Dynamic graph anomaly detection method based on hypergraph contrast learning
By using hypergraph comparison learning method in dynamic graph anomaly detection, combining hypergraph convolutional network, adaptive neighborhood learning and time series modeling, hypergraph weights are dynamically adjusted and node feature representation is optimized, which solves the problem that the existing technology is difficult to model high-order interaction relationships and temporal dynamic characteristics, and significantly improves detection performance.
Patent Information
- Application Number
- CN202510235469.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-28
- Publication Date
- 2025-05-30
AI Technical Summary
Existing dynamic graph anomaly detection methods are difficult to effectively model high-order interactions and temporal dynamic characteristics, resulting in limited detection performance.
Using a hypergraph-based contrast learning method, high-order interactive relationships are modeled through hypergraph convolutional network (HGCN), combined with adaptive neighborhood learning and time series modeling, hyper-edge weights are dynamically adjusted and node feature representation is optimized. At the same time, a dynamic collaborative comparison learning strategy was introduced to enhance the optimization feature representation through multiple rounds of alternating.
It significantly improves the performance of dynamic graph anomaly detection, can more accurately model high-order interaction relationships and temporal dynamic characteristics, and improves the robustness and accuracy of detection.
Smart Images

Figure CN120067950A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method for modeling the multi-node cooperation relationship in a dynamic graph using a hypergraph and improving the anomaly detection performance by combining contrastive learning. Aiming at the requirements of high-order interaction relationship modeling and time dynamic feature learning in the dynamic graph anomaly detection task, a dynamic graph anomaly detection method based on hypergraph contrastive learning is designed. Background Art
[0002] Dynamic Graph Anomaly Detection aims to identify abnormal patterns in complex networks that evolve over time, and has important application values in fields such as social network analysis, financial transaction monitoring, and recommendation system optimization. With the dynamic growth of data, the nodes and edges in the network structure constantly change, making the abnormal patterns often show time dependence and structural complexity, and traditional static anomaly detection methods are difficult to effectively adapt to the dynamic characteristics of dynamic graphs. Therefore, how to efficiently detect abnormal behaviors in dynamic graphs has become an important research direction in the field of graph data mining.
[0003] In recent years, deep learning technologies have made significant progress in dynamic graph modeling. Most existing studies conduct anomaly detection based on the standard graph structure, usually using graph neural networks (GNNs) to model the local features of nodes and edges, and combining time series models (such as RNN, GRU) to extract the time dependence of dynamic graphs. However, the standard graph can only represent the interaction relationship between pairwise nodes, and many abnormal patterns in dynamic graphs often involve the cooperation of multiple nodes. For example, in a financial transaction network, fraud may involve multiple users and multiple rounds of fund transfers, and the spread of false information in a social network usually depends on the joint operations of multiple users. Therefore, how to effectively model the high-order interaction relationship in dynamic graphs has become a key challenge in the dynamic graph anomaly detection task.
[0004] To solve the above problems, researchers have started to introduce hypergraphs for dynamic graph modeling in recent years. Different from the standard graph, a hypergraph can associate multiple nodes with a hyperedge simultaneously, thus naturally representing the multi-party cooperation relationship, and this feature gives it unique advantages in the anomaly detection task. The hypergraph-based dynamic graph anomaly detection method can capture the high-order structure information in complex networks more comprehensively and improve the accuracy of anomaly detection. However, existing hypergraph-based methods still have some limitations, such as fixed hyperedge weights and insufficient feature fusion, which are difficult to adaptively adjust the interaction relationship between nodes and affect the detection ability of the model.
[0005] On the other hand, contrastive learning, as a self-supervised learning method, has been widely recognized for its feature extraction ability on unlabeled data. Its core idea is to construct positive and negative sample pairs, making the representations of similar samples closer and those of different classes farther apart, thereby enhancing the discriminative ability of features. Although existing research has applied contrastive learning to anomaly detection on standard graphs, existing methods have not fully considered the high-order interaction characteristics and time dynamic information of dynamic graphs, resulting in the underutilization of the representation ability of contrastive learning.
[0006] Therefore, how to combine the high-order interaction relationship modeling ability of hypergraphs and the self-supervised feature optimization ability of contrastive learning to construct an efficient dynamic graph anomaly detection method is an important issue faced by this field currently. Summary of the Invention
[0007] In view of the fact that existing dynamic graph anomaly detection methods are difficult to effectively model high-order interaction relationships and time dynamic characteristics, the present invention proposes a dynamic graph anomaly detection method based on hypergraph contrastive learning. This method first uses a hypergraph convolutional network (HGCN) to model the high-order interaction relationships in the dynamic graph and generates high-order feature representations through the aggregation of hyperedge information to more comprehensively capture the complex interaction patterns among multiple nodes. Then, this method combines adaptive neighborhood learning and time series modeling, adaptively adjusts the hyperedge weights, and uses a gated recurrent unit (GRU) to perform time modeling on node features, thereby optimizing the structural characteristics and time evolution characteristics of the dynamic graph simultaneously. Finally, this method introduces a dynamic collaborative contrastive learning strategy, which enhances feature interaction and optimization between the standard graph and hypergraph views through multiple rounds of alternating enhancement to improve the discriminative ability of the model.
[0008] The main idea of implementing the present invention is as follows: The challenge of the dynamic graph anomaly detection task lies in that the structure of the dynamic graph evolves dynamically over time, and at the same time, the anomaly patterns often involve the cooperative effects of multiple nodes, making the detection process more complex. Existing methods usually rely on time snapshot modeling, disassembling the dynamic graph into multiple discrete static graphs and using graph neural networks (GNNs) to extract features. However, this method mainly focuses on the relationships between pairwise nodes and is difficult to depict the cooperative interaction patterns among multiple nodes, while abnormal behaviors often involve more complex high-order interactions. In addition, the lack or simple modeling of time information makes it difficult for these methods to accurately capture the dynamic evolution characteristics of the dynamic graph.
[0009] To address these issues, Hypergraph provides a natural modeling approach that can simultaneously associate multiple nodes and enhance the expression ability of high-order interaction patterns through the hyperedge structure, making the capture of abnormal patterns more accurate. At the same time, contrastive learning, as a self-supervised learning method, can optimize feature representations on unlabeled data, enabling the model to effectively distinguish normal patterns from abnormal patterns and improving the robustness of detection. However, existing methods have not fully combined the high-order relationship modeling ability of hypergraphs with the feature optimization ability of contrastive learning in dynamic graph environments, resulting in still limited expression and recognition capabilities for abnormal patterns. Therefore, the present invention applies hypergraph modeling and contrastive learning to the abnormal detection task of dynamic graphs, which may help to more accurately model high-order interaction relationships and temporal dynamic characteristics, thereby further improving the performance of dynamic graph abnormal detection.
[0010] A method for abnormal detection of dynamic graphs based on hypergraph contrastive learning includes the following steps:
[0011] (Step 1) Hypergraph construction and high-order interaction relationship modeling: Perform hypergraph modeling on the dynamic graph, map the collaborative relationships between multiple nodes to hyperedges, construct a hypergraph incidence matrix, and use a hypergraph convolutional network (HGCN) to perform high-order feature aggregation on node features.
[0012] (Step 2) Adaptive neighborhood learning: Use a dynamic weight matrix to adaptively adjust hyperedge weights, so that key interaction relationships receive higher attention during feature aggregation, thereby enhancing the effectiveness of abnormal detection.
[0013] (Step 3) Time series modeling: Adopt a GRU structure to receive the high-order node features output by the hypergraph convolutional module, update the node states slice by slice in time, and through the memory gate and update gate, retain the information of long-term dependencies in node features and suppress the interference of irrelevant information.
[0014] (Step 4) Dynamic collaborative contrastive learning: First, calculate node representations on the standard graph and hypergraph respectively to ensure the effective fusion of multi-view information. Then, use a multi-round alternating enhancement mechanism to optimize the representations of nodes in different views. Finally, through cross-view contrastive learning, constrain the feature similarity of the same node in different views, making abnormal nodes easier to distinguish.
[0015] (Step 5): Abnormal score calculation and abnormal detection: Use the Euclidean distance between the two end nodes of an edge to calculate the abnormal score of the edge, measure the degree of abnormality of the edge and set an abnormal detection threshold, identify abnormal edges, and perform abnormal pattern analysis on the dynamic graph.
[0016] Compared with the prior art, the present invention has the following obvious advantages and beneficial effects;
[0017] (1) The high-order interaction relationship is introduced by hypergraph modeling. The collaborative relationship among multiple nodes in the dynamic graph is modeled using the hypergraph structure, and the high-order feature representation ability is enhanced by combining with the hypergraph convolutional network (HGCN), thereby enhancing the model's ability to model complex interaction patterns.
[0018] (2) An adaptive neighborhood learning mechanism is introduced during the hypergraph convolution process to dynamically adjust the hyperedge weights, enabling higher attention to important interaction relationships and improving the accuracy of anomaly detection.
[0019] (3) A dynamic collaborative contrast learning strategy is designed to alternately enhance and optimize the feature representation through multiple rounds, enabling the model to generate more robust anomaly detection results in an unsupervised environment. Description of the Drawings
[0020] Figure 1 is the flowchart of this method. Detailed Implementation Manner
[0021] The following elaborates on the specific implementation manner and detailed steps of the present invention. The specific implementation process of the present invention is as Figure 1 shown, specifically including:
[0022] (Step 1) Construct a hypergraph and model the high-order interaction relationship;
[0023] The present invention proposes a dynamic graph anomaly detection method based on hypergraph contrast learning. Among them, the high-order interaction relationship of the dynamic graph is crucial for the learning of anomaly patterns. Therefore, in this step, a hypergraph is constructed to represent the cooperation among multiple nodes, and on this basis, the hypergraph convolutional network (HGCN) is used for feature extraction to enhance the ability to model high-order interaction patterns.
[0024] In the dynamic graph, the high-order interaction relationship between nodes and hyperedges is a key feature of the anomaly detection task. However, the traditional hypergraph convolutional network (HGCN) only relies on the hypergraph incidence matrix H for feature aggregation, which may ignore the importance of node self-update, thus resulting in insufficient expression of node local features. Therefore, an improved HGCN formula is proposed. By introducing the self-update path of the node, the hyperedge aggregation information is combined with the node's own features, thereby enhancing the feature expression ability. The improved HGCN formula is as follows:
[0025]
[0026] Among them, the first term represents the feature aggregation based on hyperedge information. Ω is a dynamic adaptive weight matrix used to adjust the weights of different hyperedges; the second term σ(XW) represents the self-update path of the node; σ(·) is a non-linear activation function; W is a learnable projection matrix.
[0027] This module updates the node features at the current time t through the above formula:
[0028]
[0029] Finally, through this step, the high-order interaction relationships of the dynamic graph are effectively modeled, providing high-quality initial feature representations for subsequent adaptive neighborhood learning and time series modeling.
[0030] (Step 2) Adaptive neighborhood learning;
[0031] In a dynamic graph, the influence degrees of different hyperedges on the node states are different. Therefore, it is necessary to dynamically adjust the weights of the hyperedges. For this purpose, an adaptive neighborhood learning method is proposed to dynamically update the weight matrix Ω t ∈R E×E , thus improving the effect of feature aggregation.
[0032] For each hyperedge e i ∈H t in the hypergraph, first calculate its dynamic weight, which can be defined as:
[0033]
[0034] Among them, is a similarity function (such as cosine similarity), is the feature representation of the associated nodes in the hyperedge e i ,e j , is the weight between the hyperedge e i and e j .
[0035] The calculated weight is used to update the hyperedge weight matrix Ω t :
[0036]
[0037] By dynamically updating the weight matrix Ω t , the weights of the hyperedges can not only reflect the feature changes of local nodes but also capture the important interactions between hyperedges in the dynamic graph.
[0038] (Step 3) Time series modeling;
[0039] In order to capture the feature changes of nodes in the time dimension, the present invention uses a gated recurrent unit (GRU) to perform time series modeling on the node features X t . The update formula of GRU is as follows:
[0040]
[0041] Among them, r t and z t are the reset gate and the update gate respectively; is the candidate node state; ⊙ represents element-wise multiplication.
[0042] The dynamic hypergraph convolution module effectively captures the high-order interaction relationships and temporal dynamic characteristics between nodes and hyperedges in the dynamic graph by combining hypergraph convolution, adaptive neighborhood learning, and time series modeling. The preliminarily updated time-aware node representation provides rich feature information for the subsequent dynamic collaborative contrast learning module, thereby further improving the effect of dynamic graph anomaly detection.
[0043] (Step 4) Dynamic collaborative contrast learning;
[0044] This module extracts node representations through a multi-round alternating enhancement strategy based on the dual-view information of the dynamic hypergraph and the standard graph. In each round, the representations are updated in the standard graph and the hypergraph respectively, and the node feature representations are optimized by means of contrast learning.
[0045] First, the time-aware node representation and the standard graph adjacency matrix A are input into GCN to generate the node representation The GCN representation update formula is as follows:
[0046]
[0047] Among them, W A is the learnable parameter of GCN, and σ is the activation function.
[0048] The time-aware node representation and the dynamic hypergraph incidence matrix H t are input into HGCN to generate the node representation The update form is as follows:
[0049]
[0050] The update process of HGCN follows the formula in the dynamic hypergraph convolution module.
[0051] By fusing the node representations and of the standard graph and the hypergraph, an enhanced node representation
[0052]
[0053] The fused representation Input GCN and HGCN respectively to further update the node representations of the standard graph and the hypergraph. Repeat the above process to generate node representations with multiple rounds of alternating enhancement. And finally fuse and generate
[0054]
[0055] (2) Cross-view contrastive learning
[0056] The dynamic hypergraph collaborative contrast module uses the cross-view contrastive learning strategy to optimize the enhanced node representations. The core idea of cross-view contrast is to compare the feature representations of the same node in different views (standard graph and hypergraph), thereby improving the feature expression ability.
[0057] The objects of cross-view contrast are respectively:
[0058] Loss 1 : And Loss 2 : And Loss 3 : And
[0059] The loss function used in contrastive learning is based on similarity calculation, and the formula is as follows:
[0060]
[0061] Among them, sim(·) represents the similarity calculation function, τ is the temperature parameter, and i, j represent the node indices respectively.
[0062] The final contrast loss of the module is the weighted sum of the contrast losses in each round:
[0063] L con = λ 1 Loss 1 + λ 2 Loss 2 + λ 3 Loss 3 (14)
[0064] Among them, λ 1 , λ 2 , λ 3 are hyperparameters used to adjust the weights of the contrast losses in different rounds.
[0065] The dynamic hypergraph collaborative contrast module realizes the deep integration of high-order interaction features and temporal dynamic information through multiple rounds of alternating enhancement and cross-view contrast learning. The module utilizes the dual-view information of dynamic hypergraphs and standard graphs, and combines time series modeling to generate more discriminative time-aware node representations Z t . Through the deep integration of cross-view information, the module provides rich and robust feature inputs for subsequent abnormal edge detection.
[0066] (Step 5) Abnormal score generation;
[0067] Based on the time-aware node representation Z output by the dynamic collaborative contrast learning module t , calculate the abnormal score of each edge in the dynamic graph. Specifically, let the edge connect nodes and . Its abnormal score is calculated by the Euclidean distance between the two nodes at both ends of the edge. The formula is as follows:
[0068]
[0069] where and represent the time-aware representations of nodes and respectively, and |·| is the Euclidean distance.
[0070] The size of the edge abnormal score reflects the degree of difference between the representations of the two nodes at both ends of the edge. The higher the score, the higher the degree of abnormality of the edge. By setting a threshold δ, abnormal edges can be identified, that is:
[0071] If then the edge is an abnormal edge.
[0072] The abnormality degree of the edge is calculated by the Euclidean distance between the two nodes at both ends of the edge, and the model is optimized by designing a loss function. Specifically, the loss function of the abnormal detection module can be defined as:
[0073]
[0074] The goal of this loss function is to minimize the Euclidean distance between the two nodes at both ends of the edge, so that the reconstruction error of normal edges is as small as possible, while retaining the differences of abnormal edges.
[0075] The total loss function is jointly composed of the contrast loss of the dynamic collaborative contrast learning module and the reconstruction loss of the abnormal detection module, and is defined as follows:
[0076]
[0077] Among them, the contrastive loss \(L_{contrast}\) is used to capture the high-order interaction characteristics and temporal dynamic characteristics between the standard graph and the hypergraph through the dynamic collaborative contrastive learning module. The reconstruction loss \(L\) recon By reconstructing the feature representation of the edges, it is used to directly evaluate the abnormality degree of the edges, so as to effectively capture the abnormal patterns in the dynamic graph. The weight coefficients \(\lambda_{contrast}\) and \(\lambda_{recon}\) respectively control the importance of the contrastive loss and the reconstruction loss in the total loss.
[0078] To fully verify the superiority of this method, this method is compared with existing dynamic graph anomaly detection methods on four real datasets, Reddit, MOOC, Bitcoin Alpha, and UCI Message. The experimental results are shown in Table 1.
[0079] Table 1: Performance comparison of HGCL-DGAD and four dynamic graph anomaly detection methods on four datasets
[0080]
[0081] As can be seen from Table 1, on the UCI dataset, HGCL-DGAD achieved the best performance under all anomaly ratios (1%, 5%, 10%). This indicates that in scenarios with relatively simple features and limited dynamic changes, HGCL-DGAD can fully capture high-order interaction characteristics and temporal dynamic information through the effective combination of dynamic hypergraph convolution and cross-view contrastive learning, demonstrating excellent anomaly detection capabilities.
[0082] On the Reddit and MOOC datasets, HGCL-DGAD achieved the best performance when the anomaly ratio was 1% and 5%, but it performed slightly worse than DCLDyAD when the anomaly ratio was 10%. The reason behind this phenomenon may be related to the dynamic complexity of the datasets and the characteristics of the abnormal patterns. It is worth noting that in the scenarios where the anomaly ratio of the Reddit and MOOC datasets is 10%, the AUC values of each method did not reach a high level, which reflects the specific challenges of these datasets under high anomaly ratios. First, these two datasets have rapidly changing dynamic attributes, resulting in a reduced distinguishability between the features of abnormal edges and normal edges. Especially when the anomaly ratio increases, this characteristic difference is further diluted. Second, the complex interaction patterns between users and courses in the MOOC dataset, as well as the high-dimensional dynamics of the social network in the Reddit dataset, make the distribution of abnormal edges more concealed, and it is difficult for traditional feature aggregation and temporal modeling methods to accurately capture these subtle differences. In addition, a high anomaly ratio often means a significant increase in the proportion of abnormal edges in the overall graph structure, which may interfere with the stability of normal patterns, thus posing higher requirements for the robustness of anomaly detection.
[0083] The above experiments show that through the innovative combination of dynamic hypergraph modeling and collaborative contrastive learning, this method demonstrates excellent performance and broad applicability in the task of dynamic graph anomaly detection, provides new ideas for subsequent research, and offers strong support for the accurate identification of abnormal patterns in complex networks.
Claims
1. A dynamic graph anomaly detection method based on hypergraph contrastive learning, characterized in that: The following steps are involved: Step 1: Hypergraph construction and high-order interaction relationship modeling: Hypergraph modeling is performed on the dynamic graph, the collaborative relationships between multiple nodes are mapped to hyperedges, a hypergraph association matrix is constructed, and high-order feature aggregation of node features is performed using the hypergraph convolutional network HGCN; Step 2: Adaptive neighborhood learning: Use a dynamic weight matrix to adaptively adjust the hyperedge weights so that key interaction relationships receive higher attention during feature aggregation, thereby enhancing the effectiveness of anomaly detection. Step 3: Time series modeling: The GRU structure is used to receive the high-order node features output by the hypergraph convolution module, and the node status is updated in each time slice. The long-term dependent information of the node features is retained through the memory gate and the update gate, and the interference of irrelevant information is suppressed. Step 4: Dynamic collaborative contrastive learning: Calculate node representations on the standard graph and hypergraph respectively to ensure effective fusion of multi-view information; use multiple rounds of alternating enhancement mechanisms to optimize the representation of nodes in different views; constrain the feature similarity of the same node in different views through cross-view contrastive learning, making abnormal nodes easier to distinguish; Step 5: Anomaly score calculation and anomaly detection: Use the Euclidean distance between the nodes at both ends of the edge to calculate the anomaly score of the edge, measure the degree of anomaly of the edge and set the anomaly detection threshold, identify abnormal edges, and perform abnormal pattern analysis on the dynamic graph.
2. The method for detecting anomalies in dynamic graphs based on hypergraph contrastive learning according to claim 1, characterized in that: In step 1, a hypergraph is constructed to represent the synergy between multiple nodes, and the hypergraph convolutional network HGCN is used for feature extraction to enhance the modeling ability of high-order interaction patterns; In dynamic graphs, the high-order interaction between nodes and hyperedges is a key feature of anomaly detection tasks. The improved HGCN formula is used to combine the hyperedge aggregation information with the node's own characteristics to improve the feature expression ability by introducing the node's self-update path. The improved HGCN formula is as follows: Where X represents the node feature matrix, where each row corresponds to the feature of a node; D v represents the degree matrix of the nodes in the hypergraph, represents the inverse of the square root of the diagonal elements, which is used to standardize the features; H represents the association matrix of the hypergraph, which defines the relationship between hyperedges and nodes; Ω is a dynamic adaptive weight matrix, which is used to adjust the weights of different hyperedges to enhance key interaction relationships; D e is the degree matrix of the hyperedge, represents the importance normalization of hyperedges; W is a learnable projection matrix used for feature transformation; σ(·) is the ReLU activation function to enhance feature expression capability; The node features at the current time t are updated using the above formula: Among them, X t represents the node feature matrix of the current time step t; H t represents the hypergraph incidence matrix at the current time step t; Ω t is the hyperedge weight matrix at time step t; the other parameters are the same as those in formula (1), but are dynamically updated at time step t; Ultimately, the high-order interactions of dynamic graphs are effectively modeled and provide high-quality initial feature representations for subsequent adaptive neighborhood learning and time series modeling.
3. The method for detecting anomalies in dynamic graphs based on hypergraph contrastive learning according to claim 1, characterized in that: In the dynamic graph of step 2, different hyperedges have different influences on the node status. The adaptive neighborhood learning method is used to calculate the importance weight of each hyperedge and dynamically update the weight matrix Ω. t ∈R E×E , thereby improving the effect of feature aggregation; For each hyperedge e in the hypergraph i ∈H t , first calculate its dynamic weight, which is defined as: in, represents the edge e at time t ij The weight of is a similarity function used to measure the similarity between nodes i and j in the feature space; softmax normalization is used to ensure that the sum of the weights of all edges is 1; The calculated weight Used to update the hyperedge weight matrix Ω t : Indicates whether the hyperedge weight is updated at time t; by dynamically updating the weight matrix Ω t ,The weight of the hyperedge can not only reflect the ,feature changes of local nodes, but also capture the important ,interactions between hyperedges in the dynamic graph.
4. The method for detecting anomalies in dynamic graphs based on hypergraph contrastive learning according to claim 1, characterized in that: In step 3, in order to capture the feature changes of nodes in the time dimension, the gated recurrent unit GRU is used to map the node feature X t Perform time series modeling; the update formula of GRU is as follows: Among them, r t and z t They are the reset gate and the update gate, which are used to control the forgetting and retention of information; is a candidate node state; ⊙ represents element-wise multiplication; The dynamic hypergraph convolution module effectively captures the high-order interaction relationship and temporal dynamic characteristics between nodes and hyperedges in the dynamic graph by combining hypergraph convolution, adaptive neighborhood learning and time series modeling; the initial updated time-aware node representation Provide feature information for the subsequent dynamic collaborative contrast learning module to improve the effect of dynamic graph anomaly detection.
5. The method for detecting anomalies in dynamic graphs based on hypergraph contrastive learning according to claim 1, characterized in that: In step 4, based on the dual-view information of the dynamic hypergraph and the standard graph, node representations are extracted through multiple rounds of alternating enhancement strategies; in each round, representations are updated in the standard graph and the hypergraph respectively, and the node feature representation is optimized by contrastive learning; Representing time-aware nodes And the standard graph adjacency matrix A is input into GCN to generate the node representation of the standard graph GCN represents the update formula as follows: Among them, W A is the learnable parameter of GCN, σ is the activation function; Features extracted from the standard graph by GCN; Representing time-aware nodes and the dynamic hypergraph incidence matrix H t Input HGCN to generate node representation of hypergraph The updated form is as follows: The update process of HGCN follows the formula in the dynamic hypergraph convolution module; Represents the features extracted by HGCN on the hypergraph; By representing the nodes of the standard graph and the hypergraph and Perform feature fusion to generate enhanced node representation Among them, Concat(·) represents the feature concatenation operation, which combines the features of the standard graph and the hypergraph; The fused representation Input GCN and HGCN respectively to further update the node representation of the standard graph and hypergraph; repeat the above process to generate multiple rounds of alternating enhanced node representations And finally merge to generate (2) Cross-view contrastive learning; The dynamic hypergraph collaborative comparison module optimizes the enhanced node representation using a cross-view comparison learning strategy. The core idea of cross-view comparison is to compare the feature representations of the same node in different views, thereby improving the feature expression capability. The objects compared across views are: The loss function used in contrastive learning is based on similarity calculation and is given by the following formula: in, represents the feature representation of the i-th node in the standard graph and hypergraph views; sim(·) represents the similarity calculation function; τ is the temperature parameter, which controls the smoothness of the similarity distribution; in addition, the softmax normalization term involves all possible node pairs Where j traverses all nodes; The final contrast loss of the module is the weighted sum of the contrast losses in each round: L con =λ1Loss1+λ2Loss2+λ3Loss3 (14) Among them, λ1, λ2, λ3 are weight coefficients used to adjust the contrast loss weights of different rounds; Loss1, Loss2, Loss3 represent the losses calculated during the 1st, 2nd, and 3rd rounds of training respectively; the goal of this loss is to balance the optimization effects of multiple stages and ensure that the information of each training stage is effectively integrated into the final model; The dynamic hypergraph collaborative comparison module achieves a deep fusion of high-order interactive features and temporal dynamic information through multiple rounds of alternating enhancement and cross-view contrast learning. It also generates a more discriminative time-aware node representation Z by utilizing the dual-view information of the dynamic hypergraph and the standard graph and combining it with time series modeling. t ; Through the deep fusion of cross-view information, it provides rich and robust feature input for subsequent abnormal edge detection.
6. The method for detecting anomalies in dynamic graphs based on hypergraph contrastive learning according to claim 1, characterized in that: Step 5: Time-aware node representation Z based on the output of dynamic collaborative contrastive learning module t , calculate the anomaly score of each edge in the dynamic graph; suppose the edge Connecting Nodes and The anomaly score is calculated by the Euclidean distance between the nodes at both ends of the edge. The formula is as follows: in, and Respectively represent nodes and is the time-aware representation of , |·| is the Euclidean distance; edge anomaly score The size of reflects the difference between the nodes at both ends of the edge. The higher the score, the higher the abnormality of the edge. The abnormal edge is identified by setting the threshold δ, that is: like The edge is an abnormal edge. The abnormality of the edge is calculated by the Euclidean distance between the nodes at both ends of the edge, and the model is optimized by designing the loss function; the loss function of the anomaly detection module is defined as: L recon represents the reconstruction loss, which is used to optimize the model to make the representation of normal edges more consistent; Represents the total number of edges in the current dynamic graph, ensuring that the loss is normalized and is not affected by the number of edges; the summation part traverses all normal edges e ij ∈E t , calculate the Euclidean distance between nodes of all edges, so that the characteristic distance of normal edges is as small as possible; The total loss function is composed of the contrast loss of the dynamic collaborative contrastive learning module and the reconstruction loss of the anomaly detection module, and is defined as follows: This formula represents the total loss function (Total Loss), which is used to comprehensively optimize the entire dynamic graph anomaly detection model; among them, the contrast loss Lcontrast is used to capture the high-order interaction characteristics and temporal dynamic characteristics between the standard graph and the hypergraph through the dynamic collaborative contrast learning module; the reconstruction loss L recon The feature representation of the reconstructed edge is used to directly evaluate the abnormality of the edge, thereby effectively capturing abnormal patterns in dynamic graphs; the weight coefficients λcontrast and λrecon respectively control the importance of contrast loss and reconstruction loss in the total loss.
Citation Information
Cited By
Network multi-step attack prediction method based on space-time fusion dynamic graph convolution
CN120263565A
Graph data anomaly detection method based on hypergraph contrast learning
CN120316602A
Intelligent data monitoring method and monitoring platform
CN120492213A
Video monitoring abnormal behavior real-time detection method based on graph neural network
CN121392703B
Intelligent treatment anomaly detection method and system based on dynamic space-time hypergraph evolution
CN121598268A