PCA-based QCNN-xLSTM network fault prediction method and device, and medium
Through the PCA-based QCNN-xLSTM network fault prediction method, the complex data types of network monitoring indicators and insufficient performance of machine learning methods are solved, and high-precision network fault prediction is achieved.
Patent Information
- Application Number
- CN202510193550.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-21
- Publication Date
- 2025-05-27
AI Technical Summary
In the prior art, the data types of network monitoring indicators are complex, making it difficult to select related data. In addition, machine learning methods lack the performance of network failure data mining, and the prediction accuracy is low.
The PCA-based QCNN-xLSTM network fault prediction method is used to process data through principal component analysis method, extract strong correlation features, and build a quaternary convolutional neural network and xLSTM model, and optimize hyperparameters with improved particle swarm algorithm.
It improves the robustness and accuracy of the model, and can more effectively extract the spatial and timing characteristics of network failure data, and achieve high-precision network failure prediction.
Smart Images

Figure CN120050194A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of oil and marine scientific research network information technology, and in particular to a network fault prediction method, device and medium based on PCA-QCNN-xLSTM network. Background Art
[0002] For marine oil scientific research, a large amount of data and information are required, including geological exploration data, marine environment data, oil extraction technology data, etc. The network is a key tool for obtaining and sharing information, enabling these data and information to be widely obtained and shared, thus providing comprehensive information and an in-depth research basis for scientific researchers. Therefore, the network is of crucial significance to marine oil scientific research.
[0003] Network fault prediction is to analyze based on the historical state evolution and current behavior of the network in the information system to determine whether a fault will occur. According to Heinrich's law, there must be minor accidents and multiple accident hidden dangers before every serious accident, and fault prediction can give early warnings by analyzing and mining historical data, thus preventing accidents from occurring.
[0004] Most current network fault prediction technologies rely on real-time information systems. By real-time monitoring the index data related to the network state and using machine learning technologies to achieve network fault prediction. However, there are currently two difficulties:
[0005] 1. There are too many types of index data related to the network, and it is difficult for humans to accurately judge which data is strongly related to network faults;
[0006] 2. The existing network fault algorithms based on machine learning lack in-depth mining of the relationships between features, and the prediction accuracy is relatively low.
[0007] Therefore, how to overcome the above difficulties and research new technologies to achieve high-precision prediction of network faults is a problem that needs to be solved currently. Summary of the Invention
[0008] The purpose of the present invention is to provide a network fault prediction method, device and medium based on PCA-QCNN-xLSTM network to solve the technical problems existing in the prior art, such as the complex and diverse types of network monitoring index data making it impossible to choose, and the insufficient performance of existing machine learning methods in mining network fault data. The many technical effects that can be produced by the preferred technical solutions provided by the present invention are described in detail below.
[0009] To achieve the above purpose, the present invention provides the following technical solutions:
[0010] A network fault prediction method based on PCA-QCNN-xLSTM network provided by the present invention includes the following steps:
[0011] Collect network monitoring index data, where the data includes multiple feature variables and a label variable for determining whether the current network is faulty;
[0012] Process the data using the principal component analysis method and divide the data set into a training set and a test set;
[0013] Build a prediction model based on the quaternion convolutional neural network QCNN and xLSTM;
[0014] Input the network fault data into the prediction model and formulate a training strategy;
[0015] Predict the data through the trained model and output the results.
[0016] Preferably, in the collection of network monitoring index data, where the data includes multiple feature variables and a label variable for determining whether the current network is faulty, the feature variables include:
[0017] Basic features of TCP connections, content features of TCP connections, time-based network traffic statistical features, and host-based network traffic statistical features.
[0018] Preferably, the process of using the principal component analysis method to process the data and divide the data set into a training set and a test set includes:
[0019] Encode the feature variables;
[0020] Normalize the feature variables;
[0021] Use the principal component analysis method to perform dimensionality reduction and reconstruction on the feature variables, and extract feature information strongly correlated with the label variable;
[0022] Balance the data sample types through undersampling or oversampling;
[0023] Divide the network fault data set into a training set and a test set according to a ratio of 8:2.
[0024] Preferably, the process of using the principal component analysis method to perform dimensionality reduction and reconstruction on the feature variables and extract feature information strongly correlated with the label variable includes:
[0025] Form a matrix X with the network fault data by columns;
[0026] Zero-mean each row of X;
[0027] Find the covariance matrix
[0028] Find the eigenvalues and corresponding eigenvectors of the covariance matrix;
[0029] Arrange the eigenvectors in a matrix row by row from top to bottom according to the corresponding eigenvalue magnitudes, and take the first Q rows to form matrix P;
[0030] The data after dimensionality reduction to Q dimensions is: Y = PX.
[0031] Preferably, the construction of the prediction model based on the quaternion convolutional neural network QCNN and xLSTM includes:
[0032] Build a quaternion convolutional neural network, including a quaternion convolutional layer, a normalization layer, an activation layer, and a max pooling layer, and extract hidden features through convolutional operations on the real matrix;
[0033] Adopt the cross self-attention feature fusion method to build a multi-scale feature fusion layer;
[0034] Build an xLSTM layer, including: taking the output of the quaternion convolutional neural network as the input, and using xLSTM to extract the temporal features between network fault data;
[0035] Build a fully connected layer, including: taking the output of the xLSTM layer as the input, and using the fully connected layer to map the input features to the output result, and the activation function includes ReLU.
[0036] Preferably, the construction of the xLSTM layer includes: taking the output of the quaternion convolutional neural network as the input, and using xLSTM to extract the temporal features between network fault data, including:
[0037] The first variant includes: a scalar xLSTM with exponential gating and memory mixing, and the forward propagation process is as follows:
[0038] c t = f t c t-1 + i t z t
[0039] n t = f t n t-1 + i t
[0040] h t = o t (c t / n t )
[0041]
[0042] In the formula, c t represents the cell state, n t represents the normalized state, h t represents the hidden state, zt Represents cell input, i t Represents the input gate, f t Represents the forget gate, o t Represents the output gate;
[0043] The second variant includes: a matrix xLSTM with enhanced storage capacity, and the forward propagation process is as follows:
[0044]
[0045] n t = f t n t-1 + i t k t
[0046]
[0047] q t = W q x t + b q
[0048]
[0049] v t = W v x t + b v
[0050]
[0051] o t = σ(W o x t + b o )
[0052] Where c t Represents the cell state, n t Represents the normalized state, h t Represents the hidden state, q t Represents the query input, k t Represents the key input, v t Represents the value input, i t Represents the input gate, f t Represents the forget gate, o t Represents the output gate.
[0053] Preferably, inputting the network fault data into the prediction model and formulating a training strategy includes:
[0054] Setting aside 10% of the data in the training set as the validation set;
[0055] Use binary cross-entropy as the loss function;
[0056] Use the Adam algorithm as the optimizer to optimize the parameters in the network model;
[0057] During training, adopt an early stopping strategy. If the degree of decrease in Loss on the validation set is less than a preset threshold, stop further training and use the weights after stopping as the final weights of the network;
[0058] Use the improved particle swarm optimization algorithm to optimize the hyperparameters in the QCNN-xLSTM network;
[0059] Use the trained QCNN-xLSTM model to predict the data on the test set, and compare the prediction results with the actual results, and record them in the form of a confusion matrix.
[0060] Preferably, the use of the improved particle swarm optimization algorithm to optimize the hyperparameters in the QCNN-xLSTM network includes:
[0061] Initialization, including setting the parameters of the particle swarm optimization algorithm;
[0062] Evaluation, including using the evaluation metrics in the validation set as the fitness of the particles to evaluate each particle;
[0063] Update, including updating the velocity and position of each particle;
[0064] Check whether the end condition is satisfied, including: if the current number of iterations reaches the preset maximum number or reaches the preset minimum error, stop the iteration and output the optimal solution, otherwise go to the evaluation step.
[0065] A network device includes a memory and a processor, where the memory stores executable program code, and the processor runs the executable program code to implement any step of the above method.
[0066] A computer-readable storage medium is used to store a computer program, and when the computer program is executed by a processor, it implements any step of the above method.
[0067] Compared with the prior art, the beneficial effects of the present invention are mainly as follows:
[0068] 1. The present invention combines quaternions with convolution and introduces them into the feature learning of network fault data. By quaternion convolution, it explores and preserves the underlying connections in the data information, which helps to extract more comprehensive and intrinsically interdependent feature information, thereby improving the robustness and accuracy of the model;
[0069] 2. Compared with the classical particle swarm optimization algorithm, the improved particle swarm optimization algorithm using adaptive inertia weight converges rapidly in the early stage and enhances the local fine search ability in the later stage, realizing the rapid optimization of hyperparameters in the neural network model.
[0070] 3. Considering the network traffic statistical characteristics based on time and host, and combining with the indicators monitored by the TCP protocol, the dataset used can express the network state as completely as possible.
[0071] 4. By synergistically integrating PCA, quaternion convolution, multi-scale feature fusion, xLSTM residual stacking, and particle swarm optimization algorithm, the ability of the prediction model to extract spatial features and temporal features is strengthened, thus realizing accurate network fault prediction. Description of the Drawings
[0072] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0073] Figure 1 It is a schematic diagram of the network fault prediction process in the embodiments of the present invention;
[0074] Figure 2 It is a schematic diagram of the particle swarm optimization algorithm optimization process in the embodiments of the present invention;
[0075] Figure 3 It is a training and validation loss curve graph in the embodiments of the present invention;
[0076] Figure 4 It is a training and validation accuracy curve graph in the embodiments of the present invention;
[0077] Figure 5 It is a confusion matrix of the prediction test set results in the embodiments of the present invention;
[0078] Figure 6 It is a schematic diagram of the network device structure in the embodiments of the present invention. Detailed Embodiments
[0079] To make the objectives, technical solutions, and advantages of the present invention clearer, the following will describe the technical solutions of the present invention in detail. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other implementation manners obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present invention.
[0080] Figure 1 is the flowchart of this embodiment. As Figure 1 shown, the present invention provides a network fault prediction method based on PCA (Principal Components Analysis) and QCNN-xLSTM (Quaternion Convolutional Neural Networks-Extended Long Short-Term Memory), including the following steps:
[0081] S1: Collect network monitoring metric data, which includes multiple feature variables and a label variable for determining whether the current network is faulty.
[0082] S2: Process the data using the principal component analysis method and divide the data set into a training set and a test set.
[0083] S3: Build a prediction model based on the quaternion convolutional neural network QCNN and xLSTM.
[0084] S4: Input network fault data into the prediction model and formulate a training strategy.
[0085] S5: Predict the data through the trained model and output the results.
[0086] Specifically, step S1 includes collecting network monitoring metric data from the information system. The data specifically includes the basic features of TCP (Transmission Control Protocol) connections, the content features of TCP connections, the time-based network traffic statistical features, the host-based network traffic statistical features, and a label variable for determining whether the current network is faulty.
[0087] The network fault data set used in this embodiment has 40 feature variables and 1 label variable. Among them, the 1st to 9th features are the basic features of TCP connections, including some basic attributes of the connections; the 10th to 22nd features are the content features of TCP connections; the 23rd to 31st features are the time-based network traffic statistical features; the 32nd to 40th features are the host-based network traffic statistical features. The last label variable "normal" indicates that the network connection record is normal, and a non-"normal" label indicates an abnormality.
[0088] Further, step S2 includes encoding and normalizing the feature variables, then using the principal component analysis method for dimensionality reduction and reconstruction into features strongly correlated with the label variable. For data class balancing, undersampling or oversampling of the data is required, and then the data set is divided into a training set and a test set. Specifically, it includes:
[0089] S21: Encode the feature variables; including encoding symbolic features and converting them into numerical features. Set the label variable to 1 to indicate normal network and 0 to indicate network failure.
[0090] Since there are three feature variables, namely protocol_type, service, and flag, in the network failure dataset of this embodiment that are symbolic values, they are encoded and converted into numerical features. Set the label variable for normal network connection normal to 1 and network failure connection to 0.
[0091] S22: Normalize the feature variables;
[0092] To convert the dataset into dimensionless data and ensure the unity and comparability of the data, this embodiment normalizes 40 feature variables. The specific calculation formula is as follows:
[0093]
[0094] Where, X 1 is the normalized data, X is the original data, X max is the maximum value of the original data, X min is the minimum value of the original data.
[0095] S23: Use the principal component analysis method to reduce the dimension and reconstruct the feature variables, and extract the feature information strongly correlated with the label variable; in this implementation, the network failure dataset has 40-dimensional feature variable data, which is reduced to 6 dimensions. The specific steps of dimension reduction include:
[0096] S231. Compose the network failure data into a matrix X by columns; that is, compose the network failure dataset into a 494021-row and 40-column matrix X by columns;
[0097] S232. Zero-mean each row of X, that is, subtract the mean of this row;
[0098] S233. Calculate the covariance matrix
[0099] S234. Calculate the eigenvalues and corresponding eigenvectors of the covariance matrix;
[0100] S235. Arrange the eigenvectors in a matrix row by row in descending order according to the corresponding eigenvalues, and take the first 6 rows to form a matrix P;
[0101] S236. Y = PX is the data after dimension reduction to 6 dimensions.
[0102] S24: Balance the data sample types through undersampling or oversampling;
[0103] In this embodiment, in order to balance the data sample types, undersampling is performed on the categories with more data or oversampling is performed on the categories with less data, effectively dealing with the problem of class imbalance and achieving the effect of balancing the network fault dataset.
[0104] S25: After being processed by the above steps, the network fault dataset is divided into a training set and a test set according to the ratio of 8:2, and the format of each dataset is modified into the format required by the input network.
[0105] Furthermore, step S3 includes building a prediction model based on the quaternion convolutional neural network QCNN and xLSTM, specifically including a quaternion convolutional layer, a multi-scale feature fusion layer, an xLSTM layer, and a fully connected layer, and using an improved particle swarm algorithm to optimize the hyperparameters in the model. Specifically, it includes:
[0106] S31: Build a quaternion convolutional neural network, including a quaternion convolutional layer, a normalization layer, an activation layer, and a max pooling layer, and extract hidden features by performing a convolutional operation on the real matrix;
[0107] In this embodiment, a quaternion convolutional neural network with 2 scales and a depth of 3 is used to extract rich features of network fault data. All inputs, weights, parameters, biases, and outputs are quaternion-based. By introducing QCNN, the real convolutional process in CNN is replaced by a method of extracting hidden features by performing a convolutional operation on the real matrix. The formula is as follows:
[0108]
[0109] S32: Build a multi-scale feature fusion layer using the cross self-attention feature fusion method;
[0110] Since a single connection operation for fusing multi-scale features is very likely to introduce duplicate information, the cross self-attention feature fusion method is adopted in this embodiment. The formula is as follows:
[0111]
[0112] In the formula, d k represents the dimension of Q and K, learns the self-attention input sequence, and is respectively mapped to three matrices Q, K, and V.
[0113] S33: Build an xLSTM layer, including: taking the output of the quaternion convolutional neural network as the input, and using xLSTM to extract the temporal features between network fault data;
[0114] Compared with the traditional LSTM, the improved xLSTM has two variants. One is the scalar xLSTM with exponential gating and memory mixing, and the forward propagation process is as follows:
[0115] c t = f t c t-1 + i t z t
[0116] n t = f t n t-1 + i t
[0117] h t = o t (c t / n t )
[0118]
[0119] In the formula, c t represents the cell state, n t represents the normalized state, h t represents the hidden state, z t represents the cell input, i t represents the input gate, f t represents the forget gate, o t represents the output gate.
[0120] The other is the matrix xLSTM with enhanced storage capacity, and the forward propagation process is as follows:
[0121]
[0122] n t = f t n t-1 + i t k t
[0123]
[0124] q t = W q x t + b q
[0125]
[0126] v t = W v x t + b v
[0127]
[0128] o t = σ(W o x t + b o )
[0129] where c t represents the cell state, n t represents the normalized state, h t represents the hidden state, q t represents the query input, k t represents the key input, v t represents the value input, i t represents the input gate, f t represents the forget gate, o t represents the output gate.
[0130] In addition, a residual stacking architecture similar to Transformer is introduced, integrating scalar xLSTM and matrix xLSTM into the residual block to form a deep network in the way of residual stacking. This architecture not only improves the scalability of the model but also effectively prevents the problem of gradient disappearance in the deep network, enabling the model to better learn complex historical dependencies.
[0131] S34: Build a fully connected layer, including: using the output of the xLSTM layer as the input and using the fully connected layer to map the input features to the output results, and the activation function includes ReLU (Rectified Linear Unit).
[0132] Furthermore, step S4 includes inputting network fault data to train the established prediction model based on the quaternion convolutional neural network QCNN and xLSTM, and formulating a training strategy, specifically including:
[0133] S41: Set aside 10% of the data in the training set as the validation set;
[0134] In this embodiment, 10% of the data in the training set is set aside as the validation set, which is used to evaluate the model effect during training and adjust the hyperparameters in a timely manner.
[0135] S42: Use binary cross - entropy as the loss function;
[0136] In this embodiment:
[0137]
[0138] where y is the label 0 or 1, and P(y) is the probability that the output belongs to the y label.
[0139] S43: Use the Adam algorithm as the optimizer to optimize the parameters in the network model;
[0140] The learning rate of the optimizer is a very important indicator because the learning rate determines the speed of the learning process. If the learning rate is too large, it is very likely to cross the optimal value. On the contrary, if the learning rate is too small, the optimization efficiency may be very low, resulting in a long operation time. Therefore, the learning rate is very important for the performance of the algorithm. In this embodiment, the learning rate is set in the range of 0.00001 - 0.0001, and the particle swarm algorithm is used for optimization. Then, as the number of training times increases, the learning rate is dynamically reduced to achieve both efficiency and effect. The evaluation index during the training process is Accuracy.
[0141] S44: During training, adopt an early stopping strategy. If the degree of decrease in Loss on the validation set is less than a preset threshold, stop further training and use the weights after stopping as the final weights of the network;
[0142] Specifically, during training, if the number of training epochs is set too large, it may lead to a relatively low accuracy of the model on the test set at the end. In this embodiment, an early stopping strategy is used. When the Loss on the validation set no longer decreases (i.e., the degree of decrease is less than a certain threshold), stop further training and use the weights after stopping as the final weights of the network.
[0143] S45: Use the improved particle swarm algorithm to optimize the hyperparameters in the QCNN - xLSTM network;
[0144] The improvement of the particle swarm optimization algorithm in this embodiment is that the particles can adaptively change the inertia weight during the search process, enabling the algorithm to converge quickly in the early stage and enhancing the local fine - search ability in the later stage:
[0145]
[0146] where w max is the maximum inertia weight, w min is the minimum inertia weight, iter is the current iteration number, and iter max is the maximum iteration number.
[0147] Furthermore, step S45 specifically includes:
[0148] S451: Initialization, including setting the parameters of the particle swarm algorithm;
[0149] Specifically, set the parameters of the particle swarm algorithm, such as the particle swarm size, particle dimension, individual learning factor, swarm learning factor, maximum and minimum inertia weights, and maximum number of iterations. The initial positions and velocities of the particles are usually randomly generated within the allowed range.
[0150] In this embodiment, set the particle swarm size to 20, the particle dimension to 3, both the individual learning factor and the swarm learning factor to 0.5, the maximum and minimum inertia weights to 2 and 0.4 respectively, the maximum number of iterations to 200, and initialize the hyperparameters in the QCNN-xLSTM network. The initial positions and velocities of the particles are usually randomly generated within the allowed range.
[0151] S452: Evaluation, including using the evaluation metrics in the validation set as the fitness of the particles, and evaluating each particle;
[0152] Specifically, use the evaluation metrics in the validation set as the fitness of the particles, and evaluate each particle. If it is better than the current individual extreme value of the particle, then set the historical optimal position as the position of the particle and update the individual extreme value. If the best individual extreme values of all particles are better than the current global extreme value, then set the global historical optimal position as the position of the particle, record the position of the particle and update the global extreme value.
[0153] S453: Update, including updating the velocity and position of each particle;
[0154] Specifically, through the following formula:
[0155]
[0156] In the formula, i is the particle serial number; d is the particle dimension serial number; k is the number of iterations; i is the inertia weight; c 1 is the individual learning factor; c 2 is the swarm learning factor; r 1 , r 2 is a random number within the interval [0, 1], increasing the randomness of the search; is the velocity vector of the i-th particle in the d-th dimension at the k-th iteration; is the position vector of the i-th particle in the d-th dimension at the k-th iteration; is the optimal solution found by the i-th particle after k iterations; is the optimal solution found by the entire particle swarm after k iterations.
[0157] S454: Check whether the end condition is satisfied, including: if the current number of iterations reaches the preset maximum number or reaches the preset minimum error, then stop the iteration and output the optimal solution, otherwise go to the S452 evaluation step. Thus, the parameter combination of the particle swarm algorithm optimization model can be obtained.
[0158] S46: Fault prediction, using the trained QCNN-xLSTM model to predict network fault data and output the results.
[0159] Specifically, it includes: using the trained QCNN-xLSTM model to predict the data on the test set, and comparing the prediction results with the actual results, and recording them in the form of a confusion matrix, as shown in Table 1.
[0160] TP refers to that the true class of the test set is the positive class, and the result recognized by the model is also the positive class; FN refers to that the true class of the test set is the positive class, but the model recognizes it as the negative class; FP refers to that the true class of the test set is the negative class, but the model recognizes it as the positive class; TN refers to that the true class of the test set is the negative class, and the model recognizes it as the negative class.
[0161] Table 1 Confusion Matrix
[0162]
[0163] The model evaluation metric used is Accuracy:
[0164]
[0165] The hyperparameter optimization process in this embodiment is as Figure 2 shown. By using the improved particle swarm optimization algorithm to optimize the hyperparameters of the QCNN-xLSTM model, such as the number of neurons in the xLSTM layer, the number of neurons in the fully connected layer, and the learning rate, the ability of the model to fit network fault data is improved. The loss curve during the model training process is as Figure 3 shown. The blue line represents the change of the loss value on the training set, and the orange line represents the change of the loss value on the validation set. The training loss and the validation loss decrease as the number of iterations increases, and the curve as a whole tends to be stable when the number of iterations is 150. Small fluctuations are normal. The accuracy change curve during the model training process is as Figure 4 shown. The training accuracy and the validation accuracy increase as the number of iterations increases, and the validation accuracy basically stabilizes at 99.6% after the number of iterations reaches 100. Figure 5 is the confusion matrix of the model predicting the test set results, and it can be seen that only a very small part of the data is misrecognized. Comparing the QCNN-xLSTM model with other models such as "LSTM", "SVM", and "random forest", as shown in Table 2.
[0166] Table 2 Model Comparison
[0167]
[0168] By comparison, the QCNN-xLSTM network fault prediction method based on PCA uses a series of data preprocessing methods such as feature encoding, normalization, and PCA to improve data quality and data value, providing a better data foundation for subsequent model training. A prediction model based on QCNN and xLSTM is built, and the improved particle swarm algorithm is used to optimize hyperparameters and formulate targeted training strategies, effectively improving the prediction accuracy of network fault data.
[0169] An embodiment of the present invention provides a network device, such as Figure 6 shown, which includes a memory and a processor, where the memory stores a computer program, and the processor runs the computer program to implement the steps in the above embodiment of the QCNN-xLSTM network fault prediction method based on PCA.
[0170] An embodiment of the present invention provides a computer-readable storage medium that stores a computer program, where the computer program causes a computer to execute the steps in the above embodiment of the QCNN-xLSTM network fault prediction method based on PCA.
[0171] The algorithm steps described in the embodiments provided in the present invention can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed by hardware or software depends on the specific application and design constraints of the technical solution. In addition, in each embodiment of the present invention, the functional units may be integrated in a processing unit, or each unit may exist physically alone, or two or more units may be integrated in one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0172] Some or all of the steps in the embodiments of the present invention can be completed by instructing relevant hardware through a program, and the program can be stored in a computer-readable storage medium. The storage medium includes read-only memory (ROM), random access memory (RAM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), one-time programmable read-only memory (OTPROM), electrically-erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc memories, magnetic disc memories, magnetic tape memories, or any other medium that can be used to carry or store data and is readable by a computer.
[0173] Among the technical solutions described in the embodiments of the present invention, they can be arbitrarily combined without conflict.
[0174] As mentioned above, the above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.
Claims
1. A PCA-based QCNN-xLSTM network fault prediction method, characterized in that: The steps include: Collecting network monitoring index data, the data including multiple feature variables and label variables for determining whether the current network is faulty; The data are processed using principal component analysis and the data set is divided into a training set and a test set; Build a prediction model based on quaternion convolutional neural network QCNN and xLSTM; Inputting network fault data into the prediction model and formulating a training strategy; Use the trained model to predict the data and output the results.
2. According to a PCA-based QCNN-xLSTM network fault prediction method according to claim 1, it is characterized in that: The collected network monitoring index data includes a plurality of characteristic variables and a label variable for determining whether the current network is faulty. The characteristic variables include: Basic characteristics of TCP connections, content characteristics of TCP connections, time-based network traffic statistics characteristics, and host-based network traffic statistics characteristics.
3. According to a PCA-based QCNN-xLSTM network fault prediction method according to claim 2, it is characterized in that: The principal component analysis method is used to process the data and divide the data set into a training set and a test set, including: Carrying out data encoding on the characteristic variables; Normalizing the characteristic variables; The principal component analysis method is used to reduce the dimension of the feature variables and reconstruct them, extracting the feature information that is strongly correlated with the label variable; Equalize data sample types through undersampling or oversampling; The network fault dataset is divided into a training set and a test set in a ratio of 8:
2.
4. According to a PCA-based QCNN-xLSTM network fault prediction method according to claim 3, it is characterized in that: The principal component analysis method is used to reduce the dimension of the feature variables and reconstruct the feature information that is strongly correlated with the label variable, including: The network fault data is organized into a matrix X by columns; Zero the mean of each row of X; Find the covariance matrix Find the eigenvalues and corresponding eigenvectors of the covariance matrix; Arrange the eigenvectors into a matrix by row from top to bottom according to the corresponding eigenvalues, and take the first Q rows to form the matrix P; The data after dimension reduction to Q dimension is: Y=PX.
5. A PCA-based QCNN-xLSTM network fault prediction method according to any one of claims 1 to 4, characterized in that: The prediction model based on quaternion convolutional neural network QCNN and xLSTM includes: Build a quaternion convolutional neural network, including quaternion convolution layer, normalization layer, activation layer and maximum pooling layer, and extract hidden features by performing convolution operations on the real matrix; The cross self-attention feature fusion method is used to build a multi-scale feature fusion layer; Building the xLSTM layer includes: taking the output of the quaternion convolutional neural network as input and using xLSTM to extract the time series features between network fault data; Build a fully connected layer, including: taking the output of the xLSTM layer as input, using a fully connected layer to map the input features to the output results, and the activation function includes ReLU.
6. According to the PCA-based QCNN-xLSTM network fault prediction method of claim 5, it is characterized in that: The xLSTM layer is constructed, including: taking the output of the quaternion convolutional neural network as input, and using the xLSTM to extract the time series features between network fault data, including: The first variant, including: scalar xLSTM with exponential gating and memory hybrid, the forward propagation process is as follows: c t =f t c t-1 +i t z t n t =f t n t-1 +i t h t =o t (c t / n t ) i t =exp(w i T x t +r i h t-1 +b i ) f t =σ(w f T x t +r f h t-1 +b f )ORexp(w f T x t +r f h t-1 +b f ) o t =σ(w o T x t +r o h t-1 +b o ) Where c t Indicates the cell state, n t represents the normalized state, h t represents the hidden state, z t represents cell input, i t represents the input gate, f t represents the forget gate, o t represents the output gate; The second variant, including: Matrix xLSTM with enhanced memory capacity, the forward propagation process is as follows: c t =f t c t-1 +i t v t k t T n t =f t n t-1 +i t k t h t =o t e(c t q t / max{|n t T q t |,1}) q t =W q x t +b q v t =W v x t +b v i t =exp(w i T x t +b i ) f t =σ(w f T x t +b f )ORexp(w f T x t +b f ) the t =σ(W o x t +b o ) Where c t Indicates the cell state, n t represents the normalized state, h t represents the hidden state, q t represents the query input, k t represents the key input, v t Indicates value input, i t represents the input gate, f t represents the forget gate, o t Represents the output gate.
7. A PCA-based QCNN-xLSTM network fault prediction method according to any one of claims 1 to 4, characterized in that: The inputting of network fault data into the prediction model and formulating a training strategy include: Separate 10% of the training set as a validation set; Use binary cross entropy as the loss function; Use the Adam algorithm as the optimizer to optimize the parameters in the network model; During training, an early stopping strategy is adopted. If the degree of reduction of the loss on the verification set is less than a preset threshold, the training is stopped and the weight after stopping is used as the final weight of the network; Use the improved particle swarm algorithm to optimize the hyperparameters in the QCNN-xLSTM network; Use the trained QCNN-xLSTM model to predict the data on the test set, and compare the predicted results with the actual results, and record them in the form of a confusion matrix.
8. The PCA-based QCNN-xLSTM network fault prediction method according to claim 7, characterized in that: The use of the improved particle swarm algorithm to optimize the hyperparameters in the QCNN-xLSTM network includes: Initialization, including setting the particle swarm algorithm parameters; Evaluation, including the evaluation indicators in the validation set as the fitness of the particles, and evaluating each particle; Update, including updating the velocity and position of each particle; Check whether the end condition is met, including: if the current number of iterations reaches a preset maximum number or reaches a preset minimum error, stop the iteration and output the optimal solution, otherwise go to the evaluation step.
9. A network device, characterized in that: It includes a memory and a processor, wherein the memory stores executable program codes, and the processor runs the executable program codes to implement the steps of a PCA-based QCNN-xLSTM network fault prediction method as described in any one of claims 1 to 8.
10. A computer-readable storage medium for storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of a PCA-based QCNN-xLSTM network fault prediction method according to any one of claims 1 to 8 are implemented.
Citation Information
Cited By
Method and system for detecting legal network traffic in complex environment
CN121000523A