Anomaly Data Stream Classification and Detection Method and Device Based on Unbalanced Multi-Instance Learning
Through the imbalanced multi-example learning method, the sample ratio is adjusted and the cost-sensitive loss function is constructed, which solves the problems of high false positive rate and category imbalance in network traffic monitoring, and achieves more efficient and accurate abnormal data flow detection, enhancing the robustness of the model and the ability to identify rare abnormal events.
Patent Information
- Application Number
- CN202510472665.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-16
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-04-16
AI Technical Summary
The prior art has problems with high false alarm rates and category imbalance in network traffic monitoring, making it difficult to effectively identify abnormal data flows, and ignores the correlation between multiple data packets in the same data flow.
The unbalanced multi-example learning method is adopted to adjust the positive and negative packet ratio through oversampling and undersampling, build a cost-sensitive loss function and neural network model, perform adaptive training to optimize the classifier, and detect it in combination with packet characteristics and in-session correlation.
It improves the detection accuracy of abnormal data flow, reduces the false positive rate, enhances the robustness of the model and sensitivity to rare abnormal events, and provides a more intelligent and reliable network monitoring method.
Smart Images

Figure CN120017419B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and particularly to an abnormal data stream classification and detection method and device based on unbalanced multi-instance learning. Background Art
[0002] In network traffic monitoring, identifying abnormal data streams is crucial for ensuring network security. Traditional anomaly detection methods can be divided into static feature analysis, port detection, protocol parsing, etc. However, in reality, they are easily affected by technologies such as encryption technology and non-standard ports, resulting in a high false alarm rate. In addition, traditional methods usually default that the positive and negative samples are balanced, but in actual applications, abnormal data streams often only account for a very small proportion, resulting in a highly unbalanced training set. This imbalance makes it difficult for standard machine learning models to effectively capture abnormal patterns, thus affecting the detection accuracy. In addition, traditional methods mostly analyze based on a single data packet, ignoring the correlation between multiple data packets within the same data stream. Therefore, the existing technologies have obvious deficiencies in dealing with the problem of class imbalance and multi-instance correlation, and there is an urgent need for a more efficient and accurate solution. Summary of the Invention
[0003] In view of the above defects or deficiencies in the prior art, the present invention provides an abnormal data stream classification and detection method and device based on unbalanced multi-instance learning, which can efficiently and accurately detect abnormal data streams in network traffic.
[0004] One aspect of the present invention provides an abnormal data stream classification and detection method based on unbalanced multi-instance learning, including:
[0005] Dividing network traffic into a positive packet set and a negative packet set; wherein, the positive packet set includes multiple positive packets, and a positive packet is a data stream with at least one abnormal data packet, the negative packet set includes multiple negative packets, and a negative packet is a data stream all of which are normal data packets, and both the positive packets and negative packets contain multiple instances, and each instance corresponds to a data packet;
[0006] Performing oversampling operations on all positive packets in the positive packet set to expand the instances in each positive packet, obtaining an expanded new positive packet set;
[0007] Performing undersampling operations on all negative packets in the negative packet set to reduce the instances in each negative packet, obtaining a reduced new negative packet set;
[0008] Constructing a cost-sensitive loss function of a neural network model based on cost weights and class weights; wherein, the cost weight represents the cost of misjudging an abnormal data stream as a normal data stream, and the class weight represents the weight when the label is a positive packet or a negative packet;
[0009] Construct a linear classifier of a neural network model according to the cost-sensitive loss function, where the linear classifier of the neural network model is used to determine whether the network traffic data stream is a positive packet or a negative packet;
[0010] Train the linear classifier of the neural network model, and update the cost weights of the linear classifier of the neural network model according to the number of missed alarms and false alarms in each round of training, so as to achieve adaptive cost-sensitive learning until the optimization goal is reached;
[0011] Use the optimized linear classifier of the neural network model to identify network traffic.
[0012] On the other hand, the present invention also provides an abnormal data stream classification and detection device based on unbalanced multi-instance learning, including:
[0013] A sample division module configured to divide network traffic into a positive packet set and a negative packet set; wherein, the positive packet set includes multiple positive packets, the positive packet is a data stream with at least one abnormal data packet, the negative packet set includes multiple negative packets, the negative packet is a data stream all of which are normal data packets, both the positive packet and the negative packet contain multiple instances, and each instance corresponds to a data packet;
[0014] An oversampling module configured to perform oversampling operations on all positive packets in the positive packet set to expand the instances in each positive packet to obtain an expanded new positive packet set;
[0015] An undersampling module configured to perform undersampling operations on all negative packets in the negative packet set to reduce the instances in each negative packet to obtain a reduced new negative packet set;
[0016] A loss function construction module configured to construct a cost-sensitive loss function of a neural network model based on cost weights and class weights; wherein, the cost weight represents the cost of misjudging an abnormal data stream as a normal data stream, and the class weight represents the weight when the label is a positive packet or a negative packet;
[0017] A classifier construction module configured to construct a linear classifier of a neural network model according to the cost-sensitive loss function, where the linear classifier of the neural network model is used to determine whether the network traffic data stream is a positive packet or a negative packet;
[0018] A training module configured to train the linear classifier of the neural network model, and update the cost weights of the linear classifier of the neural network model according to the number of missed alarms and false alarms in each round of training, so as to achieve adaptive cost-sensitive learning until the optimization goal is reached;
[0019] A classification and recognition module configured to use the optimized linear classifier of the neural network model to identify network traffic.
[0020] An abnormal data stream classification and detection method and device based on imbalanced multi-instance learning provided by the present invention introduce a multi-instance learning framework, which not only considers the packet features within each data stream, but also fully considers the correlation between multiple packets within the same session, so as to more comprehensively understand the overall behavior pattern of the data stream. In addition, it is optimized for the class imbalance problem, reducing the false alarm rate and missed alarm rate caused by sample imbalance, improving the sensitivity to rare abnormal events, and providing a more intelligent and reliable abnormal traffic detection means for the network monitoring system. Description of the Drawings
[0021] By reading the detailed description of the non-restrictive embodiments with reference to the following drawings, other features, purposes and advantages of the present application will become more obvious:
[0022] Figure 1 It is a schematic flowchart of an abnormal data stream classification and detection method based on imbalanced multi-instance learning provided by an embodiment of the present application;
[0023] Figure 2 It is a schematic structural diagram of an abnormal data stream classification and detection device based on imbalanced multi-instance learning provided by an embodiment of the present application. Detailed Embodiments
[0024] To make the purposes, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0025] The terms used in the embodiments of the present invention are only for the purpose of describing specific embodiments, and are not intended to limit the present invention. The singular forms "a", "said" and "the" used in the embodiments of the present invention are also intended to include the plural forms unless the context clearly indicates otherwise.
[0026] It should be understood that although the terms first, second, third, etc. may be used to describe the acquisition modules in the embodiments of the present invention, these acquisition modules should not be limited to these terms. These terms are only used to distinguish the acquisition modules from each other.
[0027] Depending on the context, as used herein, the term "if" can be interpreted as "when" or "while" or "in response to determining" or "in response to detecting". Similarly, depending on the context, the phrase "if determined" or "if detecting (stated condition or event)" can be interpreted as "when determined" or "in response to determining" or "when detecting (stated condition or event)" or "in response to detecting (stated condition or event)".
[0028] It should be noted that the orientation terms such as "upper", "lower", "left", and "right" described in the embodiments of the present invention are described from the angles shown in the drawings and should not be construed as limiting the embodiments of the present invention. In addition, in the context, it should also be understood that when it is mentioned that an element is formed "on" or "under" another element, it can not only be directly formed "on" or "under" another element, but also be indirectly formed "on" or "under" another element through an intermediate element.
[0029] An embodiment of the present invention proposes an abnormal data stream classification and detection method based on unbalanced multi-instance learning, aiming to make up for the deficiencies of the prior art in dealing with the problem of class imbalance and multi-instance correlation.
[0030] See Figure 1 , the abnormal data stream classification and detection method based on unbalanced multi-instance learning of the present invention includes the following steps:
[0031] Step S101, dividing the network traffic into a positive packet set and a negative packet set; wherein, the positive packet set includes a plurality of positive packets, the positive packet is a data stream with at least one abnormal data packet, the negative packet set includes a plurality of negative packets, the negative packet is a data stream all of which are normal data packets, both the positive packet and the negative packet contain a plurality of instances, and each instance corresponds to a data packet.
[0032] Specifically, set the logical session boundary according to the life cycle of the TCP connection. Since each data stream contains multiple data packets, the data stream can be regarded as a bag in multi-instance learning, and the multiple data packets in each data stream can be regarded as instances. Among them, all the data streams obtained containing malicious attacks are regarded as positive bags, and the data streams of normal business traffic are regarded as negative bags. If there is an abnormal data packet (positive instance) in a certain data stream, this data stream is considered an abnormal data stream (positive bag). If all the data packets in a certain data stream are normal data packets, then this data stream is normal business traffic. The data packet type, packet length, payload length, character statistical features, etc. extracted from each data packet are used as instance features. Finally, the network traffic is divided into a positive packet set and a negative packet set .
[0033] It should be noted that in actual network data streams, abnormal data usually accounts for a relatively small proportion, that is, it will cause class-imbalanced data to appear. Since the proportion of abnormal data streams in network traffic is very small, the data set obtained in step S101 is an imbalanced data set containing a small number of positive packets and a large number of negative packets, and these data sets will be used in subsequent class imbalance processing steps to optimize the sample distribution and improve the accuracy of the anomaly detection model.
[0034] Subsequently, through the hybrid sampling of step S102 and step S103, the positive-negative packet ratio is changed from the original , where , to the balanced ratio , preferably ≤3.
[0035] Step S102, perform oversampling operations on all positive packets in the positive packet set to expand the examples in each positive packet, and obtain a new positive packet set after expansion.
[0036] This step generates the example feature matrix in each positive packet in the positive packet set, where is the number of data packets, is the feature dimension (for example: data packet type, packet length, payload length, character statistical features, etc.). Then, randomly select an example from a positive packet in the positive packet set and the nearest neighbor of this example, and generate a new example according to the following formula:
[0037]
[0038] Add the new example to the positive packet, and expand each example in the positive packet in the same way until the positive packet is expanded to times its original size, where takes 3 to 5. Expand each positive packet in the positive packet set in the above manner to obtain a new positive packet set .
[0039] Step S103, perform undersampling operations on all negative packets in the negative packet set to reduce the examples in each negative packet, and obtain a new negative packet set after reduction .
[0040] This step clusters and filters the negative packet set according to specific example features, such as K-Means clustering, to obtain k subclasses, where k = / n, n is the number of negative packets in the negative packet set, = 0.2~0.5; Then, select the negative bags closest to the cluster center from each subclass, where the number of = n / k, thus forming a new set of negative bags; Adjust the values of k and r such that the ratio of the number of positive bags in the expanded new set of positive bags to the number of negative bags in the reduced new set of negative bags is , where ≤ 3.
[0041] Step S104, construct a cost-sensitive loss function for the neural network model based on cost weights and class weights; Among them, the cost weight represents the cost of misjudging an abnormal data stream as a normal data stream, and the class weight represents the weight when the label is a positive bag or a negative bag.
[0042] Specifically, construct a cost-sensitive loss function for the neural network model based on cost weights and class weights.
[0043] First, generate a cost matrix . Let be the true label (0 = negative bag, 1 = positive bag), be the predicted label, and the cost matrix is expressed as:
[0044]
[0045] Among them, represents the cost when the true label is a negative bag and the predicted label is also a negative bag; represents the cost of misjudging a normal data stream as abnormal (low risk); represents the cost weight , that is, the cost of misjudging an abnormal data stream as normal (high risk); represents the cost when the true label is a positive bag and the predicted label is also a positive bag. Preferably, > 5, more preferably, is set to 10 - 50, which can be adjusted within the above range according to the implementation scenario.
[0046] Secondly, define the class weight :
[0047]
[0048] Among them, represents the number of positive bags in the expanded new set of positive bags; represents the number of negative bags in the reduced new set of negative bags; represents the true label.
[0049] Finally, based on the above containing cost weights Cost matrix and class weights Construct the cost-sensitive loss function of the neural network model:
[0050] ;
[0051] ;
[0052] Among them, is the cost matrix; N represents the total number of positive and negative bags; is the cross-entropy loss; is the neural network weight; is the parameter to control the regularization strength; represents the true label; represents the predicted label; represents the class weight; represents the bag-level prediction probability; represents each bag; ( ) represents the instance-level classifier; represents the j-th instance in the i-th bag; represents taking the maximum value of all instances in the bag.
[0053] Step S105, construct a linear classifier of the neural network model according to the cost-sensitive loss function, and the linear classifier of the neural network model is used to determine whether the network traffic data stream is a positive bag or a negative bag.
[0054] Specifically, construct a linear classifier of the neural network model according to the cost-sensitive loss function:
[0055] ;
[0056] ;
[0057] Among them, is the linear classifier of the neural network model; is the statistical kernel mapping vector of each bag; represents each bag; is the weight vector; b is the bias term; is the -dimensional feature of the instance, ; if , it is determined as a positive bag, otherwise it is determined as a negative bag.
[0058] Step S106, train the linear classifier of the neural network model, and update the cost weight of the linear classifier of the neural network model according to the number of missed detections and false alarms in each round of training to achieve adaptive cost-sensitive learning until the optimization goal is reached.
[0059] Specifically, train the linear classifier of the neural network model, and count the current number of missed reports in each round of training and the number of false alarms , where the number of missed reports represents the number of positive packets that are not correctly identified and are misclassified as negative packets, and the number of false alarms represents the number of negative packets that are not correctly identified and are misclassified as positive packets.
[0060] Update the cost weight according to the following formula:
[0061]
[0062] where, represents the updated cost weight, represents the cost weight before update, represents the learning rate, represents a parameter to prevent division by zero.
[0063] Set the optimization objective according to the cost-sensitive loss function to satisfy the following conditions:
[0064]
[0065] where, is the cost matrix; N represents the total number of positive and negative packets; is the cross-entropy loss; is the neural network weight; is a parameter to control the regularization strength; represents the true label; represents the predicted label; represents the class weight; is the linear classifier of the neural network model; represents each packet;
[0066] When the classifier meets the optimization objective, stop training the linear classifier of the neural network model.
[0067] Step S107, use the optimized linear classifier of the neural network model to identify network traffic.
[0068] The method of this embodiment significantly improves the accuracy of abnormal data stream classification and detection by introducing an unbalanced multi-instance learning framework, especially when facing the problem of class imbalance. This method not only enhances the ability to identify rare abnormal events, but also reduces the operating costs and security risks caused by false alarms. The specific technical effects are as follows:
[0069] (1) Improve the accuracy of anomaly detection
[0070] Traditional methods have difficulty in effectively identifying rare abnormal events due to the class imbalance problem. In this embodiment, through a specially optimized hybrid sampling strategy and cost-sensitive learning, the detection ability for minority class (i.e., abnormal class) samples is significantly improved.
[0071] (2) Reduce the false alarm rate
[0072] By making a more accurate distinction between normal and abnormal traffic, the security investigation and operation costs caused by false alarms are reduced, ensuring the efficient operation of the security system.
[0073] (3) Enhance the model robustness
[0074] This embodiment not only considers the characteristics of individual data packets but also captures the correlation between multiple data packets within the same session, enhancing the model's understanding and adaptability to complex network environments. By combining static features (such as average packet size) and dynamic features (such as time series change trends), the model can more comprehensively reflect the overall behavior pattern of the data stream, improving the accuracy and robustness of classification.
[0075] (4) Improve the imbalance problem of the training set
[0076] This embodiment adopts a hybrid sampling strategy composed of oversampling and undersampling to adjust the proportion of positive and negative samples, making the training set more balanced, thereby improving the learning efficiency and generalization ability of the model. In addition, this embodiment also assigns different weights to different types of errors, especially setting asymmetric cost factors for false alarms and missed alarms, making the model pay more attention to the performance of the minority class during the training process and further improving the detection effect.
[0077] See Figure 2 , another embodiment of the present invention also provides an abnormal data stream classification detection device 200 based on imbalanced multi-instance learning, including a sample division module 201, an oversampling module 202, an undersampling module 203, a loss function construction module 204, a classifier construction module 205, a training module 206, and a classification and recognition module 207. The abnormal data stream classification detection device 200 can execute the abnormal data stream classification detection method based on imbalanced multi-instance learning in the method embodiment.
[0078] Specifically, the abnormal data stream classification detection device 200 includes:
[0079] A sample division module 201, configured to divide network traffic into a positive packet set and a negative packet set; wherein, the positive packet set includes multiple positive packets, and a positive packet is a data stream with at least one abnormal data packet, the negative packet set includes multiple negative packets, and a negative packet is a data stream all of which are normal data packets, and both the positive packets and the negative packets contain multiple instances, and each instance corresponds to a data packet;
[0080] An oversampling module 202, configured to perform an oversampling operation on all positive packets in the positive packet set to expand the examples in each positive packet, so as to obtain an expanded new positive packet set;
[0081] An undersampling module 203, configured to perform an undersampling operation on all negative packets in the negative packet set to reduce the examples in each negative packet, so as to obtain a reduced new negative packet set;
[0082] A loss function construction module 204, configured to construct a cost-sensitive loss function of a neural network model based on a cost weight and a class weight; wherein, the cost weight represents the cost of misjudging an abnormal data stream as a normal data stream, and the class weight represents the weight when the label is a positive packet or a negative packet;
[0083] A classifier construction module 205, configured to construct a linear classifier of a neural network model according to the cost-sensitive loss function, and the linear classifier of the neural network model is used to determine whether a network traffic data stream is a positive packet or a negative packet;
[0084] A training module 206, configured to train the linear classifier of the neural network model, and update the cost weight of the linear classifier of the neural network model according to the number of missed alarms and false alarms in each round of training, so as to achieve adaptive cost-sensitive learning until an optimization goal is reached;
[0085] A classification and recognition module 207, configured to identify network traffic using the optimized linear classifier of the neural network model.
[0086] It should be noted that the abnormal data stream classification and detection device 200 provided in this embodiment corresponds to the technical solutions that can be used to execute the method embodiments. The implementation principle and technical effects are similar to those of the method, and will not be elaborated here.
[0087] The above description is only a preferred embodiment of the present invention. Those skilled in the art should understand that the disclosed scope of the present invention is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above disclosed concept. For example, the technical solutions formed by mutually replacing the above features with the technical features (but not limited to) having similar functions disclosed in the present invention.
Claims
1. An abnormal data stream classification and detection method based on unbalanced multi-instance learning, characterized in that, It includes the following steps: Divide the network traffic into a positive packet set and a negative packet set; wherein, the positive packet set includes multiple positive packets, and a positive packet is a data stream with at least one abnormal data packet, the negative packet set includes multiple negative packets, and a negative packet is a data stream all of which are normal data packets, and both the positive packets and the negative packets contain multiple examples, and each example corresponds to a data packet; Perform oversampling operations on all positive packets in the positive packet set to expand the examples in each positive packet, and obtain an expanded new positive packet set; Perform undersampling operations on all negative packets in the negative packet set to reduce the examples in each negative packet, and obtain a reduced new negative packet set; Construct a cost-sensitive loss function for a neural network model based on cost weights and class weights; where the cost weight represents the cost of misjudging an abnormal data stream as a normal data stream, and the class weight represents the weight when the label is a positive packet or a negative packet; the cost-sensitive loss function is expressed as: ; ; ; Among them, is the cost matrix; represents the cost when the true label is a negative bag and the predicted label is also a negative bag; represents the cost when a normal data stream is misjudged as an abnormal data stream; represents the cost weight ; represents the cost when the true label is a positive bag and the predicted label is also a positive bag; N represents the total number of positive and negative bags; is the cross-entropy loss; is the neural network weight; is the parameter that controls the regularization strength; represents the true label; represents the predicted label; represents the class weight; represents the number of positive bags in the new expanded positive bag set; represents the number of negative bags in the new reduced negative bag set; represents the bag-level prediction probability; represents each bag; represents the example-level classifier; represents the j-th example in the i-th bag; represents taking the maximum value of all examples in the bag; represents when the true label is a positive bag; represents when the true label is a negative bag; Construct a neural network model linear classifier according to the cost-sensitive loss function, and the neural network model linear classifier is used to determine whether the network traffic data stream is a positive packet or a negative packet; the neural network model linear classifier is represented by the following formula: ; ; Among them, is the linear classifier of the neural network model; is the statistical kernel mapping vector for each packet; represents each packet; is the weight vector; b is the bias term; is the -dimensional feature of the example, ; if , it is determined as a positive packet, otherwise it is determined as a negative packet; Train the linear classifier of the neural network model and count the current number of missed detections and the number of false detections ; Update the cost weight according to the following formula to achieve adaptive cost-sensitive learning until the optimization goal is reached: Among them, represents the updated cost weight, represents the cost weight before update, represents the learning rate, represents a parameter to prevent division by zero; The optimization objective satisfies the following conditions: Among them, is the cost matrix; N represents the total number of positive and negative bags; is the cross-entropy loss; is the neural network weight; is the parameter for controlling the regularization strength; represents the true label; represents the predicted label; represents the class weight; is the linear classifier of the neural network model; represents each bag; Use the optimized neural network model linear classifier to identify the network traffic.
2. The anomaly data stream classification and detection method based on unbalanced multi-instance learning according to claim 1, wherein The step of performing oversampling operations on all positive packets in the positive packet set to expand the examples in each positive packet and obtain an expanded new positive packet set includes: Randomly select an example from a positive bag in the positive bag set and its nearest neighbor , and generate a new example according to the following formula : Add the new example to the positive bag, and expand each example in the positive bag in the same way until the positive bag is expanded to 3 to 5 times its original size; Expand each positive packet in the positive packet set in the above manner to obtain an expanded new positive packet set.
3. An abnormal data stream classification and detection device based on unbalanced multi-instance learning, characterized in that, It includes: A sample division module configured to divide the network traffic into a positive packet set and a negative packet set; wherein, the positive packet set includes multiple positive packets, and a positive packet is a data stream with at least one abnormal data packet, the negative packet set includes multiple negative packets, and a negative packet is a data stream all of which are normal data packets, and both the positive packets and the negative packets contain multiple examples, and each example corresponds to a data packet; An oversampling module configured to perform oversampling operations on all positive packets in the positive packet set to expand the examples in each positive packet and obtain an expanded new positive packet set; An undersampling module configured to perform undersampling operations on all negative packets in the negative packet set to reduce the examples in each negative packet and obtain a reduced new negative packet set; A loss function construction module, configured to construct a cost-sensitive loss function of a neural network model based on a cost weight and a class weight; wherein, the cost weight represents the cost of misjudging an abnormal data stream as a normal data stream, and the class weight represents the weight when the label is a positive packet or a negative packet; the cost-sensitive loss function is expressed as: ; ; ; Among them, is the cost matrix; represents the cost when the true label is a negative bag and the predicted label is also a negative bag; represents the cost when a normal data flow is misjudged as an abnormal data flow; represents the cost weight ; represents the cost when the true label is a positive bag and the predicted label is also a positive bag; N represents the total number of positive and negative bags; is the cross-entropy loss; is the neural network weight; is the parameter that controls the regularization strength; represents the true label; represents the predicted label; represents the class weight; represents the number of positive bags in the new expanded positive bag set; represents the number of negative bags in the new reduced negative bag set; represents the bag-level prediction probability; represents each bag; represents the example-level classifier; represents the j-th example in the i-th bag; represents taking the maximum value of all examples in the bag; represents when the true label is a positive bag; represents when the true label is a negative bag; A classifier construction module configured to construct a neural network model linear classifier according to the cost-sensitive loss function, and the neural network model linear classifier is used to determine whether the network traffic data stream is a positive packet or a negative packet; the neural network model linear classifier is represented by the following formula: ; ; Among them, is the linear classifier of the neural network model; is the statistical kernel mapping vector for each packet; represents each packet; is the weight vector; b is the bias term; is the -dimensional feature of the example, ; if , it is determined as a positive packet, otherwise it is determined as a negative packet; A training module, configured to train the linear classifier of the neural network model and count the current number of missed alarms and the number of false alarms ; update the cost weight according to the following formula to achieve adaptive cost-sensitive learning until the optimization goal is reached: Among them, represents the updated cost weight, represents the cost weight before update, represents the learning rate, represents a parameter to prevent division by zero; The optimization objective satisfies the following conditions: Among them, is the cost matrix; N represents the total number of positive and negative bags; is the cross-entropy loss; is the neural network weight; is the parameter for controlling the regularization strength; represents the true label; represents the predicted label; represents the class weight; is the linear classifier of the neural network model; represents each bag; A classification and recognition module configured to use the optimized neural network model linear classifier to identify the network traffic.
4. The abnormal data stream classification and detection device based on unbalanced multi-instance learning according to claim 3, wherein: The oversampling module is further configured to: Randomly select an example from a positive bag in the positive bag set and its nearest neighbor , and generate a new example according to the following formula : Add the new example to the positive bag, and expand each example in the positive bag in the same way until the positive bag is expanded to 3 to 5 times its original size; Expand each positive packet in the positive packet set in the above manner to obtain an expanded new positive packet set.
Citation Information
Patent Citations
Hybrid sampling network flow sample balancing method
CN119598185A