Automobile network security knowledge reasoning method based on graph neural network
By applying the knowledge inference method based on graph neural networks in the field of Internet of Vehicles security, the problem of insufficient knowledge inference ability in the existing technology is solved, more efficient and accurate knowledge inference is achieved, and the protection and response capabilities of Internet of Vehicles security are improved.
Patent Information
- Application Number
- CN202510074263.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-17
- Publication Date
- 2025-05-16
AI Technical Summary
The existing knowledge reasoning methods have problems such as insufficient semantic and structural learning ability, inference accuracy and inefficiency in the field of Internet of Vehicles security, especially when dealing with complex automotive network security knowledge graphs.
The automotive network security knowledge inference method based on graph neural network is adopted, and low-dimensional vector representation of entities and relationships, local subgraph sampling, heterogeneous graph attention network feature aggregation and implicit relationship prediction are realized through the knowledge graph embedding module, data preprocessing module, graph neural network modeling module and decoder module.
It improves the semantic and structural learning ability of the knowledge inference model, improves the accuracy and efficiency of inference, can more effectively process large-scale automotive network security knowledge graphs, and enhances the protection and response capabilities of Internet of Vehicles security.
Smart Images

Figure CN120012822A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of Internet of Vehicles security, and in particular to an automobile network security knowledge reasoning method based on graph neural network in Internet of Vehicles security. Background Art
[0002] In the context of the development of the new era, the security of the Internet of Vehicles has become one of the key research topics in the automotive industry. The Internet of Vehicles can provide users with efficient and convenient services, but with the increasing richness of its functions and the continuous growth of data volume, the complexity of the network structure has gradually increased. The actual situation shows that while the Internet of Vehicles realizes high-frequency interaction between vehicles and external devices, it also faces potential network security threats, which may extend from the network level to the personal safety level of drivers and passengers. In addition, compared with traditional networks, the security of the Internet of Vehicles has more complex scenarios and higher risk protection requirements. To this end, by constructing an automotive network security knowledge graph and carrying out knowledge reasoning tasks based on the graph, implicit relationships can be effectively discovered to enhance the security protection capabilities and threat response capabilities of the Internet of Vehicles.
[0003] With the development of research on knowledge graph-related technologies, knowledge reasoning tasks have become an important task in the downstream tasks of knowledge graphs. Existing research can be roughly divided into reasoning methods based on logical rules, reasoning methods based on representation learning, and reasoning methods based on neural networks. Reasoning methods based on logical rules use predefined rules or statistical features for statistics, which are interpretable, but cannot be used in large-scale graphs and cannot handle complex reasoning problems; reasoning methods based on representation learning map entities and relationships to low-dimensional vectors to obtain distributed representations, and then perform implicit association relationship reasoning, but do not consider the deep connection between node relationships, and have limited reasoning capabilities; with the development of deep learning technology, reasoning methods based on neural networks have achieved good results in the field of knowledge reasoning by using better learning and reasoning capabilities, but existing reasoning methods based on neural networks also have some limitations, which are more dependent on the quality of training samples, lack long-range reasoning capabilities, and fail to benefit global entity and relationship information.
[0004] Therefore, in order to improve the semantic and structural learning capabilities of the knowledge reasoning model and improve the accuracy and efficiency of reasoning, the present invention proposes an automotive network security knowledge reasoning method based on graph neural network. Summary of the invention
[0005] In order to overcome the above-mentioned shortcomings of the prior art, a method for reasoning automotive network security knowledge based on graph neural network is proposed. The technical solution of the present invention is as follows:
[0006] A method for reasoning automotive network security knowledge based on graph neural network, characterized by comprising: a knowledge graph embedding module, a data preprocessing module, a graph neural network modeling module and a decoder module, a total of four parts; wherein the knowledge graph embedding module is used to map entities and relationships into low-dimensional vector representations to generate knowledge graph embedding;
[0007] The data preprocessing module is used to extract the target entity and its multi-hop neighbor relationship through a sampling mechanism and construct a local subgraph; the graph neural network modeling module is used to calculate the feature weights of the entity and its neighbors through a graph attention network based on a heterogeneous graph, aggregate high-order semantic information, and generate updated entity and relationship vectors;
[0008] The decoder module is used to input the vector output by the graph neural network into the ConvKB decoder, calculate the triple score through convolution operation, and predict the implicit relationship that may exist between entities.
[0009] Furthermore, the knowledge graph embedding module is used to map entities and relationships into low-dimensional vector representations to generate knowledge graph embedding, specifically including:
[0010] Each entity in the knowledge graph is represented in text form and standardized. At the same time, a unique serial number is assigned to each entity, starting from 0 and increasing in sequence, to generate a mapping dictionary between entities and serial numbers. Initialize a low-dimensional vector with dimension d for each entity serial number, generate a mapping dictionary from serial number to embedded vector, then extract each edge type r in the knowledge graph, assign a unique serial number to each relationship type, starting from 0 and increasing in sequence, and generate a mapping dictionary between relationship and serial number A low-dimensional vector is initialized for each relationship number, and a mapping dictionary from the number to the embedded vector is generated. Finally, an automotive cybersecurity knowledge graph (V, E, R) represented by a vector can be obtained, where V represents the set of all entities in the knowledge graph, E represents the set of edges between all entities in the knowledge graph, and R represents the set of all relationship categories in the knowledge graph.
[0011] Furthermore, the data preprocessing module is used to extract the target entity and its multi-hop neighbor relationship through a sampling mechanism to construct a local subgraph, which specifically includes:
[0012] By selecting the nodes to be sampled, assuming that the sampled node set is V t-1 , represents the set of entities that have been visited in step t-1, and the node set can be expanded to obtain N(V t-1), which means starting from the node in step t-1, the neighboring nodes that can be accessed in one hop are constructed, and the candidate node set is then removed from the neighboring node set to avoid redundancy, and the candidate node set for step t is obtained. Then candidate nodes are sampled from Select a subset as the next target node set Where SAMP() represents sampling from candidate nodes, and the obtained V t The node set after incremental sampling includes the currently visited node set and the new node set obtained by sampling. Through iterative multi-step expansion, a node subgraph containing multiple jump relationships can be constructed. At the same time, in order to improve the accuracy and generalization of the model, positive and negative sampling is introduced. By constructing links that do not exist in the original knowledge graph, negative samples are generated, and the training subgraph is further processed.
[0013] Furthermore, the graph neural network modeling module is used to calculate the feature weights of entities and their neighbors through a graph attention network based on a heterogeneous graph, aggregate high-order semantic information, and generate updated entity and relationship vectors, specifically including:
[0014] After knowledge graph embedding and data preprocessing, the input graph structure G = (V, E, R), where V represents the set of low-dimensional embedding vectors of entities, R represents the set of embedding vectors of each relationship type, and E represents the set of edges between entities under a certain relationship. A graph neural network based on the heterogeneous graph attention mechanism is constructed to perform feature aggregation on nodes. For each entity node v, information is aggregated from its neighbor node set to obtain in is the attention weight, which represents the attention weight of node u to node v, W(l) represents the trainable weight matrix of the lth layer, represents the embedding vector of the neighbor node u at layer l. Since there are different types of relationships in the graph, it is also necessary to model the relationship type. k , introducing an independent change matrix By designing an independent weight matrix for each relationship, the characteristics of different relationship types are represented. However, in the above node information aggregation process, information is transmitted through an independent weight matrix, and the embedding of each node is simply spliced through information of different relationship categories. However, in actual situations, the information between nodes of different relationship categories may have different weights. In graph neural networks, by introducing the attention mechanism, the importance of each neighbor to the target node is measured by dynamically assigning weights to neighbor nodes. The attention weight in is a trainable attention vector used to calculate the similarity between nodes, || represents the concatenation operation of the vector, LeakyReLU is the activation function, and after aggregating the neighbor node information, the node embedding is updated through the activation function. σ is the activation function, The neighbor information is aggregated in the above process. Then, L layers of graph neural networks are stacked to capture high-order neighbor information. Through multi-layer stacking, the information of neighbor nodes is gradually integrated into the embedding of the target entity. Finally, the updated node embedding and relationship embedding are output as subsequent input.
[0015] Furthermore, the decoder module is used to input the vector output by the graph neural network into the ConvKB decoder, calculate the triple score through the convolution operation, and predict the implicit relationship that may exist between the target entities, specifically including:
[0016] After obtaining the updated node and relationship embeddings, the combined representation of entity and relationship embeddings is input into the convolutional neural network to capture the local feature interactions between entities and relationships for scoring. The two input entity embeddings and relationship embeddings are concatenated row by row into a matrix form M = [h v ; r k ;h u ], and then perform a convolution operation, extract the local feature z of the embedding matrix M through a convolution kernel w, input the convolution result z into the activation function, and then perform a pooling operation to obtain z pool , the pooled output is passed through a fully connected layer to generate a score to represent the triple (v, r k ,u) effectiveness, Represents the weight vector of the fully connected layer. By calculating the scores of different relationship categories one by one, the triple scores are ranked, and the final predicted triples are selected according to the set screening rules to complete the knowledge reasoning link prediction task.
[0017] A graph neural network-based automotive network security knowledge reasoning method, which includes a knowledge graph embedding module, a data preprocessing module, a graph neural network modeling module, and a decoder module;
[0018] The knowledge graph embedding module completes the embedded representation of entities and relationships in the knowledge graph in the field of Internet of Vehicles security. By converting entities and relationships of different categories in the knowledge graph into low-dimensional embedding vector forms, a mapping dictionary between entity numbers and vectors, and relationship numbers and vectors is constructed, providing an embedding basis for subsequent reasoning tasks.
[0019] The data preprocessing module completes the sub-graph sampling of entities and relationships in the knowledge graph. By adopting incremental sampling and positive and negative sampling, it reduces redundant samples while maintaining sample diversity, ensuring efficient use of graph information and providing high-quality input data for graph neural network modeling.
[0020] The graph neural network modeling module completes the update of node and relationship embeddings. Through the graph attention network based on heterogeneous graphs, it calculates the feature weights of entities and their neighbors, integrates the characteristics of different entity categories and relationship categories into the modeling process, aggregates high-order semantic information, and updates the embedding vector.
[0021] The decoder module completes the implicit relationship prediction task and adopts the ConvKB decoder to capture the local feature interactions in entity and relationship embeddings through convolution operations, calculate the possible relationship category scores between each pair of entities, and finally output the implicit relationship prediction results between entity pairs.
[0022] Compared with the prior art, the present invention has the following beneficial effects:
[0023] (1) The incremental sampling and positive and negative sampling strategies adopted in the automotive network security knowledge reasoning method can adapt to the characteristics of multiple entities and multiple relationship types in the Internet of Vehicles security knowledge graph, can efficiently process large-scale graph data, achieve effective and efficient sampling, and provide reasonable input subgraphs for the subsequent graph neural network modeling module.
[0024] (2) A graph attention network based on heterogeneous graphs is adopted in the automotive network security knowledge reasoning method. By designing an independent weight matrix for each relationship and using the attention mechanism, the model can dynamically assign weights to neighboring nodes, so that nodes can make full use of local and global information, which can effectively improve the reasoning ability of the model. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] Figure 1 It is a schematic diagram of the system model of the present invention;
[0026] Figure 2 An embodiment of the present invention provides an automobile network security knowledge reasoning model diagram. DETAILED DESCRIPTION
[0027] The following will describe the technical solutions in the embodiments of the present invention in detail in conjunction with the accompanying drawings in the embodiments of the present invention. The described embodiments are only part of the embodiments of the present invention.
[0028] The technical solution of the present invention to solve the above technical problems is:
[0029] Reference Figure 1-Figure 2 , the specific implementation methods of the present invention are as follows:
[0030] 1. First, each entity in the knowledge graph needs to be represented in text form and standardized. At the same time, each entity needs to be assigned a unique serial number, starting from 0 and increasing in sequence, to generate a mapping dictionary between entities and serial numbers. Initialize a low-dimensional vector with dimension d for each entity serial number, generate a mapping dictionary from serial number to embedded vector, then extract each edge type r in the knowledge graph, assign a unique serial number to each relationship type, starting from 0 and increasing in sequence, and generate a mapping dictionary between relationship and serial number A low-dimensional vector is initialized for each relationship number, and a mapping dictionary from the number to the embedded vector is generated. Finally, an automotive cybersecurity knowledge graph (V, E, R) represented by a vector can be obtained, where V represents the set of all entities in the knowledge graph, E represents the set of edges between all entities in the knowledge graph, and R represents the set of all relationship categories in the knowledge graph.
[0031] 2. After the automotive network security knowledge graph is embedded, the input needs to be sampled by selecting the nodes to be sampled. Assume that the sampled node set is V t-1 , represents the set of entities that have been visited in step t-1, and the node set can be expanded to N(V t-1 ), which means starting from the node in step t-1, the neighboring nodes that can be accessed in one hop are constructed, and the candidate node set is then removed from the neighboring node set to avoid redundancy, and the candidate node set for step t is obtained. Then candidate nodes are sampled from Select a subset as the next target node set Where SAMP() represents sampling from candidate nodes, and the obtained V t The node set after incremental sampling includes the currently visited node set and the new node set obtained by sampling. Through iterative multi-step expansion, a node subgraph containing multiple jump relationships can be constructed. At the same time, in order to improve the accuracy and generalization of the model, positive and negative sampling is introduced. By constructing links that do not exist in the original knowledge graph, negative samples are generated, and the training subgraph is further processed.
[0032] 3. After the training subgraph is obtained through embedding and data preprocessing sampling of the automotive network security knowledge graph, it needs to be input into the graph neural network model. The input graph structure G = (V, E, R), where V represents the set of low-dimensional embedding vectors of entities, R represents the set of embedding vectors of each relationship type, and E represents the set of edges between entities under a certain relationship. A graph neural network based on the heterogeneous graph attention mechanism is constructed to aggregate the features of nodes. For each entity node v, information is aggregated from its neighbor node set to obtain in is the attention weight, which represents the attention weight of node u to node v, W (l) represents the trainable weight matrix of layer l, represents the embedding vector of the neighbor node u at layer l. Since there are different types of relationships in the graph, it is also necessary to model the relationship type. k , introducing an independent change matrix By designing an independent weight matrix for each relationship, the characteristics of different relationship types are represented. However, in the above node information aggregation process, information is transmitted through an independent weight matrix, and the embedding of each node is simply spliced through information of different relationship categories. However, in actual situations, the information between nodes of different relationship categories may have different weights. In graph neural networks, by introducing the attention mechanism, the importance of each neighbor to the target node is measured by dynamically assigning weights to neighbor nodes. The attention weight in is a trainable attention vector used to calculate the similarity between nodes, || represents the concatenation operation of the vector, LeakyReLU is the activation function, and after aggregating the neighbor node information, the node embedding is updated through the activation function. σ is the activation function, The neighbor information is aggregated in the above process. Then, L layers of graph neural networks are stacked to capture high-order neighbor information. Through multi-layer stacking, the information of neighbor nodes is gradually integrated into the embedding of the target entity. Finally, the updated node embedding and relationship embedding are output as subsequent input.
[0033] 4. After obtaining the updated node and relationship embeddings, they need to be decoded and sorted to obtain the final reasoning result. By inputting the combined representation of entity and relationship embeddings into the convolutional neural network, the local feature interaction between entities and relationships is captured, and then scoring is performed. The two input entity embeddings and relationship embeddings are spliced row by row into a matrix form M = [h v ; r k ;h u ], and then perform a convolution operation, extract the local feature z of the embedding matrix M through a convolution kernel w, input the convolution result z into the activation function, and then perform a pooling operation to obtain z pool , the pooled output is passed through a fully connected layer to generate a score to represent the triple (v, r k ,u) effectiveness, Represents the weight vector of the fully connected layer. By calculating the scores of different relationship categories one by one, the triple scores are ranked, and the final predicted triples are selected according to the set screening rules to complete the knowledge reasoning link prediction task.
[0034] The above embodiments should be understood to be only used to illustrate the present invention and not to limit the protection scope of the present invention. After reading the contents of the present invention, technicians can make various changes or modifications to the present invention, and these equivalent changes and modifications also fall within the scope defined by the claims of the present invention.
Claims
1. A method for reasoning automotive network security knowledge based on graph neural network, characterized in that: include: There are four parts in total: knowledge graph embedding module, data preprocessing module, graph neural network modeling module and decoder module; The knowledge graph embedding module is used to map entities and relationships into low-dimensional vector representations to generate knowledge graph embeddings; The data preprocessing module is used to extract the target entity and its multi-hop neighbor relationship through a sampling mechanism to construct a local subgraph; The graph neural network modeling module is used to calculate the feature weights of entities and their neighbors through a graph attention network based on a heterogeneous graph, aggregate high-order semantic information, and generate updated entity and relationship vectors; The decoder module is used to input the vector output by the graph neural network into the ConvKB decoder, calculate the triple score through convolution operation, and predict the implicit relationship that may exist between entities.
2. According to claim 1, a method for reasoning automobile network security knowledge based on graph neural network is characterized in that: The knowledge graph embedding module is used to map entities and relationships into low-dimensional vector representations to generate knowledge graph embeddings, specifically including: Each entity in the knowledge graph is represented in text form and standardized. At the same time, a unique serial number is assigned to each entity, starting from 0 and increasing in sequence, to generate a mapping dictionary between entities and serial numbers. Initialize a low-dimensional vector with dimension d for each entity serial number and generate a mapping dictionary from serial number to embedded vector; Then extract the type r of each edge in the knowledge graph, assign a unique serial number to each relationship type, starting from 0 and increasing in sequence, and generate a mapping dictionary between relationships and serial numbers. Initialize a low-dimensional vector for each relation number and generate a mapping dictionary from the number to the embedded vector; Finally, we can obtain an automotive cybersecurity knowledge graph represented by a vector (V, E, R), where V represents the set of all entities in the knowledge graph, E represents the set of edges between all entities in the knowledge graph, and R represents the set of all relationship categories in the knowledge graph.
3. The method for reasoning automobile network security knowledge based on graph neural network according to claim 2 is characterized in that: The data preprocessing module is used to extract the target entity and its multi-hop neighbor relationship through a sampling mechanism and construct a local subgraph, which specifically includes: By selecting the nodes to be sampled, assuming that the sampled node set is V t-1 , represents the set of entities that have been visited in step t-1, and the node set can be expanded to N(V t-1 ), represents the neighboring nodes that can be accessed in one hop from the node in step t-1; Then, the candidate node set is constructed, and the current and previously visited nodes are removed from the neighbor node set to avoid redundancy, and the candidate node set of step t is obtained. Then candidate nodes are sampled from Select a subset as the next target node set Where SAMP() represents sampling from candidate nodes, and the obtained V t The node set after incremental sampling includes the currently visited node set and the new node set obtained by sampling. Through iterative multi-step expansion, a node subgraph containing multiple jump relationships can be constructed. At the same time, in order to improve the accuracy and generalization of the model, positive and negative sampling is introduced. By constructing links that do not exist in the original knowledge graph, negative samples are generated, and the training subgraph is further processed.
4. The method for reasoning automobile network security knowledge based on graph neural network according to claim 3 is characterized in that: The graph neural network modeling module is used to calculate the feature weights of entities and their neighbors through a graph attention network based on heterogeneous graphs, aggregate high-order semantic information, and generate updated entity and relationship vectors, specifically including: After knowledge graph embedding and data preprocessing, the input graph structure G = (V, E, R), where V represents the set of low-dimensional embedding vectors of entities, R represents the set of embedding vectors of each relationship type, and E represents the set of edges between entities under a certain relationship. A graph neural network based on the heterogeneous graph attention mechanism is constructed to perform feature aggregation on nodes. For each entity node v, information is aggregated from its neighbor node set to obtain in is the attention weight, which represents the attention weight of node u to node v, W (l) represents the trainable weight matrix of layer l, Represents the embedding vector of neighbor node u at layer l; Since there are different types of relationships in the graph, we also need to model the relationship type. k , introducing an independent change matrix By designing an independent weight matrix for each relationship, the characteristics of different relationship types are represented. However, in the above node information aggregation process, information is transmitted through an independent weight matrix, and the embedding of each node is simply spliced through information of different relationship categories. However, in actual situations, the information between nodes of different relationship categories may have different weights. In graph neural networks, by introducing the attention mechanism, the importance of each neighbor to the target node is measured by dynamically assigning weights to neighbor nodes. The attention weight where a T is a trainable attention vector used to calculate the similarity between nodes, ∥ represents the concatenation operation of the vector, and LeakyReLU is the activation function; After aggregating neighbor node information, the node embedding is updated through the activation function. σ is the activation function, The neighbor information is aggregated in the above process. Then, L layers of graph neural networks are stacked to capture high-order neighbor information. Through multi-layer stacking, the information of neighbor nodes is gradually integrated into the embedding of the target entity. Finally, the updated node embedding and relationship embedding are output as subsequent input.
5. The method for reasoning automobile network security knowledge based on graph neural network according to claim 4 is characterized in that: The decoder module is used to input the vector output by the graph neural network into the ConvKB decoder, calculate the triple score through convolution operation, and predict the implicit relationship that may exist between entities, specifically including: After obtaining the updated node and relationship embeddings, the combined representation of entity and relationship embeddings is input into the convolutional neural network to capture the local feature interactions between entities and relationships for scoring. The two input entity embeddings and relationship embeddings are concatenated row by row into a matrix form M = [h v ; r k ;h u ], and then perform a convolution operation, extract the local feature z of the embedding matrix M through a convolution kernel w, input the convolution result z into the activation function, and then perform a pooling operation to obtain z pool , the pooled output is passed through a fully connected layer to generate a score to represent the triple (v, r k ,u) effectiveness, Represents the weight vector of the fully connected layer. By calculating the scores of different relationship categories one by one, the triple scores are ranked, and the final predicted triples are selected according to the set screening rules to complete the knowledge reasoning link prediction task.
6. The method for reasoning automobile network security knowledge based on graph neural network according to claim 5 is characterized in that: include: There are four parts: knowledge graph embedding module, data preprocessing module, graph neural network modeling module and decoder module; among them, The knowledge graph embedding module completes the embedded representation of entities and relationships in the knowledge graph in the field of Internet of Vehicles security. By converting entities and relationships of different categories in the knowledge graph into low-dimensional embedding vector forms, a mapping dictionary between entity numbers and vectors, and relationship numbers and vectors is constructed, providing an embedding basis for subsequent reasoning tasks. The data preprocessing module completes the sub-graph sampling of entities and relationships in the knowledge graph. By adopting incremental sampling and positive and negative sampling, it reduces redundant samples while maintaining sample diversity, ensuring efficient use of graph information and providing high-quality input data for graph neural network modeling. The graph neural network modeling module completes the update of node and relationship embeddings. Through the graph attention network based on heterogeneous graphs, it calculates the feature weights of entities and their neighbors, integrates the characteristics of different entity categories and relationship categories into the modeling process, aggregates high-order semantic information, and updates the embedding vector. The decoder module completes the implicit relationship prediction task and adopts the ConvKB decoder to capture the local feature interactions in entity and relationship embeddings through convolution operations, calculate the possible relationship category scores between each pair of entities, and finally output the implicit relationship prediction results between entity pairs.
Citation Information
Cited By
Network state grid potential lost user identification method based on knowledge graph
CN120931105A
Question processing method and related device
CN121436178A