Intrusion detection method and system based on data balance and feature collaboration
By introducing the SKnet layer into the DCGAN generator and combining the improved SRGAN, LSTM and cross attention mechanism, the data imbalance and generator stability problems in intrusion detection are solved, and more efficient intrusion detection performance is achieved.
Patent Information
- Application Number
- CN202510503132.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-22
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-04-22
AI Technical Summary
The prior art has data imbalance problems in intrusion detection, which leads to a degradation in the performance of the detection model. The existing DCGAN generator is sensitive to hyperparameters, and is prone to gradient vanishing and gradient explosion problems.
By adding an SKnet layer after the deconvolution layer inside the initial DCGAN generator, the generator is improved to solve the data imbalance problem, and combined with the improved SRGAN, LSTM and cross attention mechanism, depth and timing features are extracted, and feature fusion is performed to improve the classification effect of intrusion detection.
It effectively solves the problem of data imbalance, improves the quality of data generated by the generator, enhances the performance and robustness of the intrusion detection model, and achieves better classification results.
Smart Images

Figure CN120017430A_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of network security technology, and specifically relates to an intrusion detection method and system based on data balance and feature collaboration. Background Art
[0002] In the current environment, the Internet has become an indispensable infrastructure for modern society. Emerging technologies such as 5G, Internet of Things, artificial intelligence, cloud computing, and blockchain continue to promote the development of the Internet, causing global data traffic to grow exponentially. The scale and frequency of cyber attacks continue to increase. Cyber attacks such as distributed denial of service attacks, ransomware, phishing emails, and zero-day vulnerability exploits have become more complex and covert. These attacks not only target individual users, but also pose a threat to enterprises and national critical infrastructure. Intrusion detection is an important part of the current Internet's defense against cyber attacks, and the study of high-performance intrusion detection methods is increasingly favored by researchers.
[0003] However, the existing technology has the following problems when performing intrusion detection: First, there is data imbalance in the public data sets on the Internet, and the attack type data is far less than the normal traffic data, which can easily lead to the detection model being unable to obtain sufficient useful information during training, thereby causing the performance of the detection model to deteriorate; Second, while solving the data imbalance problem, the existing technology often solves it by introducing deep convolutional generative adversarial networks (DCGANs). However, the existing DCGAN generator has the following problems during training: the existing DCGAN generator is sensitive to hyperparameters and is prone to gradient vanishing and gradient exploding problems, which will affect the convergence of the DCGAN generator and the discriminator, causing the DCGAN generator to learn some fixed patterns during the learning and training process, resulting in certain similarities and limitations in the generated images. Summary of the invention
[0004] The purpose of the embodiments of the present application is to provide an intrusion detection method and system based on data balance and feature collaboration, which can solve the problem of data imbalance in network attack categories in the prior art and the problem of low performance of existing intrusion detection models.
[0005] In order to solve the above technical problems, this application is implemented as follows: In a first aspect, an embodiment of the present application provides an intrusion detection method based on data balance and feature collaboration, the method comprising: An SKnet layer is added after the deconvolution layer inside the initial DCGAN generator to obtain an improved DCGAN generator, wherein the SKnet layer includes: a convolution layer, a batch normalization layer, an activation function layer, a global average pooling layer, a fully connected layer, and a Softmax layer.
[0006] Inputting a preset random noise vector into the improved DCGAN generator for dimensionality reduction processing to obtain a balanced data set; The initial SRGAN generator is improved based on a preset fully connected layer, a deflattening layer, and a residual network layer to obtain an improved SRGAN generator, wherein the improved SRGAN generator consists of an input layer, a first fully connected layer, a second fully connected layer, a deflattening layer, a first convolutional layer, a residual network layer, and a second convolutional layer connected in sequence; Inputting the balanced data set into the improved SRGAN generator to extract deep features and obtain deep features; Input the balanced data set into a preset LSTM network model to extract time series features and obtain time series features; Acquire a query vector, a value vector, and a key vector based on the deep features and the temporal features; Based on the attention mechanism, the query vector, the key vector and the value vector are processed to obtain a fused feature map; The fused feature map is sequentially subjected to feature mapping, activation and classification processing to obtain an intrusion classification result.
[0007] As an optional implementation of the first aspect of the present application, a process of inputting a preset random noise vector into an improved DCGAN generator for dimensionality reduction processing to obtain a balanced data set includes: Performing linear transformation, standardization, and activation processing on the preset random noise in sequence to obtain a first feature map, where the dimension of the first feature map is higher than the dimension of the random noise; Deconvolution and upsampling are performed on the first feature map in sequence to obtain a second feature map, where the number of channels of the second feature map is half of that of the first feature map, and both the height and width are greater than those of the first feature map; Inputting the second feature map into a plurality of branch convolution kernels of different sizes for convolution processing to obtain a third feature map and a fourth feature map, wherein the feature extraction dimension of the fourth feature map is higher than that of the third feature map; Performing feature aggregation on the third feature map and the fourth feature map to generate an attention weight matrix; Performing weighted fusion on the third feature map and the fourth feature map based on the attention weight matrix to obtain a fused feature map; Performing deconvolution processing and feature enhancement processing on the fused feature map in sequence to obtain a fifth feature map, wherein the number of channels of the fifth feature map is half of that of the fused feature map, and the height and width are both greater than those of the fused feature map; A balanced data set is obtained based on the fifth feature map.
[0008] As an optional implementation manner of the first aspect of the present application, a process of acquiring a balanced data set based on the fifth feature map includes: Acquire and preprocess a preset initial data set to obtain a grayscale image data set; Performing convolution processing and activation processing on the fifth feature map in sequence to obtain a second data set, where the second data set has the same format and size as the grayscale image data set; Performing reverse normalization processing on the second data set to obtain a third data set, wherein the data value range of the third data set is consistent with the range of the initial data set; The third data set is merged with the initial data set to obtain a balanced data set.
[0009] As an optional implementation of the first aspect of the present application, the process of improving the initial SRGAN generator based on the preset fully connected layer, the deflattening layer and the residual network layer to obtain the improved SRGAN generator includes: A fully connected layer and an unflattened layer are added after the input layer of the initial SRGAN generator, the upper layer in the initial SRGAN generator is removed, and multiple residual network layers are added between the convolutional layers inside the generator to obtain an improved SRGAN generator.
[0010] As an optional implementation of the first aspect of the present application, the balanced data set is input into the improved SRGAN generator for deep feature extraction, and the process of obtaining deep features includes: Inputting the balanced data set into the first fully connected layer to perform vector conversion processing to obtain a first vector; Inputting the first vector into a second fully connected layer for linear transformation mapping to obtain a second vector, wherein the length of the second vector is greater than that of the first vector; Input the second vector into a deflattening layer for deflattening to obtain a third vector, wherein the dimension of the third vector is higher than that of the second vector; The third vector is sequentially input into the first convolutional layer, the residual network layer and the second convolutional layer for feature extraction to obtain deep features.
[0011] As an optional implementation of the first aspect of the present application, based on the attention mechanism, the query vector, the key vector and the value vector are processed to obtain a fused feature map, including: Calculate the similarity between the query vector and the key vector based on the cross attention mechanism, and generate an attention weight matrix; The value vector is weighted based on the attention weight matrix to obtain a fused feature map.
[0012] As an optional implementation of the first aspect of the present application, the mathematical expression of the fused feature map is: ; ; in, represents the fused feature map, represents the local feature map, represents the global feature map, represents the first weight matrix, represents the second weight matrix, represents batch normalization, represents the fully connected layer mapping operation, represents the Relu activation function, represents the average pooling result, represents the fully connected weight matrix, Represents the output vector after the full connection layer transformation.
[0013] In a second aspect, an embodiment of the present application provides an intrusion detection system based on data balance and feature collaboration, the system comprising: SKnet module, which is used to add an SKnet layer after the deconvolution layer inside the initial DCGAN generator to obtain an improved DCGAN generator. The SKnet module consists of a convolution layer, a batch normalization layer, an activation function layer, a global average pooling layer, a fully connected layer, and a Softmax layer connected in sequence; A dimensionality reduction processing module, which is used to input a preset random noise vector into the improved DCGAN generator for dimensionality reduction processing to obtain a balanced data set; An SRGAN module, wherein the SRGAN module is used to improve the initial SRGAN generator according to a preset fully connected layer, an anti-flattening layer, and a residual network layer to obtain an improved SRGAN generator; A deep feature extraction module, wherein the deep feature extraction module is used to input the balanced data set into the improved SRGAN generator to perform deep feature extraction and obtain deep features; A time series feature extraction module, wherein the time series feature extraction module is used to input the balanced data set into a preset LSTM network model to extract time series features and obtain time series features; A mapping module, the mapping module is used to map the deep features to obtain a query vector, and map the time series features to obtain a value vector and a key vector; An attention mechanism module, wherein the attention mechanism module is used to calculate the similarity between the query vector and the key vector, generate an attention weight matrix, and weight the value vector based on the attention weight matrix to obtain a fused feature map; The classification module is used to perform feature mapping, activation and classification processing on the fused feature map in sequence to obtain an intrusion classification result.
[0014] In a third aspect, an embodiment of the present application provides an electronic device, which includes a processor, a memory, and a program or instruction stored in the memory and executable on the processor, wherein the program or instruction, when executed by the processor, implements the steps of the method described in the first aspect.
[0015] In a fourth aspect, an embodiment of the present application provides a readable storage medium, including a processor, a memory, and a program or instruction stored in the memory and executable on the processor, wherein the program or instruction, when executed by the processor, implements the steps of the method described in the first aspect.
[0016] Compared with the prior art, the present invention proposes an intrusion detection method based on data balance and feature collaboration. First, in view of the problem of uneven distribution of sample numbers in existing data sets, SKNet is introduced to improve the DCGAN model, and SKNet is used to assist the discriminator to efficiently discriminate between real samples and generated samples, thereby promoting the accelerated convergence of the model, improving the quality of generator generation, and solving the problem of data set imbalance in the data level intrusion detection training process. At the same time, the present invention proposes a network intrusion detection model that integrates improved SRGAN, LSTM and cross-attention mechanisms. The intrusion detection model can use the improved SRGAN generator to extract local and global deep-level feature representations of samples, use the LSTM module to model the time series to capture the global context information of samples, and dynamically adjust the feature weights through the self-attention module to complete the feature extraction of the data set and then classify it. By comparing with other models on the original data set and the balanced data set, the improved fusion model is better in overall performance. Specifically, the classification effect of the improved fusion model is better than that of the classification model of a single module, and the model performs better than the original data set on the balanced data set. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 It is a flow chart of an intrusion detection method based on data balance and feature collaboration provided by the first embodiment of the present application; Figure 2 is a schematic diagram of a training model provided in the first embodiment of the present application; Figure 3 is a structural diagram of the improved DCGAN provided in the first embodiment of the present application; Figure 4is a structural diagram of an intrusion detection model provided by the first embodiment of the present application; Figure 5 This is a structural diagram of an intrusion detection system based on data balance and feature collaboration provided in the second embodiment of the present application. DETAILED DESCRIPTION
[0018] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0019] The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described here. In addition, the "and / or" in the specification and claims represents at least one of the connected objects, and the character " / " generally represents that the objects associated with each other are in an "or" relationship.
[0020] In conjunction with the accompanying drawings, an intrusion detection method and system based on data balance and feature collaboration provided by an embodiment of the present application are described in detail through specific embodiments and their application scenarios.
[0021] Example 1 See also Figure 1 , which is a flow chart of an intrusion detection method based on data balance and feature collaboration proposed in the first embodiment of the present application. The proposed method includes steps S1 to S8.
[0022] Step S1: Add an SKnet layer after the deconvolution layer inside the initial DCGAN generator to obtain an improved DCGAN generator, wherein the SKnet layer includes: a convolution layer, a batch normalization layer, an activation function layer, a global average pooling layer, a fully connected layer, and a Softmax layer.
[0023] Among them, the convolution layer, batch normalization layer, activation function layer, global average pooling layer, fully connected layer, and Softmax layer are connected in sequence to form the SKnet layer of the present invention.
[0024] The advantage of introducing the SKnet layer in the present invention is that the present invention can use the SKnet layer to assist the discriminator to efficiently distinguish between real samples and generated samples, thereby promoting the accelerated convergence of the improved DCGAN model and improving the quality of the data generated by the generator, thereby solving the problem of data set imbalance in the data-level intrusion detection training process. Figure 2 is a schematic diagram of the training model of this application, Figure 3 This is the improved DCGAN structure diagram of this application.
[0025] Step S2: Input the preset random noise vector into the improved DCGAN generator for dimensionality reduction to obtain a balanced data set.
[0026] In step S2 of the present invention, the specific process of obtaining a balanced data set includes: inputting a preset random noise into a generator for initialization processing to obtain a first feature map, wherein the dimension of the first feature map is higher than the dimension of the random noise; performing deconvolution operations on the first feature map in sequence to achieve the purpose of upsampling, and obtaining a second feature map, wherein the number of channels of the second feature map is half of that of the first feature map, and the height and width are both higher than the first feature map; inputting the second feature map into a plurality of branch convolution kernels of different sizes for convolution processing to obtain a third feature map and a fourth feature map, wherein the fourth feature map and the third feature map are feature maps containing local details and global information, respectively; performing feature aggregation on the third feature map and the fourth feature map to generate an attention weight matrix; performing weighted fusion on the third feature map and the fourth feature map based on the attention weight matrix to obtain a fused feature map; performing deconvolution processing and feature enhancement processing on the fused feature map in sequence to obtain a fifth feature map, wherein the number of channels of the fifth feature map is half of that of the fused feature map, and the height and width are both higher than the fused feature map; and obtaining a balanced data set based on the fifth feature map.
[0027] Specifically, the preset random noise is input into the generator for initialization processing, and the process of obtaining the first feature map includes the following steps: a 1×100 random noise vector that obeys a uniform distribution or a Gaussian distribution is input into the generator, and the fully connected layer first maps the noise to a 1×1152 vector through a linear transformation, and then after reshaping, a 128×3×3 feature map is output, which is the first feature map.
[0028] Specifically, the first feature map is sequentially deconvolved and upsampled to obtain the second feature map, comprising the following steps: the 128×3×3 first feature map is input into the deconvolution layer and gradually upsampled by micro-step convolution to obtain a 64×5×5 second feature map. Obviously, the number of channels of the second feature map is 64, and the height and width are both 5. The number of channels of the first feature map is 128, and the height and width are both 3. The number of channels of the second feature map is half of that of the first feature map, and the height and width are both higher than those of the first feature map, and each deconvolution layer is followed by a batch normalization layer and a LeakyReLU layer, and the LeakyReLU layer is followed by an SK convolution layer.
[0029] Specifically, the second feature map is input into convolution kernels with multiple branches of different sizes for convolution processing to obtain the third feature map and the fourth feature map, including: inputting the 64×5×5 second feature map into convolution kernels with branch sizes of 3×3 and 5×5 for parallel convolution processing, respectively, to obtain the third feature map and the fourth feature map accordingly, wherein the 3×3 convolution kernel is used to capture the local details of the second feature map, and the 5×5 convolution kernel is used to associate the global information of the second feature map. Therefore, the feature extraction dimension of the third feature map is higher than that of the fourth feature map (the feature map dimension obtained by the small convolution kernel is slightly higher), and the number of convolution kernel branches set in the present invention is 2.
[0030] Specifically, the process of performing feature aggregation on the third feature map and the fourth feature map to generate an attention weight matrix specifically includes: first, performing global average pooling operations on the third feature map and the fourth feature map respectively, compressing them into two 1×1×C channel descriptors; then, connecting the two 1×1×C channel descriptors, and generating a channel attention vector through a fully connected layer; finally, generating an attention weight matrix based on the channel attention vector. The calculation formula of the channel descriptor is as follows: and formula As shown: in, Represents the feature map after feature fusion, and Represents feature maps of different sizes, Indicates The result after average pooling of channels is: represents the average pooling operation, and Represent the width and height of the feature map respectively, , , Represents the feature map before feature fusion.
[0031] The calculation formula of the channel attention vector is as follows and formula As shown: in, represents the output vector after the full connection layer transformation, represents the fully connected layer operation, represents the activation function, represents batch normalization, represents the fully connected weight matrix, represents the dimension after dimensionality reduction, represents the number of input feature channels, represents the scaling hyperparameter, Indicates the preset minimum latitude value. Represents the average pooling result.
[0032] Specifically, the process of weighted fusion of the third feature map and the fourth feature map based on the attention weight matrix to obtain the fused feature map includes the following steps: first, weight allocation is performed, that is, the attention weight matrix of each branch is generated based on the attention weight vector, and the calculation formula is formula and formula As shown: in, and is the attention weight of feature maps of different scales, and represents the weight matrix, Represents the feature vector obtained after average pooling.
[0033] Specifically, the third feature map and the fourth feature map are weightedly fused based on the attention weight matrix to obtain the fused feature map. The mathematical expression of the fused feature map is as follows: and formula As shown: in, represents the fused feature map, represents the local feature map, represents the global feature map, represents the first weight matrix, represents the second weight matrix, represents batch normalization, represents the fully connected layer mapping operation, represents the Relu activation function, represents the average pooling result, represents the fully connected weight matrix, Represents the output vector after the full connection layer transformation.
[0034] Specifically, the fused feature map is sequentially subjected to deconvolution processing and feature enhancement processing to obtain the fifth feature map, including: deconvolution processing of the 64×5×5 fused feature map again, and then feature enhancement processing is performed on the result obtained by the deconvolution, and then a fifth feature map of size 32×9×9 is output, wherein the number of channels of the fifth feature map is 32, and the height and width are both 9, the number of channels of the fused feature map is 64, and the height and width are both 5, the number of channels of the fifth feature map is half of that of the fused feature map, and the height and width are both higher than the fused feature map.
[0035] Specifically, the process of obtaining a balanced data set based on the fifth feature map includes: obtaining and preprocessing a preset initial data set to obtain a grayscale image data set; performing convolution processing and activation processing on the fifth feature map in sequence to obtain a second data set, and the second data set has the same format size as the grayscale image data set, both of which are 9×9; performing reverse normalization processing on the second data set to obtain a third data set, and the value range of pixels in the third data set is equal to the value range of data in the initial data set; merging the third data set with the initial data set to obtain a balanced data set.
[0036] In summary, the present invention first generates two sets of feature maps through multi-scale feature branches. These two sets of feature maps can capture local details and be associated with the global context, thereby improving the flexibility of feature expression. Next, feature aggregation and attention weight generation operations are performed on these two sets of feature maps, and attention weight calculations are performed to concatenate the channel descriptors of each branch to generate a channel attention vector. Finally, dynamic feature fusion is performed, that is, the weight matrix of each branch is obtained based on the generated channel attention vector, and the two sets of feature maps generated by the multi-scale feature branch are weightedly fused to output the fused feature map. The fused feature map can not only capture the feature information of different scales after deconvolution, but also enrich the details of the image generated by the generator.
[0037] Step S3: The initial SRGAN generator is improved based on the preset fully connected layer, deflattening layer and residual network layer to obtain an improved SRGAN generator, wherein the improved SRGAN generator consists of an input layer, a first fully connected layer, a second fully connected layer, a deflattening layer, a first convolutional layer, a residual network layer, and a second convolutional layer connected in sequence.
[0038] In step S3 of the present invention, compared with the initial SRGAN generator, the improved SRGAN generator of the present invention adds a fully connected layer and a deflattening layer after the input layer of the initial SRGAN generator, removes the upper layer in the initial SRGAN generator, and adds 5 residual blocks between the first convolutional layer and the second convolutional layer inside the generator.
[0039] The function of the first fully connected layer of the present invention is: when the data set is input to the input layer of the improved SRGAN generator to obtain the output of the input layer, the first fully connected layer can perform vector conversion on the output of the input layer to obtain the converted vector; the function of the second fully connected layer of the present invention is: the converted vector can be mapped to obtain a vector of higher length; the deflattening layer of the present invention is used to realize the mapping of the input one-dimensional vector to the high-dimensional feature space to adapt to the input of the subsequent convolutional layer. At the same time, the upper adoption layer in the initial SRGAN generator is removed, and 5 residual blocks are added between the convolutional layers inside the generator, so that the network can learn deep feature representation more easily, solving the gradient disappearance and degradation problems that occur with the increase of network depth.
[0040] Step S4: Input the balanced data set into the improved SRGAN generator to extract deep features and obtain deep features.
[0041] In step S4 of the present invention, the specific step of obtaining the deep feature includes: inputting the balanced data set into the fully connected layer after the input layer of the SRGAN generator to perform vector conversion to obtain a first vector of 1×79; inputting the first vector of 1×79 into the fully connected layer after the input layer of the SRGAN generator again to perform linear transformation mapping processing to obtain a second vector of 1×81, wherein the length of the second vector is 81, which is greater than the length of the first vector 79; inputting the second vector into the deflattening layer of the SRGAN generator to perform deflattening processing to obtain a third vector of 1×9×9, wherein the dimension of the third vector is three-dimensional, which is greater than the two-dimensional dimension of the second vector; inputting the third vector of 1×9×9 into the first convolutional layer of the SRGAN generator to perform feature extraction to obtain the deep features of the balanced data set.
[0042] Specifically, when performing feature extraction, the upsampling layer of the original SRGAN generator needs to be removed. At the same time, the present invention sets the number of residual blocks to 5, and adds 5 residual blocks between the convolutional layers inside the improved SRGAN generator so that the network can learn deep feature representation more easily. The mathematical expression of the residual block is as follows: As shown: in, represents a series of nonlinear transformation operations, represents the parameter weight of the residual block, is the input of the residual block, is a deep feature.
[0043] Step S5: Input the balanced data set into a preset LSTM network model to extract time series features and obtain time series features.
[0044] In step S5 of the present invention, the LSTM network model enables the network to retain information over a long time span through its unique unit structure. The most important parts are the forget gate, input gate and output gate, and the processing object is called a "cell". The internal structure of the LSTM network model used in the present invention specifically includes the following three parts: 1) Forget gate; The balanced data set is converted into a 1×79 vector as the current "cell" input. The forget gate calculates the cell state of the previous time step and the current input, and outputs a value between 0 and 1 to control the degree of information forgetting, that is, it determines which information in the current cell state needs to be discarded. The calculation formula is as follows: As shown: in, is the weight matrix of the forget gate, is the bias vector of the forget gate, Indicates the hidden state at the last moment. represents the Sigmoid activation function, is the output of the forget gate, Used to control the degree of forgetting for each element in the cell state.
[0045] 2) Input gate; The input gate determines what new information needs to be added to the "cell" state. It combines the current input and the hidden state of the previous time step to generate an update value and combine it with the candidate memory. The calculation formula is as follows As shown: in, is the switch state vector of the input gate, which is used to control the degree of addition of the current input information. represents the Sigmoid activation function, is the candidate cell state vector, is the weight matrix of the input gate, is the input gate bias vector, is the weight matrix used when generating candidate cell states, is the bias vector used when generating candidate cell states, is the current cell state, is the cell state at the previous moment.
[0046] 3) Output gate; The output gate controls the hidden state output of the current time step so that useful information can be passed to the next time step. The calculation formula is as follows: and formula As shown: in, is the current hidden state, is the switch state vector of the output gate, is the weight matrix of the output gate, is the bias vector of the output gate, is the current cell state, is the Sigmoid activation function, Indicates the hidden state at the last moment. Used to control the degree of forgetting for each element in the cell state.
[0047] In summary, after the balanced data set is input into the forget gate, input gate, and output gate in sequence, the temporal characteristics of the balanced data set can be obtained.
[0048] Step S6: Acquire a query vector, a value vector and a key vector based on the deep features and the temporal features.
[0049] In step S6 of the present invention, the specific steps of obtaining the query vector, the value vector and the key vector include: mapping the deep features to obtain the query vector, and mapping the time series features to obtain the value vector and the key vector.
[0050] Step S7: Based on the attention mechanism, the query vector, the key vector and the value vector are processed to obtain a fused feature map.
[0051] In step S7 of the present invention, the specific steps of obtaining the fused feature map include: calculating the similarity between the query vector and the key vector based on the cross attention mechanism to generate an attention weight matrix; weighting the value vector based on the attention weight matrix to obtain the fused feature map. The calculation formula of the similarity between the query vector and the key vector is as follows: As shown: in, represents the query vector, represents the key vector, represents the matrix transpose, represents the scaling factor, Represents the query vector With key vector The similarity.
[0052] Specifically, the mathematical expression of the attention weight matrix is as follows: As shown: in, represents the attention weight matrix, express Activation function, represents the query vector, represents the key vector, represents the matrix transpose, Represents the scaling factor.
[0053] The mathematical expression of the fusion feature map is as follows: and As shown: in, represents the cross attention calculation, represents the query vector, represents the key vector, represents a value vector, express Activation function, represents the matrix transpose, represents the scaling factor, represents the deep features of the balanced dataset, represents the time series characteristics of the balanced data set, represents the output of the cross-attention mechanism, represents the attention calculation, Represents the exclusive-or operation.
[0054] Step S8: performing feature mapping, activation and classification processing on the fused feature map in sequence to obtain an intrusion classification result.
[0055] Specifically, see Figure 4, represents the structural diagram of the intrusion detection model provided by the present invention. The present invention constructs an intrusion detection model based on SRGAN, LSTM and cross attention mechanism. After the fusion feature map is sequentially feature mapped, Softmax normalization is adopted, and the output of the intrusion detection model integrating SRGAN, LSTM and cross attention mechanism is converted into a category probability distribution through Sigmoid activation function, and optimized through the cross entropy loss function, so that the predicted probability of the intrusion detection model matches the true category distribution as much as possible, and the corresponding predicted value is obtained. Moreover, the intrusion detection model of the present invention can make a final category judgment on the predicted value based on the principle of probability maximization, and finally obtain the intrusion classification result.
[0056] In order to illustrate the feasibility of the intrusion detection method based on data balance and feature collaboration proposed by the present invention, a simulation experiment is conducted below. The present invention conducts a balancing experiment on a few types of data, including botnets, brute force attacks, cross-site scripting attacks, penetration attacks, SQL injection attacks, and heartbleed attacks. By introducing SKNet into the DCGAN generator, the data enhancement effect is obvious, as shown in Table 1.
[0057] Table 1 Data quantity distribution table before and after balancing The comparison of FID (Frechet Inception Distance) between the initial DCGAN and the improved DCGAN is shown in Table 2. Among them, the Frechet distance can represent the similarity of images and is one of the evaluation indicators of image similarity.
[0058] Table 2 Comparison of FID values between initial DCGAN and improved DCGAN As can be seen from Table 2, among the data generated by the improved DCGAN, the FID values of the first three types are basically reduced to about 30, and the FID values of the last three types are also reduced compared to the original model. This shows that the data generated by the improved DCGAN is closer to the real data than the data generated by the initial DCGAN.
[0059] In order to verify the improved DCGAN data enhancement effect, the MLP classification model was used to carry out control experiments on the initial dataset, DCGAN enhanced dataset and improved DCGAN enhanced dataset.
[0060] It should be noted that the present invention selects the public data set CICIDS-2017 for data preprocessing, and the preprocessing process includes data cleaning (deleting outliers and missing values), category merging, feature screening, character feature digitization, and data normalization steps. The initial data set selected by the present invention has 79 features in CSV format. Because the 79th feature is a character feature, it needs to be uniquely encoded first, and then mapped to pixels, that is, the normalized feature is multiplied by 255 and mapped to a grayscale value, and two zero pixels are added at the end to obtain a 9×9 grayscale image, and then 75% of them are selected as a training set and 25% as a test set. The performance comparison table of the initial DCGAN and the improved DCGAN is shown in Table 3.
[0061] Table 3 Performance comparison of initial DCGAN and improved DCGAN As can be seen from Table 3, the average precision, recall and F1 score of the improved DCGAN enhanced dataset have all improved, which shows that the quality of generated data can be improved after SKNet improves the initial DCGAN model.
[0062] In order to verify the effectiveness of the intrusion detection model proposed in the present invention, a control experiment was conducted between multiple existing models and the intrusion detection model proposed in the present invention. The results are shown in Table 4: Table 4 Performance comparison of the intrusion detection model of the present invention It can be seen from Table 4 that the intrusion detection model proposed in the present invention outperforms other models on all data sets, especially on the improved DCGAN enhanced data set, with an accuracy of 99.6%, a recall of 99.5%, and an F1 score of 99.5%. This shows that the intrusion detection model proposed in the present invention has a strong ability to recognize complex attack behaviors.
[0063] Compared with the prior art, the present invention firstly introduces the SKNet layer to improve the initial DCGAN model to address the problem of uneven distribution of sample numbers in existing data sets. The SKNet layer is used to assist the internal discriminator of the initial DCGAN model to efficiently distinguish between real samples and generated samples, thereby promoting the convergence speed of the intrusion detection model, improving the quality of data generated by the generator, and solving the problem of data set imbalance in the intrusion detection training process at the data level.
[0064] In summary, the present invention aims at the problems and shortcomings of the existing network intrusion detection related methods, and proposes an intrusion detection model that integrates improved SRGAN, LSTM and cross-attention mechanism. The intrusion detection model can use the improved SRGAN generator to extract the local and global deep-level feature representation of the sample, use the LSTM time series modeling ability to capture the global context information of the sample, and dynamically adjust the feature weights through the self-attention module to complete the feature extraction of the data set and then classify it. By comparing with other models on the initial data set and the balanced data set, the intrusion detection model proposed by the present invention has better overall performance.
[0065] Example 2 See also Figure 5 , shown is an intrusion detection system based on data balance and feature collaboration proposed in the second embodiment of the present application, including: SKnet module, the SKnet module is used to add an SKnet layer after the deconvolution layer inside the initial DCGAN generator to obtain an improved DCGAN generator, the SKnet module includes: a convolution layer, a batch normalization layer, an activation function layer, a global average pooling layer, a fully connected layer and a Softmax layer; A dimensionality reduction processing module, which is used to input a preset random noise vector into the improved DCGAN generator for dimensionality reduction processing to obtain a balanced data set; An SRGAN module, wherein the SRGAN module is used to improve the initial SRGAN generator according to the fully connected layer, the deflattening layer, and the residual block to obtain an improved SRGAN generator; A deep feature extraction module, wherein the deep feature extraction module is used to input the balanced data set into the improved SRGAN generator to perform deep feature extraction and obtain deep features; A time series feature extraction module, wherein the time series feature extraction module is used to input the balanced data set into a preset LSTM network model to extract time series features and obtain time series features; A mapping module, the mapping module is used to map the deep features to obtain a query vector, and map the time series features to obtain a value vector and a key vector; A cross attention mechanism module, wherein the cross attention mechanism module is used to calculate the similarity between the query vector and the key vector, generate an attention weight matrix, and weight the value vector based on the attention weight matrix to obtain a fused feature map; The classification module is used to perform feature mapping, activation and classification processing on the fused feature map in sequence to obtain an intrusion classification result.
[0066] The beneficial effect of an intrusion detection system based on data balance and feature collaboration proposed by the present invention is that the present invention adds an SKnet module after the deconvolution layer inside the initial DCGAN generator, and performs three core operations of the SKnet module: multi-scale feature branch generation, feature aggregation and attention weight generation, and feature map fusion. Among them, the local feature map generated by the multi-scale feature branch can capture local details, and the generated global feature map can be associated with the global context, thereby improving the flexibility of feature expression; through feature aggregation and attention weight generation, and attention weight calculation, the channel descriptors of each branch are spliced to generate a channel attention vector, and the timing feature and depth feature are obtained; based on the timing feature and the depth feature, the feature map fusion operation is performed, and the fused feature map is finally output. The fused feature map generated by the SKnet module can capture the feature information of different scales after deconvolution, enrich the details of the generated image, and also enhance the expression ability and robustness of the model.
[0067] Secondly, the SRGAN module proposed in the present invention changes the original convolutional layer of the SRGAN generator into a fully connected layer, and then introduces a deflattening layer to realize the mapping of the input one-dimensional vector to a high-dimensional feature space to adapt to the input of the subsequent convolutional layer. To realize the feature extraction operation, it is also necessary to remove the original upsampling layer of the generator, and add 5 residual blocks between the two convolutional layers so that the network can more easily learn deep feature representations, solving the problem of gradient disappearance and degradation that occurs as the network depth increases.
[0068] Finally, the present invention integrates the SRGAN module, the preset LSTM network model and the cross-attention mechanism module to build the intrusion detection model of the present invention. After preprocessing, the original data set is subjected to feature extraction by the improved SRGAN and LSTM models respectively, and the extracted features are input into the cross-attention mechanism module respectively. The cross-attention mechanism module maps the features extracted by the SRGAN generator to a query vector, maps the features extracted by the LSTM to a value vector and a key vector, and calculates the similarity between the query vector and the key vector to obtain a similarity score matrix and an attention weight matrix, and finally uses the weight matrix to weight the value vector to obtain the final feature. The cross-attention mechanism builds an interactive bridge for the features extracted by the SRGAN generator and the LSTM, which allows the intrusion detection model of the present invention to dynamically adjust the attention to each feature according to the context, so that the intrusion detection model of the present invention can combine spatial features and temporal features when processing data.
[0069] An intrusion detection system based on data balance and feature collaboration in the embodiment of the present application can be a device, or a component, integrated circuit, or chip in a terminal. The device can be a mobile electronic device or a non-mobile electronic device. Exemplarily, the mobile electronic device can be a mobile phone, a tablet computer, a laptop computer, a PDA, an in-vehicle electronic device, a wearable device, an ultra-mobile personal computer (ultra-mobile personal computer, UMPC), a netbook or a personal digital assistant (personal digital assistant, PDA), etc., and the non-mobile electronic device can be a server, a network attached storage (Network Attached Storage, NAS), a personal computer (personal computer, PC), a television (television, TV), a teller machine or a self-service machine, etc., which is not specifically limited in the embodiment of the present application.
[0070] In the embodiment of the present application, an intrusion detection system based on data balance and feature coordination can be a device with an operating system. The operating system can be an Android operating system, an iOS operating system, or other possible operating systems, which are not specifically limited in the embodiment of the present application.
[0071] The intrusion detection system based on data balance and feature collaboration provided in the embodiment of the present application can achieve Figures 1 to 4 In the method embodiment, each process of implementing an intrusion detection system based on data balance and feature collaboration is not described here to avoid repetition.
[0072] Optionally, an embodiment of the present application also provides an electronic device, including a processor, a memory, and a program or instruction stored in the memory and executable on the processor. When the program or instruction is executed by the processor, each process of the above-mentioned intrusion detection method embodiment based on data balance and feature collaboration is implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.
[0073] An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, each process of the above-mentioned intrusion detection method embodiment based on data balance and feature collaboration is implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.
[0074] The processor is the processor in the electronic device described in the above embodiment. The readable storage medium includes a computer readable storage medium, such as a computer read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0075] It should be noted that, in this article, the terms "comprise", "include" or any other variant thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise one..." do not exclude the presence of other identical elements in the process, method, article or device including the element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in reverse order according to the functions involved, for example, the described method may be performed in an order different from that described, and various steps may also be added, omitted, or combined. In addition, the features described with reference to certain examples may be combined in other examples.
[0076] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, a magnetic disk, or an optical disk), and includes a number of instructions for a terminal (which can be a mobile phone, a computer, a server, an air conditioner, or a network device, etc.) to execute the methods described in each embodiment of the present application.
[0077] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of the present application, ordinary technicians in this field can also make many forms without departing from the purpose of the present application and the scope of protection of the claims, all of which are within the protection of the present application.
Claims
1. An intrusion detection method based on data balance and feature collaboration, characterized in that: include: Add an SKnet layer after the deconvolution layer inside the initial DCGAN generator to obtain an improved DCGAN generator, wherein the SKnet layer includes: a convolution layer, a batch normalization layer, an activation function layer, a global average pooling layer, a fully connected layer, and a Softmax layer; Inputting a preset random noise vector into the improved DCGAN generator for dimensionality reduction processing to obtain a balanced data set; The initial SRGAN generator is improved based on a preset fully connected layer, a deflattening layer, and a residual network layer to obtain an improved SRGAN generator, wherein the improved SRGAN generator consists of an input layer, a first fully connected layer, a second fully connected layer, a deflattening layer, a first convolutional layer, a residual network layer, and a second convolutional layer connected in sequence; Inputting the balanced data set into the improved SRGAN generator to extract deep features and obtain deep features; Input the balanced data set into a preset LSTM network model to extract time series features and obtain time series features; Acquire a query vector, a value vector, and a key vector based on the deep features and the temporal features; Based on the attention mechanism, the query vector, the key vector and the value vector are processed to obtain a fused feature map; The fused feature map is sequentially subjected to feature mapping, activation and classification processing to obtain an intrusion classification result.
2. According to claim 1, an intrusion detection method based on data balance and feature collaboration is characterized in that: The process of inputting the preset random noise vector into the improved DCGAN generator for dimensionality reduction to obtain a balanced data set includes: Performing linear transformation, standardization, and activation processing on the preset random noise in sequence to obtain a first feature map, where the dimension of the first feature map is higher than the dimension of the random noise; Deconvolution and upsampling are performed on the first feature map in sequence to obtain a second feature map, where the number of channels of the second feature map is half of that of the first feature map, and both the height and width are greater than those of the first feature map; Inputting the second feature map into a plurality of branch convolution kernels of different sizes for convolution processing to obtain a third feature map and a fourth feature map, wherein the feature extraction dimension of the fourth feature map is higher than that of the third feature map; Performing feature aggregation on the third feature map and the fourth feature map to generate an attention weight matrix; Performing weighted fusion on the third feature map and the fourth feature map based on the attention weight matrix to obtain a fused feature map; Performing deconvolution processing and feature enhancement processing on the fused feature map in sequence to obtain a fifth feature map, wherein the number of channels of the fifth feature map is half of that of the fused feature map, and the height and width are both greater than those of the fused feature map; A balanced data set is obtained based on the fifth feature map.
3. The intrusion detection method based on data balance and feature collaboration according to claim 2 is characterized in that: The process of obtaining a balanced data set based on the fifth feature map includes: Acquire and preprocess a preset initial data set to obtain a grayscale image data set; Performing convolution processing and activation processing on the fifth feature map in sequence to obtain a second data set, where the second data set has the same format and size as the grayscale image data set; Performing reverse normalization processing on the second data set to obtain a third data set, wherein the data value range of the third data set is consistent with the range of the initial data set; The third data set is merged with the initial data set to obtain a balanced data set.
4. The intrusion detection method based on data balance and feature collaboration according to claim 1 is characterized in that: The process of improving the initial SRGAN generator based on the preset fully connected layer, deflattening layer and residual network layer to obtain the improved SRGAN generator includes: A fully connected layer and an unflattened layer are added after the input layer of the initial SRGAN generator, the upper layer in the initial SRGAN generator is removed, and multiple residual network layers are added between the convolutional layers inside the generator to obtain an improved SRGAN generator.
5. The intrusion detection method based on data balance and feature collaboration according to claim 1 is characterized in that: The balanced data set is input into the improved SRGAN generator for deep feature extraction. The process of obtaining deep features includes: Inputting the balanced data set into the first fully connected layer to perform vector conversion processing to obtain a first vector; Inputting the first vector into a second fully connected layer for linear transformation mapping to obtain a second vector, wherein the length of the second vector is greater than that of the first vector; Input the second vector into a deflattening layer for deflattening to obtain a third vector, wherein the dimension of the third vector is higher than that of the second vector; The third vector is sequentially input into the first convolutional layer, the residual network layer and the second convolutional layer for feature extraction to obtain deep features.
6. The intrusion detection method based on data balance and feature collaboration according to claim 1 is characterized in that: The process of processing the query vector, the key vector, and the value vector based on the attention mechanism to obtain a fused feature map includes: Calculate the similarity between the query vector and the key vector based on the cross attention mechanism, and generate an attention weight matrix; The value vector is weighted based on the attention weight matrix to obtain a fused feature map.
7. The intrusion detection method based on data balance and feature collaboration according to claim 6 is characterized in that: The mathematical expression of the fusion feature map is: ; ; in, represents the fused feature map, represents the local feature map, represents the global feature map, represents the first weight matrix, represents the second weight matrix, represents batch normalization, represents the fully connected layer mapping operation, represents the Relu activation function, represents the average pooling result, represents the fully connected weight matrix, Represents the output vector after transformation of the fully connected layer.
8. An intrusion detection system based on data balance and feature collaboration, characterized in that: The system comprises: SKnet module, which is used to add an SKnet layer after the deconvolution layer inside the initial DCGAN generator to obtain an improved DCGAN generator. The SKnet module consists of a convolution layer, a batch normalization layer, an activation function layer, a global average pooling layer, a fully connected layer, and a Softmax layer connected in sequence; A dimensionality reduction processing module, which is used to input a preset random noise vector into the improved DCGAN generator for dimensionality reduction processing to obtain a balanced data set; An SRGAN module, wherein the SRGAN module is used to improve the initial SRGAN generator according to a preset fully connected layer, an anti-flattening layer, and a residual network layer to obtain an improved SRGAN generator; A deep feature extraction module, wherein the deep feature extraction module is used to input the balanced data set into the improved SRGAN generator to perform deep feature extraction and obtain deep features; A time series feature extraction module, wherein the time series feature extraction module is used to input the balanced data set into a preset LSTM network model to extract time series features and obtain time series features; A mapping module, the mapping module is used to map the deep features to obtain a query vector, and map the time series features to obtain a value vector and a key vector; An attention mechanism module, wherein the attention mechanism module is used to calculate the similarity between the query vector and the key vector, generate an attention weight matrix, and weight the value vector based on the attention weight matrix to obtain a fused feature map; The classification module is used to perform feature mapping, activation and classification processing on the fused feature map in sequence to obtain an intrusion classification result.
9. An electronic device, characterized in that: It includes a processor, a memory, and a program or instruction stored in the memory and executable on the processor. When the program or instruction is executed by the processor, the steps of an intrusion detection method based on data balance and feature collaboration as described in any one of claims 1 to 7 are implemented.
10. A readable storage medium, characterized in that: The readable storage medium stores programs or instructions, and when the programs or instructions are executed by the processor, the steps of an intrusion detection method based on data balance and feature collaboration as described in any one of claims 1-7 are implemented.
Citation Information
Patent Citations
Gaussian blur image restoration method based on generate antagonistic network
CN109118438A
Rotating machine fault imbalance data generation method and computer equipment
CN114611233A
AD prediction algorithm based on multi-scale feature fusion and bilinear residual network
CN115394446A
Cloud platform network intrusion detection method
CN116980176A
Method and system for accelerated acquisition and artifact reduction of undersampled MRI using a deep learning based 3D generative adversarial network
US20220381861A1