Industrial control system anomaly detection method based on deep meta learning, medium and equipment

Through the deep meta-learning method, the convolutional neural network model enhanced by the meta-module is trained, which solves the problem of abnormal detection in industrial control systems under the condition of few samples, realizes efficient abnormal detection and improves system security.

CN119945704APending Publication Date: 2025-05-06SHENYANG INST OF AUTOMATION - CHINESE ACAD OF SCI
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202411722917.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-11-28
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

It is difficult for industrial control systems to effectively conduct abnormal detection under the conditions of few samples, resulting in an increase in safety risks.

Method used

The abnormal detection method of industrial control system based on deep meta-learning is adopted, and the convolutional neural network model based on meta-module enhancement is trained by collecting abnormal traffic data, building data sets, random task sampling and multi-step loss function optimization.

Benefits of technology

It improves the abnormal detection capability under the condition of few samples, enhances the model's generalization ability of unknown abnormal traffic, and effectively improves the security and reliability of ICS.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945704A_ABST
    Figure CN119945704A_ABST
Patent Text Reader

Abstract

The invention discloses an industrial control system anomaly detection method based on deep meta learning, a medium and equipment, and the method comprises the steps: collecting the abnormal traffic data of an industrial control system, and constructing an abnormal traffic data set based on the abnormal traffic data of the industrial control system; performing multi-category and multi-sample random task sampling on the abnormal traffic data set to obtain a plurality of training tasks; an anomaly detection model is trained through the training task, the anomaly detection model comprises a convolutional neural network based on meta-module enhancement, and in the training process, internal loop parameter updating is carried out based on a gradient descent method, external loop parameter updating is carried out based on a multi-step loss function, and external loop learning rate updating is carried out based on a cosine annealing algorithm; and performing traffic data anomaly detection by using the trained anomaly detection model. The industrial control system anomaly detection method based on deep meta learning has remarkable advantages in solving the anomaly detection problem under the condition of few samples, and the safety and reliability of ICS can be effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of industrial control systems, and in particular to an industrial control system anomaly detection method, medium and equipment based on deep meta-learning. Background Art

[0002] Industrial Control System (ICS) is a collection of equipment, networks, and systems used to operate and control industrial automation production processes, aiming to achieve accurate monitoring and control of the production process. With the rapid development of the industrial Internet, information technology (IT) and operational technology (OT) are accelerating their integration, which has continuously improved the connectivity, openness, and complexity of ICS, while also increasing the vulnerability and intrusion threats of the system. In recent years, the network security issues of ICS have become increasingly prominent, and industrial control security incidents have occurred frequently, bringing new challenges to the security research of industrial control systems. Therefore, anomaly detection is crucial to ensuring the security of ICS. By detecting abnormal behaviors, timely discovering and responding to potential security threats, the reliability and security of ICS can be ensured.

[0003] However, many malicious traffic uses undisclosed vulnerabilities to carry out network attacks. Usually, relevant data can only be obtained after the attack occurs, resulting in extremely scarce available learning samples. In this case, industrial control systems will face huge security risks. Therefore, it is particularly urgent to study anomaly detection methods that can operate effectively under few sample conditions and have high generalization capabilities. Summary of the invention

[0004] In view of this, the embodiments of the present application provide an industrial control system anomaly detection method, medium and device based on deep meta-learning. The industrial control system anomaly detection method based on deep meta-learning has significant advantages in solving the anomaly detection problem under few sample conditions, and can effectively improve the security and reliability of ICS.

[0005] According to one aspect of the present application, a method for detecting anomalies in an industrial control system based on deep meta-learning is provided, the method comprising:

[0006] Collecting abnormal flow data of the industrial control system, and constructing an abnormal flow data set based on the abnormal flow data of the industrial control system;

[0007] Performing multi-category and multi-sample random task sampling on the abnormal traffic data set to obtain multiple training tasks;

[0008] The anomaly detection model is trained using the training task, wherein the anomaly detection model includes a convolutional neural network based on meta-module enhancement, and during the training process, inner loop parameters are updated based on a gradient descent method, outer loop parameters are updated based on a multi-step loss function, and outer loop learning rate is updated based on a cosine annealing algorithm;

[0009] The trained anomaly detection model is used to perform anomaly detection on traffic data.

[0010] Optionally, collecting abnormal flow data of the industrial control system and constructing an abnormal flow data set based on the abnormal flow data of the industrial control system includes:

[0011] Acquire feature data containing abnormal behavior characteristics from the industrial control system communication traffic;

[0012] Using an average distribution method to evenly distribute the feature data into a matrix at the same interval, so as to convert the feature data from numerical single-row data into two-dimensional matrix data, wherein different feature data are represented by different numerical values, and positions without feature data are filled with zero values;

[0013] The two-dimensional matrix data is subjected to image-based three-dimensional data structure mapping to be converted into RGB image data to obtain the abnormal flow data, and the abnormal flow data set is constructed.

[0014] Optionally, the abnormal traffic data set includes samples of multiple categories; and performing multi-category and multi-sample random task sampling on the abnormal traffic data set to obtain multiple training tasks includes:

[0015] Random task sampling is performed on the abnormal traffic data set to obtain multiple training tasks, wherein each training task contains samples of N categories, and each category includes K samples, and the number of sample categories in the abnormal traffic data set is greater than N.

[0016] Optionally, the anomaly detection model includes a feature extraction network, a fully connected layer, and an output layer. The feature extraction network includes a plurality of feature extraction units connected in sequence, each feature extraction unit includes a convolutional layer, an activation layer, a pooling layer and a meta-module in sequence, and the meta-module includes a convolutional layer, an activation layer, a convolutional layer, an activation layer and a regularization layer in sequence.

[0017] Optionally, the inner loop parameter updating based on the gradient descent method includes:

[0018] During the training process, for the current training task in each training task, the inner loop parameters are calculated using the back propagation of the loss function and the meta-objective, and updated by gradient descent.

[0019] Optionally, the updating of outer loop parameters based on the multi-step loss function includes:

[0020] The weight loss factor is set to be dynamically adjusted, the loss is updated based on each gradient of each training task, and a multi-step loss function is used to update the outer loop parameters.

[0021] Optionally, the method further comprises:

[0022] The outer loop learning rate is updated based on the cosine annealing algorithm.

[0023] Optionally, after the anomaly detection model is trained using the training task, the method further includes:

[0024] Step 1: Acquire new abnormal traffic data from the industrial control system and construct a test set, wherein the test set includes samples of multiple categories, and the test set includes sample categories that belong to different subcategories under the same parent category as the sample categories in the abnormal traffic data;

[0025] Step 2: Sample the abnormal traffic data in the test set to obtain a test task. The test task T i Includes samples of N categories, and each category includes K samples;

[0026] Step 3: input the test task into the trained anomaly detection model, fine-tune the anomaly detection model based on the model output result, and input the samples in the test set except those sampled into the test task into the fine-tuned anomaly detection model to determine whether the traffic data is abnormal based on the model output result;

[0027] Step 4: Determine the model performance of the anomaly detection model based on the model output results and the corresponding sample categories.

[0028] According to another aspect of the present application, a storage medium is provided, on which a computer program is stored. When the program is executed by a processor, the above-mentioned industrial control system anomaly detection method based on deep meta-learning is implemented.

[0029] According to another aspect of the present application, a computer device is provided, including a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, wherein the processor implements the above-mentioned industrial control system anomaly detection method based on deep meta-learning when executing the program.

[0030] Through the above technical solutions, the embodiments of the present application provide an industrial control system anomaly detection method, medium and device based on deep meta-learning. Through random task sampling and multi-step loss function optimization, the model can be effectively trained under limited abnormal traffic data, thereby improving the anomaly detection capability under few-sample conditions. The introduction of the meta-module enables the model to dynamically adjust its structure and parameters according to different training tasks, thereby enhancing the model's generalization ability for unknown abnormal traffic. In summary, the industrial control system anomaly detection method based on deep meta-learning in the embodiments of the present application has significant advantages in solving the anomaly detection problem under few-sample conditions, and can effectively improve the security and reliability of ICS.

[0031] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0033] Figure 1 A schematic diagram of a process flow of an industrial control system anomaly detection method based on deep meta-learning provided in an embodiment of the present application is shown;

[0034] Figure 2 A schematic diagram of the structure of an anomaly detection model provided in an embodiment of the present application is shown;

[0035] Figure 3 A flow chart of another method for detecting anomalies in an industrial control system based on deep meta-learning provided in an embodiment of the present application is shown. DETAILED DESCRIPTION

[0036] The present application will be described in detail below with reference to the accompanying drawings and in combination with embodiments. It should be noted that the embodiments and features in the embodiments of the present application can be combined with each other without conflict.

[0037] In this embodiment, a method for detecting anomalies in an industrial control system based on deep meta-learning is provided. Figure 1 As shown, the method includes:

[0038] Step 101: Collect abnormal flow data of the industrial control system, and construct an abnormal flow data set based on the abnormal flow data of the industrial control system.

[0039] Step 102: Perform multi-category and multi-sample random task sampling on the abnormal traffic data set to obtain multiple training tasks.

[0040] Step 103: Train the anomaly detection model using the training task, wherein the anomaly detection model includes a convolutional neural network based on meta-module enhancement. During the training process, inner loop parameters are updated based on the gradient descent method, outer loop parameters are updated based on the multi-step loss function, and outer loop learning rate is updated based on the cosine annealing algorithm.

[0041] Step 104: Use the trained anomaly detection model to perform anomaly detection on the traffic data.

[0042] In the embodiment of the present application, in view of the network security problems faced by the industrial control system (ICS) mentioned in the background technology, especially the urgent need to effectively detect abnormal behavior under the condition of few samples, the proposed industrial control system anomaly detection method based on deep meta-learning is intended to solve this problem. First, the abnormal traffic data occurring in the industrial control system ICS is collected, which is the basis for subsequent model training and detection. Specifically, the network traffic of the ICS can be monitored to screen out the traffic data marked as abnormal (which may come from known attack instances or simulated attacks) to form an abnormal traffic data set. Then, by random sampling, the training scenario under the condition of few samples is simulated, and samples of different categories and different numbers are randomly selected from the abnormal traffic data set to form multiple training tasks. Different tasks are used to simulate different anomaly detection scenarios. The model can experience a variety of anomaly detection tasks during the training process and improve its generalization ability. Then, the training task is used to train the anomaly detection model. The anomaly detection model adopts a meta-module-enhanced convolutional neural network (Meta Convolutional Neural Network, M-CNN), and the meta-module can dynamically adjust the model structure or parameters to adapt to different training tasks. During the training process, within each training task, the model parameters are updated using optimization algorithms such as gradient descent to minimize the loss function of the current task to achieve inner loop parameter updates. After multiple training tasks are completed, the parameters of the meta-module enhanced convolutional neural network are updated based on the multi-step loss function and the cosine annealing algorithm (which may consider the weights or performance of different tasks) to optimize the overall performance of the model on different tasks to achieve outer loop parameter updates. Finally, the trained model is deployed to the ICS to perform anomaly detection on network traffic in real time or periodically. The model can identify traffic similar to the abnormal patterns learned during training, thereby triggering alarms or taking other security measures.

[0043] By applying the technical solution of this embodiment, through random task sampling and internal and external loop optimization, the model can be effectively trained under limited abnormal traffic data, improving the anomaly detection ability under few sample conditions. The introduction of the meta-module enables the model to dynamically adjust its structure and parameters according to different training tasks, thereby enhancing the model's generalization ability for unknown abnormal traffic. In summary, the industrial control system anomaly detection method based on deep meta-learning in the embodiment of the present application has significant advantages in solving the anomaly detection problem under few sample conditions, and can effectively improve the security and reliability of ICS.

[0044] In an embodiment of the present application, optionally, step 101 includes: obtaining feature data containing abnormal behavior characteristics from the communication traffic of the industrial control system; using an average distribution method to evenly distribute the feature data into a matrix at the same interval to convert the feature data from numerical single-row data into two-dimensional matrix data, wherein different feature data are represented by different numerical values, and positions without feature data are filled with zero values; performing image-based three-dimensional data structure mapping on the two-dimensional matrix data to convert it into RGB image data to obtain the abnormal traffic data, and construct the abnormal traffic data set.

[0045] In this embodiment, in order to adapt to the requirements of the deep learning model for the input data format and improve the efficiency and accuracy of data processing. First, feature data containing abnormal behavior features are obtained from the communication traffic of the industrial control system, so as to extract key feature data that can reflect abnormal behavior from the communication traffic of the ICS. Then, the collected abnormal traffic data is evenly distributed to the entire matrix at the same interval using an average distribution method, and then the numerical single-row data is converted into two-dimensional matrix data. Among them, different feature data are represented by different numerical values, and the position without feature data is filled with zero values. The three-dimensional data structure of the two-dimensional matrix data is further mapped to the image and converted into RGB image data, a complete abnormal traffic data set is constructed, and an abnormal traffic data set for model training is obtained, so as to be used for model training in subsequent steps. The embodiment of the present application improves the efficiency and accuracy of model training by finally converting the feature data into RGB image data, so that the data format matches the input requirements of the convolutional neural network based on the meta-module enhancement, and enhances the representation ability of the feature data through the average distribution method and color mapping, so that the model can more easily identify abnormal behavior. And by introducing image processing technology and deep meta-learning, the model's generalization ability for unknown abnormal behaviors is improved, enabling the model to better adapt to the ever-changing security threats in ICS.

[0046] In an embodiment of the present application, optionally, the abnormal traffic data set includes samples of multiple categories; step 102 includes: performing random task sampling on the abnormal traffic data set to obtain multiple training tasks, wherein each training task includes samples of N categories, and each category includes K samples, and the number of sample categories in the abnormal traffic data set is greater than N.

[0047] In this embodiment, after constructing the abnormal traffic data set, the data set is sampled by tasks, each task includes N categories, K samples, and the total number of samples in each category is R. Different tasks are used to simulate different anomaly detection scenarios, and the model can experience a variety of anomaly detection tasks during the training process, thereby improving its generalization ability. Specifically, when constructing the abnormal traffic data set, various forms of network attack traffic, such as denial of service (DoS), distributed denial of service (DDoS), etc., are collected. Tasks are randomly collected, and task A may include categories 1, 2, 3, 4, and 5, while task B may include categories 6, 7, 8, 9, and 10. This difference in categories can simulate different scenarios. And even under the same category, there will be differences between the attack traffic of each category. Even for the same attack category, there will be differences due to the specific methods used during the attack, different attack intensities, and different attack targets. Therefore, due to the large differences between the same type and different types of attack traffic, different tasks can simulate different anomaly detection scenarios.

[0048] In the embodiment of the present application, optionally, Figure 2 As shown, the anomaly detection model includes a feature extraction network, a fully connected layer, and an output layer. The feature extraction network includes a plurality of feature extraction units connected in sequence, each feature extraction unit includes a convolutional layer, an activation layer, a pooling layer, and a meta-module in sequence, and the meta-module includes a convolutional layer, an activation layer, a convolutional layer, an activation layer, and a regularization layer in sequence;

[0049] The expression of the convolutional layer is:

[0050]

[0051] Among them, x conv represents the output features of the convolutional layer, x conv-1 represents the input features of the convolutional layer, w conv and b conv Represent the weight factor and bias factor of the convolution layer respectively, * represents the convolution operation, f conv (·) is the convolution function;

[0052] The expression of the activation layer is:

[0053] x conv′ =ReLU(x)=max(xconv ,0),

[0054] Among them, x conv′ ReLU represents the data after the activation function transformation, and ReLU(·) represents the activation function;

[0055] The expression of the pooling layer is:

[0056] x maxpool =max(x conv′ ),

[0057] Among them, x maxpool Represents the output after maximum pooling.

[0058] In the above embodiment, the collected training tasks are input into Figure 2 The meta-module enhanced convolutional neural network shown in the figure performs feature extraction. The meta-module enhanced convolutional neural network is trained in a task-based learning manner. In each iteration, the meta-module enhanced convolutional neural network receives multiple tasks as input and efficiently extracts key features under limited sample conditions, thereby accelerating the learning process.

[0059] In order to enable the meta-module enhanced convolutional neural network to learn more abnormal traffic data features, X convolutional layers are added to extract abnormal traffic features through convolution operations between the convolution kernel and the input data. The output of the input features after processing by the convolution layer is as follows:

[0060]

[0061] Among them, x conv is the output feature of the convolutional layer, x conv-1 is the input feature of the convolutional layer, w conv and b conv are the weight factor and bias factor of the convolution layer, * is the convolution operation, f conv (·) is the convolution function.

[0062] In order to further enhance the feature extraction capability, the meta-module enhanced convolutional neural network uses the ReLU function for nonlinear transformation and limits the output value to a fixed range to improve the performance of the method when processing abnormal traffic data with higher complexity. conv After transformation, it is as follows:

[0063] x conv′ =ReLU(x)=max(x conv ,0),

[0064] Among them, x conv′ is the data after the activation function transformation, and ReLU(·) is the activation function.

[0065] In order to reduce the amount of data processing and improve computational efficiency, this paper adds a pooling layer after the convolution layer and activation function to achieve dimensionality reduction and reduce network parameters. The maximum pooling method can effectively highlight the important features in abnormal traffic data and avoid the problems of over-smoothing of data and loss of key features caused by average pooling. conv′ After pooling, it is as follows:

[0066] x maxpool =max(x conv′ ),

[0067] Among them, x maxpool is the output after max pooling.

[0068] In order to retain the detailed information of the data as much as possible and quickly adapt to new tasks, the embodiment of the present application is designed as follows Figure 2 The meta-module shown in the figure includes a convolution layer, an activation function, and a regularization layer. The meta-module adopts a double convolution layer design, performs two convolution operations in sequence, and introduces a ReLU activation function after each convolution. The stacking of double-layer convolution helps to capture more complex and abstract features, thereby capturing complex feature expressions. The ReLU activation function after each convolution layer introduces nonlinear factors, allowing the module to process complex data more effectively. Through multiple nonlinear transformations, the module's expressive power and ability to process complex data are significantly enhanced. It should be noted that the pooling layer is not used in the meta-module. The pooling layer is usually used to downsample the feature map, but too many pooling operations will cause the feature map size to shrink, thereby losing key information. By omitting the pooling layer, the meta-module retains more detailed features during the convolution process and enhances the expressive power of the data. To prevent overfitting in few-sample tasks, the meta-module introduces the Dropout regularization technique. By randomly discarding some neurons, the model reduces its dependence on specific features, prompting it to learn more extensive and dispersed features, thereby improving generalization performance. At the same time, the introduction of regularization layers also helps control model complexity and enhance the adaptability and stability of meta-modules in different tasks. The meta-module-enhanced convolutional neural network builds a deep structure by repeatedly using convolutional layers, activation functions, pooling layers, and meta-modules, ensuring the scalability and uniformity of the structure, so that the network has strong generalization capabilities while maintaining complex feature extraction.

[0069] In the embodiment of the present application, optionally, the inner loop parameter update based on the gradient descent method includes: during the training process, for the current training task T in each training task, i train , using the loss function The back propagation and meta-objective of are updated through gradient descent to calculate the inner loop parameters; the update formula of the inner loop parameters is Among them, α represents the inner loop parameter learning rate, θ′ iRepresents the trained task T i train The updated model parameters, Indicates that after the current training task T i train Anomaly detection model before update, θ i Represents anomaly detection model Model parameters of

[0070] The expression of the meta-goal is:

[0071]

[0072] The expression of the loss function is:

[0073]

[0074] Among them, T i Represents the current training task, represents the anomaly detection model f φ For training task T i The loss function, X (j) , Y (j) Represents sampling in training task T i The input-output pairs in .

[0075] In the above embodiment, the meta-module enhanced convolutional neural network is composed of f θ Denotes that the parameter is θ. During training, when faced with a new task T i train When using its loss function Back propagation, after gradient descent update, the inner loop parameters are calculated. Each time the model is iteratively trained, multiple training tasks are used. Each iteration sets the input task c, the number of input samples = c·N·K, and the new task T i train The i in represents the i-th task. The inner loop parameters are updated as follows: Among them, α is the inner loop parameter learning rate; the meta-module enhanced convolutional neural network uses the current task T i train Sample loss, optimize the current task T i train Produced To train θ i , we get θ i ', in order to update the model parameters.

[0076] The meta-goals are as follows:

[0077]

[0078] The loss function is as follows:

[0079]

[0080] Among them, X (j) , Y (j) It is an input-output pair sampled in the data set. The input-output pair represents a specific input data sample and the label corresponding to the sample, that is, abnormal traffic data and the corresponding category label.

[0081] In the embodiment of the present application, optionally, the outer loop parameter update based on the multi-step loss function includes: s It is set to dynamically adjust, based on each gradient update loss of each training task, and uses a multi-step loss function to update the outer loop parameters; the expression of the multi-step loss function is:

[0082]

[0083] Where I represents the number of training tasks used in each iteration, S represents the number of gradient updates performed by the anomaly detection model on each training task, β represents the outer loop learning rate, θ represents the model parameters of the anomaly detection model; the loss weight factor v s The calculation formula is:

[0084]

[0085] Among them, E represents the total training rounds, e is the current training round, and v smin is the minimum value of the loss weight factor.

[0086] In the above embodiment, deep meta-learning uses a multi-step loss function when calculating the loss, introducing a loss weight factor v s , taking into account the loss of each gradient update for each task, and finally updating the outer loop parameters

[0087] is the weighted sum of the multiple gradient update losses of multiple tasks. The multi-step loss function is as follows:

[0088]

[0089] Among them, I represents the number of tasks used in each meta-training iteration, S represents the number of gradient updates performed by the model on each task, and β represents the outer loop learning rate. The outer loop parameters are updated through this multi-step loss function, and the model parameters θ are updated as follows: Replace the original θ. In addition, in the embodiment of the present application, v sSet to dynamic adjustment so that the loss after the gradient update step occupies a greater weight in the model parameter update. In this process, the larger s is, the greater the proportion of the calculated loss in the overall loss calculation, guiding the model to adjust the parameters more carefully and avoid falling into the local optimal solution.

[0090] Loss of weight factor v s as follows:

[0091]

[0092] Among them, S represents the number of gradient updates performed by the model on each task, E is the total number of training rounds, e is the current training round, and v smin is the minimum value of the loss weight factor.

[0093] In the embodiment of the present application, optionally, the method further comprises: updating the outer loop learning rate using a cosine annealing algorithm. The learning rate update formula is:

[0094]

[0095] Among them, β CA is the learning rate after the cosine annealing algorithm, b is a constant, lr max is the maximum learning rate setting, lr min is the minimum learning rate set, it c is the current iteration number, it max is the total number of iterations. The outer loop learning rate of the anomaly detection model performs a parameter update in each iteration, and each iterative training uses multiple training tasks.

[0096] In this embodiment, in order to avoid the problem of falling into local optimum and unstable training caused by the static learning rate of the outer loop, the present application adopts the cosine annealing algorithm to dynamically adjust the learning rate, so that the model converges quickly with a higher learning rate in the early stage of training, and achieves more stable parameter optimization in the later stage as the learning rate decreases, avoiding falling into local optimum. The learning rate update process is as follows: Among them, β CA is the outer loop learning rate after the cosine annealing algorithm changes, b is a constant, for example, set to 0.5, lr max is the maximum learning rate setting, lr min It is the minimum learning rate. c is the current iteration number, it max is the total number of iterations, and the model performs a parameter update in each iteration.

[0097] In the embodiment of the present application, optionally, after step 103, a method for testing the trained anomaly detection model is also included, including:

[0098] Step 1: Acquire new abnormal traffic data from the industrial control system and construct a test set, wherein the test set includes samples of multiple categories, and the test set includes sample categories that belong to different subcategories under the same parent category as the sample categories in the abnormal traffic data;

[0099] Step 2: Sample the abnormal traffic data in the test set to obtain a test task. The test task T i Includes samples of N categories, and each category includes K samples;

[0100] Step 3: input the test task into the trained anomaly detection model, fine-tune the anomaly detection model based on the model output result, and input the samples in the test set except those sampled into the test task into the fine-tuned anomaly detection model to determine whether the traffic data is abnormal based on the model output result;

[0101] Step 4: Determine the model performance of the anomaly detection model based on the model output results and the corresponding sample categories.

[0102] In this embodiment, the collected numerical single-row data of abnormal traffic of the industrial control system is first processed into images, converted into data in the form of images, and a test set of abnormal traffic data is constructed. The specific method is the same as the method of constructing the abnormal traffic data set, which will not be repeated here. The test set has no intersection with the abnormal traffic categories in the training set in the previous text, and there is no data duplication. Among them, the abnormal traffic category refers to the specific abnormal cause (i.e., subclass) under a certain abnormal situation (i.e., parent category). For example, the abnormal situation of denial of service can correspond to multiple abnormal causes, and each abnormal cause corresponds to an abnormal traffic category. The abnormal traffic categories included in the test set have no intersection with the abnormal traffic categories included in the abnormal traffic data used for model training in the above text, but the abnormal situations corresponding to the abnormal traffic categories in the test set belong to the abnormal situations corresponding to the abnormal traffic categories included in the abnormal traffic data. The goal of meta-learning is to enable the model to quickly adapt to new tasks (i.e., categories that have not been seen) based on the learned tasks. There is no duplication in the categories of the test set and the training set. If the model performs well on the test set, it can be said that it can have the same excellent detection ability for completely new categories that have not been learned. Figure 3 As shown in Figure 1, after obtaining the training model in a given training cycle, anomaly detection test is performed. First, the test set is input into the saved training model. The image data in the test set (i.e., the samples in the test set) is sampled to obtain the test task T. i , each task T i There are N categories and K samples. The test task T i Enter the meta-module enhanced convolutional neural network for feature extraction and use the following formula to calculate the task T i The loss value

[0103]

[0104] Among them, X (j) , Y (j) is the input-output pair in the test task. The following formula is used to obtain the fine-tuned parameters θ of the convolutional neural network enhanced by the K sample data pairs. i ′, Among them, α is the inner loop parameter learning rate. Test task T i The remaining samples are used to enter the meta-module enhanced convolutional neural network for anomaly detection to verify the effect of model fine-tuning. After fine-tuning, the meta-module enhanced convolutional neural network outputs the predicted label results of the samples to determine the category of the traffic data and whether it is abnormal. The model performance is further evaluated based on the model's predicted label results and the corresponding sample categories.

[0105] By applying the technical solution of this embodiment, an industrial control system anomaly detection method based on deep meta-learning is proposed. Among them, the inner loop extracts sample features, and the outer loop dynamically updates parameters to improve the generalization ability of the model and meet the needs of few sample detection. Then, a meta-module enhanced convolutional neural network is designed, and the inner loop model parameters are updated based on the gradient descent method to improve the feature extraction ability. Furthermore, an outer loop model parameter update algorithm based on a multi-step loss function is proposed to improve the algorithm stability. At the same time, the cosine annealing algorithm is used to dynamically update the outer loop learning rate to solve the problem of insufficient generalization ability of the algorithm.

[0106] The embodiment of the present application also provides a computer device, which can be a personal computer, a server, a network device, etc. The computer device includes a bus, a processor, a memory and a communication interface, and can also include an input and output interface and a display device. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store location information. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, the steps in each method embodiment are implemented.

[0107] Those skilled in the art will appreciate that the structure of the above-mentioned computer device is only a partial structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components, or combine certain components, or have a different arrangement of components.

[0108] In one embodiment, a computer-readable storage medium is provided. The computer-readable storage medium may be non-volatile or volatile, and stores a computer program thereon. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.

[0109] In one embodiment, a computer program product is provided, including a computer program, which implements the steps in the above method embodiments when executed by a processor.

[0110] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.

[0111] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. Non-relational databases may include distributed databases based on blockchains, etc., but are not limited to this. The processor involved in each embodiment provided in this application may be a general-purpose processor, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., but are not limited to this.

[0112] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0113] The above-described embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.

Claims

1. A method for detecting anomalies in industrial control systems based on deep meta-learning, characterized in that: The method comprises: Collecting abnormal flow data of the industrial control system, and constructing an abnormal flow data set based on the abnormal flow data of the industrial control system; Performing multi-category and multi-sample random task sampling on the abnormal traffic data set to obtain multiple training tasks; The anomaly detection model is trained using the training task, wherein the anomaly detection model includes a convolutional neural network based on meta-module enhancement, and during the training process, inner loop parameters are updated based on a gradient descent method, outer loop parameters are updated based on a multi-step loss function, and outer loop learning rate is updated based on a cosine annealing algorithm; The trained anomaly detection model is used to perform anomaly detection on traffic data.

2. The method according to claim 1, characterized in that The collecting of abnormal flow data of the industrial control system and constructing an abnormal flow data set based on the abnormal flow data of the industrial control system include: Acquire feature data containing abnormal behavior characteristics from the industrial control system communication traffic; Using an average distribution method to evenly distribute the feature data into a matrix at the same interval, so as to convert the feature data from numerical single-row data into two-dimensional matrix data, wherein different feature data are represented by different numerical values, and positions without feature data are filled with zero values; The two-dimensional matrix data is subjected to image-based three-dimensional data structure mapping to be converted into RGB image data to obtain the abnormal flow data, and the abnormal flow data set is constructed.

3. The method according to claim 1, characterized in that The abnormal traffic data set includes samples of multiple categories; the multi-category and multi-sample random task sampling is performed on the abnormal traffic data set to obtain multiple training tasks, including: Random task sampling is performed on the abnormal traffic data set to obtain multiple training tasks, wherein each training task contains samples of N categories, and each category includes K samples, and the number of sample categories in the abnormal traffic data set is greater than N.

4. The method according to claim 1, characterized in that: The anomaly detection model includes a feature extraction network, a fully connected layer, and an output layer. The feature extraction network includes a plurality of feature extraction units connected in sequence, each feature extraction unit includes a convolutional layer, an activation layer, a pooling layer, and a meta-module in sequence, and the meta-module includes a convolutional layer, an activation layer, a convolutional layer, an activation layer, and a regularization layer in sequence.

5. The method according to claim 1, characterized in that The inner loop parameter updating based on the gradient descent method includes: During the training process, for the current training task in each training task, the back propagation of the loss function and the meta-objective are used to obtain the inner loop parameters through gradient descent update.

6. The method according to claim 5, characterized in that The outer loop parameter updating based on the multi-step loss function includes: The weight loss factor is set to be dynamically adjusted, the loss is updated based on each gradient of each training task, and a multi-step loss function is used to update the outer loop parameters.

7. The method according to claim 6, characterized in that The method further comprises: The outer loop learning rate is updated based on the cosine annealing algorithm.

8. The method according to claim 1, characterized in that After the anomaly detection model is trained using the training task, the method further includes: Step 1: Acquire new abnormal traffic data from the industrial control system and construct a test set, wherein the test set includes samples of multiple categories, and the test set includes sample categories that belong to different subcategories under the same parent category as the sample categories in the abnormal traffic data; Step 2: Sample the abnormal traffic data in the test set to obtain a test task. The test task T i Includes samples of N categories, and each category includes K samples; Step 3: input the test task into the trained anomaly detection model, fine-tune the anomaly detection model based on the model output result, and input the samples in the test set except those sampled into the test task into the fine-tuned anomaly detection model to determine whether the traffic data is abnormal based on the model output result; Step 4: Determine the model performance of the anomaly detection model based on the model output results and the corresponding sample categories.

9. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 8 is implemented.

10. A computer device comprising a storage medium, a processor, and a computer program stored in the storage medium and executable on the processor, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 8 is implemented.

Citation Information

Cited By

  • Multi-mode split-flow aerobic granular sludge reactor and control method thereof

    CN120943419A