Intrusion detection method and system based on metric element learning, and storage medium

By adopting the metric meta-learning method in the intrusion detection system, combining autocorrelation representation and cross-correlation attention modules, embedding the ResNet12 network, optimizing the sample space mapping function parameters of the detection model, the existing intrusion detection system is solved, and the accuracy and efficiency of the existing intrusion detection system is low in the face of complex network threats, achieving higher malicious traffic detection accuracy and small sample detection capabilities.

CN120128386APending Publication Date: 2025-06-10GUANGXI TAYI INFORMATION TECH CO LTD +1

Patent Information

Application Number
CN202510315182.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-18
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

Existing intrusion detection systems have difficulty maintaining high accuracy and efficiency in the face of new network traffic protocols, attack variants and large amounts of network access, especially in terms of insufficient training data and model interpretability.

Method used

The intrusion detection method based on metric meta-learning is adopted, and the intrusion detection module is constructed through the autocorrelation representation module and the mutual correlation attention module, and embedded it in the backbone network ResNet12. Combined with the meta-learning framework, the sample space mapping function parameters of the detection model are optimized to improve the feature capture ability of malicious traffic.

Benefits of technology

It effectively improves the feature capture capability of malicious traffic, improves the detection accuracy in a small sample category, and overcomes the problem of poor generalization ability of traditional machine learning in small sample intrusion detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128386A_ABST
    Figure CN120128386A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of network security, and discloses an intrusion detection method and system based on metric element learning, and a storage medium. The intrusion detection method comprises the following steps: S1, acquiring flow data and preprocessing the flow data; s2, dividing a training set, a verification set and a test set, and generating a task composed of a support set and a query set; s3, constructing an intrusion detection module by adopting an autocorrelation representation module and a cross-correlation attention module, and embedding the intrusion detection module into the backbone network to form an intrusion detection model; s4, constructing a meta learning framework, using a training set to optimize sample space mapping function parameters of the detection model through a meta learning mode, searching an optimal meta learner under the detection model, and performing fine tuning to achieve an optimal state of new task detection; and S5, applying the intrusion detection model to actual intrusion detection. According to the method, the model generalization is high, a small number of sample categories can be trained, high accuracy can be kept in evaluation, and the classification effect of small sample intrusion detection is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security, and particularly relates to an intrusion detection method, system and storage medium based on metric element learning. Background Technique

[0002] With the continuous development of Internet technology, various industries are integrated with the Internet, and the accompanying Internet intrusion threats need to be constantly vigilant. As a barrier to network security, intrusion detection systems also face problems such as new network traffic protocols making the network security detection process more difficult, variants of existing attacks and small-sample attacks making it difficult for intrusion detection systems to prevent, and a large amount of network traffic posing higher requirements for the accuracy and efficiency of intrusion detection systems. Therefore, it is necessary to further improve intrusion detection systems to cope with the increasingly complex network security situation.

[0003] The Residual Neural Network (ResNet) is a deep learning model that solves the problem of gradient disappearance in the training of deep networks by introducing "residual connections". This structure allows information to be propagated more effectively in the network, enabling good performance even in very deep networks. ResNet forms a skip connection by directly adding the input to the output of the subsequent layer, thereby enhancing the learning ability and stability of the network. It has performed excellently in tasks such as image recognition and has become an important milestone in deep learning.

[0004] The application of ResNet in network intrusion detection systems (NIDS) has gradually attracted attention, mainly due to its powerful feature extraction ability and the advantages of deep learning. Researchers use ResNet to build models to identify different types of network attacks, such as DDoS, malware, and port scanning. By processing network traffic data, ResNet can automatically learn complex feature representations and improve detection accuracy.

[0005] Currently, many studies have attempted to combine ResNet with other technologies, such as generative adversarial networks (GANs) or transfer learning, to further improve detection performance and generalization ability. For example, CN118353689A discloses an intrusion detection method based on improved GAN+EA and ResNet. Aiming at the challenges of unknown threats in the network environment and the high false alarm rate of traditional intrusion detection methods, the traditional generative adversarial network is improved by introducing an encoder structure to enable the GAN to have the ability to learn meaningful feature representations. The Wasserstein distance and gradient penalty are used to constrain the discriminator, alleviating the problems of gradient disappearance and gradient explosion in training. This method proposes to use the EA evolutionary algorithm to use the samples generated by the generative adversarial network as the first-generation population for crossover and mutation evolution to generate new features, and proposes a new fitness calculation method to retain the offspring, expanding the diversity of data samples while alleviating data imbalance and better simulating unknown threats.

[0006] Another example is that CN117692210A discloses a network traffic intrusion detection method and system based on image enhancement, including: performing feature scaling and label encoding on numerical features and label features in traffic data respectively; assuming that the number of pixels generated above is s, filling and reconstructing the pixels generated in the above steps to generate a square grayscale image; using the nearest neighbor interpolation method to enlarge the generated grayscale image to enhance the quality of the generated grayscale image; training a neural network (Resnet) with the generated grayscale image to extract the features of the grayscale image, and then training a classifier to perform aggressive detection of network traffic and identify malicious intrusion traffic.

[0007] Despite the excellent performance of ResNet, it still faces challenges such as insufficient training data and model interpretability. Summary of the Invention

[0008] The purpose of the present invention is to overcome at least one deficiency of the prior art and provide an intrusion detection method, system and storage medium based on metric meta-learning.

[0009] The technical solution adopted by the present invention is:

[0010] In the first aspect of the present invention, there is provided:

[0011] An intrusion detection method based on metric meta-learning, including the following steps: S1. Obtain traffic data and perform preprocessing, where the preprocessing includes cutting the data, converting it into an image of a standard size, and adding label information to each piece of data according to the requested features; S2. Divide the preprocessed traffic data into a training set, a validation set, and a test set. Randomly select n categories of traffic data, and sample k labeled samples for each category to form a support set. The remaining unlabeled samples of each category form a query set, and generate a task composed of the support set and the query set. S3. Build an intrusion detection module using an autocorrelation representation module and a cross-correlation attention module, and embed the intrusion detection module into the backbone network ResNet12 to build an intrusion detection model. S4. Build a meta-learning framework. Use the meta-learning method to optimize the parameters of the sample space mapping function of the detection model with a sufficient amount of training data. Integrate the training results of the base learners on multiple tasks to update the meta-learner, and find the optimal meta-learner under this detection model. During the training process, the classification of the query set uses the category mapping of the support set with the closest cosine distance as the classification result. After training, the meta-learner undergoes training on a new task to achieve model fine-tuning and reach the best state for detecting new tasks. S5. Use the intrusion detection model for actual intrusion detection.

[0012] The label information is the traffic sample label, including benign samples and malicious samples.

[0013] Tasks can be divided into training tasks and test tasks. Training tasks are the training data in meta-learning, and test tasks are the test data in meta-learning. The support set and the query set in training tasks are both used for learning the model parameters, while the support set in test tasks is used for learning the model parameters and the query set is used for model evaluation. The generation process of the support set and the query set is to randomly select n categories of traffic data, and sample k labeled samples for each category to form a support set, and the remaining unlabeled samples of each category form a query set.

[0014] In some instances of intrusion detection methods, in step S1, obtaining traffic data includes: S11) Use a bypass monitoring model to obtain and save the complete data stream. The traffic data includes at least normal traffic and multiple types of malicious traffic. S12) After data acquisition, group and preprocess the data. The data grouping is specifically to group the captured traffic data according to the seven-tuple features of the data stream, namely the source IP address, destination IP address, protocol, source port number, destination port number, source MAC address, and destination MAC address. The data streams within the group are sorted according to the packet arrival time.

[0015] In some instances of intrusion detection methods, data preprocessing and adding labels specifically include: 1) Normalize the values of all traffic data to the range of [0 - 255]. 2) Remove invalid feature bytes. 3) Cut the data. Each data stream group retains the first M data packets and the first N bytes. For the part without data, zero padding is used, and the data format is adjusted to a two-dimensional matrix of [M, N]. 4) Save the two-dimensional matrix as an image with a width of M and a length of N, and add label information to each piece of data according to the requested features.

[0016] In some instances of intrusion detection methods, step S2 includes: dividing the data set into a training set, a validation set, and a test set. The three data categories do not intersect. Taking the task as the basic unit, the task contains a support set and a query set. The data categories within the support set of the task can be adjusted as needed but at least contain two categories, and the number of each category needs to be the same. The data categories within the query set contain at least one of the categories in the support set.

[0017] In some instances of intrusion detection methods, in step S3, the autocorrelation representation module is expressed as Calculate the Hadamard product of the C-dimensional vector at each position and its neighborhood to obtain the autocorrelation tensor , and the tensor R is expressed as having an output of a C-dimensional vector; After the calculation, add a convolutional block composed of a four-layer four-dimensional convolutional neural network, batch normalization, activation function ReLU, and a fully connected layer, and output a feature tensor with a spatial dimension of 1, that is The output is .

[0018] In some instances of intrusion detection methods, in step S3, the cross-correlation attention module uses the query and the support of the autocorrelation representation as an input pair, and uses a two-dimensional convolutional layer to convert the query sample and the support sample into a more compact representation and , reducing its channel dimension C to C′, obtaining and , and then constructing a four-dimensional correlation tensor , and the calculation formula is ; where x represents the spatial position on the feature map, and sin() represents calculating the cosine similarity between two features; After passing through a convolutional block composed of a two-layer four-dimensional convolutional network, batch normalization, and activation function ReLU, and then calculating through the formula , finally generating the corresponding attention map and ; where γ is the temperature factor, is the position and The matching score between

[0019] In some instances of intrusion detection methods, after the cross-correlation attention module calculates, and are multiplied element-wise to obtain the final embedding of the query sample Then pooling is performed. The processing of the support sample is the same as that of the query sample. Finally, the cosine similarity of the support sample embedding image is compared, and the maximum value is taken as the query category.

[0020] In some instances of intrusion detection methods, step S4 is specifically as follows:

[0021] The meta-learning framework adopts an inner-loop and outer-loop design. The inner loop inputs a task set composed of multiple training tasks and test tasks in the validation set for learning the meta-learner. The outer loop inputs the task set data of the training set for learning the base learner. The condition for entering the inner loop is set as needed. The inner loop and the outer loop jointly update the intrusion detection model and the loss gradient;

[0022] A metric-based loss function is adopted, specifically: , The optimizer adopts the SGD optimizer;

[0023] After reaching the specified accuracy or the number of loops, the test set is used to evaluate the final intrusion detection model.

[0024] The above technical features can be arbitrarily combined without conflict.

[0025] The second aspect of the present invention provides:

[0026] An intrusion detection system based on metric meta-learning. The system adopts the intrusion detection method based on metric meta-learning described in the first aspect of the present invention. The system includes a data acquisition module, a data set division module, an intrusion detection model construction module, and a meta-learning framework construction module; The data acquisition module is used to acquire traffic data and perform preprocessing; The data set division module is used to divide the training set, the validation set, and the test set; The intrusion detection model construction module is used to construct an intrusion detection module by adopting an autocorrelation representation module and a cross-correlation attention module, and embed the intrusion detection module into the backbone network ResNet12 to form an intrusion detection model; The meta-learning framework construction module is used to construct a meta-learning framework, optimize the parameter setting of the sample space mapping function through the training set, and use the category mapped by the support set with the closest cosine distance as the classification result for query set classification.

[0027] The third aspect of the present invention provides:

[0028] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the intrusion detection method based on metric meta-learning described in the first aspect of the present invention.

[0029] The beneficial effects of the present invention are as follows:

[0030] For the intrusion detection methods of some examples of the present invention, by using the autocorrelation representation module and the cross-correlation attention module to construct the intrusion detection module, it is possible to mine the enhanced relationship patterns in the underlying feature maps, pay attention to the spatial and temporal feature representations of malicious traffic, and be able to learn the joint attention relationships in the query and support samples, effectively improving the feature capture of malicious traffic.

[0031] For the intrusion detection methods of some examples of the present invention, a meta-learner that obtains prior knowledge guides the base learner, which can complete the fine-tuning of the detection model parameters in the case of only a small number of sample categories of malicious traffic for detection, and has a high accuracy in detecting a small number of sample categories of malicious traffic, overcoming the problems of poor model generalization ability and low accuracy in traditional machine learning for detecting few sample categories, and improving the classification effect of small sample intrusion detection. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] Figure 1 It is a flowchart of obtaining traffic data and preprocessing by the method of the present invention.

[0033] Figure 2 It is a flowchart of model construction by the method of the present invention.

[0034] Figure 3 It is a flowchart of the training process by the method of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0035] In this specification, terms such as "including", "comprising" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.

[0036] The present invention will be further described in detail below in conjunction with the embodiments and the accompanying drawings, but the embodiments of the present invention are not limited thereto.

[0037] Embodiment

[0038] An intrusion detection method based on metric meta-learning includes the following steps: S1. Obtain traffic data and perform preprocessing; In this embodiment, the traffic data is obtained specifically by using a bypass monitoring model to obtain and save the complete data stream. The traffic data includes at least normal traffic and various malicious traffics; After the data is obtained, the data is grouped, preprocessed, and labeled. The data grouping is specifically to group the captured traffic data according to the seven-tuple features of the data stream, that is, the source IP address, the destination IP address, the protocol, the source port number, the destination port number, the source MAC address, and the destination MAC address. The data streams within the group are sorted according to the packet arrival time.

[0039] As Figure 1 shown, the data preprocessing specifically includes: Normalize the values of all traffic data to the range of [0 - 255]; Eliminate invalid feature bytes, such as version numbers, IP addresses, and time to live; Cut the data. Each group of data streams retains the first M data packets and the first N bytes. The part without data is filled with zeros, and the data format is adjusted to a two-dimensional matrix of [M, N]; Save the two-dimensional matrix as an image with a width of M and a length of N, and add label information to each piece of data according to the requested features.

[0040] S2. Divide the training set, validation set, and test set, specifically as follows:

[0041] Divide the data set into a training set, a validation set, and a test set. The data categories of the three do not intersect. Taking the task as the basic unit, the support set and the query set are included within the task. The data categories within the support set of the task can be adjusted as needed but at least include two categories, and the number of each category needs to be the same. The data categories within the query set include at least one of the categories in the support set.

[0042] In this embodiment, taking 2-Way 1-shot as an example, that is, randomly select 2 types of samples, randomly select 1 instance of each type of sample as the support set, and 1 sample as the query set. The support set and the query set need to be included within the task. The data categories within the support set of the task are 2 types, and the number of each category is 1. The data categories within the query set are one of the categories in the support set and the number is 1. The data in the support set and the query set cannot appear repeatedly, and the data between tasks cannot appear repeatedly either. The training set, validation set, and test set are divided by category and in the ratio of 5:3:2.

[0043] S3. Construct an intrusion detection module using the autocorrelation representation module and the cross-correlation attention module, and embed the intrusion detection module into the backbone network ResNet12 to form an intrusion detection model.

[0044] In this embodiment, the model is constructed as Figure 2 shown. Taking two groups of samples of different categories as input examples, the samples are subjected to feature extraction through the backbone network ResNet12 to obtain and which are basically represented as and the autocorrelation representation calculation is performed. Through the dimensional vectors at each position and the Hadamard product of its neighborhood, the autocorrelation tensor is obtained; The tensor R can be represented as having a C-dimensional vector output; After the calculation is completed, four layers of four-dimensional convolutional neural network (the convolutional kernels are 1, 1, 1, 1, the convolutional parameter C of the first layer is the original number of channels, and the convolutional parameter C' of the remaining convolutional layers is the number of channels obtained from the previous convolutional layer) are added. After batch normalization, activation function ReLU, and fully connected layer dimensionality reduction, the output is , and finally the output of the autocorrelation representation is F = + Z.

[0045] In this embodiment, the cross-correlation attention module uses the query and the support of the autocorrelation representation as the input pair, and uses a two-dimensional convolutional neural network (the convolutional kernels are 1, 1, and the parameter C is the number of input channels) to convert the query sample and the support sample representations into a more compact representation and , reducing its channel dimension C to C', to obtain and , and then constructing a four-dimensional correlation tensor , and the calculation formula is ; where x represents the spatial position on the feature map, and sin( ) represents calculating the cosine similarity between two features; After passing through a convolutional block composed of two layers of four-dimensional convolutional networks (the convolutional kernels are 3, 3, 3, 3, the number of channels is 1, and the number of channels x of the second convolutional layer is set to the output of the first layer channels), batch normalization, and activation function ReLU, and then performing the attention formula calculation Finally, the corresponding attention maps and are generated; where γ is the temperature factor, is the position and the matching score between them.

[0046] After the cross-correlation attention calculation, is multiplied pointwise to obtain the final embedding of the query sample Pooling is then performed, and two different query views are obtained. The support samples are the same as above. Finally, the cosine similarity of the support sample embedded images is compared, and the maximum value is taken as the query category.

[0047] S4. Build a meta-learning framework. Optimize the parameter settings of the sample space mapping function through the training set. The classification of the query set uses the mapping category of the support set with the closest cosine distance as the classification result. Specifically:

[0048] The meta-learning framework adopts an inner and outer loop design. The inner loop inputs the task set in the validation set for the learning of the meta-learner. The outer loop inputs the task set data of the training set for the learning of the base learner. Set the conditions for entering the inner loop as needed. The inner loop and the outer loop jointly update the intrusion detection model and the loss gradient.

[0049] The metric-based loss function is calculated as: , The optimizer is the SGD optimizer; After reaching the specified accuracy or the number of loops, use the test set to evaluate the final intrusion detection model.

[0050] In this embodiment, the specific training process is as Figure 3 shown. Set the number of iterations Episode to 100. Use the SGD optimizer with a momentum of 0.9 and a learning rate of 0.1 during training, and set the learning rate decay to 0.05. Set BatchSize to 128. The meta-training stage is the outer loop, and the meta-validation is the inner loop. After each episode ends, it is judged whether to enter the meta-validation or enter the evaluation. The meta-validation stage will use the parameters learned in the meta-training stage to quickly learn and classify the untrained samples, and use the classification results as the basis for judging the overall model effect, jointly updating the intrusion detection model parameters and the gradient loss. In the flowchart, it is judged whether to enter the meta-test based on whether episode can be divisible by 5, and the total number of training rounds is 100 times. Finally, when the model iteration times exceed 100 times or reach the specified accuracy, use the test set to evaluate the model. The test set is the sample categories that have not participated in the training.

[0051] S5. Use the intrusion detection model for actual intrusion detection.

[0052] In another embodiment, an intrusion detection system based on metric meta-learning is provided. The system adopts the intrusion detection method based on metric meta-learning in the above embodiment. The system includes a data acquisition module, a data set division module, an intrusion detection model construction module, and a meta-learning framework construction module; The data acquisition module is used to acquire traffic data and perform preprocessing; A dataset division module for dividing the training set, validation set, and test set; An intrusion detection model construction module for constructing an intrusion detection module using an autocorrelation representation module and a cross-correlation attention module, and embedding the intrusion detection module into the backbone network ResNet12 to form an intrusion detection model; A meta-learning framework construction module for constructing a meta-learning framework, optimizing the parameter settings of the sample space mapping function through the training set, and classifying the query set with the support set mapping category closest in cosine distance as the classification result.

[0053] In another embodiment, a computer-readable storage medium is provided, storing a computer program, which when executed by a processor, implements the intrusion detection method based on metric meta-learning in the above embodiment.

[0054] The storage medium can be transient or non-transient. Exemplarily, the storage medium includes but is not limited to various media such as USB flash drives, mobile hard disks, read-only memories (ROM), random access memories (RAM), magnetic disks, or optical discs that can store computer program code.

[0055] Exemplarily, the processor can be a central processing unit (CPU), a microprocessor unit (MPU), a digital signal processor (DSP), or a field programmable gate array (FPGA), etc.

[0056] The above is a further detailed description of the present invention and should not be regarded as a limitation on the specific implementation of the present invention. For those of ordinary skill in the technical field to which the present invention pertains, simple deductions or substitutions without departing from the concept of the present invention are within the protection scope of the present invention.

Claims

1. An intrusion detection method based on metric meta-learning, characterized in that: The following steps are involved: S1. Obtain traffic data and perform preprocessing, wherein the preprocessing includes cutting the data, converting the data into a standard size image, and adding label information to each piece of data according to the request characteristics; S2. Divide the preprocessed traffic data into a training set, a validation set, and a test set. Randomly extract n categories of traffic data, sample k labeled samples from each category to form a support set, and the remaining unlabeled samples of each category to form a query set, and generate a task consisting of a support set and a query set. S3, using the autocorrelation representation module and the mutual attention module to build an intrusion detection module, and embedding the intrusion detection module into the backbone network ResNet12 to build an intrusion detection model; S4. Build a meta-learning framework, use enough training sets to optimize the sample space mapping function parameters of the detection model through meta-learning, integrate the training results of the basic learners on multiple tasks to update the meta-learner, and find the optimal meta-learner under the detection model; During the training process, the query set is classified using the support set category mapping with the closest cosine distance as the classification result. After the training, the meta-learner is trained on the new task to achieve model fine-tuning and reach the optimal state for the new task detection. S5. Use the intrusion detection model for actual intrusion detection.

2. The intrusion detection method according to claim 1, characterized in that: In step S1, obtaining traffic data includes: S11) using a bypass monitoring model to obtain and save the complete data flow, where the traffic data at least includes normal traffic and multiple malicious traffic; S12) After data acquisition, the data is grouped and preprocessed. Specifically, the captured traffic data needs to be grouped according to the seven-tuple characteristics of the data flow, namely, source IP address, destination IP address, protocol, source port number, destination port number, source MAC address and destination MAC address. The data flow in the group is sorted according to the packet arrival time.

3. The intrusion detection method according to claim 2, characterized in that: Data preprocessing and labeling specifically include: 1) Standardize the values ​​of all traffic data to between [0-255]; 2) Eliminate invalid feature bytes; 3) Split the data, keep the first M data packets and the first N bytes of each data stream, fill the part without data with zero, and adjust the data format to a two-dimensional matrix of [M, N]; 4) The two-dimensional matrix is ​​converted into an image with a width of M and a length of N, and label information is added to each piece of data according to the requested features.

4. The intrusion detection method according to claim 1, characterized in that: Step S2 includes: dividing the data set into a training set, a validation set and a test set, the three data categories are non-overlapping, and the task is used as the basic unit. The task contains a support set and a query set. The data categories in the support set within the task are adjusted as needed but contain at least two categories, and the number of each category needs to be consistent. The data categories in the query set contain at least one category in the support set.

5. The intrusion detection method according to claim 1, characterized in that: In step S3, the autocorrelation representation module is represented as calculate The vector at each position The Hadamard product of its neighborhood gives the autocorrelation tensor , the tensor R is represented as having a C-dimensional vector output; After the calculation is completed, a convolution block consisting of a four-layer four-dimensional convolutional neural network, batch normalization, activation function ReLU, and a fully connected layer is added to output a feature tensor with a spatial dimension of 1, that is, The output is .

6. The intrusion detection method according to claim 1 or 5, characterized in that: In step S3, the mutual attention module uses query Support for autocorrelation representation As input pairs, a 2D convolutional layer is used to transform query samples and support samples into a more compact representation and , reducing its channel dimension C to C′, we get and , and then construct a four-dimensional correlation tensor , the calculation formula is ; Among them, x represents the spatial position on the feature map, and sin() represents the calculation of the cosine similarity between two features; After passing through a convolution block consisting of two layers of four-dimensional convolutional networks, batch normalization and activation function ReLU, it is calculated by the formula , and finally generate the corresponding attention map and ; Where γ is the temperature factor, It's location and The matching score between .

7. The intrusion detection method according to claim 6, characterized in that: After the mutual attention module calculates, and Perform point multiplication to get the final embedding of the query sample After pooling, the processing of support samples is the same as that of query samples. Finally, the cosine similarity of the embedded images of support samples is compared, and the maximum value is taken as the query category.

8. The intrusion detection method according to claim 1, characterized in that: Step S4 is specifically as follows: The meta-learning framework adopts an inner and outer loop design. The inner loop inputs the task set consisting of multiple training tasks and test tasks in the validation set to learn the meta-learner, and the outer loop inputs the task set data of the training set to learn the basic learner. The conditions for entering the inner loop are set as needed. The inner and outer loops jointly update the intrusion detection model and loss gradient. A metric-based loss function is used, specifically: , The optimizer uses SGD optimizer; After reaching the specified accuracy or number of cycles, the final intrusion detection model is evaluated using the test set.

9. An intrusion detection system based on metric meta-learning, characterized in that: The system adopts the intrusion detection method based on metric meta-learning according to any one of claims 1 to 8, and the system includes a data acquisition module, a data set partitioning module, an intrusion detection model construction module and a meta-learning framework construction module; Data acquisition module, used to acquire traffic data and perform preprocessing; The data set partitioning module is used to partition the training set, validation set, and test set; An intrusion detection model construction module is used to construct an intrusion detection module using an autocorrelation representation module and a mutual attention module, and embed the intrusion detection module into a backbone network ResNet12 to form an intrusion detection model; The meta-learning framework building module is used to build a meta-learning framework, optimize the sample space mapping function parameter settings through the training set, and classify the query set using the support set mapping category with the closest cosine distance as the classification result.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the intrusion detection method based on metric meta-learning described in any one of claims 1 to 8 is implemented.

Citation Information

Patent Citations

  • Network traffic intrusion detection method and system based on image enhancement

    CN117692210A

  • Intrusion detection method based on improved GAN + EA and ResNet

    CN118353689A

Cited By

  • Method and device for detecting unknown attack of Internet of Things and medium

    CN120415924A