Internet of Things security protection system and method based on artificial intelligence
By adopting a security protection system based on artificial intelligence in the Internet of Things network, building a network state prediction model and topology diagram structure, it solves the problem that traditional systems are difficult to cope with dynamic IoT networks and real-time attacks, and achieves stronger adaptability and early warning capabilities, reducing security risks.
Patent Information
- Application Number
- CN202510154588.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-12
- Publication Date
- 2025-05-13
AI Technical Summary
Traditional IoT security protection systems are difficult to deal with dynamic IoT networks and cannot respond to real-time attacks and network failures in a timely manner, especially when dealing with complex distributed denial of service attacks and device hijacking, which is significant latency.
The Internet of Things security protection system based on artificial intelligence is adopted to collect equipment data and communication data through the data acquisition module, and after preprocessing, the topology diagram structure is constructed, the network status prediction model is used to predict equipment status scores, and protection measures are generated based on the scores.
Effectively respond to dynamic changes in the Internet of Things network, improve real-time monitoring capabilities of device status, accurately predict potential device failures or network attacks, quickly take protective measures, reduce security risks, and improve system adaptability and early warning capabilities.
Smart Images

Figure CN119995999A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of Internet of Things equipment monitoring, and specifically relates to an Internet of Things security protection system and method based on artificial intelligence. Background Art
[0002] With the rapid popularization of IoT technology, the IoT network environment is becoming more and more complex and dynamic. IoT devices are of various types and are used in various application scenarios, from smart homes to industrial IoT. Their network structure, device status and communication links change frequently. Traditional methods rely on static rules and signature libraries, which are difficult to cope with the dynamic characteristics of IoT networks, such as frequent device up and down and topology changes. In the face of real-time attacks and network failures, traditional methods are usually unable to respond in time, especially when dealing with complex distributed denial of service attacks and device hijacking, with significant delays.
[0003] Therefore, there is an urgent need for an Internet of Things security protection system and method to solve the above problems. Summary of the invention
[0004] The present invention provides an Internet of Things security protection system and method based on artificial intelligence, which solves the technical problems in related technologies that the system cannot cope with dynamic Internet of Things networks and cannot respond to real-time attacks and network failures in a timely manner.
[0005] The present invention provides an Internet of Things security protection system and method based on artificial intelligence, including:
[0006] A data acquisition module, which is used to collect device data of M devices in a region G within a first preset time period T and communication data between devices according to a preset time interval t, and represent the device data of the device and the communication data between devices at each time point by a first feature sequence; the mth sequence unit of the first feature sequence at the nth time point represents the device data of the mth device at the nth time point and the communication data between other devices with which the data is transmitted, wherein 1≤m≤M, 1≤n≤N, and N=T / t;
[0007] Device data includes: device serial number, device type, device operating status, memory usage, signal strength, and battery status;
[0008] Communication data includes: communication frequency, bandwidth and latency;
[0009] A preprocessing module, which is used to perform data preprocessing on the first feature sequence to obtain a second feature sequence;
[0010] A topology construction module is used to construct a topology structure according to the second feature sequence, wherein the topology structure includes: nodes, initial features of nodes, edges and initial features of edges; a mapping relationship is established between nodes and devices, a mapping relationship is established between the initial features of nodes and device data of devices for which the mapping relationship is established, and a mapping relationship is established between the initial features of edges and communication data between devices;
[0011] A network status prediction module, which is used to construct a network status prediction model according to the topology structure, the input of the network status prediction model is the topology structure, and the output is the status score of M devices in the area G within the second preset time period Q; the value range of the status score is an integer from 0 to 100, indicating the status of the device from high risk to safe;
[0012] The protection measure generation module is used to generate protection measures according to the status scores of M devices in the area G within the second preset time period Q.
[0013] Furthermore, T, t, M, m, G, N, n, and Q are all custom parameters.
[0014] Furthermore, the device type, device working status, memory usage, signal strength and battery status are represented by real number codes, and the communication frequency represents the number of communications between devices, and the communication frequency is represented by real number codes.
[0015] Furthermore, the pre-processing step includes:
[0016] Step S201, check device data and remove duplicate values in the device data;
[0017] Step S202, the missing values in the device data are filled by taking the average value of the value of the previous sequence unit and the value of the next sequence unit;
[0018] Step S203, normalizing the first feature sequence by using a z-score normalization method.
[0019] Furthermore, the edges in the topology graph structure are constructed through wired connections and wireless connections between devices. The wired connection means that the devices are connected through physical cables, and the wireless connection means that the devices communicate and transmit data through network protocols.
[0020] Further, the network state prediction model includes a hidden layer and a classifier;
[0021] The hidden layer includes N first units, the nth first unit inputs the topological graph structure at the nth time point, and outputs the first updated feature at the nth time point;
[0022] The input of the classifier is the first updated feature of the node at the Nth time point, and the classification space of the classifier represents the state score of the node.
[0023] Furthermore, the nth first unit of the hidden layer inputs the topological graph structure at the nth time point, updates the feature of the mth node at the nth time point, and updates the node feature weight matrix through the gated recurrent unit, and the formula includes:
[0024]
[0025]
[0026] in represents the feature of the mth node at the n+1th time point, represents the feature of the mth node at the nth time point, W n represents the node feature weight matrix at the nth time point, represents the feature of the edge between node m and node j at the nth time point, W e represents the feature weight matrix of the edge, It indicates that the node feature weight matrix is updated according to the node feature weight matrix and node features at the n-1th time point through the gated recurrent unit.
[0027] Furthermore, by deploying intelligent computing nodes at the edge of the network, local computing and decision-making can be performed.
[0028] Furthermore, in the data collection and preprocessing stage, Gaussian noise is added to the existing samples to simulate the uncertainty in the environment. The formula is: ε~K(0,σ 2 ), where x represents the collected data, represents the data after noise processing, ε represents the noise with mean 0 and standard deviation σ.
[0029] Furthermore, by using Simulink professional modeling software, the device data and communication data of the equipment in area G are combined to build a digital twin model of the Internet of Things; through simulation, the device and communication data are collected as sample data of the network status prediction model; according to the preset system operating environment, manual annotation is used to generate sample labels for the network status prediction model for the collected data.
[0030] Furthermore, the status scores of the M devices in the area G in the second preset time period Q are divided into four levels. The status scores between 76 and 100 are the safety level, and no protective measures are taken at the safety level; the status scores between 51 and 75 are the low-risk level, and the protective measures for the low-risk level are to increase the monitoring frequency and conduct regular inspections; the status scores between 26 and 50 are the medium-risk level, and the protective measures for the medium-risk level are to immediately inspect the device and dispatch technicians to repair or replace the device; the status scores between 0 and 25 are the high-risk level, and the protective measures for the high-risk level are to immediately isolate the device, disconnect the network connection, and repair or replace the device.
[0031] The present invention provides an Internet of Things security protection method based on artificial intelligence, comprising the following steps:
[0032] Step S301, collecting device data of M devices in a region G within a first preset time period T and communication data between devices at a preset time interval t;
[0033] Step S302, performing data preprocessing on the device data of the M devices and the communication data between the devices to obtain a second feature sequence;
[0034] Step S303, constructing a topological graph structure according to the second characteristic sequence;
[0035] Step S304, constructing a network status prediction model according to the topology structure and predicting the status score of the device;
[0036] Step S305: Generate protection measures according to the status score of the device.
[0037] The beneficial effect of the present invention is that the network status prediction model constructed by the present invention dynamically updates the weight matrix through GRU, and updates the node features in combination with the features of the edges in the topology graph, which can effectively cope with the dynamic changes of the Internet of Things network. The model not only improves the real-time monitoring capability of the device status, but also can accurately predict potential device failures or network attacks, and then quickly take protective measures to reduce security risks. Through dynamic adjustment, the system has stronger adaptability and early warning capabilities, ensuring the security and stability of the Internet of Things network. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] Figure 1 It is a module schematic diagram of an Internet of Things security protection system based on artificial intelligence of the present invention;
[0039] Figure 2 It is a flow chart of an Internet of Things security protection method based on artificial intelligence of the present invention.
[0040] In the figure: a data collection module 101, a preprocessing module 102, a topology map building module 103, a network status prediction module 104 and a protection measure generation module 105. DETAILED DESCRIPTION
[0041] The subject matter described herein will now be discussed with reference to example embodiments. It should be understood that the discussion of these embodiments is only to enable those skilled in the art to better understand and implement the subject matter described herein, and the functions and arrangements of the elements discussed may be changed without departing from the scope of protection of the contents of this specification. Each example may omit, replace or add various processes or components as needed. In addition, the features described relative to some examples may also be combined in other examples.
[0042] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in one or more embodiments of the present invention should be understood by people with ordinary skills in the field to which the present invention belongs. The words "first", "second" and similar words used in one or more embodiments of the present invention do not indicate any order, quantity or importance, but are only used to distinguish different components. "Include" or "comprise" and similar words mean that the elements or objects appearing before the word include the elements or objects listed after the word and their equivalents, without excluding other elements or objects. "Connect" or "connected" and similar words are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. "Up", "down", "left", "right" and the like are only used to indicate relative positional relationships. When the absolute position of the described object changes, the relative positional relationship may also change accordingly.
[0043] like Figure 1-Figure 2 As shown, an IoT security protection system based on artificial intelligence includes:
[0044] The data collection module 101 is used to collect device data of M devices in a region G within a first preset time period T and communication data between devices according to a preset time interval t, and represent the device data of the device and the communication data between devices at each time point by a first feature sequence; the mth sequence unit of the first feature sequence at the nth time point represents the device data of the mth device at the nth time point and the communication data between other devices that perform data transmission with it, wherein 1≤m≤M, 1≤n≤N, and N=T / t;
[0045] Device data includes: device serial number, device type, device operating status, memory usage, signal strength, and battery status;
[0046] Communication data includes: communication frequency, bandwidth and latency;
[0047] A preprocessing module 102, which is used to perform data preprocessing on the first feature sequence to obtain a second feature sequence;
[0048] A topology construction module 103 is used to construct a topology structure according to the second feature sequence, wherein the topology structure includes: nodes, initial features of nodes, edges and initial features of edges; a mapping relationship is established between nodes and devices, a mapping relationship is established between the initial features of nodes and device data of devices for which a mapping relationship is established, and a mapping relationship is established between the initial features of edges and communication data between devices;
[0049] The network status prediction module 104 is used to construct a network status prediction model according to the topology structure. The input of the network status prediction model is the topology structure, and the output is the status score of M devices in the area G within the second preset time period Q. The value range of the status score is an integer from 0 to 100, indicating the status of the device from high risk to safe;
[0050] The protection measure generating module 105 is used to generate protection measures according to the status scores of the M devices in the area G within the second preset time period Q.
[0051] In one embodiment of the present invention, T, t, M, m, G, N, n and Q are all custom parameters. Preferably, T is set to 20 minutes and t is set to 1 minute.
[0052] In one embodiment of the present invention, device types include: temperature sensors, gas sensors, smart lamps, smart sockets, smart air conditioners and washing machines, and the device types are represented by real number codes 1 to 6, for example, smart sockets are represented by 4; device working states include online and offline, and the device working states are represented by real number codes, for example, online is represented by 1, and offline is represented by 0; memory usage is represented by real number codes, for example, when the memory usage is 73%, it is represented by 73; signal strength includes: weak, medium and strong, and the signal strength is represented by real number codes 1 to 3, for example, when the signal strength is medium, it is represented by 2; battery status includes: poor, medium, good and excellent, and the battery status is represented by real number codes 1 to 4, for example, when the battery status is poor, it is represented by 1; the communication frequency represents the number of communications between devices, and the communication frequency is represented by a real number code.
[0053] In one embodiment of the present invention, the pre-processing step includes:
[0054] Step S201, check device data and remove duplicate values in the device data;
[0055] Step S202, the missing values in the device data are filled by taking the average value of the value of the previous sequence unit and the value of the next sequence unit;
[0056] Step S203, normalizing the first feature sequence by using a z-score normalization method.
[0057] In one embodiment of the present invention, the edges in the topological graph structure are constructed by wired connections and wireless connections between devices. The wired connection means that the devices are connected by physical cables, and the wireless connection means that the devices communicate and transmit data through network protocols, such as Ethernet protocol, WiFi protocol and Bluetooth protocol.
[0058] In one embodiment of the present invention, the network status prediction model includes a hidden layer and a classifier;
[0059] The hidden layer includes N first units, the nth first unit inputs the topological graph structure at the nth time point, and outputs the first updated feature at the nth time point;
[0060] The input of the classifier is the first updated feature of the node at the Nth time point, and the classification space of the classifier represents the state score of the node.
[0061] In one embodiment of the present invention, the nth first unit of the hidden layer inputs the topological graph structure at the nth time point, updates the feature of the mth node at the nth time point, and updates the node feature weight matrix through the gated recurrent unit, and the formula includes:
[0062]
[0063]
[0064] in represents the feature of the mth node at the n+1th time point, represents the feature of the mth node at the nth time point, W n represents the node feature weight matrix at the nth time point, represents the feature of the edge between node m and node j at the nth time point, W e represents the feature weight matrix of the edge, It means that the node feature weight matrix is updated according to the node feature weight matrix and node features at the n-1th time point through the gated recurrent unit. It is worth noting that it can also be
[0065] In one embodiment of the present invention, by deploying intelligent computing nodes at the edge of the network (such as routers, gateways, terminal devices, etc.) to perform local computing and decision-making, the pressure of transmitting all data to the central server can be reduced. For the network status prediction model, it can be distributed to multiple edge nodes for execution. Each node processes the device data and communication data within its monitoring range, calculates the status score of the device in real time, and executes preset protection measures based on the status score, such as adjusting network traffic, allocating bandwidth, and blocking suspicious devices to prevent threats from spreading to the entire network; when multiple edge nodes detect a threat, the information can be aggregated to the central server for further analysis.
[0066] In one embodiment of the present invention, during the data collection and preprocessing stage, Gaussian noise can be added to the existing samples to simulate the uncertainty in the environment, while increasing the diversity of the training data and improving the generalization ability of the network state prediction model. The formula is: ε~K(0,σ 2 ), where x represents the collected data, represents the data after noise processing, ε represents the noise with mean 0 and standard deviation σ.
[0067] In one embodiment of the present invention, a digital twin model is constructed by using Simulink professional modeling software, combining the device data and communication data of the devices in area G. The model can simulate real operating environments such as device failure, communication interruption, and network attack. Through simulation, the device and communication data are collected as sample data for the network status prediction model; according to the preset system operating environment, labels are generated for the collected data using manual annotation, thereby providing training data and labels for the network status prediction model for model training and optimization.
[0068] In one embodiment of the present invention, the status scores of M devices in the area G in the second preset time period Q are divided into four levels. The status scores of 76 to 100 are security levels, and no protective measures are taken at the security level; the status scores of 51 to 75 are low-risk levels, and there are slight abnormalities in the equipment. At this time, the monitoring frequency is increased and regular inspections are performed; the status scores of 26 to 50 are medium-risk levels, and the equipment may be attacked. At this time, the equipment should be checked immediately and technicians should be dispatched to repair or replace the equipment; the status scores of 0 to 25 are high-risk levels, and the equipment may have been attacked or seriously malfunctioned. At this time, the equipment should be isolated immediately, the network connection should be disconnected, and the equipment should be repaired or replaced.
[0069] In one embodiment of the present invention, Figure 2 As shown, the present invention provides an Internet of Things security protection method based on artificial intelligence, comprising the following steps:
[0070] Step S301, collecting device data of M devices in a region G within a first preset time period T and communication data between devices at a preset time interval t;
[0071] Step S302, performing data preprocessing on the device data of the M devices and the communication data between the devices to obtain a second feature sequence;
[0072] Step S303, constructing a topological graph structure according to the second characteristic sequence;
[0073] Step S304, constructing a network status prediction model according to the topology structure and predicting the status score of the device;
[0074] Step S305: Generate protection measures according to the status score of the device.
[0075] The above describes an embodiment of the present embodiment, but the present embodiment is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of the present embodiment, ordinary technicians in this field can also make many forms, all of which are within the protection of the present embodiment.
Claims
1. An IoT security protection system based on artificial intelligence, characterized in that: include: A data collection module, which is used to collect device data and inter-device communication data of M devices in a region G within a first preset time period T at a preset time interval t, and represent the device data and inter-device communication data of the device at each time point by a first feature sequence; The mth sequence unit of the first characteristic sequence at the nth time point represents the device data of the mth device at the nth time point and the communication data between the device and other devices that perform data transmission therewith, where 1≤m≤M, 1≤n≤N, and N=T / t; Device data includes: device serial number, device type, device operating status, memory usage, signal strength, and battery status; Communication data includes: communication frequency, bandwidth and latency; A preprocessing module, which is used to perform data preprocessing on the first feature sequence to obtain a second feature sequence; A topology construction module is used to construct a topology structure according to the second feature sequence, wherein the topology structure includes: nodes, initial features of nodes, edges and initial features of edges; a mapping relationship is established between nodes and devices, a mapping relationship is established between the initial features of nodes and device data of devices for which the mapping relationship is established, and a mapping relationship is established between the initial features of edges and communication data between devices; A network status prediction module, which is used to construct a network status prediction model according to the topology structure, the input of the network status prediction model is the topology structure, and the output is the status score of M devices in the area G within the second preset time period Q; the value range of the status score is an integer from 0 to 100, indicating the status of the device from high risk to safe; The protection measure generation module is used to generate protection measures according to the status scores of M devices in the area G within the second preset time period Q.
2. The IoT security protection system based on artificial intelligence according to claim 1 is characterized in that: T, t, M, m, G, N, n, and Q are custom parameters.
3. The IoT security protection system based on artificial intelligence according to claim 1 is characterized in that: The device type, device working status, memory usage, signal strength and battery status are represented by real number codes. The communication frequency represents the number of communications between devices. The communication frequency is represented by real number codes.
4. The IoT security protection system based on artificial intelligence according to claim 1 is characterized in that: The edges in the topology graph are constructed through wired and wireless connections between devices. Wired connections mean that devices are connected through physical cables, and wireless connections mean that devices communicate and transmit data through network protocols.
5. The IoT security protection system based on artificial intelligence according to claim 1 is characterized in that: The network status prediction model includes a hidden layer and a classifier; The hidden layer includes N first units, the nth first unit inputs the topological graph structure at the nth time point, and outputs the first updated feature at the nth time point; The input of the classifier is the first updated feature of the node at the Nth time point, and the classification space of the classifier represents the state score of the node.
6. The IoT security protection system based on artificial intelligence according to claim 5 is characterized in that: The nth first unit of the hidden layer inputs the topological graph structure at the nth time point, updates the features of the mth node at the nth time point, and updates the node feature weight matrix through the gated recurrent unit. The formula includes: in represents the feature of the mth node at the n+1th time point, represents the feature of the mth node at the nth time point, W n represents the node feature weight matrix at the nth time point, represents the feature of the edge between node m and node j at the nth time point, W e represents the feature weight matrix of the edge, It indicates that the node feature weight matrix is updated according to the node feature weight matrix and node features at the n-1th time point through the gated recurrent unit.
7. The IoT security protection system based on artificial intelligence according to claim 1 is characterized in that: By deploying intelligent computing nodes at the edge of the network, local computing and decision-making can be performed.
8. The IoT security protection system based on artificial intelligence according to claim 1 is characterized in that: By using Simulink professional modeling software, the device data and communication data of the equipment in area G are combined to build an IoT digital twin model. Through simulation, the device and communication data are collected as sample data for the network status prediction model. According to the preset system operating environment, sample labels for the network status prediction model are generated for the collected data using manual annotation.
9. The IoT security protection system based on artificial intelligence according to claim 1, characterized in that: The status scores of the M devices in the area G in Q during the second preset time period are divided into four levels: a status score between 76 and 100 is a safe level, and no protective measures are taken at the safe level; a status score between 51 and 75 is a low-risk level, and the protective measures for the low-risk level are to increase the monitoring frequency and conduct regular inspections; a status score between 26 and 50 is a medium-risk level, and the protective measures for the medium-risk level are to immediately inspect the device and dispatch technicians to repair or replace the device; a status score between 0 and 25 is a high-risk level, and the protective measures for the high-risk level are to immediately isolate the device, disconnect the network connection, and repair or replace the device.
10. An Internet of Things security protection method based on artificial intelligence, characterized in that: An artificial intelligence-based IoT security protection system as described in any one of claims 1 to 9 is adopted, comprising the following steps: Step S301, collecting device data of M devices in a region G within a first preset time period T and communication data between devices at a preset time interval t; Step S302, performing data preprocessing on the device data of the M devices and the communication data between the devices to obtain a second feature sequence; Step S303, constructing a topological graph structure according to the second characteristic sequence; Step S304, constructing a network status prediction model according to the topology structure and predicting the status score of the device; Step S305: Generate protection measures according to the status score of the device.
Citation Information
Patent Citations
Highway traffic condition detection system based on artificial intelligence
CN118887802A
Regional communication local area network construction method based on digital twinning
CN119232598A
Monitoring and early warning system and method based on digital eagle eyes
CN119356231A