Node anomaly detection method and device, equipment, medium and program product

By using static and enhanced node graphs for node structure and attribute abnormality detection in import and export scenarios, the problem of low accuracy of traditional identification methods is solved, and the accurate identification and reminder of abnormal behaviors during the import and export of dangerous goods is achieved, which reduces security risks.

CN120145245AActive Publication Date: 2025-06-13SHENZHEN ACAD OF INSPECTION & QUARANTINE +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510199387.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-21
Publication Date
2025-06-13
Estimated Expiration
2045-02-21

Smart Images

  • Figure CN120145245A_ABST
    Figure CN120145245A_ABST
Patent Text Reader

Abstract

The invention provides a node anomaly detection method and device, equipment, a medium and a program product, and the method comprises the steps: obtaining a static node graph and an enhanced node graph of a target interaction scene, the enhanced node graph being a node graph obtained by employing a graph diffusion algorithm and a proximity algorithm to carry out graph diffusion enhancement on a node structure relation of the static node graph; determining a structural abnormal value of the target node for the target node according to the static node graph and the enhanced node graph; and performing abnormal node identification on the target node according to the structure abnormal value of the target node, and when the target node is identified as an abnormal node, performing abnormality reminding on an interaction behavior object or a preset article corresponding to the target node. According to the embodiment, the structural abnormal condition of the target node and other nodes can be predicted, the accuracy of identifying the abnormal node in the target interaction scene is improved, the abnormal behavior of the target interaction scene can be accurately identified and prompted in time, and the safety risk of the target interaction scene such as an import and export scene is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of artificial intelligence technology, and in particular, to a method, device, equipment, medium and program product for detecting node anomalies. Background Art

[0002] With the increasing types of dangerous goods such as hazardous chemicals and the growing number of global import and export ports, the interaction relationships between dangerous goods and various trading parties and ports have become more complex and diverse. Normal import and export activities usually follow certain rules and are carried out at certain specific ports. If there are some behavioral changes that deviate from the rules during the import and export process of dangerous goods, there may be potential abnormal behaviors, posing certain safety hazards to the supervision system and the social environment. Therefore, it is crucial to identify abnormal behaviors during the import and export process of dangerous goods.

[0003] Traditional methods for identifying abnormal import and export behaviors usually identify abnormal behaviors based on relevant supervision rules or simple statistical analysis of behavioral patterns. The traditional methods for identifying abnormal import and export behaviors are relatively simple and cannot cope with the increasingly complex import and export interaction relationships. The accuracy of abnormal behavior identification is relatively low, making it difficult to accurately identify abnormal behaviors during the import and export process of dangerous goods, resulting in safety risks for the import and export of dangerous goods. Summary of the Invention

[0004] The present invention provides a method, device, equipment, medium and program product for detecting node anomalies to solve the problem that the traditional method for identifying abnormal import and export behaviors has relatively low identification accuracy and is difficult to accurately identify abnormal behaviors during the import and export process of dangerous goods, resulting in safety risks for the import and export of dangerous goods.

[0005] In a first aspect, an embodiment of the present application provides a method for detecting node anomalies, including:

[0006] Obtain a static node graph and an enhanced node graph of a target interaction scenario. The static node graph is used to simulate the interaction relationship between interaction behavior objects and preset items participating in the interaction under the target interaction scenario. The enhanced node graph is a node graph obtained by enhancing the node structure relationship of the static node graph using a graph diffusion algorithm and a proximity algorithm;

[0007] Perform node structure anomaly detection on at least one target node according to the static node graph and the enhanced node graph to determine the structure anomaly value of the target node. The target node is a node in the preset static node graph;

[0008] Identify abnormal nodes for the target node according to the structure anomaly value of the target node;

[0009] When it is identified that the target node is an abnormal node, give an abnormal reminder for the interaction behavior object or preset item corresponding to the target node.

[0010] Optionally, for anomaly node identification of the target nodes, it includes:

[0011] Based on the static node graph, the enhanced node graph, and the attribute data of each target node, perform attribute anomaly detection on the target nodes to determine the node attribute anomaly values of the target nodes;

[0012] Based on the structural anomaly values and node attribute anomaly values of the target nodes, determine the anomaly scores of the target nodes;

[0013] When the anomaly scores of the target nodes are not within the preset threshold range, determine the target nodes as anomaly nodes.

[0014] Optionally, the structural anomaly values include overall structural anomaly values and sub-graph structural anomaly values. Based on the structural anomaly values and node attribute anomaly values of each target node, determine the anomaly scores of each target node, including:

[0015] Respectively determine the weight coefficients of the node attribute anomaly values, overall structural anomaly values, and sub-graph structural anomaly values;

[0016] Based on the corresponding weight coefficients, perform weighted summation on the node attribute anomaly values, overall structural anomaly values, and sub-graph structural anomaly values of the target nodes to obtain the anomaly scores of the target nodes.

[0017] Optionally, based on the static node graph, the enhanced node graph, and the attribute data of each target node, perform attribute anomaly detection on the target nodes to determine the node attribute anomaly values of the target nodes, including:

[0018] Obtain the first target sub-graph and the second target sub-graph of the target node. The first target sub-graph is the first sampled sub-graph containing the target node obtained after sampling a sub-graph of the static node graph with a preset size, and the second target sub-graph is the second sampled sub-graph containing the target node obtained after sampling a sub-graph of the enhanced node graph with a preset size;

[0019] Based on the attribute data of the target node, the first target sub-graph, and the second target sub-graph, determine the attribute generation error between the target node and the sub-graph to obtain the node attribute anomaly value of the target node.

[0020] Optionally, based on the static node graph and the enhanced node graph, perform node structure anomaly detection on at least one target node to determine the structural anomaly values of the target nodes, including:

[0021] Perform sub-graph sampling on the static node graph with a preset size to obtain multiple first sampled sub-graphs. Based on the multiple first sampled sub-graphs, use the contrastive learning algorithm to perform anomaly detection on the structural relationship of the target node in the static node graph to obtain the first overall anomaly value of the target node;

[0022] Perform subgraph sampling of a preset size on the enhanced node graph to obtain multiple second sampled subgraphs. Based on the multiple second sampled subgraphs, use a contrastive learning algorithm to perform anomaly detection on the structural relationship of the target node in the enhanced node graph, and obtain the second overall anomaly value of the target node;

[0023] Determine the structural anomaly value of the target node according to the first overall anomaly value and the second overall anomaly value.

[0024] Optionally, the structural anomaly value includes an overall structural anomaly value and a subgraph structural anomaly value. Determining the structural anomaly value of the target node according to the first overall anomaly value and the second overall anomaly value includes:

[0025] Take the mean of the first overall anomaly value and the second overall anomaly value as the overall structural anomaly value of the target node;

[0026] Detect the anomaly situation of the target node in the subgraph structure according to the first target subgraph and the second target subgraph, and obtain the subgraph structural anomaly value of the target node. The first target subgraph is the first sampled subgraph containing the target node, and the second target subgraph is the second sampled subgraph containing the target node.

[0027] In a second aspect, an embodiment of the present application provides a node anomaly detection device, including:

[0028] An acquisition module, configured to acquire a static node graph and an enhanced node graph of a target interaction scenario. The static node graph is used to simulate the interaction relationship between interaction behavior objects and preset items participating in the interaction under the target interaction scenario. The enhanced node graph is a node graph obtained by performing graph diffusion enhancement on the node structure relationship of the static node graph using a graph diffusion algorithm and a proximity algorithm;

[0029] A detection module, configured to perform node structure anomaly detection on at least one target node according to the static node graph and the enhanced node graph, and determine the structural anomaly value of the target node. The target node is a node in the preset static node graph;

[0030] An identification module, configured to perform anomaly node identification on the target node according to the structural anomaly value of the target node;

[0031] A reminder module, configured to perform an anomaly reminder on the interaction behavior object or preset item corresponding to the target node when it is identified that the target node is an anomaly node.

[0032] In a third aspect, an embodiment of the present application provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the above node anomaly detection method are implemented.

[0033] Fourthly, an embodiment of the present application provides a readable storage medium storing a computer program, and when the computer program is executed by a processor, the steps of the above node anomaly detection method are implemented.

[0034] Fifthly, an embodiment of the present application provides a computer program product, which includes a computer program that, when executed by a processor, enables the implementation of the steps of the above node anomaly detection method.

[0035] In a solution provided by the above node anomaly detection method, device, equipment, medium, and program product, by obtaining a static node graph and an enhanced node graph of a target interaction scenario, the static node graph is used to simulate the interaction relationship between interaction behavior objects and preset items participating in the interaction in the target interaction scenario, and the enhanced node graph is a node graph obtained by performing graph diffusion enhancement on the node structure relationship of the static node graph using a graph diffusion algorithm and a proximity algorithm; performing node structure anomaly detection on at least one target node according to the static node graph and the enhanced node graph to determine the structure anomaly value of the target node, where the target node is a node in the pre-specified static node graph; identifying an abnormal node for the target node according to the structure anomaly value of the target node, and when it is identified that the target node is an abnormal node, giving an anomaly reminder for the interaction behavior object or preset item corresponding to the target node. In this embodiment, the interaction relationship between interaction behavior objects and preset items participating in the interaction in the target interaction scenario is simulated through the static node graph, and the potential relationship between the preset items and the interaction behavior objects is mined through the enhanced node graph. Furthermore, according to the static node graph and the enhanced node graph, the structure anomaly situation of the target node and other nodes can be predicted, improving the accuracy of abnormal node identification in the target interaction scenario, accurately identifying abnormal behaviors in the target interaction scenario and giving timely reminders, and reducing the security risks of target interaction scenarios such as import and export scenarios. Description of the Drawings

[0036] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for describing the embodiments of the present invention will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can also obtain other drawings without creative efforts based on these drawings.

[0037] Figure 1 is a structural schematic diagram of a node anomaly detection system in an embodiment of the present invention;

[0038] Figure 2 is a flowchart of a node anomaly detection method in an embodiment of the present invention;

[0039] Figure 3 is a structural schematic diagram of a static node graph and an enhanced node graph;

[0040] Figure 4 is Figure 2 a schematic flowchart of an implementation of step S20 in

[0041] Figure 5 is Figure 4 a schematic flowchart of an implementation of step S23 in

[0042] Figure 6 is Figure 2 a schematic flowchart of an implementation of step S30 in

[0043] Figure 7 is Figure 6 a schematic flowchart of an implementation of step S31 in

[0044] Figure 8 a schematic structural diagram of a node anomaly detection device in an embodiment of the present invention;

[0045] Figure 9 a schematic structural diagram of a computer device in an embodiment of the present invention. Detailed implementation manners

[0046] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without making creative efforts shall fall within the protection scope of the present invention.

[0047] It should be understood that when used in the specification and the appended claims of the present invention, the term "comprising" indicates the presence of the described features, wholes, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or their combinations. It should also be understood that the term " / and" as used in the specification and the appended claims of the present invention refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.

[0048] In addition, in the description of the specification and the appended claims of the present invention, the terms "first", "second", "third", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.

[0049] References to "one embodiment" or "some embodiments" etc. described in the specification of the present invention mean that a particular feature, structure, or characteristic described in connection with that embodiment is included in one or more embodiments of the present invention. Thus, statements such as "in one embodiment", "in some embodiments", "in other some embodiments", "in still other embodiments", etc. that appear in different places in this specification do not necessarily all refer to the same embodiment, but rather mean "one or more but not all embodiments", unless otherwise specifically emphasized. The terms "comprising", "including", "having" and their variants all mean "including but not limited to", unless otherwise specifically emphasized.

[0050] It should be understood that the magnitudes of the sequence numbers of the steps in the following embodiments do not imply the order of execution, and the order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.

[0051] In order to illustrate the technical solution of the present invention, specific embodiments are used for illustration below.

[0052] The node anomaly detection method provided by the embodiments of the present invention can be applied in a Figure 1 node anomaly detection system as shown. The node anomaly detection system includes a client and a node anomaly detection device, wherein the client communicates with the node anomaly detection device through a network.

[0053] When anomaly detection is required for a target interaction scenario, the user sends an anomaly detection instruction to the node anomaly detection device through the client. The anomaly detection instruction is used to instruct the node anomaly detection device to detect anomalies in one or more participating nodes in the target interaction scenario. After receiving the anomaly detection instruction, the node anomaly detection device obtains the static node graph and the enhanced node graph of the target interaction scenario. Among them, the static node graph is used to simulate the interaction relationships between interaction behavior objects and preset items participating in the interaction in the target interaction scenario. The nodes of the static node graph represent preset items and interaction behavior objects, and the connection edges of the nodes represent the interaction relationships between the interaction behavior objects and the preset items. The enhanced node graph is a node graph obtained by graph diffusion enhancement of the node structure relationship of the static node graph using the graph diffusion algorithm and the proximity algorithm. That is, the nodes in the enhanced node graph are the same as the nodes in the static node graph, but the connection relationships between the nodes are not exactly the same. Then, the node anomaly detection device performs node structure anomaly detection on at least one target node according to the static node graph and the enhanced node graph to determine the structure anomaly value of the target node. The target node is a node in the preset static node graph specified in advance; the target node is identified as an abnormal node according to the structure anomaly value of the target node, and when the target node is identified as an abnormal node, an anomaly reminder is sent to the interaction behavior object or preset item corresponding to the target node, so that the user can timely learn about the anomalies in the target interaction scenario and take corresponding measures to reduce the safety risks related to the target interaction scenario.

[0054] In this embodiment, the interaction relationships between interaction behavior objects and preset items participating in the interaction in the target interaction scenario are simulated through the static node graph, and the potential relationships between the preset items and the interaction behavior objects are mined through the enhanced node graph. Furthermore, according to the static node graph and the enhanced node graph, the structural anomaly situations of the target node and other nodes can be predicted, improving the accuracy of abnormal node identification in the target interaction scenario, accurately identifying abnormal behaviors in the target interaction scenario and timely reminding, and reducing the safety risks of target interaction scenarios such as import and export scenarios.

[0055] Among them, the client, also known as the user end, refers to a program that provides local services for customers. The client can be installed on, but not limited to, various personal computers, laptop computers, smartphones, tablet computers, and portable wearable devices. The dangerous goods risk monitoring device can be a server, and the server can be implemented by an independent server or a server cluster composed of multiple servers.

[0056] In one embodiment, as Figure 2 shown, a node anomaly detection method is provided. Taking the example that this method is applied to the Figure 1 federated learning system as an example, the method includes the following steps:

[0057] S10: Obtain the static node graph and the enhanced node graph of the target interaction scenario.

[0058] When abnormal detection needs to be performed on the participating nodes (i.e., preset items and interactive behavior objects) in a target interaction scenario (such as a chemical import and export scenario), the user sends an abnormal detection instruction to the node abnormal detection device through the client. This abnormal detection instruction is used to instruct the node abnormal detection device to perform abnormal situation detection on one or more participating nodes in the target interaction scenario.

[0059] After receiving the abnormal detection instruction, the node abnormal detection device obtains the static node graph of the target interaction scenario. Among them, the static node graph is used to simulate the interaction relationship between the interactive behavior objects and the preset items participating in the interaction in the target interaction scenario.

[0060] The interaction data of the target interaction scenario includes the interaction data between different interactive behavior objects and the preset items participating in the interaction in the target interaction scenario. This interaction data not only includes the interaction behaviors of the preset items and different interactive behavior objects, but also includes attribute data related to the interaction behaviors, such as the basic data of the preset items, the basic data of the interactive behavior objects, and the relevant data required by the interaction behavior itself.

[0061] Taking the import and export items (such as dangerous chemicals) in the import and export scenario as an example of the preset items, different interactive behavior objects include the trading parties of the import and export items (such as the buyer and the seller), ports (such as the import port and the export port), and the item storage and transportation participants in the process of transporting the dangerous import and export items to the import and export ports. The attribute data related to the interaction behavior in the interaction data of the import and export items in the import and export scenario, such as the basic information of the import and export items (such as the item category, name, and declaration element information, etc.), port type, transaction amount, transportation tool, etc. information. In this embodiment, the preset item is an import and export item, and the target interaction scenario is an import and export scenario only for exemplary illustration. In other embodiments, the preset item can also be other trading items, such as sold goods, and the target interaction scenario can also be other scenarios based on other preset items, such as an online trading scenario.

[0062] Among them, the static node graph can be generated by the node abnormal detection device according to the interaction data of the target interaction scenario. The process of constructing the static node graph is as follows: The node abnormal detection device pre-collects or receives the interaction data between the interactive behavior objects and the preset items participating in the interaction in the target interaction scenario sent by the client, and then constructs a static attribute graph according to the interaction data between the interactive behavior objects and the preset items participating in the interaction in the target interaction scenario to obtain the static node graph. When constructing the static node graph, the preset items and interactive behavior objects are used as the nodes of the static node graph, and the interaction relationship between the interactive behavior objects and the preset items is used as the connection edge of the nodes; among them, each node contains the attribute data of each node.

[0063] Among them, the static node graph It can be expressed as (X, A), where A represents the adjacency matrix of the static node graph, and the adjacency matrix is ​​used to represent the connection relationship between the n nodes in the static node graph; X represents the attribute matrix of all nodes v in the static node graph. The attribute matrix is ​​generated according to the attribute data of each node.

[0064] In other embodiments, the user may send the static node graph together with the anomaly detection instruction to the node anomaly detection device through the client.

[0065] In addition, the node anomaly detection device needs to obtain an enhanced node graph of the static node graph, where the enhanced node graph is a node graph obtained by performing graph diffusion enhancement on the node structure relationship of the static node graph using a graph diffusion algorithm and a proximity algorithm.

[0066] Among them, the enhanced node graph can also be a node graph obtained by the node anomaly detection device using a graph diffusion algorithm and a neighboring algorithm to perform graph diffusion enhancement on the node structure relationship of the static node graph. The acquisition process of the enhanced node graph is as follows: the node anomaly detection device uses a graph diffusion algorithm (such as a random walk algorithm) to perform graph diffusion on the node relationship of the static node graph to obtain a diffusion matrix of the random diffusion graph, and according to the node similarity in the static node graph, the K nearest neighbor algorithm is used to reconstruct the node relationship (i.e., the node connection relationship) in the static node graph to obtain a reconstructed feature graph, and then according to the adjacency matrix of the reconstructed feature graph, the diffusion matrix of the random diffusion graph is filtered on the possible noise edges, and the shared edges between the reconstructed feature graph and the random diffusion graph are retained (i.e., the edges that still exist in the reconstructed feature graph and the random diffusion graph), and the unshared edges between the reconstructed feature graph and the random diffusion graph are eliminated to obtain an enhanced node graph. This method can filter the noise edges between nodes according to the structural information shared by the random diffusion graph and the reconstructed feature graph, improve the accuracy of the enhanced node graph, and accurately mine the association information of different interactive behavior objects in the target interactive scene.

[0067] For example, Figure 3 As shown in the figure, the static node graph includes 1-9 nodes; among them, node 1 and nodes 2, 3, 4, and 5 are all connected by edges, node 4 is connected by edges with node 6, node 2 is connected by edges with nodes 7 and 9, and node 7 is connected by edges with node 8. The enhanced node graph is obtained by performing graph diffusion enhancement on the node structure relationship of the static node graph using the graph diffusion algorithm and the neighboring algorithm. Figure 3 It can be seen that the connection edge between node 1 and node 6 is increased, the connection edge between node 3 and node 7, the connection edge between node 3 and 8, and the connection edge between node 7 and node 9 are increased. The enhanced node graph can obviously mine the association information between other nodes, improving the diversity and accuracy of the graph structure information expression.

[0068] In other embodiments, the user can send the static node graph, the enhanced node graph, and the anomaly detection instruction to the node anomaly detection device through the client.

[0069] S20: Perform node structure anomaly detection on at least one target node according to the static node graph and the enhanced node graph, and determine the structure anomaly value of the target node.

[0070] After obtaining the static node graph and the enhanced node graph, the node anomaly detection device performs node structure anomaly detection on at least one target node according to the static node graph and the enhanced node graph, and determines the structure anomaly value of the target node. Among them, the target node is a node in the pre-specified static node graph, and the target node is specified according to user requirements. The target node can be any one or all nodes of the static node graph.

[0071] S30: Identify the abnormal node for the target node according to the structure anomaly value of the target node.

[0072] After obtaining the structure anomaly value of the target node, the node anomaly detection device identifies the abnormal node for the target node according to the structure anomaly value of the target node. The node anomaly detection device can obtain the pre-calibrated information related to each node or the preset threshold range of normal behavior. The preset threshold range can be obtained by analyzing the historical interaction data of each node in the target interaction scenario; the node anomaly detection device directly compares the structure anomaly value of the target node with the preset threshold range. When the structure anomaly value of the target node is within the preset threshold range, it means that the information or behavior of the node changes little or not at all in the target interaction scenario, and then it is determined that the target node is a normal node; when the structure anomaly value of the target node exceeds the preset threshold range, it means that the information or behavior of the node changes greatly in the target interaction scenario, and then it is determined that the target node is an abnormal node.

[0073] S40: When it is identified that the target node is an abnormal node, an anomaly reminder is given to the interaction behavior object or preset item corresponding to the target node.

[0074] When it is identified that the target node is an abnormal node, it means that the information or behavior of the node changes greatly in the target interaction scenario and there is a security risk. The node anomaly detection device gives an anomaly reminder to the interaction behavior object or preset item corresponding to the target node, so that the user can timely learn the interaction behavior object or preset item where the anomaly occurs, and then take corresponding measures to reduce the security risk.

[0075] In this embodiment, the interaction relationship between the interaction behavior objects and the preset items participating in the interaction in the target interaction scenario is simulated through a static node graph, and the potential relationship between the preset items and the interaction behavior objects is mined through an enhanced node graph. Furthermore, based on the static node graph and the enhanced node graph, the structural anomaly situation of the target node and other nodes can be predicted, improving the accuracy of abnormal node recognition in the target interaction scenario, accurately identifying abnormal behaviors in the target interaction scenario and giving timely reminders, and reducing the security risks of target interaction scenarios such as import and export scenarios.

[0076] In one embodiment, as Figure 4 shown, in step S20, that is, node structure anomaly detection is performed on at least one target node according to the static node graph and the enhanced node graph to determine the structural anomaly value of the target node, which specifically includes the following steps:

[0077] S21: Perform subgraph sampling of a preset size on the static node graph to obtain multiple first sampled subgraphs. Based on the multiple first sampled subgraphs, use the contrastive learning algorithm to perform anomaly detection on the structural relationship of the target node in the static node graph to obtain the first overall anomaly value of the target node.

[0078] Among them, the node anomaly detection device uses the Random Walk with Restart (RWR) algorithm to perform subgraph sampling of a preset size on the static node graph to obtain multiple first sampled subgraphs of the same image size. Among them, the multiple first sampled subgraphs include a first target subgraph and a first auxiliary subgraph. The first target subgraph is the first sampled subgraph containing the target node, and the first auxiliary subgraph is the first sampled subgraph not containing the target node. Then, the node anomaly detection device takes the target node and the first target subgraph as a positive sample pair, and takes the target node and the first auxiliary subgraph as a negative sample pair, and uses a graph neural network to calculate the node-subgraph relationship for the positive sample pair and the negative sample pair respectively to obtain the first overall anomaly value of the target node;

[0079] It should be understood that the anomaly degree of the target node v i is related to the similarity of the vector embeddings of the target node and the subgraph. Node-subgraph contrast can be used to judge the similarity degree between the two, so as to judge the anomaly degree of the structure of the target node in the graph. Specifically, the calculation process of the first overall anomaly value of the target node includes the following steps:

[0080] S211: Use a graph convolutional network to perform low-dimensional embedding encoding on the first target subgraph and the first auxiliary subgraph respectively to obtain the vector embedding of the first target subgraph and the vector embedding of the first auxiliary subgraph, and use a multi-layer perceptron to perform vector encoding on the target node to obtain the vector embedding of the target node.

[0081] The process of the node anomaly detection device using the Graph Convolutional Network (GCN) to perform low-dimensional embedding encoding on the first target subgraph (the first auxiliary subgraph) is as follows: First, use the GCN to encode the nodes in the first target subgraph (the first auxiliary subgraph) separately to obtain the vector embeddings of the nodes in the first target subgraph (the first auxiliary subgraph); use the average readout function to average the vector embeddings of all nodes in the first target subgraph (the first auxiliary subgraph) to obtain the vector embedding of the first target subgraph (the first auxiliary subgraph). In one embodiment, to ensure the accuracy of the structural relationship calculation and exclude the influence of other information, before performing low-dimensional embedding encoding on the first target subgraph and the first auxiliary subgraph, it is necessary to mask the attribute data of the target nodes (mask the attribute data with zero vectors) in the first target subgraph and the first auxiliary subgraph respectively, and then perform low-dimensional embedding encoding on the first target subgraph and the first auxiliary subgraph after masking the attribute information of the target nodes to obtain more accurate subgraph vector embeddings.

[0082] Among them, the vector embedding of the nodes in the first target subgraph (the first auxiliary subgraph) is expressed by the following formula:

[0083]

[0084] Among them, H i represents the vector embedding of node i in the first target subgraph (or the first auxiliary subgraph); represents the vector embedding representation of node i in the l-th layer of the graph convolutional network in the first target subgraph (or the first auxiliary subgraph); is the normalized data of the adjacency matrix A of node i in the first target subgraph (or the first auxiliary subgraph), D is the degree matrix of the adjacency matrix A; W (l) is the network parameter of the graph convolutional network, and ReLU(·) is the activation function.

[0085] Among them, the vector embedding of the first target subgraph (the first auxiliary subgraph) is represented by the following formula:

[0086]

[0087] Among them, e i represents the vector embedding of the first target subgraph (the first auxiliary subgraph); Readout(·) represents the average readout function; H i represents the vector embedding of node i in the first target subgraph (or the first auxiliary subgraph); n i represents the number of nodes in the first target subgraph (or the first auxiliary subgraph); the value of j ranges from 1 to n i , j = 1, 2, 3...n i .

[0088] Among them, a Multilayer Perceptron (MLP) is used to perform vector encoding on the target node to obtain the vector embedding of the target node. The vector embedding of the target node is represented by the following formula:

[0089]

[0090] where z i represents the vector embedding of the target node; represents the vector embedding of the l-th layer after inputting the target node into the Multilayer Perceptron; W (l) is the network parameter of the Multilayer Perceptron shared with the GCN.

[0091] S212: According to the node anomaly detection device, the vector embedding of the target node and the vector embedding of the first target subgraph are used as positive sample pairs, and the vector embedding of the target node and the vector embedding of the first auxiliary subgraph are used as negative sample pairs. The contrastive learning algorithm is used to calculate the node-subgraph relationship for the positive sample pairs and the negative sample pairs respectively, and the first overall anomaly value of the target node is obtained.

[0092] Among them, the contrastive learning algorithm is used to calculate the node-subgraph relationship for the positive sample pairs to obtain the structural anomaly value of the positive sample pairs, and the contrastive learning algorithm is used to calculate the node-subgraph relationship for the negative sample pairs to obtain the structural anomaly value of the negative sample pairs; then, according to the structural anomaly value of the positive sample pairs and the structural anomaly value of the negative sample pairs, the first overall anomaly value of the target node is calculated. For example, directly using the sum of the structural anomaly values of the negative sample pairs minus the sum of the structural anomaly values of the positive sample pairs to obtain the first overall anomaly value of the target node.

[0093] Among them, the structural anomaly value of the positive sample pairs is represented by the following formula:

[0094]

[0095] where represents the structural anomaly value of the positive sample pairs; Bilinear represents the bilinear model; z i represents the vector embedding of the target node; e i represents the vector embedding of the first target subgraph; sigmoid(·) represents the logistic regression function. Similarly, the structural anomaly value of the negative sample pairs can be calculated according to the above formula

[0096] Among them, the first overall anomaly value of the target node is represented by the following formula:

[0097]

[0098] where Represents the target node v i 's first overall outlier; Represents the structural outlier of the positive sample pair; Represents the structural outlier of the negative sample pair. In the case where there are multiple positive sample pairs, Represents the sum of the structural outliers of all positive sample pairs; In the case where there are multiple positive sample pairs, Represents the sum of the structural outliers of all negative sample pairs.

[0099] S22: Subgraph sampling of the enhanced node graph with a preset size is performed to obtain multiple second sampled subgraphs. Based on the multiple second sampled subgraphs, a contrastive learning algorithm is used to perform outlier detection on the structural relationship of the target node in the enhanced node graph, and the second overall outlier of the target node is obtained.

[0100] Among them, the node outlier detection device performs subgraph sampling of the enhanced node graph with a preset size to obtain multiple second sampled subgraphs. The multiple second sampled subgraphs include a second target subgraph and a second auxiliary subgraph. The second target subgraph is the second sampled subgraph containing the target node, and the second auxiliary subgraph is the second sampled subgraph not containing the target node. Then the node outlier detection device takes the target node and the second target subgraph as a positive sample pair, and takes the target node and the second auxiliary subgraph as a negative sample pair, and uses the contrastive learning algorithm to calculate the relationship between the node and the subgraph for the positive sample pair and the negative sample pair respectively, and obtains the second overall outlier of the target node.

[0101] The process of calculating the second overall outlier of the target node includes: The node outlier detection device uses a graph convolutional network to perform low-dimensional embedding encoding on the second target subgraph and the second auxiliary subgraph respectively to obtain the vector embedding of the second target subgraph and the vector embedding of the second auxiliary subgraph, and uses a multi-layer perceptron to perform vector encoding on the target node to obtain the vector embedding of the target node. The node outlier detection device takes the vector embedding of the target node and the vector embedding of the second target subgraph as a positive sample pair, and takes the vector embedding of the target node and the vector embedding of the second auxiliary subgraph as a negative sample pair, and uses the contrastive learning algorithm to calculate the node-subgraph relationship for the positive sample pair and the negative sample pair respectively, and obtains the first overall outlier of the target node.

[0102] Among them, the calculation process of the second overall outlier of the target node refers to the calculation process of the above first overall outlier, the difference is that the static node graph in the above process is replaced by the enhanced node graph, and the first target subgraph and the first auxiliary subgraph are replaced by the second target subgraph and the second auxiliary subgraph respectively.

[0103] S23: Determine the structural outlier of the target node according to the first overall outlier and the second overall outlier.

[0104] After calculating the first overall outlier value and the second overall outlier value of the target node, the node outlier detection device determines the structural outlier value of the target node according to the first overall outlier value and the second overall outlier value.

[0105] For example, the average of the first overall outlier value and the second overall outlier value can be directly used as the overall structural outlier value of the target node in the static node and enhanced node graph, as the structural outlier value of the target node. In other embodiments, the first overall outlier value and the second overall outlier value can be weighted averaged according to different weights to obtain the overall structural outlier value of the target node as the structural outlier value of the target node. The weight of the second overall outlier value can be greater than the first overall outlier value.

[0106] In this embodiment, a subgraph of a preset size is sampled on a static node graph to obtain a plurality of first sampling subgraphs. Based on the plurality of first sampling subgraphs, a contrastive learning algorithm is used to perform anomaly detection on the structural relationship of the target node in the static node graph to obtain a first overall outlier value of the target node; a subgraph of a preset size is sampled on an enhanced node graph to obtain a plurality of second sampling subgraphs. Based on the plurality of second sampling subgraphs, a contrastive learning algorithm is used to perform anomaly detection on the structural relationship of the target node in the enhanced node graph to obtain a second overall outlier value of the target node; the structural outlier value of the target node is determined based on the first overall outlier value and the second overall outlier value. A node-subgraph comparison is performed based on the static node and enhanced node graphs to construct a comparison target of a balanced feature space, shorten the distance between positive sample pairs, and push away negative sample pairs to reduce their influence, thereby improving the semantic discriminability of the target node, alleviating the semantic embedding confusion between normal nodes and abnormal nodes, and facilitating the detection accuracy of abnormal nodes.

[0107] In one embodiment, the structural outliers include overall structural outliers and subgraph structural outliers. Figure 5 As shown, in step S23, the structural outlier value of the target node is determined according to the first overall outlier value and the second overall outlier value, which specifically includes the following steps:

[0108] S231: Taking the average of the first overall outlier value and the second overall outlier value as the overall structural outlier value of the target node.

[0109] For example, the node anomaly detection device may directly average the first overall anomaly value and the second overall anomaly value to obtain the overall structural anomaly value of the target node, or may perform weighted average processing on the first overall anomaly value and the second overall anomaly value according to different weights to obtain the overall structural anomaly value of the target node. The weight of the second overall anomaly value may be greater than that of the first overall anomaly value.

[0110] S232: Detect the abnormal situation of the target node in the subgraph structure based on the first target subgraph and the second target subgraph, and obtain the subgraph structure outlier of the target node.

[0111] It should be understood that through the node-subgraph discrimination method, the abnormal situation of the target node in the overall graph information can be detected by using the positive sample pairs and negative sample pairs. However, it is difficult to judge the structural abnormality of the target node in the subgraph, and insufficient topological information is captured. In addition, the generation of the overall structure outlier only depends on the node-level discrimination in the graph space, ignoring the abnormal substructures formed by the structural abnormalities. And the structurally abnormal nodes have different neighborhood substructures, which may show significant semantic deviations and provide additional self-supervised signals. Using the semantic deviation of the node neighborhood substructures for node anomaly detection can improve the accuracy of anomaly detection.

[0112] In summary, the node anomaly detection device detects the abnormal situation of the target node in the subgraph structure based on the first target subgraph and the second target subgraph, and obtains the subgraph structure outlier of the target node. In this embodiment, the structure outlier includes the overall structure outlier and the subgraph structure outlier.

[0113] Specifically, the vector embedding of the target node and its subgraph can be obtained through a graph convolutional network, and then the mean variance of the vector embeddings of the nodes in the subgraph is used. The greater the variance, the greater the possibility of subgraph structure abnormality. Detecting the abnormal situation of the target node in the subgraph structure through the mean variance of the subgraph node vector embeddings can obtain an accurate structural outlier of the target node in the subgraph. When calculating the subgraph structure outlier, the attribute data of each node needs to be retained.

[0114] Among them, the calculation process of the subgraph structure outlier of the target node includes: calculating the vector embedding variance of the vector embeddings of the nodes in the first target subgraph to detect the structural abnormality of the target node in the first target subgraph and obtain the first subgraph outlier of the target node; calculating the vector embedding variance of the vector embeddings of the nodes in the second target subgraph to detect the structural abnormality of the target node in the second target subgraph and obtain the second subgraph outlier of the target node; determining the subgraph structure outlier of the target node according to the first subgraph outlier and the second subgraph outlier of the target node. For example, the mean of the first subgraph outlier and the second subgraph outlier can be directly used as the subgraph structure outlier.

[0115] Specifically, the calculation process of the first subgraph outlier of the target node is as follows: The graph convolutional network is used to perform vector encoding on each node in the first target subgraph to obtain the vector embeddings of each node in the first target subgraph; the mean value of the vector embeddings of each node in the first target subgraph is determined, and the vector squared difference of each node in the first target subgraph is determined according to the determined mean value of the vector embeddings of each node; the L1 norm (absolute value norm) is used to sum the vector squared differences of each node in the first target subgraph to obtain the first subgraph outlier of the target node.

[0116] Specifically, the calculation process of the second subgraph outlier of the target node is as follows: The graph convolutional network is used to perform vector encoding on each node in the second target subgraph to obtain the vector embeddings of each node in the first target subgraph; according to the vector embeddings of each node in the second target subgraph, the vector squared difference of each node in the second target subgraph is determined, and the L1 norm is used to sum the vector squared differences of each node in the second target subgraph to obtain the second subgraph outlier of the target node.

[0117] Among them, the mean value of the vector embeddings of each node is represented by the following formula:

[0118]

[0119] Among them, the vector squared difference of the node is represented by the following formula:

[0120]

[0121] Among them, represents the mean value of the vector embeddings of each node in the first target subgraph (second target subgraph); z j represents the vector embedding of the node in the first target subgraph (second target subgraph); represents the number of nodes in the first target subgraph (second target subgraph); Variance(v i ) represents the vector squared difference of a certain node v i in the first target subgraph (second target subgraph), and this value reflects the semantic deviation degree of the node attributes in the first target subgraph (second target subgraph).

[0122] Among them, the first subgraph outlier of the target node is represented by the following formula:

[0123]

[0124] Among them, represents the first subgraph outlier of the target node; Variance(v i ) represents the vector squared difference of a certain node v i in the first target subgraph; |·| 1 represents the L1 norm.

[0125] Among them, the outlier of the second subgraph of the target node is represented by the following formula:

[0126]

[0127] Among them, represents the outlier of the second subgraph of the target node; Variance(v i ) represents the vector squared difference of a certain node v i in the second target subgraph; |·| 1 represents the L1 norm.

[0128] The vector embeddings of the target node and its subgraph are obtained through a graph convolutional network, and then the mean variance of the vector embeddings of the nodes in the subgraph is used to detect the anomalies of the target node in the subgraph structure, obtaining the structural outlier of the target node in the subgraph. The semantic deviation of the target node in the subgraph is shown through the structural outlier of the subgraph, which can provide additional self-supervised signals for anomaly detection and improve the accuracy of anomaly detection.

[0129] In this embodiment, the mean of the first overall outlier and the second overall outlier is used as the overall structural outlier of the target node. According to the first target subgraph and the second target subgraph, the anomalies of the target node in the subgraph structure are detected, obtaining the subgraph structural outlier of the target node. When detecting the overall anomalies of the target node in the static node graph and the enhanced node graph, the structural anomaly detection of the target node in the subgraph structure is also added, improving the diversity and accuracy of the structural outlier.

[0130] In one embodiment, as Figure 6 shown, in step S30, that is, the abnormal node identification of the target node is performed according to the structural outlier of the target node, which specifically includes the following steps:

[0131] S31: According to the static node graph, the enhanced node graph, and the attribute data of the target node, perform attribute anomaly detection on the target node to determine the node attribute outlier of the target node.

[0132] It should be understood that the essence of attribute anomalies in nodes is that there are significant differences between the attributes of the nodes and their neighbor nodes (i.e., the adjacent nodes directly connected by edges). By distinguishing the consistency of the attributes between the nodes and their neighbor nodes in the subgraph, the essence of anomalies can be captured, improving the accuracy of anomaly detection.

[0133] The node anomaly detection device can perform attribute anomaly detection on the target node according to the static node graph, the enhanced node graph, and the attribute data of the target node to determine the node attribute outlier of the target node.

[0134] For example, static node graphs and enhanced node graphs can be used to detect attribute anomalies of target nodes. For example, the attribute error between the attribute data of the target node and the attribute data of other nodes in the static node graph can be calculated to obtain the first attribute error of the target node, and the attribute error between the attribute data of the target node and the attribute data of other nodes in the enhanced node graph can be calculated to obtain the second attribute error of the target node. Then, the first attribute error and the second attribute error are weighted and averaged to obtain the node attribute anomaly value of the target node.

[0135] S32: Determine the anomaly score of the target node according to the structural anomaly value and the node attribute anomaly value of the target node.

[0136] Then, the node anomaly detection device determines the anomaly score of the target node according to the structural anomaly value and the node attribute anomaly value of the target node.

[0137] Among them, the structural anomaly value includes the overall structural anomaly value and the subgraph structural anomaly value; the node anomaly detection device can respectively determine the weight coefficients of the node attribute anomaly value, the overall structural anomaly value and the subgraph structural anomaly value; according to the corresponding weight coefficients, the attribute anomaly value, the overall structural anomaly value and the subgraph structural anomaly value of the target node are weighted and summed to obtain the anomaly score of the target node. Among them, since the attribute anomaly value, the overall structural anomaly value and the subgraph structural anomaly value are calculated through the vector embedding of the graph structure, in order to ensure the accuracy of subsequent calculations, it is necessary to normalize the attribute anomaly value, the overall structural anomaly value and the subgraph structural anomaly value respectively, and then according to the corresponding weight coefficients, the normalized attribute anomaly value, the overall structural anomaly value and the subgraph structural anomaly value are weighted and summed to obtain the anomaly score of the target node, ensuring the accuracy of the anomaly score.

[0138] Among them, the calculation process of the anomaly score of the target node is as follows:

[0139] score(v i )=score ns (v i )+α·score gen (v i )+β·score str (v i );

[0140] Among them, score(v i ) represents the anomaly score of the target node v i ; score ns (v i ) represents the overall structural anomaly value of the target node v i ; score str (v i ) represents the overall structural anomaly value of the target node v iSub - graph structure outlier of; score gen (v i ) represents the target node v i Attribute outlier of; α and β are weight coefficients used to represent the importance of different types of outliers.

[0141] In other embodiments, the structural outlier can also be represented alone by the overall structural outlier (or sub - graph structural outlier). According to the attribute outlier of the target node, the overall structural outlier (or sub - graph structural outlier), and their weight coefficients, a weighted sum of the attribute outlier of the target node and the overall structural outlier (or sub - graph structural outlier) is performed to obtain the outlier score of the target node.

[0142] S33: When the outlier score of the target node is not within the preset threshold range, determine that the target node is an outlier node.

[0143] After determining the outlier score of the target node, the node outlier detection device determines whether the outlier score of the target node is within the preset threshold range to perform node outlier detection according to the judgment result. Among them, when the outlier score of the target node is not within the preset threshold range, the node outlier detection device determines that the target node is an outlier node.

[0144] In this embodiment, according to the static node graph, the enhanced node graph, and the attribute data of each target node, attribute outlier detection is performed on the target node to determine the node attribute outlier of the target node. According to the structural outlier and the node attribute outlier of the target node, the outlier score of the target node is determined. When the outlier score of the target node is not within the preset threshold range, the target node is determined to be an outlier node. Determining the outlier score of the target node through the structural outlier and the node attribute outlier of the target node increases the judgment of node attribute outliers, can improve the accuracy of the outlier score of the target node, and thus improves the accuracy of outlier node detection.

[0145] In one embodiment, as Figure 7 shown, in step S31, that is, according to the static node graph, the enhanced node graph, and the attribute data of each target node, attribute outlier detection is performed on the target node to determine the node attribute outlier of the target node, which specifically includes the following steps:

[0146] S311: Obtain the first target sub - graph and the second target sub - graph of the target node.

[0147] The node anomaly detection device obtains the first target subgraph and the second target subgraph of the target node. As shown above, the first target subgraph is the first sampled subgraph containing the target node obtained by sampling a subgraph of a preset size from the static node graph, that is, the first target subgraph is the local node graph containing the target node in the static node graph; the second target subgraph is the second sampled subgraph containing the target node obtained by sampling a subgraph of a preset size from the enhanced node graph, that is, the second target subgraph is the local node graph containing the target node in the enhanced node graph.

[0148] S312: According to the attribute data of the target node, the first target subgraph, and the second target subgraph, determine the attribute generation error between the target node and the subgraph, and obtain the node attribute anomaly value of the target node.

[0149] After obtaining the first target subgraph and the second target subgraph of the target node, the node anomaly detection device determines the attribute generation error between the target node and the subgraph according to the attribute data of the target node, the first target subgraph, and the second target subgraph, and obtains the node attribute anomaly value of the target node. Specifically, it includes the following steps:

[0150] S3121: Respectively perform vector encoding on the attribute data of the nodes in the first target subgraph through a contrastive learning network, generate the attribute generation vector of the first target subgraph according to the attribute vector embeddings of the nodes in the first target subgraph, and determine the Euclidean distance between the attribute vector embedding of the target node and the attribute generation vector of the first target subgraph as the attribute generation error between the target node and the first target subgraph.

[0151] Specifically, by respectively performing vector encoding on the attribute data of the nodes in the first target subgraph through a contrastive learning network, the attribute embedding vectors of the nodes in the first target subgraph can be obtained; concatenate the attribute embedding vectors of the nodes in the first target subgraph into a one-dimensional vector, and use a multi-layer perceptron to map this one-dimensional vector into an attribute vector with the same dimension size as the attribute vector embedding of the target node as the attribute generation vector of the first target subgraph; adopt the Euclidean norm (i.e., L2 norm) to calculate the Euclidean distance between the attribute embedding vector of the target node (i.e., the vector embedding of the attribute data of the target node) and the attribute generation vector of the first target subgraph, and use it as the attribute generation error between the target node and the first target subgraph.

[0152] Among them, the calculation formula for the attribute generation error between the target node and the first target subgraph is expressed as:

[0153]

[0154] Among them, represents the attribute generation error between the target node and the first target subgraph; MLP represents the multi-layer perceptron; MLP(E i) represents the attribute generation vector of the first target subgraph; E i represents the one-dimensional vector obtained by concatenating the attribute embedding vectors of each node in the first target subgraph; x i represents the vector embedding of the attribute of the target node, that is, the vector embedding of the attribute data of the target node; represents the L2 norm.

[0155] S3122: Respectively perform vector encoding on the attribute data of the nodes in the second target subgraph through the contrast learning network, generate the attribute generation vector of the second target subgraph according to the attribute vector embeddings of each node in the second target subgraph, and determine the Euclidean distance between the attribute vector embedding of the target node and the attribute generation vector of the second target subgraph as the attribute generation error between the target node and the second target subgraph.

[0156] Specifically, by respectively performing vector encoding on the attribute data of the nodes in the second target subgraph through the contrast learning network, the attribute embedding vectors of each node in the second target subgraph can be obtained; the attribute embedding vectors of each node in the second target subgraph are concatenated into a one-dimensional vector, and a multi-layer perceptron is used to map this one-dimensional vector into an attribute vector with the same dimension size as the attribute vector embedding of the target node as the attribute generation vector of the first target subgraph; the Euclidean norm (i.e., L2 norm) is used to calculate the Euclidean distance between the attribute embedding vector of the target node (i.e., the vector embedding of the attribute data of the target node) and the attribute generation vector of the second target subgraph, and it is used as the attribute generation error between the target node and the second target subgraph.

[0157] Among them, the calculation formula for the attribute generation error between the target node and the second target subgraph is expressed as:

[0158]

[0159] Among them, represents the attribute generation error between the target node and the second target subgraph; MLP represents the multi-layer perceptron; MLP(E i ) represents the attribute generation vector of the second target subgraph; E i represents the one-dimensional vector obtained by concatenating the attribute embedding vectors of each node in the second target subgraph; x i represents the attribute vector embedding of the attribute data of the target node, that is, the vector embedding of the attribute data of the target node; represents the L2 norm.

[0160] S3123: Generate the node attribute outlier of the target node according to the attribute generation error between the target node and the first target subgraph and the attribute generation error between the target node and the second target subgraph.

[0161] For example, directly generate the mean of the errors of two attributes to obtain the node attribute outlier of the target node. In other embodiments, different weights can be set, and the errors generated by the two attributes are weighted and averaged through the corresponding weight values to obtain the node attribute outlier of the target node.

[0162] In this embodiment, the attribute vectors of the nodes in the first target subgraph are embedded and spliced into a one-dimensional vector, and the one-dimensional vector is mapped by a multi-layer perceptron (MLP) into a vector with the same dimension size as the attribute embedding vector of the target node to obtain the attribute generation vector of the first target subgraph. The Euclidean distance between the attribute vector embedding of the target node and the attribute vector embedding of the first target subgraph is determined using the L2 norm as the attribute generation error between the target node and the first target subgraph. The attribute vectors of the nodes in the second target subgraph are embedded and spliced into the attribute vector embedding of the second target subgraph, and the Euclidean distance between the attribute vector embedding of the target node and the attribute vector embedding of the second target subgraph is determined using the L2 norm as the attribute generation error between the target node and the second target subgraph. Based on the attribute generation error between the target node and the first target subgraph and the attribute generation error between the target node and the second target subgraph, the node attribute outlier of the target node is generated. By regenerating the attributes of the masked target node through the attribute vector embeddings of the nodes in the subgraph, the error between the attribute vector embedding of the subgraph and the attribute vector embedding of the target node is determined to obtain the attribute generation error between the node and the subgraph. Then, based on the attribute generation error between the node and the subgraph, node anomalies are detected. A larger attribute generation error indicates potential node anomalies, with high accuracy.

[0163] In the above embodiments, by obtaining the first target subgraph and the second target subgraph of the target node, and determining the attribute generation error between the target node and the subgraph based on the attribute data of the target node, the first target subgraph, and the second target subgraph, the node attribute outlier of the target node is obtained. Node anomalies can be detected through the attribute data of the target node and the attribute error of the subgraph, improving the accuracy of the node attribute outlier and thus the accuracy of anomaly detection.

[0164] In the node anomaly detection method proposed in the above embodiments, the static node graph is enhanced through graph data augmentation to obtain an enhanced node graph. Then, through the static node graph and the enhanced node graph, contrastive learning of node and graph features is performed. The contrastive learning process of graph feature encoding and the anomaly detection process are decoded, enabling accurate detection and score estimation of node anomalies, effectively mining high-order structure information in the target interaction scenario, improving the learning ability of graph structure information, thus optimizing the node anomaly detection task, improving the detection accuracy, and handling complex anomaly detection tasks in different interaction scenarios.

[0165] Among them, in order to evaluate the anomaly detection ability of the node anomaly detection method, six datasets commonly used in the field of anomaly detection are adopted to evaluate the detection effect of the node anomaly detection method provided by the embodiments of the present application.

[0166] Among them, the detailed information of the six datasets is shown in Table 1:

[0167] Table 1. Detailed Information of Datasets

[0168]

[0169] In order to detect the effectiveness of the node anomaly detection method provided by the embodiments of the present application, the node anomaly detection method HSGDC provided by this embodiment is compared with nine relatively advanced anomaly detection methods on the market. Among them, the nine anomaly detection methods include: AMEN, Radar, ANOMALOUS, DOMINANT, CoLA, ANEMONE, SL-GAD, Sub-CR, GRADATE. The anomaly detection accuracy of the node anomaly detection method HSGDC in this embodiment and the nine anomaly detection methods on the above six datasets is shown in Table 2 below.

[0170] It can be seen from Table 2 that the anomaly detection accuracy of HSGDC on the above six datasets is higher than that of the other nine anomaly detection methods, that is, the detection effect of the node anomaly detection method HSGDC provided by this embodiment on the above six datasets is significantly better than that of other methods.

[0171] Among them, for the node anomaly detection method HSGDC provided by this embodiment on the Cora, CiteSeer, DBLP, Citation, ACM, and Pubmed datasets, the AUC values are increased by 3.30%, 3.36%, 4.30%, 3.87%, 7.11%, and 1.47% respectively; these results verify the effectiveness and significance of the HSGDC model in distinguishing abnormal nodes from normal nodes.

[0172] Table 2. Anomaly Detection Effects of HSGDC and Other Nine Anomaly Detection Methods

[0173]

[0174] As can be seen from the anomaly detection effect in Table 2, compared with other deep learning methods, the improved node anomaly detection algorithm HSGDC in this embodiment has stronger detection ability. Because HSGDC decouples the process of contrast learning and anomaly detection, improves the semantic discrimination ability of nodes, and thus solves the semantic mixing problem existing in related methods; at the same time, HSGDC adopts a data augmentation strategy to construct an enhanced node graph, which can enhance the information of the graph structure to enrich the high-order structure information of nodes, enabling HSGDC to better model the relationship between nodes and their neighborhoods and mine rich structure information and attribute information in the graph; in addition, by aggregating the overall structure scores, attribute regression scores, and node sub-structure variance scores of node and sub-graph sample pairs, HSGDC can better capture attribute anomalies and structure anomalies in the graph and improve the accuracy of anomaly node detection.

[0175] It should be understood that the magnitudes of the sequence numbers of the steps in the above embodiments do not mean the order of execution. The order of execution of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.

[0176] In one embodiment, a node anomaly detection device is provided, which corresponds one-to-one with the node anomaly detection method in the above embodiment. As Figure 8 shown, the node anomaly detection device includes an acquisition module 801, a detection module 802, an identification module 803, and a reminder module 804. The detailed description of each functional module is as follows:

[0177] The acquisition module 801 is configured to acquire a static node graph and an enhanced node graph of a target interaction scenario. The static node graph is used to simulate the interaction relationship between interaction behavior objects and preset items participating in the interaction under the target interaction scenario. The enhanced node graph is a node graph obtained by performing graph diffusion enhancement on the node structure relationship of the static node graph using a graph diffusion algorithm and a proximity algorithm;

[0178] The detection module 802 is configured to perform node structure anomaly detection on at least one target node according to the static node graph and the enhanced node graph, and determine the structure anomaly value of the target node. The target node is a node in the pre-specified static node graph;

[0179] The identification module 803 is configured to identify an anomaly node for the target node according to the structure anomaly value of the target node;

[0180] The reminder module 804 is configured to give an anomaly reminder to the interaction behavior object or preset item corresponding to the target node when the target node is identified as an anomaly node.

[0181] Optionally, the identification module 803 is specifically configured to:

[0182] Based on the static node graph, the enhanced node graph, and the attribute data of each target node, perform attribute anomaly detection on the target node to determine the node attribute anomaly value of the target node;

[0183] Based on the structural anomaly value and the node attribute anomaly value of the target node, determine the anomaly score of the target node;

[0184] When the anomaly score of the target node is not within the preset threshold range, determine that the target node is an abnormal node.

[0185] Optionally, the structural anomaly value includes the overall structural anomaly value and the subgraph structural anomaly value. The recognition module 803 is specifically further configured to:

[0186] Determine the weight coefficients of the node attribute anomaly value, the overall structural anomaly value, and the subgraph structural anomaly value respectively;

[0187] According to the corresponding weight coefficients, perform weighted summation on the node attribute anomaly value, the overall structural anomaly value, and the subgraph structural anomaly value of the target node to obtain the anomaly score of the target node.

[0188] Optionally, the recognition module 803 is specifically further configured to:

[0189] Obtain the first target subgraph and the second target subgraph of the target node. The first target subgraph is the first sampled subgraph containing the target node obtained by sampling the static node graph with a preset size of the subgraph, and the second target subgraph is the second sampled subgraph containing the target node obtained by sampling the enhanced node graph with a preset size of the subgraph;

[0190] According to the attribute data of the target node, the first target subgraph, and the second target subgraph, determine the attribute generation error between the target node and the subgraph, and obtain the node attribute anomaly value of the target node.

[0191] Optionally, the detection module 802 is specifically configured to:

[0192] Perform subgraph sampling with a preset size on the static node graph to obtain multiple first sampled subgraphs. Based on the multiple first sampled subgraphs, use the contrastive learning algorithm to perform anomaly detection on the structural relationship of the target node in the static node graph to obtain the first overall anomaly value of the target node;

[0193] Perform subgraph sampling with a preset size on the enhanced node graph to obtain multiple second sampled subgraphs. Based on the multiple second sampled subgraphs, use the contrastive learning algorithm to perform anomaly detection on the structural relationship of the target node in the enhanced node graph to obtain the second overall anomaly value of the target node;

[0194] According to the first overall anomaly value and the second overall anomaly value, determine the structural anomaly value of the target node.

[0195] Optionally, the structural outliers include overall structural outliers and subgraph structural outliers. Specifically, the detection module 802 is further configured to:

[0196] Take the average of the first overall outlier and the second overall outlier as the overall structural outlier of the target node;

[0197] Detect the abnormal situation of the target node in the subgraph structure according to the first target subgraph and the second target subgraph, and obtain the subgraph structural outlier of the target node. The first target subgraph is the first sampled subgraph containing the target node, and the second target subgraph is the second sampled subgraph containing the target node.

[0198] It should be noted that for the information interaction, execution process, etc. between the above-mentioned devices / units, since they are based on the same concept as the method embodiments of the present application, their specific functions and the technical effects brought can be specifically referred to in the method embodiment part, and will not be elaborated here.

[0199] Those skilled in the art can clearly understand that for the convenience and conciseness of description, only the above-mentioned division of each functional unit and module is used as an example for illustration. In actual applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit. In addition, the specific names of each functional unit and module are only for the convenience of mutual distinction and do not limit the protection scope of the present application. The specific working process of the units and modules in the above system can refer to the corresponding process in the foregoing method embodiment and will not be elaborated here.

[0200] In one embodiment, a computer device is provided. The computer device can be a server or a client. The computer device includes a processor, a memory, a network interface, and a database connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store the data used and generated by the above node anomaly detection method, such as a static node graph, an enhanced node graph, the structural outlier of the target node, etc. The network interface of the computer device is used to communicate with external devices through a network connection. When the computer program is executed by the processor, it implements a node anomaly detection method.

[0201] An embodiment of this application also provides a computer device, such as Figure 9 shown. The computer device includes: at least one processor, a memory, and a computer program stored in the memory and executable on the at least one processor. When the processor executes the computer program, the steps in any of the above method embodiments are implemented, or when the processor executes the computer program, the functions of each module / unit in the above device embodiments are implemented.

[0202] Exemplarily, the computer program can be divided into one or more modules / units. The one or more modules / units are stored in the memory and executed by the processor to complete this application. The one or more modules / units can be a series of computer program instruction segments capable of completing specific functions, and these instruction segments are used to describe the execution process of the computer program in the computer device.

[0203] Those skilled in the art can understand that Figure 9 merely examples of the computer device, and do not constitute a limitation on the computer device. It may include more or fewer components than shown in the figure, or combine certain components, or different components. For example, the computer device may also include input / output devices, network access devices, buses, etc.

[0204] The above-mentioned processor may be a Central Processing Unit (CPU), or may also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0205] The memory may be an internal storage unit of the computer device, such as the hard disk or memory of the computer device. The memory may also be an external storage device of the computer device, such as a plug-in hard disk equipped on the computer device, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc. Further, the memory may also include both the internal storage unit and the external storage device of the computer device.

[0206] An embodiment of the present application also provides a readable storage medium storing a computer program, which when executed by a processor can implement the steps in the above-mentioned method embodiments.

[0207] An embodiment of the present application provides a computer program product, which when running on a mobile terminal enables the mobile terminal to implement the steps in the above-mentioned method embodiments when executed.

[0208] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, to implement all or part of the processes in the above-mentioned method embodiments of the present application, a computer program can be used to instruct the relevant hardware to complete. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file or some intermediate form, etc. The computer-readable medium can at least include: any entity or device capable of carrying the computer program code to the photographing device / terminal device, recording medium, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electrical carrier signal, telecommunication signal, and software distribution medium. For example, a USB flash drive, a mobile hard disk, a magnetic disk or an optical disc, etc. In some jurisdictions, according to legislation and patent practice, the computer-readable medium may not be an electrical carrier signal and a telecommunication signal.

[0209] In the above embodiments, the descriptions of the various embodiments have their own focuses. For the parts not detailed or recorded in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0210] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0211] In the embodiments provided in the present application, it should be understood that the disclosed apparatus / devices and methods can be implemented in other ways. For example, the apparatus / device embodiments described above are merely illustrative. For example, the division of the modules or units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of the apparatus or unit can be in electrical, mechanical or other forms.

[0212] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0213] The above-described embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.

Claims

1. A node anomaly detection method, characterized in that: include: Obtaining a static node graph and an enhanced node graph of a target interaction scene, wherein the static node graph is used to simulate the interaction relationship between the interaction behavior objects and the preset items participating in the interaction in the target interaction scene, and the enhanced node graph is a node graph obtained by performing graph diffusion enhancement on the node structure relationship of the static node graph using a graph diffusion algorithm and a proximity algorithm; Performing node structure anomaly detection on at least one target node according to the static node graph and the enhanced node graph to determine a structural anomaly value of the target node, wherein the target node is a pre-specified node in the static node graph; Performing abnormal node identification on the target node according to the structural abnormal value of the target node; When the target node is identified as an abnormal node, an abnormal reminder is given to the interactive behavior object or the preset item corresponding to the target node.

2. The node anomaly detection method according to claim 1, characterized in that: The performing abnormal node identification on the target node according to the structural abnormal value of the target node includes: According to the static node graph, the enhanced node graph and the attribute data of the target node, performing attribute anomaly detection on the target node to determine a node attribute anomaly value of the target node; Determine an anomaly score of the target node according to the structural anomaly value and the node attribute anomaly value of the target node; When the abnormal score of the target node is not within a preset threshold range, the target node is determined to be an abnormal node.

3. The node anomaly detection method according to claim 2, characterized in that: The structural outlier value includes an overall structural outlier value and a subgraph structural outlier value, and the outlier score of each target node is determined according to the structural outlier value and the node attribute outlier value of each target node, including: Determine the weight coefficients of the node attribute outlier, the overall structure outlier, and the subgraph structure outlier respectively; According to the corresponding weight coefficient, the attribute outlier value, the overall structure outlier value and the subgraph structure outlier value of the target node are weighted and summed to obtain the outlier score of the target node.

4. The node anomaly detection method according to claim 2, characterized in that: The performing attribute anomaly detection on the target node according to the static node graph, the enhanced node graph and the attribute data of each target node to determine the node attribute anomaly value of the target node includes: Obtain a first target subgraph and a second target subgraph of the target node, wherein the first target subgraph is a first sampling subgraph including the target node obtained by sampling a subgraph of a preset size on the static node graph, and the second target subgraph is a second sampling subgraph including the target node obtained by sampling a subgraph of a preset size on the enhanced node graph; According to the attribute data of the target node, the first target subgraph and the second target subgraph, an attribute generation error between the target node and the subgraph is determined to obtain a node attribute abnormal value of the target node.

5. The node anomaly detection method according to any one of claims 1 to 4, characterized in that: The performing node structure anomaly detection on at least one target node according to the static node graph and the enhanced node graph to determine the structural anomaly value of the target node includes: Sampling subgraphs of a preset size on the static node graph to obtain a plurality of first sampling subgraphs, and using a contrastive learning algorithm to perform anomaly detection on a structural relationship of the target node in the static node graph based on the plurality of first sampling subgraphs to obtain a first overall anomaly value of the target node; Sampling the subgraphs of the preset size on the enhanced node graph to obtain a plurality of second sampling subgraphs, and based on the plurality of second sampling subgraphs, using the contrastive learning algorithm to perform anomaly detection on the structural relationship of the target node in the enhanced node graph to obtain a second overall anomaly value of the target node; A structural outlier value of the target node is determined according to the first overall outlier value and the second overall outlier value.

6. The node anomaly detection method according to claim 5, characterized in that: The structural outlier value includes an overall structural outlier value and a subgraph structural outlier value, and determining the structural outlier value of the target node according to the first overall outlier value and the second overall outlier value includes: Taking the average of the first overall outlier value and the second overall outlier value as the overall structural outlier value of the target node; According to the first target subgraph and the second target subgraph, the abnormal situation of the target node in the subgraph structure is detected to obtain the subgraph structure abnormal value of the target node, the first target subgraph is the first sampling subgraph including the target node, and the second target subgraph is the second sampling subgraph including the target node.

7. A node anomaly detection device, characterized in that: include: An acquisition module is used to acquire a static node graph and an enhanced node graph of a target interaction scene, wherein the static node graph is used to simulate the interaction relationship between the interaction behavior objects and the preset items participating in the interaction in the target interaction scene, and the enhanced node graph is a node graph obtained by performing graph diffusion enhancement on the node structure relationship of the static node graph using a graph diffusion algorithm and a proximity algorithm; A detection module, configured to perform node structure anomaly detection on at least one target node according to the static node graph and the enhanced node graph, and determine a structural anomaly value of the target node, wherein the target node is a pre-specified node in the static node graph; An identification module, used for identifying abnormal nodes of the target node according to the structural abnormal value of the target node; The reminder module is used to provide an abnormal reminder to the interactive behavior object or the preset item corresponding to the target node when the target node is identified as an abnormal node.

8. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the node anomaly detection method according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the node anomaly detection method according to any one of claims 1 to 6 are implemented.

10. A computer program product, characterized in that The computer program product comprises a computer program, which, when executed by a processor, implements the steps of the node anomaly detection method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Node detection model training method and device and computer equipment

    CN117521770A

  • Social network anomaly detection method based on comparative learning

    CN117708742A

  • Unsupervised abnormal node detection method for comprehensive global information of social media

    CN118503875A

  • Two-channel social network abnormal user detection method based on mutual distillation

    CN119025969A