Intrusion signal detection method based on dual-core single-class width learning auto-encoder
Through the intrusion signal detection method based on dual-core single-class width learning autoencoder, the problem of traditional intrusion detection methods insufficient recognition ability of unknown intrusion behavior is solved, efficient and accurate intrusion signal detection is achieved, and false alarms and missed response rates are reduced.
Patent Information
- Application Number
- CN202510535293.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-27
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-04-27
AI Technical Summary
Traditional intrusion detection methods lack effective response capabilities in the face of unknown or new types of intrusion behaviors, and maintaining and updating the rule base requires a large amount of manpower and time resources, and the false alarm rate or missed rate is high.
The intrusion signal detection method based on dual-core single-class width learning autoencoder is adopted, and the signal data is processed through two-core function mapping and reconstruction to improve the accuracy of intrusion signal detection.
It provides a reliable anomaly detection mechanism that can quickly and accurately identify potential intrusion behaviors, improving the ability to process complex data sets and stability and accuracy in high-dimensional spaces.
Smart Images

Figure CN120067773A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of signal detection, and specifically to an intrusion signal detection method based on a dual-core single-class width learning autoencoder. Background Art
[0002] In today's digital and networked era, network security has become a crucial field. With the rapid development of information technology, the Internet has penetrated into all aspects of people's lives, from personal communication, commercial transactions to the management of national infrastructure, and is almost ubiquitous. However, this dependence has also brought new risks and challenges, especially when facing various network intrusion behaviors.
[0003] Traditional intrusion detection methods have certain limitations. For example, rule-based intrusion detection systems (IDS) need to pre-define a large number of rules to identify known types of attack patterns. This method lacks effective response capabilities for unknown or new intrusion behaviors because they cannot predict all possible attack methods. In addition, maintaining and updating these rule bases also requires a large amount of human and time resources, increasing the operating cost of the system.
[0004] On the other hand, statistics-based methods attempt to identify abnormal activities by analyzing the behavior patterns of network traffic. Although this method can discover some unforeseen attack behaviors to a certain extent, its judgment criteria are often relatively single, easily leading to a high false alarm rate or missed alarm rate. This means that normal network activities may be wrongly marked as suspicious behaviors, or real intrusion behaviors may not be detected in time.
[0005] Therefore, it is particularly important to urgently develop an efficient, accurate and adaptive intrusion signal detection technology to effectively improve the recognition ability of unknown attack patterns and reduce the additional overhead caused by false alarms or missed alarms. Summary of the Invention
[0006] To solve the above problems, the present invention proposes an intrusion signal detection method based on a dual-core single-class width learning autoencoder, which improves the accuracy of intrusion signal detection by performing two kernel function mappings and reconstruction optimization on signal data.
[0007] The specific solution is as follows:
[0008] On the one hand, the intrusion signal detection method based on a dual-core single-class width learning autoencoder includes:
[0009] S1, receiving signal data and dividing the signal data into a test set and a training set;
[0010] S2, map the signal data in the training set through a kernel function to obtain the feature layer data of the training set;
[0011] S3, generate a random matrix based on the feature layer data of the training set, use this random matrix to reconstruct the signal data of the training set, obtain the reconstructed feature layer data, set the error caused by the reconstruction as the first objective function, and transform the first objective function into a first unconstrained optimization problem through the augmented Lagrangian multiplier method, solve the first unconstrained optimization problem, and obtain the first optimal kernel function matrix;
[0012] S4, map the reconstructed feature layer data through a kernel function to obtain the enhanced layer data of the training set;
[0013] S5, generate a random matrix based on the enhanced layer data, use this random matrix to reconstruct the feature layer data of the training set, obtain the reconstructed enhanced layer data, set the error caused by the reconstruction as the second objective function, and transform the second objective function into a second unconstrained optimization problem through the augmented Lagrangian multiplier method, solve the second unconstrained optimization problem, and obtain the second optimal kernel function matrix;
[0014] S6, concatenate the reconstructed feature layer data and the reconstructed enhanced layer data to obtain the hidden layer, reconstruct the hidden layer data, obtain the reconstruction error generated during the reconstruction, define the F-norm of the reconstruction error as the loss function, take the derivative of the loss function, and obtain the optimal output layer weight matrix;
[0015] S7, calculate the reconstruction losses of the signal data in the training set, sort these losses from largest to smallest to obtain an error ranking set, and set a proportionality coefficient based on this error ranking set to determine the judgment threshold;
[0016] S8, confirm the intrusion signals in the test set signal data based on the first optimal kernel function matrix, the second optimal kernel function matrix, the optimal output layer weight matrix, and the judgment threshold.
[0017] Further, in S3, the calculation formula of the first objective function is as follows:
[0018] ;
[0019] Wherein, is the signal data; is the kernel transformation matrix from the signal data in the training set to the reconstructed feature layer data; represents the square of the F-norm of the matrix, which is used to measure the overall size of the matrix elements; is the regularization parameter, which is used to balance the weights of the reconstruction error and the regularization term; represents the matrix of The norm is used to regularize the matrix; U is an intermediate variable; denotes finding and making the loss function minimum; Z represents the reconstructed feature layer data.
[0020] Furthermore, in S3, the first objective function is transformed into a first unconstrained optimization problem by the augmented Lagrangian multiplier method, and the formula is as follows:
[0021] ;
[0022] where R is the Lagrange multiplier matrix for dealing with the constraint conditions; denotes the penalty parameter in the augmented Lagrangian function; denotes the inner product of matrices.
[0023] The first unconstrained optimization problem is solved by the alternating direction multiplier method algorithm, and the calculation formula is as follows:
[0024] ;
[0025] where I is the identity matrix for maintaining the dimension and properties of the matrix in matrix operations.
[0026] Furthermore, in S6, the F norm of the reconstruction error is defined as the loss function, specifically as follows:
[0027] ;
[0028] where is the loss function, is the output layer weight matrix; denotes the square of the F norm of the matrix; is the regularization parameter for balancing the weights of the reconstruction error and the regularization term; is the hidden layer data; is the signal data.
[0029] Furthermore, in S6, the optimal output layer weight matrix, the calculation formula is as follows:
[0030] ;
[0031] where is the regularization parameter; I is the identity matrix, A is the hidden layer data; is the optimal output layer weight matrix.
[0032] Furthermore, the said S8 specifically includes:
[0033] Reconstruct the signal data in the test set through the first optimal kernel function matrix to obtain intrusion detection feature data. Reconstruct the intrusion detection feature data through the second optimal kernel function matrix to obtain intrusion detection feature enhanced data. Concatenate the intrusion detection feature data and the intrusion detection feature enhanced data to obtain the hidden layer data. Reconstruct the hidden layer data through the optimal output layer weight matrix to obtain the reconstruction error of the test data. Determine the signal data with a reconstruction error greater than the judgment threshold as the intrusion signal.
[0034] Further, the definition of the reconstruction error is specifically as follows:
[0035] ;
[0036] Where, is the reconstruction error of the signal data in the i-th test set; represents the reconstruction output of the signal data in the i-th training set; represents the square of the norm of the vector;
[0037] The judgment threshold is set to ; Where, is the error sorting set; is the threshold scale parameter used to control the size of the threshold, ; n is the number of signal data in the test set.
[0038] The present invention adopts the above technical solutions and has the following beneficial effects:
[0039] (1) The present invention confirms the intrusion signals in the test set through the first optimal kernel function matrix, the second optimal kernel function matrix, the optimal output layer weight matrix, and the set judgment threshold, providing a reliable anomaly detection mechanism, enabling the system to quickly and accurately identify potential intrusion behaviors in practical applications;
[0040] (2) The present invention transforms the objective function into an unconstrained optimization problem for solution by using the augmented Lagrangian multiplier method to obtain the optimal kernel function matrix, improving the ability to process complex data sets and ensuring stability and accuracy in high-dimensional spaces;
[0041] (3) The present invention improves the accuracy of anomaly signal detection by optimizing the reconstruction error and setting the judgment threshold based on the error sorting set. Description of the Drawings
[0042] Figure 1 is the flow chart of the intrusion signal detection method based on the dual-core single-class width learning autoencoder according to the embodiment of the present invention. Detailed implementation mode
[0043] The present invention will be further described in detail below in conjunction with embodiments and the accompanying drawings, but the implementation mode of the present invention is not limited thereto. As Figure 1 shown, the intrusion signal detection method based on the dual-core single-class width learning autoencoder of the present invention includes:
[0044] S1. Receive signal data and divide the signal data into a test set and a training set.
[0045] Specifically, this embodiment is carried out on an intrusion detection data set constructed by NSL-KDD and UNSW-NB15. For each experiment, 20 independent trials are carried out. In each trial, the target class is randomly and evenly divided into a training set and a test set, and abnormal samples are added to the test set. To evaluate the performance, in line with the methods commonly used in single-classification research, it is implemented based on Sciki-learn and run on an Intel Core i7-12700 CPU with 2.10 GHz.
[0046] S2. Map the signal data in the training set through a kernel function to obtain the feature layer data of the training set.
[0047] Specifically, in the input signal, the distribution of normal data and abnormal data is complex and difficult to distinguish with a simple model. The kernel function can map the data from the low-dimensional original space to the high-dimensional feature space, making the data that was originally mixed and linearly inseparable become linearly separable in the high-dimensional space.
[0048] S3. Generate a random matrix based on the feature layer data of the training set, reconstruct the signal data of the training set with the random matrix to obtain the reconstructed feature layer data, set the error caused by the reconstruction as the first objective function, transform the first objective function into a first unconstrained optimization problem through the augmented Lagrangian multiplier method, and solve the first unconstrained optimization problem to obtain the first optimal kernel function matrix.
[0049] Specifically, the calculation formula of the first objective function is as follows:
[0050] ;
[0051] Among them, is the signal data; is the kernel transformation matrix from the signal data in the training set to the reconstructed feature layer data; represents the square of the F norm of the matrix, which is used to measure the overall size of the matrix elements; is the regularization parameter, which is used to balance the weights of the reconstruction error and the regularization term; represents the matrix of The norm is used to regularize the matrix; U is an intermediate variable; denotes finding and minimizes the loss function; Z represents the reconstructed feature layer data.
[0052] Specifically, the first objective function is transformed into a first unconstrained optimization problem by the augmented Lagrangian multiplier method, and the formula is as follows:
[0053] ;
[0054] where R is the Lagrangian multiplier matrix for handling the constraint conditions; denotes the penalty parameter in the augmented Lagrangian function; denotes the inner product of matrices.
[0055] The first unconstrained optimization problem is solved by the alternating direction multiplier method algorithm, and the calculation formula is as follows:
[0056] ;
[0057] where I is the identity matrix for maintaining the dimension and properties of the matrix in matrix operations.
[0058] S4. Map the reconstructed feature layer data through a kernel function to obtain the enhanced layer data of the training set;
[0059] S5. Generate a random matrix based on the enhanced layer data, use this random matrix to reconstruct the feature layer data of the training set to obtain the reconstructed enhanced layer data, set the error caused by the reconstruction as the second objective function, transform the second objective function into a second unconstrained optimization problem by the augmented Lagrangian multiplier method, and solve the second unconstrained optimization problem to obtain the second optimal kernel function matrix ;
[0060] S6. Concatenate the reconstructed feature layer data and the reconstructed enhanced layer data to obtain the hidden layer, reconstruct the hidden layer data, obtain the reconstruction error generated during the reconstruction, define the F norm of the reconstruction error as the loss function, and take the derivative of the loss function to obtain the optimal output layer weight matrix.
[0061] Specifically, define the F norm of the reconstruction error as the loss function, as follows:
[0062] ;
[0063] where is the loss function, is the output layer weight matrix; denotes the square of the F norm of the matrix; is a regularization parameter used to balance the weights of the reconstruction error and the regularization term; is the data of the hidden layer; is the signal data.
[0064] Specifically, the formula for the optimal output layer weight matrix is as follows:
[0065] ;
[0066] where, is the regularization parameter; I is the identity matrix, and A is the data of the hidden layer; is the optimal output layer weight matrix.
[0067] S7. Calculate the reconstruction losses of the signal data in the training set, sort these losses from largest to smallest to obtain an error sorting set, and set a proportionality coefficient based on this error sorting set to determine the judgment threshold.
[0068] S8. Based on the first optimal kernel function matrix, the second optimal kernel function matrix, the optimal output layer weight matrix, and the judgment threshold, identify the intrusion signals in the test set signal data.
[0069] Specifically, the S8 specifically includes:
[0070] Reconstruct the signal data in the test set through the first optimal kernel function matrix to obtain intrusion detection feature data, reconstruct the intrusion detection feature data through the second optimal kernel function matrix to obtain enhanced intrusion detection feature data, splice the intrusion detection feature data and the enhanced intrusion detection feature data to obtain the data of the hidden layer, reconstruct the data of the hidden layer with the optimal output layer weight matrix to obtain the reconstruction error of the test data, and determine the signal data with the reconstruction error greater than the judgment threshold as the intrusion signal.
[0071] Specifically, the definition of the reconstruction error is as follows:
[0072] ;
[0073] where, is the reconstruction error of the i-th signal data in the test set; represents the reconstruction output of the i-th signal data in the training set; represents the square of the norm of the vector;
[0074] The judgment threshold is set to ; where, is the error sorting set; is the threshold scale parameter used to control the size of the threshold, ; n is the number of signal data in the test set.
[0075] Classify according to the threshold as follows:
[0076]
[0077] is the judgment threshold obtained after sorting. When the reconstruction error is greater than the judgment threshold, it is marked as an abnormal sample; when it is less than or equal to the judgment threshold, it is marked as a normal sample.
[0078] Specifically, in this embodiment, the network structure corresponding to the intrusion signal detection method based on the dual-core single-class width learning autoencoder mainly includes an input layer, a hidden layer, and an output layer; the hidden layer is composed of a feature layer and an enhancement layer combined; ① Feature layer: The feature layer is constructed by cascading groups of feature nodes, , and the expression is ], where is the number of groups of feature layer nodes and is a positive integer; represents the -th group of nodes in the feature layer, ; , where is the -th kernel function. Gaussian, polynomial, and linear kernels are selected as the basic kernels, and multiple kernel functions are obtained by setting different parameters; and are the sample vectors in the original input data; ② Enhancement layer: The enhancement layer is composed of groups of nodes, , that is, ], where q is the number of groups of enhancement layer nodes and is a positive integer; represents the -th group of nodes in the enhancement layer, , and here is also a kernel function, and are the sample vectors output by the feature layer; The hidden layer A is composed of the connection of the feature layer and the enhancement layer, that is, .
[0079] Generally speaking, in the present invention, first, the received signal data is mapped to a high-dimensional feature space through a kernel function (step S2), which is similar to the fast feature mapping in the wide learning system and aims to capture complex data features. Then, based on the generated random matrix, these feature layer data are reconstructed, and the first optimal kernel function matrix is obtained through an optimization process (step S3), further enhancing the representation ability of the model. Next, a similar strategy is used to perform kernel function mapping and reconstruction on the reconstructed feature layer data again to obtain the second optimal kernel function matrix (steps S4 - S5), thus forming enhanced layer data. The concatenated feature layer and enhanced layer constitute the hidden layer, and the reconstruction error is calculated as the loss function to solve the output layer weight matrix (step S6), which is the core idea of the autoencoder, that is, minimizing the difference between the input and the reconstructed output to learn an effective data representation. Finally, a judgment threshold is set based on the reconstruction error of the training set, and this model is used to identify intrusion signals in the test set (steps S7 - S8). This method combines the efficiency of the wide learning system and the reconstruction characteristics of the autoencoder, specifically for learning normal samples for anomaly detection, fully demonstrating the application of the one-class wide learning autoencoder.
[0080] Although the present invention has been specifically shown and described with reference to the preferred embodiments, those skilled in the art should understand that various changes in form and details may be made to the present invention without departing from the spirit and scope of the present invention as defined by the appended claims, and all such changes are within the scope of protection of the present invention.
Claims
1. An intrusion signal detection method based on dual-core single-class width learning autoencoder, characterized in that: include: S1, receiving signal data, and dividing the signal data into a test set and a training set; S2, mapping the signal data in the training set through the kernel function to obtain the feature layer data of the training set; S3, generating a random matrix based on the feature layer data of the training set, reconstructing the signal data of the training set with the random matrix to obtain the reconstructed feature layer data, setting the error caused by the reconstruction as the first objective function, converting the first objective function into a first unconstrained optimization problem by using the augmented Lagrange multiplier method, solving the first unconstrained optimization problem, and obtaining a first optimal kernel function matrix; S4, mapping the reconstructed feature layer data through the kernel function to obtain the enhanced layer data of the training set; S5, generating a random matrix based on the enhanced layer data, reconstructing the feature layer data of the training set with the random matrix to obtain reconstructed enhanced layer data, setting the error caused by the reconstruction as the second objective function, converting the second objective function into a second unconstrained optimization problem by using the augmented Lagrange multiplier method, solving the second unconstrained optimization problem, and obtaining a second optimal kernel function matrix; S6, concatenating the reconstructed feature layer data and the reconstructed enhancement layer data to obtain a hidden layer, reconstructing the hidden layer data, obtaining a reconstruction error generated in the reconstruction process, defining the F norm of the reconstruction error as a loss function, and deriving the loss function to obtain an optimal output layer weight matrix; S7, calculating the reconstruction loss of the signal data in the training set, and sorting the losses from large to small to obtain an error sorting set, and setting a proportional coefficient based on the error sorting set to determine the judgment threshold; S8, confirming the intrusion signal in the test set signal data based on the first optimal kernel function matrix, the second optimal kernel function matrix, the optimal output layer weight matrix and the judgment threshold.
2. The intrusion signal detection method based on dual-core single-class width learning autoencoder according to claim 1 is characterized in that: In S3, the calculation formula of the first objective function is as follows: ; in, is the signal data; is the kernel transformation matrix from the signal data in the training set to the reconstructed feature layer data; Represents the square of the F-norm of the matrix, which is used to measure the overall size of the matrix elements; is the regularization parameter, which is used to balance the weight of the reconstruction error and the regularization term; Representation Matrix of Norm, used to regularize the matrix; U is an intermediate variable; Indicates found and Minimize the loss function; Z represents the reconstructed feature layer data.
3. The intrusion signal detection method based on dual-core single-class width learning autoencoder according to claim 2 is characterized in that: In S3, the first objective function is transformed into the first unconstrained optimization problem by the augmented Lagrange multiplier method, and the formula is as follows: ; Among them, R is the Lagrange multiplier matrix, which is used to deal with constraints; represents the penalty parameter in the augmented Lagrangian function; represents the inner product of a matrix; The first unconstrained optimization problem is solved by the alternating direction multiplier method algorithm, and the calculation formula is as follows: ; Among them, I is the identity matrix, which is used to maintain the dimension and properties of the matrix in matrix operations.
4. The intrusion signal detection method based on dual-core single-class width learning autoencoder according to claim 1 is characterized in that: In S6, the F-norm of the reconstruction error is defined as the loss function as follows: ; in, is the loss function, is the output layer weight matrix; represents the square of the F norm of the matrix; is the regularization parameter, which is used to balance the weight of the reconstruction error and the regularization term; is the hidden layer data; is the signal data.
5. The intrusion signal detection method based on dual-core single-class width learning autoencoder according to claim 4 is characterized in that: In S6, the optimal output layer weight matrix is calculated as follows: ; in, is the regularization parameter; I is the unit matrix, A is the hidden layer data; is the optimal output layer weight matrix.
6. The intrusion signal detection method based on dual-core single-class width learning autoencoder according to claim 1 is characterized in that: The S8 specifically includes: The signal data in the test set is reconstructed by the first optimal kernel function matrix to obtain intrusion detection feature data, the intrusion detection feature data is reconstructed by the second optimal kernel function matrix to obtain intrusion detection feature enhanced data, the intrusion detection feature data and the intrusion detection feature enhanced data are spliced to obtain hidden layer data, the hidden layer data is reconstructed by the optimal output layer weight matrix to obtain the reconstruction error of the test data, and the signal data with the reconstruction error greater than the judgment threshold is judged as an intrusion signal.
7. The intrusion signal detection method based on dual-core single-class width learning autoencoder according to claim 6 is characterized in that: The definition of the reconstruction error is as follows: ; in, is the reconstruction error of the signal data in the i-th test set; represents the signal data in the i-th training set The reconstructed output of Represents a vector The square of the norm; The judgment threshold is set to ;in, Sort the set of errors; is the threshold scale parameter, which is used to control the size of the threshold. ; n is the number of signal data in the test set.
Citation Information
Patent Citations
Network intrusion detection method based on GPU and SVM
CN103685268A
Intrusion detection method and system, equipment and readable storage medium
CN112734000A
Analysis apparatus and method for abnormal network traffic
US20110261710A1