Internet of Things equipment hidden danger risk analysis method and system based on artificial intelligence
By collecting and analyzing device operation data in the risk analysis of IoT devices, building a concept drift prediction model and dynamically adjusting the weight parameters of the AI model, the false alarms and missed reports caused by concept drift are solved, and the accuracy and security of the analysis are improved.
Patent Information
- Application Number
- CN202510486607.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-18
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2045-04-18
AI Technical Summary
The existing technology is difficult to effectively deal with the concept drift problem in the analysis of hidden dangers of IoT devices, resulting in false alarms and missed reports in AI models when identifying abnormal behaviors and detecting malicious traffic, increasing security risks.
By collecting the operating data of IoT devices, including network traffic, system logs and device behavior patterns, and performing feature extraction, an AI model input feature set is constructed. Combining the data distribution change analysis of short-time windows and long-time windows, we judge the data distribution drift rate and AI model confidence changes, build a concept drift prediction model, generate a concept drift index, and trigger the dynamic adjustment mechanism of the AI model when the threshold is exceeded, and optimize the weight parameters to improve detection accuracy.
Real-time evaluation of the adaptability of AI models is achieved, the false alarm rate and the missed report of new attacks is reduced, and the accuracy and reliability of IoT device risk analysis is improved.
Smart Images

Figure CN120034394A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data processing technology, and in particular to an artificial intelligence-based method and system for analyzing hidden dangers of Internet of Things devices. Background Art
[0002] With the widespread application of Internet of Things (IoT) technology, the number of connected devices in smart homes, industrial control, smart healthcare, and Internet of Vehicles has grown exponentially. However, since IoT devices usually have limited computing resources, lack a sound security mechanism, and are exposed to complex network environments for a long time, they are vulnerable to network attacks, data leakage, and abnormal failures. Traditional security protection technologies mainly rely on rule matching and feature library detection, which makes it difficult to effectively respond to new attacks and unknown security risks. In recent years, the application of artificial intelligence (AI) technology in the field of network security has gradually emerged, especially intelligent analysis methods based on machine learning and deep learning, which can be used to identify abnormal behaviors, detect malicious traffic, and predict potential risks.
[0003] The prior art has the following deficiencies: In the risk analysis of hidden dangers of IoT devices, AI models are usually trained based on historical data to identify abnormal behaviors or attack patterns. However, due to the highly dynamic environment of IoT, the normal behavior, communication mode and attack methods of devices will continue to evolve, causing AI models to face the problem of concept drift, that is, the security rules learned during model training gradually become invalid. When concept drift occurs, AI may misjudge new normal behaviors as abnormalities, increasing the false alarm rate, or fail to identify new attack patterns, resulting in missed reports. Especially in zero-day attack or advanced persistent threat (APT) scenarios, attackers will constantly adjust their strategies to make their behaviors gradually approach normal traffic, induce AI models to adapt to incorrect classification standards, and ultimately render the detection system useless. In addition, since concept drift usually occurs gradually and is difficult to detect in the early stages, it is easy to lead to the accumulation of long-term security risks, posing serious security risks to IoT systems. Summary of the invention
[0004] The purpose of the present invention is to provide an artificial intelligence-based method and system for analyzing hidden dangers of IoT devices to address the deficiencies in the background technology.
[0005] In order to achieve the above object, the present invention provides the following technical solution: a method for analyzing hidden dangers of IoT devices based on artificial intelligence, comprising: Collect the operation data of IoT devices, including network traffic, system logs, and device behavior patterns, and extract features from the collected data to build the AI model input feature set; Analyze the degree of change in data distribution within short time windows and long time windows, determine the drift rate of data distribution change, and analyze the prediction stability of the AI model for the current data to determine the change in the confidence of the AI model; Build a concept drift prediction model, comprehensively calculate the drift rate of data distribution changes and the changes in AI model confidence, and obtain the concept drift index of the AI model in the IoT environment; The calculated concept drift index is compared with the pre-set concept drift threshold. When the concept drift index is greater than or equal to the concept drift threshold, the dynamic adjustment mechanism of the AI model is triggered, including adjusting the weight parameters of the AI model to optimize the drift detection accuracy.
[0006] Preferably, the collection of operating data of IoT devices includes: collecting network traffic data, data sources include IoT gateways, switches / routers, port mirroring and deep packet inspection systems; collecting system log data, data sources include device operating systems, IoT device firmware logs, event management systems and remote log servers; collecting device behavior pattern data, data sources include device-side sensor data, device operation logs and device access control records.
[0007] Preferably, a data distribution drift rate value is generated according to the drift rate of the data distribution change, and a method for obtaining the data distribution drift rate value is: Set the probability distribution calculation for the network traffic distribution characteristics, and construct the probability distribution in the short time window and the long time window respectively: Short time window distribution: ; Long time window distribution: ; where: n is the number of categories in the distribution, Represents the probability of the nth type of data in a short time window, and the expression is: ; Represents the probability of the nth type of data in a long time window, expressed as: ; Calculate the difference between two probability distributions P and Q , and its calculation formula is: ; Calculate the data distribution drift rate value , the expression is: ;in: is the time span of the short time window.
[0008] Preferably, a confidence fluctuation index is generated after analyzing the confidence change of the AI model when processing the current input data. The confidence fluctuation index is obtained as follows: For the same input sample x, perform T forward propagations, randomly discard some neurons each time, and record the output probability distribution of each forward propagation, expressed as: ;in: is the probability distribution of the model output for the tth forward propagation; T is the total number of Monte Carlo simulations; the predicted mean is calculated as: ;in: Represents the average predicted probability of each category after T inferences; calculate the prediction variance: ;in: The prediction variance represents the degree of change in the model's prediction confidence for the input data. The confidence fluctuation index CFI is defined as the weighted sum of the confidence variances of all categories. The calculation formula is: ; Where: CFI represents the confidence fluctuation index, and N is the total number of categories.
[0009] Preferably, a concept drift prediction model is constructed, and the drift rate of data distribution changes and the changes in AI model confidence are comprehensively calculated to obtain a concept drift index of the AI model in the Internet of Things environment, specifically including: normalizing the data distribution drift rate value and the confidence fluctuation index so that they are both between [0,1], and calculating the concept drift index based on the normalized data distribution drift rate value and the confidence fluctuation index.
[0010] Preferably, the calculated concept drift index is compared with a pre-set concept drift threshold; when the concept drift index is less than the concept drift threshold, it means that the concept drift has a small impact, and the AI model can still effectively detect the security risks of IoT devices without additional adjustment; when the concept drift index is greater than or equal to the concept drift threshold, it means that the concept drift has a large impact and dynamic adjustment is required to reduce the false alarm rate and underreporting of new attacks.
[0011] Preferably, triggering the dynamic adjustment mechanism of the AI model includes adjusting the weight parameters of the AI model to optimize the drift detection accuracy, including: the formula for adjusting the weight parameters of the AI model is: ; Where: ΔW is the adjustment amount of the AI model weight parameter, η is the learning rate, which controls the step size of the weight adjustment; represents the gradient change of the data distribution drift rate to the model weight, It represents the gradient change of confidence fluctuation index to model weight, α and β are weight adjustment factors; After each concept drift detection, the weights are adjusted according to the gradient: ;in: is the updated AI model weight matrix, is the weight matrix of the current AI model, and ΔW is the calculated weight adjustment; Increasing η speeds up model adaptation: ; where λ is the adjustment factor, is the adjusted learning rate.
[0012] The present invention also provides an artificial intelligence-based IoT equipment hidden danger risk analysis system, comprising a data acquisition module, a data analysis module, a calculation module and an adjustment module; Data collection module: collects the operating data of IoT devices, including network traffic, system logs, and device behavior patterns, extracts features from the collected data, and builds the AI model input feature set; Data analysis module: Analyze the degree of change in data distribution within short-term windows and long-term windows, determine the drift rate of data distribution changes, analyze the prediction stability of the AI model for current data, and determine the changes in the confidence of the AI model; Calculation module: Build a concept drift prediction model, comprehensively calculate the drift rate of data distribution changes and the changes in AI model confidence, and obtain the concept drift index of the AI model in the IoT environment; Adjustment module: compares the calculated concept drift index with the pre-set concept drift threshold. When the concept drift index is greater than or equal to the concept drift threshold, the dynamic adjustment mechanism of the AI model is triggered, including adjusting the weight parameters of the AI model to optimize the drift detection accuracy.
[0013] In the above technical solution, the technical effects and advantages provided by the present invention are: 1. The present invention collects network traffic, system logs and device behavior patterns of IoT devices and performs feature extraction. The present invention can comprehensively analyze the operating status of the device. Furthermore, the present invention adopts a combination of short-time windows and long-time windows to calculate the drift rate of data distribution changes, and uses the Monte Carlo method to analyze the prediction stability of the AI model for the current data, calculate the confidence fluctuation index CFI, and thus construct a concept drift prediction model. The present invention generates a concept drift index CDI by comprehensively calculating the data distribution drift rate and the AI model confidence change, and compares it with the preset concept drift threshold to achieve real-time evaluation of the adaptability of the AI model.
[0014] 2. When the concept drift index exceeds the threshold, the present invention automatically triggers the dynamic adjustment mechanism of the AI model, including optimizing the weight parameters of the AI model, adjusting the learning rate, and adopting incremental learning and transfer learning strategies to ensure that the AI model can adapt to new data patterns, thereby improving the accuracy of security detection and reducing the false alarm rate and missed reports of new attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the present invention. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.
[0016] Figure 1 The present invention is a flow chart of the method.
[0017] Figure 2 It is a system module diagram of the present invention. DETAILED DESCRIPTION
[0018] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0019] Example 1, please refer to Figure 1 As shown, the method for analyzing hidden dangers of IoT devices based on artificial intelligence in this embodiment includes: Collect the operation data of IoT devices, including network traffic, system logs, and device behavior patterns, and extract features from the collected data to build the AI model input feature set; Analyze the degree of change in data distribution within short time windows and long time windows, determine the drift rate of data distribution change, and analyze the prediction stability of the AI model for the current data to determine the change in the confidence of the AI model; Build a concept drift prediction model, comprehensively calculate the drift rate of data distribution changes and the changes in AI model confidence, and obtain the concept drift index of the AI model in the IoT environment; The calculated concept drift index is compared with the pre-set concept drift threshold. When the concept drift index is greater than or equal to the concept drift threshold, the dynamic adjustment mechanism of the AI model is triggered, including adjusting the weight parameters of the AI model to optimize the drift detection accuracy.
[0020] In order to improve the accuracy and real-time performance of artificial intelligence (AI) models in risk analysis of hidden dangers in Internet of Things (IoT) devices, it is first necessary to collect the operating data of IoT devices, including network traffic, system logs, and device behavior patterns, and perform feature extraction on them to finally build the input feature set of the AI model.
[0021] Data collection is the basis of AI analysis, which involves collecting relevant data from IoT devices, network environments, and log systems.
[0022] Collect network traffic data from: IoT gateways, switches / routers, device port mirroring, and DPI (deep packet inspection) systems; Collection method: Passive monitoring: Mirror traffic on the IoT gateway or switch port and collect all packets passing through in real time. Traffic logging: Store traffic data in NetFlow, sFlow, or PCAP (Wireshark) format. Protocol parsing: Analyze the communication patterns of common IoT protocols such as TCP / IP, MQTT, CoAP, HTTP, DNS, Modbus, etc.
[0023] Collect system log data, data sources: device operating system (Linux, Windows, RTOS), IoT device firmware log, event management system (SIEM), remote log server (Syslog), collection method: uniformly collect device logs through Syslog protocol, parse JSON / XML format log files, and obtain log information through API calls (such as cloud IoT devices). Collect device behavior pattern data, data sources: device-side sensor data (temperature, humidity, acceleration, etc.), device operation log (user operation, automatic control log), device access control record (user authentication, permission management); collection method: collect data through the API interface or sensor data bus of IoT devices, obtain device status information through MQTT / CoAP protocol, and collect user access behavior in combination with identity management system (IAM).
[0024] Raw data usually contains noise, redundant information and inconsistent formats, and needs to be cleaned, converted and formatted to ensure the quality of AI model input data.
[0025] Remove invalid data: such as null values, incomplete logs, and data in the wrong format; Deduplication: remove duplicate traffic records or log entries; Outlier detection: identify and correct abnormal data points, such as extremely large traffic spikes.
[0026] Unify the timestamp format (ISO 8601: YYYY-MM-DD HH:MM:SS), unify the IP address format (IPv4 / IPv6 standard), and convert categorical data (protocol type, log level) into numerical representation (such as one-hot encoding). Numerical normalization: map numerical data to the [0,1] interval. Time series alignment: align traffic data, log data, and device behavior data according to the time axis to form a multi-dimensional time series data set.
[0027] The purpose of feature extraction is to extract the key information that is most helpful for AI model analysis from the raw data, so as to improve the recognition ability and computing efficiency of the model.
[0028] Network traffic feature extraction: Based on statistics: mean, variance, peak, traffic rate, etc. of traffic packet size; Based on time: session duration, burst traffic detection (such as DDoS); Based on traffic pattern: access frequency of specific ports, abnormal protocol combinations (such as DNS tunnels).
[0029] System log feature extraction: Error code mode: Analyze the most frequent error codes and detect device anomalies. User behavior analysis: Calculate the access frequency and number of login failures of different users. Permission change records: Whether there is any unauthorized user privilege escalation.
[0030] Device behavior pattern feature extraction: Sensor data pattern: the temperature, vibration and other change trends of the device operating environment. Operation log sequence analysis: the time interval between user command inputs to detect whether there are any abnormalities. Automatic control pattern: whether the device has any unexpected automatic control instructions.
[0031] Construct AI model input feature set: construct a time series feature matrix to synchronize features from different sources (traffic, logs, behaviors); use feature selection algorithms (such as PCA and Lasso regression) to select the most critical features, reduce dimensions, and improve AI model calculation efficiency. Normalization: ensure that all feature values have consistent dimensions to improve AI model training stability.
[0032] In order to analyze the degree of change in data distribution, it is necessary to define short time windows and long time windows: Short-Term Window (STW): used to capture recent data change trends. The window length is usually set to a few minutes to a few hours (such as 1 hour).
[0033] Long-Term Window (LTW): It is used to reflect the overall data distribution pattern. The window length is usually set to a few days to a few weeks (such as 7 days).
[0034] The following characteristic data are collected in each window: network traffic characteristics (traffic rate, port usage distribution, protocol distribution, etc.); log characteristics (event frequency, error code distribution, user access pattern, etc.); device behavior characteristics (sensor data trends, device status changes, etc.).
[0035] The data distribution drift rate value is generated according to the drift rate of the data distribution change. The method for obtaining the data distribution drift rate value is: Set to calculate the probability distribution of network traffic distribution characteristics, and construct probability distributions within short-time windows and long-time windows respectively: Short-time window distribution: ; Long-time window distribution: ; Where: n is the number of categories in the distribution, such as different port numbers, different protocol types, different log events, etc. Represents the probability of the nth type of data within the short-time window, and the expression is: ; Represents the probability of the nth type of data within the long-time window, and the expression is: ; Calculate the difference between the two probability distributions P and Q , and its calculation formula is: ; Where: If = 0, then it is stipulated that = 0 (to avoid logarithmic calculation errors). If > 0, then define as infinity, indicating that a new mode appears in the short-time window that does not appear in the long-time window, and there is a serious drift. Calculate the data distribution drift rate value , and the expression is: ; Where: is the time span of the short-time window (such as 1 hour, 10 minutes, etc.), and the unit is seconds.
[0036] To detect the severity of concept drift, set a threshold DRthreshold and make the following judgment: If DR < DRthreshold: The data distribution changes little, and the AI model is still applicable; if DR ≥ DRthreshold: The data distribution changes greatly, indicating that concept drift has occurred and the AI model needs to be adjusted (such as retraining, parameter updating).
[0037] The prediction stability of AI models for current data can be analyzed by model uncertainty (MU), which measures the change in the confidence of the model when processing the current input data. If the prediction results of the model for similar input samples fluctuate greatly, it means that its stability in the data environment is poor, which may be affected by concept drift or changes in data distribution. Common analysis methods include Bayesian Neural Network (BNN) and Monte Carlo Dropout (MCDropout), which calculate the variance of the predicted distribution through multiple forward propagations to evaluate the stability of the model. In addition, confidence entropy can also be used to measure the uncertainty of the predicted distribution. The higher the entropy value, the lower the confidence of the model in the current data, and there is a greater risk of misjudgment. When the uncertainty of the model exceeds the set threshold, it is necessary to adjust the learning parameters, update the training data, or use transfer learning to enhance the adaptability of the model to the new data environment and improve the accuracy and reliability of risk analysis of hidden dangers of IoT devices.
[0038] The confidence fluctuation index is generated by analyzing the confidence changes of the AI model when processing the current input data. The confidence fluctuation index is obtained as follows: For the same input sample x, perform T forward propagations, randomly discarding some neurons each time (using Dropout). Record the output probability distribution of each forward propagation, expressed as: ;in: is the probability distribution of the model output at the tth forward propagation (for classification tasks); T is the total number of Monte Carlo simulations (usually 20-100).
[0039] Calculate the predicted mean (average confidence), the expression is: ;in: Represents the average predicted probability of each category after T inferences; calculate the prediction variance (confidence fluctuation): ;in: The prediction variance represents the degree of change in the model's prediction confidence for the input data. If the variance is large, it means that the model's prediction stability is low and may be affected by concept drift. The confidence fluctuation index CFI is defined as the weighted sum of the confidence variances of all categories, and the calculation formula is: ; Where: CFI represents the confidence fluctuation index, which measures the predictive stability of the model on the input data, and N is the total number of categories (for example, N=2 for binary classification tasks and N>2 for multi-classification tasks).
[0040] Set a confidence fluctuation threshold CFIthreshold to determine whether there is a problem of unstable model prediction: if CFI < CFIthreshold, it indicates that the model prediction confidence is stable, and the AI system is still applicable to the current data environment; if CFI ≥ CFIthreshold, it indicates that the model prediction confidence fluctuates greatly and may be affected by concept drift, and it is necessary to trigger the dynamic adjustment mechanism of the AI model (such as retraining, parameter adjustment, transfer learning, etc.).
[0041] Construct a concept drift prediction model to comprehensively calculate the drift rate of data distribution change and the change of AI model confidence, and obtain the concept drift index of the AI model in the Internet of Things environment, specifically including: normalizing the data distribution drift rate value and the confidence fluctuation index so that they are both in the range of [0, 1], and calculating the concept drift index according to the normalized data distribution drift rate value and the confidence fluctuation index.
[0042] For example, the present invention can use the following calculation formula of the concept drift prediction model to calculate the concept drift index, and the calculation expression is:[[]] ; where: is the concept drift index, is the data distribution drift rate value, is the confidence fluctuation index, are the weight coefficients of the data distribution drift rate value and the confidence fluctuation index (which can be optimized according to experimental experience or machine learning), and are all greater than 0.
[0043] Compare the calculated concept drift index with the pre-set concept drift threshold; when the concept drift index is less than the concept drift threshold, it indicates that the impact of concept drift is small, and the AI model can still effectively detect the security risks of Internet of Things devices without additional adjustment; when the concept drift index is greater than or equal to the concept drift threshold, it indicates that the impact of concept drift is large, and dynamic adjustment is required to reduce the false alarm rate and the missed report of new attacks.
[0044] In order to make the AI model adapt to the new data distribution and confidence fluctuation situation, it is necessary to adjust the weight parameter W of the AI model according to the data distribution drift rate value DR and the confidence fluctuation index CFI to optimize the drift detection accuracy.
[0045] The formula for adjusting the weight parameter of the AI model is:[[]] ; where: ΔW is the adjustment amount of the weight parameter of the AI model (in matrix / vector form); η is the learning rate, which controls the step size of weight adjustment, and the value range is usually [0.001, 0.1].[[]]
[0046] Indicates the gradient change of the data distribution drift rate on the model weight, indicating the impact of data changes on the model weight; It represents the gradient change of the confidence fluctuation index on the model weight, and the influence of the model prediction confidence on the weight. α, β are weight adjustment factors, which can be determined based on experimental experience or optimization algorithms (such as Bayesian optimization or grid search adjustment). and The gradient descent method can be used to calculate using back propagation.
[0047] After each concept drift detection, the weights are adjusted according to the gradient: ;in: is the updated AI model weight matrix, is the weight matrix of the current AI model, and ΔW is the calculated weight adjustment.
[0048] If the CDI is greater than or equal to the set threshold , indicating that the AI model needs major adjustments. The adjustment strategy is as follows: Increasing η speeds up model adaptation: ; where λ is the adjustment factor, For adjusted learning rates, enable adaptive learning rates (such as Adam or RMSProp) to more finely tune the model weights.
[0049] When CDI is greater than or equal to the set threshold When the AI model is outdated, it may need more substantial adjustments, such as: training the model in small batches with new data. Fine-tuning the high-level parameters of the model with new data to improve adaptability. Recalculating feature importance, removing outdated features, and improving model generalization. Recalculating the optimal decision boundary to avoid misclassification.
[0050] Example 2, please refer to Figure 2 As shown, the artificial intelligence-based IoT device hidden danger risk analysis system described in this embodiment includes a data acquisition module, a data analysis module, a calculation module and an adjustment module; Data collection module: collects the operating data of IoT devices, including network traffic, system logs, and device behavior patterns, extracts features from the collected data, and builds the AI model input feature set; Data analysis module: Analyze the degree of change in data distribution within short-term windows and long-term windows, determine the drift rate of data distribution changes, analyze the prediction stability of the AI model for current data, and determine the changes in the confidence of the AI model; Calculation module: Build a concept drift prediction model, comprehensively calculate the drift rate of data distribution changes and the changes in AI model confidence, and obtain the concept drift index of the AI model in the IoT environment; Adjustment module: Compare the calculated concept drift index with the pre-set concept drift threshold. When the concept drift index is greater than or equal to the concept drift threshold, the dynamic adjustment mechanism of the AI model is triggered, including adjusting the weight parameters of the AI model to optimize the drift detection accuracy.
[0051] The above formulas are all dimensionless and numerical calculations. The formula is a formula for the most recent real situation obtained by collecting a large amount of data and performing software simulation. The preset parameters in the formula are set by technicians in this field according to actual conditions.
[0052] It should be understood that the term "and / or" in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. A and B can be singular or plural. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship, but it may also indicate an "and / or" relationship. Please refer to the context for specific understanding.
[0053] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0054] The above description is only a specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application.
Claims
1. A method for analyzing hidden dangers of IoT devices based on artificial intelligence, characterized by: include: Collect the operation data of IoT devices, including network traffic, system logs, and device behavior patterns, and extract features from the collected data to build the AI model input feature set; Analyze the degree of change in data distribution within short time windows and long time windows, determine the drift rate of data distribution change, and analyze the prediction stability of the AI model for the current data to determine the change in the confidence of the AI model; Build a concept drift prediction model, comprehensively calculate the drift rate of data distribution changes and the changes in AI model confidence, and obtain the concept drift index of the AI model in the IoT environment; The calculated concept drift index is compared with the pre-set concept drift threshold. When the concept drift index is greater than or equal to the concept drift threshold, the dynamic adjustment mechanism of the AI model is triggered, including adjusting the weight parameters of the AI model to optimize the drift detection accuracy.
2. The method for analyzing hidden dangers of IoT devices based on artificial intelligence according to claim 1, characterized in that: The collection of IoT device operation data includes: collecting network traffic data, data sources include IoT gateways, switches / routers, port mirroring and deep packet inspection systems; collecting system log data, data sources include device operating systems, IoT device firmware logs, event management systems and remote log servers; collecting device behavior pattern data, data sources include device-side sensor data, device operation logs and device access control records.
3. The method for analyzing hidden dangers of IoT devices based on artificial intelligence according to claim 1 is characterized in that: The data distribution drift rate value is generated according to the drift rate of the data distribution change. The method for obtaining the data distribution drift rate value is: Set the probability distribution calculation for the network traffic distribution characteristics, and construct the probability distribution in the short time window and the long time window respectively: Short time window distribution: ; Long time window distribution: ; where: n is the number of categories in the distribution, Represents the probability of the nth type of data in a short time window, and the expression is: ; Represents the probability of the nth type of data in a long time window, expressed as: ; Calculate the difference between two probability distributions P and Q , and its calculation formula is: ; Calculate the data distribution drift rate value , the expression is: ;in: is the time span of the short time window.
4. The method for analyzing hidden dangers of IoT devices based on artificial intelligence according to claim 3 is characterized in that: The confidence fluctuation index is generated by analyzing the confidence change of the AI model when processing the current input data. The confidence fluctuation index is obtained as follows: For the same input sample x, perform T forward propagations, randomly discard some neurons each time, and record the output probability distribution of each forward propagation, expressed as: ;in: is the probability distribution of the model output for the tth forward propagation; T is the total number of Monte Carlo simulations; the predicted mean is calculated as: ;in: Represents the average predicted probability of each category after T inferences; calculate the prediction variance: ;in: The prediction variance represents the degree of change in the model's prediction confidence for the input data. The confidence fluctuation index CFI is defined as the weighted sum of the confidence variances of all categories. The calculation formula is: ; Where: CFI represents the confidence fluctuation index, and N is the total number of categories.
5. The method for analyzing hidden dangers of IoT devices based on artificial intelligence according to claim 4 is characterized in that: A concept drift prediction model is constructed, and the drift rate of data distribution changes and the changes in AI model confidence are comprehensively calculated to obtain the concept drift index of the AI model in the IoT environment. Specifically, the data distribution drift rate value and the confidence fluctuation index are normalized so that they are both between [0,1], and the concept drift index is calculated based on the normalized data distribution drift rate value and the confidence fluctuation index.
6. The method for analyzing hidden dangers of IoT devices based on artificial intelligence according to claim 5 is characterized in that: The calculated concept drift index is compared with the pre-set concept drift threshold; when the concept drift index is less than the concept drift threshold, it means that the concept drift has a small impact, and the AI model can still effectively detect the security risks of IoT devices without additional adjustment; when the concept drift index is greater than or equal to the concept drift threshold, it means that the concept drift has a large impact and dynamic adjustment is needed to reduce the false alarm rate and underreporting of new attacks.
7. The method for analyzing hidden dangers of IoT devices based on artificial intelligence according to claim 6 is characterized in that: Triggering the dynamic adjustment mechanism of the AI model, including adjusting the weight parameters of the AI model to optimize the drift detection accuracy, including: The formula for adjusting the weight parameters of the AI model is: ; Where: ΔW is the adjustment amount of the AI model weight parameter, η is the learning rate, which controls the step size of the weight adjustment; represents the gradient change of the data distribution drift rate to the model weight, It represents the gradient change of confidence fluctuation index to model weight, α and β are weight adjustment factors; After each concept drift detection, the weights are adjusted according to the gradient: ;in: is the updated AI model weight matrix, is the weight matrix of the current AI model, and ΔW is the calculated weight adjustment; Increasing η speeds up model adaptation: ; where λ is the adjustment factor, is the adjusted learning rate.
8. An artificial intelligence-based IoT device hidden danger risk analysis system, used to implement an artificial intelligence-based IoT device hidden danger risk analysis method according to any one of claims 1 to 7, characterized in that: It includes data acquisition module, data analysis module, calculation module and adjustment module; Data collection module: collects the operating data of IoT devices, including network traffic, system logs, and device behavior patterns, extracts features from the collected data, and builds the AI model input feature set; Data analysis module: Analyze the degree of change in data distribution within short-term windows and long-term windows, determine the drift rate of data distribution changes, analyze the prediction stability of the AI model for current data, and determine the changes in the confidence of the AI model; Calculation module: Build a concept drift prediction model, comprehensively calculate the drift rate of data distribution changes and the changes in AI model confidence, and obtain the concept drift index of the AI model in the IoT environment; Adjustment module: compares the calculated concept drift index with the pre-set concept drift threshold. When the concept drift index is greater than or equal to the concept drift threshold, the dynamic adjustment mechanism of the AI model is triggered, including adjusting the weight parameters of the AI model to optimize the drift detection accuracy.
Citation Information
Patent Citations
Malicious software detector concept drift resisting method based on generative adversarial network
CN111259393A
Message analysis method and device based on xml configuration
CN115633106A
Non-equilibrium concept drift data stream classification system and classification method thereof
CN117009884A
AI sensor data stream intrusion detection framework based on prototype
CN117411696A
System and method for modeling and quantifying regulatory capital, key risk indicators, probability of default, exposure at default, loss given default, liquidity ratios, and value at risk, within the areas of asset liability management, credit risk, market risk, operational risk, and liquidity risk for banks
US20150088783A1
Cited By
Communication method based on Internet of Things
CN120547209A
Network security level protection evaluation method and system based on artificial intelligence
CN120639476A