samples by simulating abnormal types, and improves the generalization ability of the model. The GNN-based contrast learning module uses the GNN coding graph representation to guide the encoder to distinguish between normal and abnormal nodes through contrast loss. Finally, the anomaly detection module uses the decoder to reconstruct the input network and identify anomalies by calculating the reconstruction error. Data instances with large errors are regarded as anomalies, which realizes accurate anomaly detection of optical cable network data and accurate identification of safety risks in the power communication network. The model uses L cl and L recon From the comparison sample G ano and attribute network G.
[0061] In order to verify the effectiveness and effect of the method of the present invention, this embodiment is verified by specific experiments, as follows:
[0062] 1. Dataset
[0063] The data of this embodiment is derived from the topological data of a provincial power communication network. The optical cable data set is obtained through a series of table association and selection operations. The data set includes the topological structure and attribute information of the optical cable of the communication network, covering multiple key indicators such as bandwidth utilization, overload degree, port occupancy, etc. In order to ensure the reliability and accuracy of the data, a series of rigorous data preprocessing processes are performed. First, the noise data is carefully removed to reduce the analysis error; secondly, for the missing values in the data set, a scientific and reasonable method is used to fill them to ensure the integrity and coherence of the data; finally, all features are standardized to improve the accuracy and efficiency of subsequent data analysis. The preprocessed data set includes 2000 optical cables, each with 10 attributes, and a total of 160 abnormal optical cables. In the data set preparation stage, this paper divides the sorted data into training set, test set and validation set according to the ratio of 60%, 20%, and 20%.
[0064] 2. Experimental Setup
[0065] The hardware device used in the experiment is a computer with an Intel Core i7 processor. In terms of software environment, Python3 environment and PyTorch library are used to conduct experiments on graph neural networks. The initialization parameters of the experiment are shown in Table 1.
[0066] Table 1 Model parameters
[0067]
[0068] 3. Method Comparison Experimental Results
[0069] The evaluation indicators are as follows:
[0070] 1. ROC-AUC
[0071] ROC-AUC is an important binary classification model evaluation indicator, which quantitatively evaluates the performance of the model by drawing the ROC curve and calculating its area under it.
[0072] 2. Recall@K
[0073] For the output anomaly sorted list, consider the first K edges as possible anomaly edges. The calculation method is as follows:
[0074] Recall = (the number of actual anomalies among the first K predicted anomalies) / (the total number of anomalies)
[0075] Table 2 AUC comparison of different algorithms
[0076] method AUC Dominant 0.7632 GCNAE 0.7713 Method of the present invention 0.8337
[0077] Table 3 Comparison of Recall@K of different algorithms
[0078] method K=500 K=800 Dominant 0.6963 0.7294 GCNAE 0.6595 0.7785 Method of the present invention 0.7117 0.8773
[0079] According to the experimental results shown in Tables 2 and 3, the graph anomaly detection method based on graph contrast learning adopted by the present invention shows comparative advantages in both AUC and Recall@K evaluation indicators. Specifically, compared with other comparative methods (Dominant, GCNAE), the AUC value and Recall@K of the method of the present invention are higher than those of other methods, indicating that the introduction of graph contrast learning brings richer information, and the model can learn high-quality graph representations to well preserve the characteristics and structural information of graph data. In summary, the method of the present invention has a comparative advantage in the identification of security risks in power communication networks, can relatively accurately identify security risks in the network, and provides strong technical support for the safe operation and maintenance of power communication networks.
Claims
1. A method for identifying security risks in power communication networks based on graph contrast learning, characterized in that: The steps include: S1: preprocessing the collected raw data of the power communication network to obtain the characteristic matrix and adjacency matrix of the optical cable; S2: Generate attribute network G based on feature matrix and adjacency matrix; S3: Introduce prior knowledge into the attribute network G to generate an enhanced attribute graph G ano ; S4: Use the GNN network as an encoder to learn the representation of the graph, and combine the attribute network G and the enhanced attribute graph G ano Input to the encoder, use the GNN network to transform the attribute network G and the enhanced attribute graph G ano Encoded into the same latent space, the encoder is guided to distinguish normal and abnormal nodes through contrastive loss; S5: Reconstruct the feature matrix and the adjacency matrix using the decoder and calculate the reconstruction error; S6: The total loss is obtained based on the comparison loss and the reconstruction error loss, and the security risk identification result of the power communication network is obtained.
2. According to claim 1, a method for identifying security risks of power communication network based on graph contrast learning is characterized in that: In step S1, a characteristic matrix of optical cables is constructed by performing table association and selection operations on the complex data in the database; and an adjacency matrix of optical cables is obtained by matching the sites connected to the A end and the Z end of each optical cable.
3. According to claim 1, a method for identifying security risks of power communication network based on graph contrast learning is characterized in that: The attribute network G in step S2 is represented as: G = {A, X}, where A∈R n×n represents the adjacency matrix of the optical cable, X∈R n×d represents the characteristic matrix of the optical cable; x u ∈R d represents the attribute of the u-th edge. Each edge has an abnormal label, where y u =0 or y u =1 indicates edge e u Is normal or abnormal; design a detection method f(G): G→{0,1} n .
4. According to claim 1, a method for identifying security risks of power communication network based on graph contrast learning is characterized in that: The encoding method of the encoder in step S4 is: Enc encodes G and G through stacked GAT layers ano To finally represent Z and Based on the contrast loss function, the comparison is performed on z i and , that is, the representation of each object i in the normal view and the abnormal view.
5. The method for identifying security risks of power communication network based on graph contrast learning according to claim 4 is characterized in that: The contrast loss function in step S4 is defined as follows: Where I is the indicator function of the subscript condition. When contrast loss is applied, if y i =1, that is, object i is in G ano is considered abnormal, and its representation in normal view and abnormal view The distance between them will be maximized, where m is a hyperparameter that controls the minimum acceptable value of the distance; if y i =0, that is, node i is in G ano is not considered abnormal, then will be minimized.
6. A method for identifying security risks of power communication network based on graph contrast learning according to claim 5, characterized in that: The decoder in step S5 consists of a GAT layer, which reconstructs the adjacency and feature matrices from z, and the F-norm of the difference between the input and matrices is the reconstruction error.
7. The method for identifying security risks of power communication network based on graph contrast learning according to claim 6 is characterized in that: The loss function of the reconstruction error in step S5 is: Among them, σ(·) is a nonlinear activation function, λ It is a weighting factor that balances the two reconstruction error scales for structure and attributes.
8. The method for identifying security risks of power communication network based on graph contrast learning according to claim 7 is characterized in that: The total loss L in step S6 is the comparison loss L cl and the reconstruction loss L recon The sum of is as follows: L=·L cl +(1-n)L recon (5) Here, η is a weighting factor that balances the two loss terms.
Citation Information
Cited By
Power optical cable safety checking method and system based on graph contrast learning and XGB
CN120811793A
Power cable safety checking method and system based on graph contrast learning and XGB
CN120811793B