Intrusion Signal Detection Method Based on Dual-Core Single-Class Width Learning Autoencoder
Through the intrusion signal detection method based on dual-core single-class width learning autoencoder, the kernel function mapping and reconstruction optimization processing signal data are used to solve the problem of insufficient recognition capabilities of unknown attacks in the prior art, and efficient and accurate intrusion signal detection is achieved.
Patent Information
- Application Number
- CN202510535293.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-27
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2045-04-27
AI Technical Summary
The existing intrusion detection methods lack effective response capabilities when facing unknown or new types of cyber attacks, and the false alarm rate and missed alarm rate are high, resulting in increased operating costs and insufficient identification capabilities.
The intrusion signal detection method based on dual-core single-class width learning autoencoder is adopted, and the signal data is processed through two kernel function mapping and reconstruction optimization. The objective function is converted into an unconstrained optimization problem by using the augmented Lagrangian multiplier method, and the optimal kernel function matrix and the output layer weight matrix are solved, and the judgment threshold is set to identify the intrusion signal.
It improves the accuracy and stability of intrusion signal detection, reduces false alarm rate, enhances the ability to identify unknown attack patterns, and reduces operational costs.
Smart Images

Figure CN120067773B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of signal detection, and in particular to an intrusion signal detection method based on a dual-core single-class width learning autoencoder. Background Art
[0002] In today's digital and networked era, network security has become a crucial field. With the rapid development of information technology, the Internet has penetrated into all aspects of people's lives, from personal communication, commercial transactions to the management of national infrastructure, and is almost ubiquitous. However, this dependence has also brought new risks and challenges, especially when facing various network intrusion behaviors.
[0003] Traditional intrusion detection methods have certain limitations. For example, rule-based intrusion detection systems (IDS) need to pre-define a large number of rules to identify known types of attack patterns. This method lacks effective response capabilities for unknown or new intrusion behaviors because they cannot predict all possible attack methods. In addition, maintaining and updating these rule bases also requires a large amount of human and time resources, increasing the operating cost of the system.
[0004] On the other hand, statistics-based methods attempt to identify abnormal activities by analyzing the behavior patterns of network traffic. Although this method can discover some unforeseen attack behaviors to a certain extent, its judgment criteria are often relatively single, easily leading to a high false alarm rate or missed alarm rate. This means that normal network activities may be mislabeled as suspicious behaviors, or real intrusion behaviors may not be detected in time.
[0005] Therefore, it is particularly important to develop an efficient, accurate and adaptive intrusion signal detection technology, which can effectively improve the ability to identify unknown attack patterns and reduce the additional overhead caused by false alarms or missed alarms. Summary of the Invention
[0006] To solve the above problems, the present invention proposes an intrusion signal detection method based on a dual-core single-class width learning autoencoder, which processes signal data through two kernel function mappings and reconstruction optimizations, improving the accuracy of intrusion signal detection.
[0007] The specific solution is as follows:
[0008] On the one hand, the intrusion signal detection method based on a dual-core single-class width learning autoencoder includes:
[0009] S1, receiving signal data, and dividing the signal data into a test set and a training set;
[0010] S2, map the signal data in the training set through a kernel function to obtain the feature layer data of the training set;
[0011] S3, generate a random matrix based on the feature layer data of the training set, use this random matrix to reconstruct the signal data of the training set, obtain the reconstructed feature layer data, set the error caused by the reconstruction as the first objective function, transform the first objective function into a first unconstrained optimization problem through the augmented Lagrangian multiplier method, solve the first unconstrained optimization problem, and obtain the first optimal kernel function matrix;
[0012] S4, map the reconstructed feature layer data through a kernel function to obtain the enhanced layer data of the training set;
[0013] S5, generate a random matrix based on the enhanced layer data, use this random matrix to reconstruct the feature layer data of the training set, obtain the reconstructed enhanced layer data, set the error caused by the reconstruction as the second objective function, transform the second objective function into a second unconstrained optimization problem through the augmented Lagrangian multiplier method, solve the second unconstrained optimization problem, and obtain the second optimal kernel function matrix;
[0014] S6, concatenate the reconstructed feature layer data and the reconstructed enhanced layer data to obtain the hidden layer, reconstruct the hidden layer data, obtain the reconstruction error generated during the reconstruction, define the Frobenius norm of the reconstruction error as the loss function, take the derivative of the loss function, and obtain the optimal output layer weight matrix;
[0015] S7, calculate the reconstruction losses of the signal data in the training set, sort these losses from large to small to obtain an error sorting set, and set a proportionality coefficient based on this error sorting set to determine the judgment threshold;
[0016] S8, confirm the intrusion signals in the test set signal data based on the first optimal kernel function matrix, the second optimal kernel function matrix, the optimal output layer weight matrix, and the judgment threshold.
[0017] Furthermore, in S3, the calculation formula of the first objective function is as follows:
[0018]
[0019] where X is the signal data; W K is the kernel transformation matrix from the signal data in the training set to the reconstructed feature layer data; represents the square of the Frobenius norm of the matrix, which is used to measure the overall size of the matrix elements; λ is the regularization parameter, which is used to balance the weights of the reconstruction error and the regularization term; ||U|| 2.1 represents the l 2,1 norm of the matrix U, which is used to regularize the matrix; U is an intermediate variable; represents finding WK and U to minimize the loss function; Z represents the reconstructed feature layer data.
[0020] Further, in S3, the first objective function is transformed into a first unconstrained optimization problem by the augmented Lagrangian multiplier method, and the formula is as follows:
[0021]
[0022] where R is the Lagrange multiplier matrix for dealing with the constraint conditions; μ represents the penalty parameter in the augmented Lagrangian function; <> represents the inner product of matrices.
[0023] The first unconstrained optimization problem is solved by the alternating direction multiplier method algorithm, and the calculation formula is as follows:
[0024] W K =(X T X + μI) -1 (X T Z + μU + R T );
[0025] where I is the identity matrix for maintaining the dimension and properties of the matrix in matrix operations.
[0026] Further, in S6, the F-norm of the reconstruction error is defined as the loss function, specifically as follows:
[0027]
[0028] where L MKOC-BLSAE is the loss function, W out is the output layer weight matrix; represents the square of the F-norm of the matrix; λ is the regularization parameter for balancing the weights of the reconstruction error and the regularization term; A is the hidden layer data; X is the signal data.
[0029] Further, in S6, the optimal output layer weight matrix, the calculation formula is as follows:
[0030] W′ out =(λI + A T A) -1 A T X;
[0031] where λ is the regularization parameter; I is the identity matrix, A is the hidden layer data; W′ out is the optimal output layer weight matrix.
[0032] Further, the said S8 specifically includes:
[0033] Reconstruct the signal data in the test set through the first optimal kernel function matrix to obtain intrusion detection feature data, reconstruct the intrusion detection feature data through the second optimal kernel function matrix to obtain intrusion detection feature enhancement data, splice the intrusion detection feature data and the intrusion detection feature enhancement data to obtain hidden layer data, and reconstruct the hidden layer data through the optimal output layer weight matrix to obtain the reconstruction error of the test data. Determine the signal data with a reconstruction error greater than the judgment threshold as intrusion signals.
[0034] Further, the definition of the reconstruction error is specifically as follows:
[0035]
[0036] Among them, r i is the reconstruction error of the signal data in the i-th test set; Rebuild(x i ) represents the reconstruction output of x i of the signal data in the i-th training set; represents the square of the l2 norm of the vector;
[0037] The judgment threshold θ is set to θ = R S (∈ * n); among them, R S is the error sorting set; ∈ is the threshold scale parameter used to control the size of the threshold, ∈ ∈ [0, 1]; n is the number of signal data in the test set.
[0038] The present invention adopts the above technical solutions and has the following beneficial effects:
[0039] (1) The present invention confirms the intrusion signals in the test set through the first optimal kernel function matrix, the second optimal kernel function matrix, the optimal output layer weight matrix, and the set judgment threshold, providing a reliable anomaly detection mechanism, enabling the system to quickly and accurately identify potential intrusion behaviors in practical applications;
[0040] (2) The present invention transforms the objective function into an unconstrained optimization problem for solution by using the augmented Lagrangian multiplier method to obtain the optimal kernel function matrix, improving the ability to process complex data sets and ensuring stability and accuracy in high-dimensional spaces;
[0041] (3) The present invention improves the accuracy of anomaly signal detection by optimizing the reconstruction error and setting the judgment threshold based on the error sorting set. Description of the Drawings
[0042] Figure 1 is the flowchart of the intrusion signal detection method based on the dual-core single-class width learning autoencoder according to the embodiment of the present invention. Detailed Embodiment
[0043] The present invention will be further described in detail below in conjunction with embodiments and the accompanying drawings, but the embodiments of the present invention are not limited thereto.
[0044] As Figure 1 shown, the intrusion signal detection method based on the dual-core single-class width learning autoencoder of the present invention includes:
[0045] S1. Receive signal data and divide the signal data into a test set and a training set.
[0046] Specifically, this embodiment is carried out on an intrusion detection data set constructed by NSL-KDD and UNSW-NB15. For each experiment, 20 independent trials are conducted. In each trial, the target class is randomly and evenly divided into a training set and a test set, and abnormal samples are added to the test set. To evaluate the performance, consistent with the methods commonly used in single-classification research, it is implemented based on Sciki-learn and run on an Intel Core i7-12700 CPU with 2.10 GHz.
[0047] S2. Map the signal data in the training set through a kernel function to obtain the feature layer data of the training set.
[0048] Specifically, in the input signal, the distribution of normal data and abnormal data is complex and difficult to distinguish with a simple model. The kernel function can map the data from the low-dimensional original space to the high-dimensional feature space, making the data that was originally mixed and linearly inseparable become linearly separable in the high-dimensional space.
[0049] S3. Generate a random matrix based on the feature layer data of the training set, use this random matrix to reconstruct the signal data of the training set to obtain the reconstructed feature layer data, set the error caused by the reconstruction as the first objective function, transform the first objective function into a first unconstrained optimization problem through the augmented Lagrangian multiplier method, and solve the first unconstrained optimization problem to obtain the first optimal kernel function matrix.
[0050] Specifically, the calculation formula of the first objective function is as follows:
[0051]
[0052] where X is the signal data; W K is the kernel transformation matrix from the signal data in the training set to the reconstructed feature layer data; represents the square of the F norm of the matrix, which is used to measure the overall size of the matrix elements; λ is the regularization parameter, which is used to balance the weights of the reconstruction error and the regularization term; ||U|| 2.1 represents the l 2,1 norm of the matrix U, which is used to regularize the matrix; U is an intermediate variable; Indicates that W is found K and U such that the loss function is minimized; Z represents the reconstructed feature layer data.
[0053] Specifically, the first objective function is transformed into a first unconstrained optimization problem by the augmented Lagrangian multiplier method, and the formula is as follows:
[0054]
[0055] where R is the Lagrangian multiplier matrix for dealing with the constraint conditions; μ represents the penalty parameter in the augmented Lagrangian function; <> represents the inner product of matrices.
[0056] The first unconstrained optimization problem is solved by the alternating direction multiplier method algorithm, and the calculation formula is as follows:
[0057] W K =(X T X + μI) -1 (X T Z + μU + R T );
[0058] where I is the identity matrix for maintaining the dimension and properties of the matrix in matrix operations.
[0059] S4. Map the reconstructed feature layer data through a kernel function to obtain the enhanced layer data of the training set;
[0060] S5. Generate a random matrix based on the enhanced layer data, use this random matrix to reconstruct the feature layer data of the training set to obtain the reconstructed enhanced layer data, set the error caused by the reconstruction as the second objective function, transform the second objective function into a second unconstrained optimization problem by the augmented Lagrangian multiplier method, and solve the second unconstrained optimization problem to obtain the second optimal kernel function matrix W e ;
[0061] S6. Concatenate the reconstructed feature layer data and the reconstructed enhanced layer data to obtain the hidden layer, reconstruct the hidden layer data, obtain the reconstruction error generated during the reconstruction, define the Frobenius norm of the reconstruction error as the loss function, and take the derivative of the loss function to obtain the optimal output layer weight matrix.
[0062] Specifically, define the Frobenius norm of the reconstruction error as the loss function, as follows:
[0063]
[0064] where L MKOC-BLSAE is the loss function, and W out is the output layer weight matrix; Denotes the square of the Frobenius norm of the matrix; λ is the regularization parameter used to balance the weights of the reconstruction error and the regularization term; A is the data of the hidden layer; X is the signal data.
[0065] Specifically, the formula for the optimal output layer weight matrix is as follows:
[0066] W′ out =(λI + A T A) -1 A T X;
[0067] Where λ is the regularization parameter; I is the identity matrix, A is the data of the hidden layer; W′ 0ut is the optimal output layer weight matrix.
[0068] S7. Calculate the reconstruction losses of the signal data in the training set, sort these losses from largest to smallest to obtain an error sorting set, and set a proportionality coefficient based on this error sorting set to determine the judgment threshold.
[0069] S8. Based on the first optimal kernel function matrix, the second optimal kernel function matrix, the optimal output layer weight matrix, and the judgment threshold, identify the intrusion signals in the test set signal data.
[0070] Specifically, S8 specifically includes:
[0071] Reconstruct the signal data in the test set through the first optimal kernel function matrix to obtain intrusion detection feature data, reconstruct the intrusion detection feature data through the second optimal kernel function matrix to obtain intrusion detection feature enhanced data, splice the intrusion detection feature data and the intrusion detection feature enhanced data to obtain the hidden layer data, reconstruct the hidden layer data through the optimal output layer weight matrix to obtain the reconstruction error of the test data, and determine the signal data with a reconstruction error greater than the judgment threshold as the intrusion signal.
[0072] Specifically, the definition of the reconstruction error is as follows:
[0073]
[0074] Where r i is the reconstruction error of the i-th signal data in the test set; Rebuild(x i ) represents the reconstruction output of x i of the i-th signal data in the training set; represents the square of the l2 norm of the vector;
[0075] The judgment threshold θ is set to θ = R S (∈*n); where R SIt is a set for sorting errors; ∈ is a threshold scale parameter used to control the size of the threshold, and ∈ ∈ [0, 1]; n is the number of signal data in the test set.
[0076] Classification is performed according to the threshold as follows:
[0077]
[0078] θ is the judgment threshold obtained after sorting. When the reconstruction error is greater than the judgment threshold, it is marked as an abnormal sample; when it is less than or equal to the judgment threshold, it is marked as a normal sample.
[0079] Specifically, in this embodiment, the network structure corresponding to the intrusion signal detection method based on the dual-core single-class width learning autoencoder mainly includes an input layer, a hidden layer, and an output layer; the hidden layer is composed of a feature layer and an enhancement layer combined; ① Feature layer: The feature layer Z is constructed by cascading p groups of feature nodes, and the expression is Z = [Z1, Z2, …, Z p , where p is the number of groups of feature layer nodes, which is a positive integer; Z m represents the mth group of nodes in the feature layer, m = 1, 2, …, p; Z m = K m (x i , x k ), where K m is the mth kernel function, and Gaussian, polynomial, and linear kernels are selected as the basic kernels, and multiple kernel functions are obtained by setting different parameters; x i and x k are sample vectors in the original input data; ② Enhancement layer: The enhancement layer H is composed of q groups of nodes, that is, H = [H1, H2, …, H q , where q is the number of groups of enhancement layer nodes, which is a positive integer; H m represents the mth group of nodes in the enhancement layer, m = 1, 2, …, q; H m = K m (Z i , Z k ), and here K m is also a kernel function, and Z i and Z k are sample vectors output by the feature layer; the hidden layer A is composed of the connection of the feature layer and the enhancement layer, that is, A = [Z|H].
[0080] Generally speaking, in the present invention, first, the received signal data is mapped to a high-dimensional feature space through a kernel function (step S2), which is similar to the fast feature mapping in the wide learning system and aims to capture complex data features. Then, based on the generated random matrix, these feature layer data are reconstructed, and the first optimal kernel function matrix is obtained through an optimization process (step S3), further enhancing the representation ability of the model. Next, a similar strategy is used to perform kernel function mapping and reconstruction on the reconstructed feature layer data again to obtain the second optimal kernel function matrix (steps S4-S5), thereby forming enhanced layer data. The concatenated feature layer and the enhanced layer form a hidden layer, and the reconstruction error is calculated as a loss function to solve the output layer weight matrix (step S6), which is the core idea of the autoencoder, that is, minimizing the difference between the input and the reconstructed output to learn an effective data representation. Finally, a judgment threshold is set based on the reconstruction error of the training set, and this model is used to identify intrusion signals in the test set (steps S7-S8). This method combines the efficiency of the wide learning system and the reconstruction characteristics of the autoencoder, specifically for learning normal samples for anomaly detection, fully demonstrating the application of the one-class wide learning autoencoder.
[0081] Although the present invention has been specifically shown and described in conjunction with the preferred embodiments, those skilled in the art should understand that various changes can be made to the present invention in terms of form and details without departing from the spirit and scope of the present invention defined by the appended claims, and all of them fall within the protection scope of the present invention.
Claims
1. An intrusion signal detection method based on a dual-core single-class width learning autoencoder, characterized in that, Including: S1, receiving signal data and dividing the signal data into a test set and a training set; S2, mapping the signal data in the training set through a kernel function to obtain the feature layer data of the training set; S3, generating a random matrix based on the feature layer data of the training set, using the random matrix to reconstruct the signal data of the training set to obtain the reconstructed feature layer data, setting the error caused by the reconstruction as the first objective function, transforming the first objective function into a first unconstrained optimization problem through the augmented Lagrangian multiplier method, and solving the first unconstrained optimization problem to obtain the first optimal kernel function matrix; S4, mapping the reconstructed feature layer data through a kernel function to obtain the enhanced layer data of the training set; S5, generating a random matrix based on the enhanced layer data, using the random matrix to reconstruct the feature layer data of the training set to obtain the reconstructed enhanced layer data, setting the error caused by the reconstruction as the second objective function, transforming the second objective function into a second unconstrained optimization problem through the augmented Lagrangian multiplier method, and solving the second unconstrained optimization problem to obtain the second optimal kernel function matrix; S6, concatenating the reconstructed feature layer data and the reconstructed enhanced layer data to obtain a hidden layer, reconstructing the hidden layer data, obtaining the reconstruction error generated during the reconstruction, defining the Frobenius norm of the reconstruction error as the loss function, and taking the derivative of the loss function to obtain the optimal output layer weight matrix; S7, calculating the reconstruction loss of the signal data in the training set, sorting these losses from large to small to obtain an error sorting set, and setting a proportionality coefficient based on the error sorting set to determine the judgment threshold; S8, based on the first optimal kernel function matrix, the second optimal kernel function matrix, the optimal output layer weight matrix, and the judgment threshold, identifying the intrusion signals in the test set signal data; The calculation formula of the first objective function is as follows: where X is the signal data; W K is the kernel transformation matrix from the signal data in the training set to the reconstructed feature layer data; represents the square of the Frobenius norm of the matrix, which is used to measure the overall magnitude of the matrix elements; λ is the regularization parameter, which is used to balance the weights of the reconstruction error and the regularization term; ||U|| 2.1 represents the l 2,1 norm of the matrix U, which is used to regularize the matrix; U is an intermediate variable; denotes finding W K and U to minimize the loss function; Z represents the reconstructed feature layer data; the first objective function is transformed into the first unconstrained optimization problem by the augmented Lagrangian multiplier method, and the formula is as follows: Among them, R is the Lagrange multiplier matrix for handling constraint conditions; μ represents the penalty parameter in the augmented Lagrangian function; <> represents the inner product of matrices; Solving the first unconstrained optimization problem through the alternating direction multiplier method algorithm, the calculation formula is as follows: W K = (X T X + μI) -1 (X T Z + μU + R T ); Among them, I is the identity matrix for maintaining the dimension and properties of the matrix in matrix operations.
2. The intrusion signal detection method based on a dual-core single-class width learning autoencoder according to claim 1, characterized in that In S6, defining the Frobenius norm of the reconstruction error as the loss function, specifically as follows: Among them, L MKOC-BLSAE is the loss function, and W out is the weight matrix of the output layer; A is the data of the hidden layer.
3. The intrusion signal detection method based on a dual-core single-class width learning autoencoder according to claim 2, wherein In S6, the optimal output layer weight matrix, the calculation formula is as follows: W′ out =(λI + A T A) -1 A T X; Among them, W′ out is the optimal output layer weight matrix.
4. The intrusion signal detection method based on a dual-core single-class width learning autoencoder according to claim 1, wherein The said S8 specifically includes: Reconstructing the signal data in the test set through the first optimal kernel function matrix to obtain intrusion detection feature data, reconstructing the intrusion detection feature data through the second optimal kernel function matrix to obtain intrusion detection feature enhancement data, concatenating the intrusion detection feature data and the intrusion detection feature enhancement data to obtain hidden layer data, reconstructing the hidden layer data with the optimal output layer weight matrix to obtain the reconstruction error of the test data, and determining the signal data with the reconstruction error greater than the judgment threshold as intrusion signals.
5. The intrusion signal detection method based on a dual-core single-class width learning autoencoder according to claim 4, characterized in that The definition of the said reconstruction error is specifically as follows: where r i is the reconstruction error of the signal data in the i-th test set; Rebuild(x i ) represents the reconstruction output of x i of the signal data in the i-th training set; represents the square of the l2 norm of the vector; The judgment threshold θ is set to θ = R S (∈ * n); where R S is the error sorting set; ∈ is the threshold scale parameter used to control the size of the threshold, ∈ ∈ [0, 1]; n is the number of signal data in the test set.
Citation Information
Patent Citations
Network intrusion detection method based on GPU and SVM
CN103685268A
Intrusion detection method and system, equipment and readable storage medium
CN112734000A