Abnormal data stream classification detection method and device based on unbalanced multi-instance learning
By adopting an imbalanced multi-example learning method in network traffic monitoring, we deal with category imbalance and multi-example correlation problems, and building a neural network model with cost-sensitive loss function, we solve the problem of low detection accuracy of abnormal data flow in the prior art, and achieve more efficient and accurate detection effects.
Patent Information
- Application Number
- CN202510472665.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-16
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-04-16
AI Technical Summary
The prior art is difficult to effectively identify abnormal data flows in network traffic monitoring, especially in terms of category imbalance and multi-example correlation, resulting in high false alarm rates and missed alarm rates.
Using an unbalanced multi-example learning method, by dividing network traffic into positive packet sets and negative packet sets, oversampling and undersampling, building a neural network model with cost-sensitive loss function, and realizing adaptive cost-sensitive learning.
It significantly improves the detection accuracy of abnormal data flow, reduces the false alarm rate and missed alarm rate, enhances the sensitivity to rare abnormal events, and provides a more intelligent and reliable abnormal traffic detection method.
Smart Images

Figure CN120017419A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a method and device for abnormal data flow classification detection based on unbalanced multi-instance learning. Background Art
[0002] In network traffic monitoring, identifying abnormal data flows is crucial to ensuring network security. Traditional anomaly detection methods can be divided into static feature analysis, port detection, protocol analysis, etc. However, in reality, they are easily affected by encryption technology, non-standard ports and other technologies, resulting in a high false alarm rate. In addition, traditional methods usually assume that positive and negative samples are balanced, but in actual applications, abnormal data flows often only account for a small proportion, resulting in a highly unbalanced training set. This imbalance makes it difficult for standard machine learning models to effectively capture abnormal patterns, thereby affecting detection accuracy. In addition, traditional methods are mostly based on analysis of a single data packet, ignoring the correlation between multiple data packets in the same data stream. Therefore, the existing technology has obvious deficiencies in dealing with class imbalance problems and multi-example correlation, and a more efficient and accurate solution is urgently needed. Summary of the invention
[0003] In view of the above-mentioned defects or deficiencies in the prior art, the present invention provides a method and device for abnormal data flow classification detection based on unbalanced multi-instance learning, which can efficiently and accurately detect abnormal data flows in network traffic.
[0004] One aspect of the present invention provides a method for abnormal data flow classification detection based on unbalanced multi-instance learning, comprising: Divide the network traffic into a positive packet set and a negative packet set; wherein the positive packet set includes a plurality of positive packets, the positive packet is a data flow with at least one abnormal data packet, the negative packet set includes a plurality of negative packets, the negative packet is a data flow with all normal data packets, and the positive packets and negative packets both contain a plurality of examples, each example corresponding to a data packet; Perform an oversampling operation on all positive packets in the positive packet set to expand the examples in each positive packet to obtain an expanded new positive packet set; Performing undersampling operations on all negative bags in the negative bag set to reduce the examples in each negative bag and obtain a reduced new negative bag set; The cost-sensitive loss function of the neural network model is constructed based on the cost weight and the category weight. The cost weight represents the cost of an abnormal data flow being misjudged as a normal data flow, and the category weight represents the weight when the label is a positive packet or a negative packet. Constructing a neural network model linear classifier according to the cost-sensitive loss function, wherein the neural network model linear classifier is used to determine whether a network traffic data flow is a positive packet or a negative packet; Training the linear classifier of the neural network model, and updating the cost weight of the linear classifier of the neural network model according to the number of missed alarms and false alarms in each round of training to achieve adaptive cost-sensitive learning until the optimization goal is achieved; The network traffic is identified using the optimized neural network model linear classifier.
[0005] Another aspect of the present invention further provides an abnormal data stream classification detection device based on unbalanced multi-instance learning, comprising: The sample division module is configured to divide the network traffic into a positive packet set and a negative packet set; wherein the positive packet set includes a plurality of positive packets, the positive packet is a data flow with at least one abnormal data packet, the negative packet set includes a plurality of negative packets, the negative packet is a data flow with all normal data packets, and the positive packet and the negative packet both contain a plurality of examples, each example corresponding to a data packet; An oversampling module is configured to perform an oversampling operation on all positive packets in the positive packet set to expand the examples in each positive packet to obtain an expanded new positive packet set; An undersampling module is configured to perform an undersampling operation on all negative packets in the negative packet set to reduce the examples in each negative packet to obtain a reduced new negative packet set; A loss function building module is configured to build a cost-sensitive loss function of a neural network model based on a cost weight and a class weight; wherein the cost weight represents the cost of an abnormal data flow being misjudged as a normal data flow, and the class weight represents the weight when a label is a positive packet or a negative packet; A classifier construction module is configured to construct a neural network model linear classifier according to the cost-sensitive loss function, wherein the neural network model linear classifier is used to determine whether a network traffic data flow is a positive packet or a negative packet; A training module is configured to train the linear classifier of the neural network model, and update the cost weight of the linear classifier of the neural network model according to the number of missed alarms and false alarms in each round of training to achieve adaptive cost-sensitive learning until the optimization goal is achieved; The classification and recognition module is configured to use an optimized neural network model linear classifier to recognize network traffic.
[0006] The present invention provides an abnormal data flow classification detection method and device based on unbalanced multi-instance learning. By introducing a multi-instance learning framework, not only the data packet characteristics in each data flow are considered, but also the correlation between multiple data packets in the same session is fully considered, so as to more comprehensively understand the overall behavior pattern of the data flow. In addition, the problem of category imbalance is optimized to reduce the false alarm rate and missed alarm rate caused by sample imbalance, improve the sensitivity to rare abnormal events, and provide a more intelligent and reliable abnormal traffic detection method for the network monitoring system. BRIEF DESCRIPTION OF THE DRAWINGS
[0007] Other features, objects and advantages of the present application will become more apparent by reading the detailed description of non-limiting embodiments made with reference to the following drawings: Figure 1 It is a flowchart of an abnormal data stream classification detection method based on unbalanced multi-instance learning provided by an embodiment of the present application; Figure 2 It is a structural diagram of an abnormal data stream classification detection device based on unbalanced multi-instance learning provided by an embodiment of the present application. DETAILED DESCRIPTION
[0008] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0009] The terms used in the embodiments of the present invention are only for the purpose of describing specific embodiments, and are not intended to limit the present invention. The singular forms "a", "said" and "the" used in the embodiments of the present invention are also intended to include plural forms, unless the context clearly indicates other meanings.
[0010] It should be understood that although the terms first, second, third, etc. may be used to describe the acquisition modules in the embodiments of the present invention, the acquisition modules should not be limited to these terms. These terms are only used to distinguish the acquisition modules from each other.
[0011] The word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining" or "in response to detecting", depending on the context. Similarly, the phrases "if it is determined" or "if (stated condition or event) is detected" may be interpreted as "when it is determined" or "in response to determining" or "when detecting (stated condition or event)" or "in response to detecting (stated condition or event)", depending on the context.
[0012] It should be noted that the directional words such as "upper", "lower", "left", and "right" described in the embodiments of the present invention are described at the angles shown in the drawings and should not be understood as limiting the embodiments of the present invention. In addition, in the context, it should also be understood that when it is mentioned that an element is formed "on" or "under" another element, it can not only be formed directly "on" or "under" another element, but also be formed "on" or "under" another element indirectly through an intermediate element.
[0013] An embodiment of the present invention proposes an abnormal data stream classification detection method based on unbalanced multi-instance learning, aiming to make up for the shortcomings of the prior art in dealing with the problem of category imbalance and multi-instance correlation.
[0014] See also Figure 1 The abnormal data flow classification detection method based on unbalanced multi-instance learning of the present invention comprises the following steps: Step S101, divide the network traffic into a positive packet set and a negative packet set; wherein the positive packet set includes multiple positive packets, the positive packet is a data flow with at least one abnormal data packet, the negative packet set includes multiple negative packets, the negative packet is a data flow consisting entirely of normal data packets, and both the positive packet and the negative packet contain multiple examples, each example corresponding to a data packet.
[0015] Specifically, the logical session boundary is set according to the life cycle of the TCP connection. Since each data stream contains multiple data packets, the data stream can be regarded as a bag in multi-instance learning, and the multiple data packets in each data stream can be regarded as instances. Among them, all acquired data streams containing malicious attacks are regarded as positive bags, and data streams with normal business traffic are regarded as negative bags. If there is an abnormal data packet (positive instance) in a data stream, this data stream is considered to be an abnormal data stream (positive packet). If all data packets in a data stream are normal data packets, this data stream is normal business traffic. The data packet type, packet length, payload length, character statistical features, etc. extracted from each data packet are used as instance features. Finally, the network traffic is divided into a set of positive packets. and negative bag collection .
[0016] It should be noted that in actual network data flows, abnormal data usually accounts for a small proportion, which will cause class imbalance data. Since the proportion of abnormal data flows in network traffic is very small, step S101 obtains an unbalanced data set containing a small number of positive packets and a large number of negative packets. These data sets will be used in subsequent class imbalance processing steps to optimize sample distribution and improve the accuracy of the anomaly detection model.
[0017] Subsequently, through mixed sampling in step S102 and step S103, the positive and negative packet ratio is changed from the original ,in , optimized to a balanced ratio , preferably ≤3.
[0018] Step S102 , performing an oversampling operation on all positive packets in the positive packet set to expand the examples in each positive packet to obtain an expanded new positive packet set.
[0019] This step generates each positive packet of the positive packet set. The example feature matrix in ,in is the number of packets, is the feature dimension (e.g., data packet type, packet length, payload length, character statistics, etc.). Then, a sample of a positive packet in the positive packet set is randomly selected. and the nearest neighbor of this example , generate new examples according to the following formula : The new example Add to the main package, and expand each example in the main package in the same way until the main package is expanded to the original times, of which Take 3 to 5. Expand each positive packet in the positive packet set in the above manner to obtain a new positive packet set after expansion .
[0020] Step S103, performing undersampling operation on all negative packets in the negative packet set to reduce the examples in each negative packet to obtain a reduced new negative packet set .
[0021] This step performs clustering screening on the negative bag set according to specific sample features, such as K-Means clustering, to obtain k subclasses, where k = / n, n is the number of negative packets in the negative packet set, =0.2~0.5; then select the closest to the cluster center from each sub-class negative packages, of which =n / k, thus forming a new negative packet set; adjusting the values of k and r, so that the ratio of the number of positive packets in the expanded new positive packet set to the number of negative packets in the reduced new negative packet set is for ,in ≤3.
[0022] Step S104, constructing a cost-sensitive loss function of the neural network model based on the cost weight and the category weight; wherein the cost weight represents the cost of an abnormal data flow being misjudged as a normal data flow, and the category weight represents the weight when the label is a positive packet or a negative packet.
[0023] Specifically, a cost-sensitive loss function of a neural network model is constructed based on cost weights and class weights.
[0024] First, generate the cost matrix .set up is the true label (0 = negative bag, 1 = positive bag), To predict the label, the cost matrix It is expressed as: in, Indicates that the true label is a negative bag and the predicted label is also a negative bag; Indicates the cost of a normal data flow being misjudged as abnormal (low risk); Represents cost weight , i.e., the cost of abnormal data flow being misjudged as normal (high risk); Indicates the cost of the true label being a positive bag and the predicted label being a positive bag. Preferably, >5, more preferably, Set to 10~50, It can be adjusted within the above range according to the implementation scenario.
[0025] Next, define the category weights : in, Indicates the number of positive packets in the expanded new positive packet set; Indicates the number of negative packets in the reduced new negative packet set; represents the true label.
[0026] Finally, based on the above contained cost weights Cost matrix and class weights Constructing a cost-sensitive loss function for a neural network model: ; ; in, is the cost matrix; N represents the total number of positive and negative packages; is the cross entropy loss; is the neural network weight; is a parameter that controls the strength of regularization; represents the true label; represents the predicted label; represents the category weight; represents the package-level prediction probability; Represents each package; ( ) represents an example-level classifier; represents the jth example in the i-th package; Indicates taking the maximum value of all examples in the bag.
[0027] Step S105, constructing a neural network model linear classifier according to the cost-sensitive loss function, wherein the neural network model linear classifier is used to determine whether the network traffic data flow is a positive packet or a negative packet.
[0028] Specifically, a neural network model linear classifier is constructed based on the cost-sensitive loss function: ; ; in, is a linear classifier for the neural network model; is the statistical kernel mapping vector for each packet; Represents each package; is the weight vector; b is the bias term; For example Dimensional features, ;like , it is judged as a positive packet, otherwise it is judged as a negative packet.
[0029] Step S106, training the linear classifier of the neural network model, and updating the cost weight of the linear classifier of the neural network model according to the number of missed alarms and false alarms in each round of training to achieve adaptive cost-sensitive learning until the optimization goal is achieved.
[0030] Specifically, the linear classifier of the neural network model is trained, and the current number of missed reports in each round of training is counted. and false positives , of which the number of missed reports Indicates the number of positive packets that were not correctly identified and incorrectly classified as negative packets, the number of false positives It indicates the number of negative packets that were not correctly identified and were incorrectly classified as positive packets.
[0031] Update the cost weights according to the following formula: in, represents the updated cost weight, represents the cost weight before updating, represents the learning rate, Represents a parameter that is protected against division by zero.
[0032] According to the cost-sensitive loss function, the optimization objective is set to meet the following conditions: in, is the cost matrix; N represents the total number of positive and negative packages; is the cross entropy loss; is the neural network weight; is a parameter that controls the strength of regularization; represents the true label; represents the predicted label; represents the category weight; is a linear classifier for the neural network model; Represents each package; When the classifier meets the optimization goal, stop training the linear classifier of the neural network model.
[0033] Step S107, using the optimized neural network model linear classifier to identify network traffic.
[0034] The method of this embodiment significantly improves the accuracy of abnormal data stream classification detection by introducing an unbalanced multi-instance learning framework, especially when facing the problem of category imbalance. This method not only enhances the ability to identify rare abnormal events, but also reduces the operating costs and security risks caused by false alarms. The specific technical effects are as follows: (1) Improving anomaly detection accuracy Traditional methods have difficulty in effectively identifying rare abnormal events due to the problem of class imbalance. However, this embodiment significantly improves the detection capability of minority class (i.e., abnormal class) samples through a specially optimized hybrid sampling strategy and cost-sensitive learning.
[0035] (2) Reduce the false alarm rate By more accurately distinguishing between normal and abnormal traffic, security investigation and operating costs caused by false alarms are reduced, ensuring the efficient operation of the security system.
[0036] (3) Enhance model robustness This embodiment not only considers the characteristics of a single data packet, but also captures the correlation between multiple data packets in the same session, enhancing the model's understanding and adaptability to complex network environments. By combining static features (such as average packet size) and dynamic features (such as time series change trends), the model can more comprehensively reflect the overall behavior pattern of the data flow, improving the accuracy and robustness of classification.
[0037] (4) Improving the problem of imbalanced training sets This embodiment adopts a mixed sampling strategy consisting of oversampling and undersampling, adjusts the ratio of positive and negative samples, makes the training set more balanced, and thus improves the learning efficiency and generalization ability of the model. In addition, this embodiment also assigns different weights to different types of errors, especially setting asymmetric cost factors for false positives and false negatives, so that the model pays more attention to the performance of minority classes during training, further improving the detection effect.
[0038] See also Figure 2 Another embodiment of the present invention further provides an abnormal data stream classification detection device 200 based on unbalanced multi-instance learning, including a sample division module 201, an oversampling module 202, an undersampling module 203, a loss function construction module 204, a classifier construction module 205, a training module 206 and a classification recognition module 207. The abnormal data stream classification detection device 200 can execute the abnormal data stream classification detection method based on unbalanced multi-instance learning in the method embodiment.
[0039] Specifically, the abnormal data flow classification detection device 200 includes: The sample division module 201 is configured to divide the network traffic into a positive packet set and a negative packet set; wherein the positive packet set includes a plurality of positive packets, the positive packet is a data flow with at least one abnormal data packet, the negative packet set includes a plurality of negative packets, the negative packet is a data flow with all normal data packets, and the positive packet and the negative packet both contain a plurality of examples, each example corresponding to a data packet; The oversampling module 202 is configured to perform an oversampling operation on all positive packets in the positive packet set to expand the examples in each positive packet to obtain an expanded new positive packet set; The undersampling module 203 is configured to perform an undersampling operation on all negative packets in the negative packet set to reduce the examples in each negative packet to obtain a reduced new negative packet set; The loss function construction module 204 is configured to construct a cost-sensitive loss function of the neural network model based on a cost weight and a class weight; wherein the cost weight represents the cost of an abnormal data flow being misjudged as a normal data flow, and the class weight represents the weight when the label is a positive packet or a negative packet; A classifier construction module 205 is configured to construct a neural network model linear classifier according to the cost-sensitive loss function, wherein the neural network model linear classifier is used to determine whether a network traffic data flow is a positive packet or a negative packet; The training module 206 is configured to train the linear classifier of the neural network model, and update the cost weight of the linear classifier of the neural network model according to the number of missed alarms and false alarms in each round of training to achieve adaptive cost-sensitive learning until the optimization goal is achieved; The classification and identification module 207 is configured to identify network traffic using an optimized neural network model linear classifier.
[0040] It should be noted that the abnormal data flow classification detection device 200 provided in this embodiment corresponds to a technical solution that can be used to execute various method embodiments, and its implementation principle and technical effect are similar to the method, which will not be repeated here.
[0041] The above description is only a preferred embodiment of the present invention. Those skilled in the art should understand that the scope of disclosure involved in the present invention is not limited to the technical solution formed by a specific combination of the above technical features, but also should cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above disclosed concept. For example, the above features are replaced with the technical features with similar functions disclosed in the present invention (but not limited to) to form a technical solution.
Claims
1. A method for abnormal data stream classification detection based on unbalanced multi-instance learning, characterized in that: The steps include: Divide the network traffic into a positive packet set and a negative packet set; wherein the positive packet set includes a plurality of positive packets, the positive packet is a data flow with at least one abnormal data packet, the negative packet set includes a plurality of negative packets, the negative packet is a data flow with all normal data packets, and the positive packets and negative packets both contain a plurality of examples, each example corresponding to a data packet; Perform an oversampling operation on all positive packets in the positive packet set to expand the examples in each positive packet to obtain an expanded new positive packet set; Performing undersampling operations on all negative bags in the negative bag set to reduce the examples in each negative bag and obtain a reduced new negative bag set; The cost-sensitive loss function of the neural network model is constructed based on the cost weight and the category weight. The cost weight represents the cost of an abnormal data flow being misjudged as a normal data flow, and the category weight represents the weight when the label is a positive packet or a negative packet. Constructing a neural network model linear classifier according to the cost-sensitive loss function, wherein the neural network model linear classifier is used to determine whether a network traffic data flow is a positive packet or a negative packet; Training the linear classifier of the neural network model, and updating the cost weight of the linear classifier of the neural network model according to the number of missed alarms and false alarms in each round of training to achieve adaptive cost-sensitive learning until the optimization goal is achieved; The network traffic is identified using the optimized neural network model linear classifier.
2. According to claim 1, a method for abnormal data flow classification detection based on unbalanced multi-instance learning is characterized in that: The step of performing an oversampling operation on all positive packets in the positive packet set to expand the examples in each positive packet to obtain an expanded new positive packet set includes: An example of randomly selecting a positive bag from a set of positive bags and the nearest neighbor of this example , generate new examples according to the following formula : The new example Add to the positive package, and expand each example in the positive package in the same way until the positive package is expanded to 3 to 5 times the original size; Each positive packet in the positive packet set is expanded in the above manner to obtain a new expanded positive packet set.
3. According to the method for abnormal data flow classification detection based on unbalanced multi-instance learning in claim 1, it is characterized in that: The step of performing an undersampling operation on all negative packets in the negative packet set to reduce the examples in each negative packet to obtain a reduced new negative packet set includes: The negative bag set is clustered and screened according to specific example features to obtain k subclasses, where k= / n, n is the number of negative packets in the negative packet set, Take 0.2~0.5; From each sub-cluster, select the cluster closest to the cluster center. negative packages, of which =n / k, thus forming a new negative bag set Adjust the values of k and r so that the ratio of the number of positive packets in the expanded new positive packet set to the number of negative packets in the reduced new negative packet set is ,in ≤3.
4. According to claim 1, a method for abnormal data flow classification detection based on unbalanced multi-instance learning is characterized in that: The cost-sensitive loss function It is expressed as: ; ; ; in, is the cost matrix; Indicates that the true label is a negative bag and the predicted label is also a negative bag; It represents the cost of normal data flow being misjudged as abnormal; Represents cost weight ; Indicates the cost when the true label is a positive package and the predicted label is also a positive package; N represents the total number of positive packages and negative packages; is the cross entropy loss; is the neural network weight; is a parameter that controls the strength of regularization; represents the true label; represents the predicted label; represents the category weight; Indicates the number of positive packets in the expanded new positive packet set; Indicates the number of negative packets in the reduced new negative packet set; represents the package-level prediction probability; Represents each package; represents an example-level classifier; represents the jth example in the i-th package; Indicates taking the maximum value of all examples in the bag.
5. The abnormal data flow classification detection method based on unbalanced multi-instance learning according to claim 4 is characterized in that: The neural network model linear classifier is represented by the following formula: ; ; in, is a linear classifier for the neural network model; is the statistical kernel mapping vector for each packet; Represents each package; is the weight vector; b is the bias term; For example Dimensional features, ; like , it is judged as a positive packet, otherwise it is judged as a negative packet.
6. The abnormal data flow classification detection method based on unbalanced multi-instance learning according to claim 5 is characterized in that: The step of training the linear classifier of the neural network model and updating the cost weight of the linear classifier of the neural network model according to the number of missed alarms and false alarms in each round of training includes: Count the current number of missed reports and false positives ; Update the cost weights according to the following formula: in, represents the updated cost weight, represents the cost weight before updating, represents the learning rate, Represents a parameter that is protected against division by zero.
7. The abnormal data flow classification detection method based on unbalanced multi-instance learning according to claim 6 is characterized in that: The optimization goal meets the following conditions: in, is the cost matrix; N represents the total number of positive and negative packages; is the cross entropy loss; is the neural network weight; is a parameter that controls the strength of regularization; represents the true label; represents the predicted label; represents the category weight; is a linear classifier for the neural network model; Represents each packet.
8. An abnormal data stream classification detection device based on unbalanced multi-instance learning, characterized in that: include: The sample division module is configured to divide the network traffic into a positive packet set and a negative packet set; wherein the positive packet set includes a plurality of positive packets, the positive packet is a data flow with at least one abnormal data packet, the negative packet set includes a plurality of negative packets, the negative packet is a data flow with all normal data packets, and the positive packet and the negative packet both contain a plurality of examples, each example corresponding to a data packet; An oversampling module is configured to perform an oversampling operation on all positive packets in the positive packet set to expand the examples in each positive packet to obtain an expanded new positive packet set; An undersampling module is configured to perform an undersampling operation on all negative packets in the negative packet set to reduce the examples in each negative packet to obtain a reduced new negative packet set; A loss function building module is configured to build a cost-sensitive loss function of a neural network model based on a cost weight and a class weight; wherein the cost weight represents the cost of an abnormal data flow being misjudged as a normal data flow, and the class weight represents the weight when a label is a positive packet or a negative packet; A classifier construction module is configured to construct a neural network model linear classifier according to the cost-sensitive loss function, wherein the neural network model linear classifier is used to determine whether a network traffic data flow is a positive packet or a negative packet; A training module is configured to train the linear classifier of the neural network model, and update the cost weight of the linear classifier of the neural network model according to the number of missed alarms and false alarms in each round of training to achieve adaptive cost-sensitive learning until the optimization goal is achieved; The classification and recognition module is configured to use an optimized neural network model linear classifier to recognize network traffic.
9. The abnormal data stream classification detection device based on unbalanced multi-instance learning according to claim 8 is characterized in that: The oversampling module is further configured as follows: An example of randomly selecting a positive bag from a set of positive bags and the nearest neighbor of this example , generate new examples according to the following formula : The new example Add to the positive package, and expand each example in the positive package in the same way until the positive package is expanded to 3 to 5 times the original size; Expand each positive packet in the positive packet set in the above manner to obtain a new expanded positive packet set; The undersampling module is further configured to: The negative bag set is clustered and screened according to specific example features to obtain k subclasses, where k= / n, n is the number of negative packets in the negative packet set, Take 0.2~0.5; From each sub-cluster, select the cluster closest to the cluster center. negative packages, of which =n / k, thus forming a new negative bag set Adjust the values of k and r so that the ratio of the number of positive packets in the expanded new positive packet set to the number of negative packets in the reduced new negative packet set is ,in ≤3.
10. The abnormal data stream classification detection device based on unbalanced multi-instance learning according to claim 8, characterized in that: The cost-sensitive loss function It is expressed as: ; ; ; in, is the cost matrix; Indicates that the true label is a negative bag and the predicted label is also a negative bag; It represents the cost of normal data flow being misjudged as abnormal; Represents cost weight ; Indicates the cost when the true label is a positive package and the predicted label is also a positive package; N represents the total number of positive packages and negative packages; is the cross entropy loss; is the neural network weight; is a parameter that controls the strength of regularization; represents the true label; represents the predicted label; represents the category weight; Indicates the number of positive packets in the expanded new positive packet set; Indicates the number of negative packets in the reduced new negative packet set; represents the package-level prediction probability; Represents each package; represents an example-level classifier; represents the jth example in the i-th package; It means taking the maximum value of all examples in the bag; The neural network model linear classifier is represented by the following formula: ; ; in, is a linear classifier for the neural network model; is the statistical kernel mapping vector for each packet; Represents each package; is the weight vector; b is the bias term; For example Dimensional features, ;like , it is judged as a positive packet, otherwise it is judged as a negative packet; The training module is further configured to: count the current number of missed reports and false positives ; Update the cost weight according to the following formula: in, represents the updated cost weight, represents the cost weight before updating, represents the learning rate, Represents a parameter that is protected against division by zero.
Citation Information
Patent Citations
Intrusion detection method based on flow model and ensemble learning
CN117272083A
Weighted integrated unbalanced classification method and system, storage medium, equipment and terminal
CN117312920A
Hybrid sampling network flow sample balancing method
CN119598185A
Method and system for detecting intrusion in parallel based on unbalanced data deep belief network
US20220382864A1