Internet of Things network efficient intrusion detection method based on deep learning network

By adopting the intrusion detection method of deep learning networks in the Internet of Things network, using stacked asymmetric deep autoencoder and SVM classifiers, the features in the Internet of Things network are extracted and processed, and the problems of difficulty in feature extraction and low detection efficiency in the prior art are solved, and efficient and accurate intrusion detection and attack mitigation are achieved.

CN120150983APending Publication Date: 2025-06-13ZHEJIANG UNIV OF TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510118182.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-24
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

The existing botnet detection system based on deep learning has problems such as difficulty in extracting features, high false alarm rates and low detection efficiency, making it difficult to effectively identify and deal with intrusion attacks in the Internet of Things network.

Method used

The IoT network efficient intrusion detection method is adopted based on deep learning networks, and IoT devices are managed through communication modules, features of six dimensions are extracted and converted into feature vectors, and detection models are constructed using stacked asymmetric depth autoencoder and SVM classifier to achieve rapid intrusion detection and attack mitigation.

Benefits of technology

It improves the efficiency and detection accuracy of data feature extraction in the Internet of Things network, reduces the false alarm rate and detection time, and effectively slows down the impact of intrusion attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120150983A_ABST
    Figure CN120150983A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of network security and machine learning, and discloses an Internet of Things network efficient intrusion detection method based on a deep learning network, all Internet of Things devices in the Internet of Things network are managed by using a communication module, and the Internet of Things network efficient intrusion detection method based on the deep learning network is implemented in the Internet of Things devices. Comprising the following steps: extracting data features based on a data packet sent by a communication module, and converting the data features into feature vectors; using a stacked asymmetric depth auto-encoder to output coding features according to the feature vectors, inputting the coding features into an SVM classifier, and outputting an intrusion detection result by the SVM classifier; if the intrusion detection result is that the data packet is an attack data packet, all communication of the Internet of Things equipment is cut off through a communication module; otherwise, normal communication of the Internet of Things equipment is maintained. According to the method, attack detection can be quickly realized, and the influence caused by attacks can be effectively relieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical fields of network security and machine learning, and particularly relates to an efficient intrusion detection method for Internet of Things (IoT) networks based on a deep learning network. Background Art

[0002] With the rapid development of the Internet of Things (IoT), network security issues based on the IoT have attracted wide attention, especially botnets. A botnet is a network composed of multiple computers or IoT devices that are controlled by a remote attacker without the knowledge of the users. Botnets are often used to carry out various intrusion attacks, including but not limited to distributed denial of service (DDoS) attacks, flooding, and spam. These attacks usually cause serious network and system performance problems and may even lead to the complete paralysis of network services.

[0003] A major challenge faced by the security of IoT networks is various vulnerabilities. There are many ways to exploit these vulnerabilities to attack IoT devices, and it is very difficult for security personnel to fully predict these vulnerabilities in advance. Therefore, traditional signature-based detection methods cannot perform well in attack detection. This is because signature-based detection methods are mainly used to detect known malicious behaviors or attack patterns, and their basic principle is to use predefined features or rules (i.e., signatures) to identify malicious behaviors in network traffic. In the IoT environment, a large amount of data is continuously generated, and it is a challenging task to identify abnormal data from these data streams. In this case, the deep learning approach is appropriate because deep neural networks are very effective in analyzing large amounts of data, discovering patterns and relationships between them, and classifying data. However, current deep learning-based botnet systems have problems such as difficult feature extraction, high false positive rates, and low detection efficiency. Summary of the Invention

[0004] Aiming at the deficiencies of the prior art, the present invention proposes an efficient intrusion detection method for IoT networks based on a deep learning network, which can better extract data features in IoT networks. On this basis, a detection model for botnet attacks is automatically learned using a deep neural network, which can quickly achieve attack detection and effectively mitigate the impact caused by attacks.

[0005] To achieve the above object, the technical solution adopted by the present invention is as follows:

[0006] An efficient intrusion detection method for IoT networks based on a deep learning network uses a communication module to manage all IoT devices in the IoT network. The efficient intrusion detection method for IoT networks based on a deep learning network is implemented on IoT devices and includes:

[0007] Extract data features from the data packets sent by the communication module and convert the data features into feature vectors;

[0008] Use a stacked asymmetric deep autoencoder to output encoded features according to the feature vectors, and input the encoded features into an SVM classifier, and the SVM classifier outputs the intrusion detection result; the encoder in the stacked asymmetric deep autoencoder connects the input and output of the encoder through a residual connection, and the decoder in the stacked asymmetric deep autoencoder uses an attention mechanism to weight the output of the encoder;

[0009] If the intrusion detection result is that the data packet is an attack data packet, cut off all communications of the IoT device where it is located through the communication module; otherwise, maintain the normal communication of the IoT device where it is located.

[0010] The following also provides several optional methods, but it is not an additional limitation to the above overall solution, but only a further supplement or preference. On the premise of no technical or logical contradiction, each optional method can be combined with the above overall solution alone, or multiple optional methods can be combined with each other.

[0011] Preferably, the communication module includes a connection module, a network simulation module, and an interface module;

[0012] The connection module receives the original bit stream from the IoT network, converts the original bit stream into a data packet, and sends the data packet to the network simulation module; it is also used to receive the data packet from the network simulation module, convert the data packet into the original bit stream, and send the original bit stream to the IoT network;

[0013] The network simulation module receives the data packet from the connection module and forwards the data packet to the interface module; it is also used to receive the data packet from the interface module and forward the data packet to the connection module;

[0014] The interface module creates a data packet exchange interface and realizes data interaction between the network simulation module and the IoT device through the data packet exchange interface.

[0015] Preferably, the data features include features in six dimensions, namely source IP, destination IP, data value, IoT device activity time, transmission rate, and reception rate.

[0016] Preferably, the conversion of the data features into feature vectors includes:

[0017] Process the source IP, destination IP, IoT device activity time, transmission rate, and reception rate respectively using probability distributions to obtain corresponding feature values;

[0018] Process the data value using the word embedding model to obtain the corresponding feature value;

[0019] Combine the feature values corresponding to the features in six dimensions to obtain a feature vector.

[0020] Preferably, the loss function in the training process of the SVM classifier is defined as follows:

[0021]

[0022] In the formula, LossFunction represents the function, λ represents the regularization parameter, w represents the weight vector to be trained by the SVM classifier, ||·|| 2 represents the L2 norm, n represents the total number of training samples, y i represents the true label of the i-th training sample, <x i , w> represents the predicted value calculated by the SVM classifier using the weight vector w and the encoded features of the i-th training sample.

[0023] Preferably, the stacked asymmetric deep autoencoder includes multiple layers of asymmetric deep autoencoders;

[0024] In each layer of the asymmetric deep autoencoder, the encoder connects the input and output of the encoder through a residual connection, including:

[0025] z b l =σ b (W b l x l +b b l )

[0026] h l =z b l +x l

[0027] In the formula, h l represents the output of the encoder in the l-th layer of the asymmetric deep autoencoder, z b l represents the intermediate feature of the encoder in the l-th layer of the asymmetric deep autoencoder, x l represents the input of the encoder in the l-th layer of the asymmetric deep autoencoder, σ b (·) represents the non-linear transformation operation of the encoder in the l-th layer of the asymmetric deep autoencoder, W b l represents the weight of the encoder in the l-th layer of the asymmetric deep autoencoder, b b l represents the bias of the encoder in the l-th layer of the asymmetric deep autoencoder;

[0028] The decoder in each layer of the asymmetric deep autoencoder uses an attention mechanism to weight the output of the encoder, including:

[0029] z j l = σ j (W j l h l + b j l )

[0030] s l = z j l + h l

[0031] a l = softmax(s l )

[0032]

[0033] In the formula, z j l represents the intermediate feature of the decoder in the l-th layer of the asymmetric deep autoencoder, σ j (·) represents the non-linear transformation operation of the decoder in the l-th layer of the asymmetric deep autoencoder, W j l represents the weight of the decoder in the l-th layer of the asymmetric deep autoencoder, b j l represents the bias of the decoder in the l-th layer of the asymmetric deep autoencoder, s l represents the similarity score between the intermediate feature of the encoder and the input of the encoder, softmax(·) represents the softMax function, a l represents the attention weight, x l +1 represents the output of the decoder in the l-th layer of the asymmetric deep autoencoder, that is, the input of the encoder in the (l + 1)-th layer of the asymmetric deep autoencoder, q represents the q-th dimension, represents the value of the q-th dimension in the attention weight a l in, represents the value of the q-th dimension in the input h l of the decoder in the l-th layer of the asymmetric deep autoencoder.

[0034] An efficient intrusion detection method for an IoT network based on a deep learning network provided by the present invention has the following beneficial effects compared with the prior art:

[0035] 1. Efficient feature extraction and processing mechanism: By analyzing the common attack patterns of botnets, six-dimensional features are extracted. Then, according to the characteristics of different features, an efficient feature processing scheme is implemented to quickly obtain the feature vectors of data packets.

[0036] 2. Advanced model construction and training strategy: The stacked asymmetric deep autoencoder is optimized. Residual connections are introduced in the encoder to enhance the model's ability to extract deep features; the attention mechanism is adopted in the decoder, enabling the model to pay more attention to the key parts of the data packet features, thereby improving the effect of feature learning and the robustness of the model.

[0037] 3. Intelligent attack mitigation strategy: By managing the data packet processing in the IoT network through the communication module, when an attack is detected, the attack can be blocked immediately to timely mitigate the impact caused by the attack. Brief Description of the Drawings

[0038] Figure 1 is a flowchart of an efficient intrusion detection method for an IoT network based on a deep learning network according to the present invention;

[0039] Figure 2 is a schematic structural diagram of the stacked asymmetric deep autoencoder and the SVM classifier according to the present invention. Detailed Embodiment

[0040] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0041] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present invention belongs. The terms used in the specification of the present invention herein are only for the purpose of describing specific embodiments and are not intended to limit the present invention.

[0042] As Figure 1 shown, this embodiment proposes an efficient intrusion detection method for an IoT network based on a deep learning network. This embodiment uses a communication module to manage all IoT devices in the IoT network for efficient data packet processing and communication management. The communication module includes a connection module, a network simulation module, and an interface module.

[0043] The communication module is installed and applied to all IoT devices, and its main functions are as follows:

[0044] Connection Module: As a key component of network communication, the connection module undertakes the tasks of initializing network detection and beacon broadcasting. It sends signals to all connected IoT devices in the network. Its responsibilities include parsing the broadcast beacon information, intercepting the handshake data packets between devices, and reviewing session requests, and maintaining a protocol table for an active communication protocol. The connection module receives the raw bit stream from the IoT network, converts the raw bit stream into data packets according to the communication protocol of the corresponding device, and sends the data packets to the network simulation module; it is also used to receive data packets from the network simulation module, convert the data packets into raw bit streams according to the communication protocol of the corresponding device, and send the raw bit streams to the IoT network. In addition, the connection module uses auxiliary storage as a buffer to temporarily store these converted data packets.

[0045] Network Simulation Module: The network simulation module is not directly connected to the IoT network. It is responsible for obtaining data packets from the connection module, selecting network protocols for processing, and sending the data packets to the target IoT device. Specifically, the network simulation module receives data packets from the connection module and forwards the data packets to the interface module; it is also used to receive data packets from the interface module and forward the data packets to the connection module.

[0046] Interface Module: Creates a data packet exchange interface, controls the data transmission and reception between the network simulation module and the IoT device through the data packet exchange interface, and manages the operations of the connection module and the network simulation module at the same time.

[0047] Specifically, based on the communication module, the efficient intrusion detection method for the IoT network based on the deep learning network in this embodiment is implemented on the IoT device, including the following steps:

[0048] (1) Feature Extraction: Extract data features based on the data packets sent by the communication module and convert the data features into feature vectors.

[0049] (1-1) IoT devices communicate on the network through data packets managed by relevant communication protocols. Any abnormality is related to the data packets. The purpose of feature extraction is to extract features in six dimensions, as shown in Table 1.

[0050] Table 1 Features in Six Dimensions

[0051] Serial number Feature Symbol 1 Source IP <![CDATA[IP s > 2 Destination IP <![CDATA[IP d > 3 Data value <![CDATA[D v > 4 Activity time of IoT device <![CDATA[E a > 5 Transmission rate <![CDATA[T s > 6 Receiving rate <![CDATA[R s >

[0052] Among them, IP s and IP d and D v can be obtained from the data packets. The specific extraction steps are as follows:

[0053] 1. Extract the header information of the data packet to determine how many layers the data packet has (for example: data link layer, network layer, etc.);

[0054] 2. For each layer, separate its header information and data information;

[0055] 3. Parse the source IP and destination IP in the separated header information of each layer and add them to the feature sequence;

[0056] 4. Add the data information as the data value to the feature sequence.

[0057] In addition, E a , T s , R s are obtained from the interface module of the communication module. In the Internet of Things, usually, the transmission rates of the sender and the receiver are the same. If there are significant differences, it indicates that a Denial of Service (DoS) attack may have occurred.

[0058] (1 - 2) Feature value processing: To facilitate passing the features as input to the neural network, these six feature values need to be processed so that the deep neural network can accept them.

[0059] For the features IP s , IP d , E a , T s , R s among these 5 features, a probability distribution is used to process them, as shown in Formula 1, where P fx represents the feature value of the x-th feature, and P(f x ) represents the unit probability of each value observed in the x-th feature. Suppose the 5 features of IP s , IP d , E a , T s , R s in the data packet are 1, 1, 1, 2, and 2 respectively. Then the feature value of the first feature is 3 / 5, and so on, to obtain the feature values of each feature.

[0060] P fx = P(f 0 ), P(f 1 ),...P(f x ) (1)

[0061] For the feature D v , word2vec is used to generate feature vectors. Word2vec is a model for generating word embeddings, which can convert words into vector representations by training a shallow neural network. Denote the generated feature vector value of D v as P v , and IP s , IP d, E a , T s , R s The generated eigenvalues are respectively denoted as P s , P d , P e , P t , P r . Finally, the feature vector P formed by each data packet is P = [P s , P d , P v , P e , P t , P r .

[0062] (2) Model Encoding: Use a stacked asymmetric deep autoencoder to output encoded features based on the feature vector.

[0063] Through the stacked asymmetric deep autoencoder (Non-symmetric Deep Auto-Encoder, NDAE), unsupervised feature learning can be performed layer by layer. This architecture can better learn the complex associations between various features and can optimize the model by giving priority to the most important features. However, the classification accuracy of the stacked autoencoders (Stacked Auto-Encoders, SAE) with a typical softmax layer is relatively limited. Therefore, in this embodiment, SVM is used for shallow classification.

[0064] Referring to Figure 2 , using the feature vector P as the input, and then using the encoded features learned by the stacked asymmetric deep autoencoder (including three layers of asymmetric deep autoencoders, each layer of asymmetric deep autoencoder contains three hidden layers Hidden Layer) to train the SVM classifier to identify normal data packets and attack data packets. To prevent the SVM classifier from overfitting, its loss function is defined as shown in Equation 2:

[0065]

[0066] In the formula, LossFunction represents the function, λ represents the regularization parameter, w represents the weight vector to be trained by the SVM classifier, ||·|| 2 represents the L2 norm, ||w|| 2 represents the L2 norm of the weight vector w, that is, the square root of the sum of the squares of each element of the weight vector, n represents the total number of training samples, y i represents the true label of the i-th training sample, <x i , w> represents the predicted value calculated by the SVM classifier using the weight vector w and the encoded features of the i-th training sample. Indicates the gap between the predicted values and the true values of all samples.

[0067] To further improve the performance of the stacked asymmetric deep autoencoder, residual connections are introduced in the encoder. By connecting the input and output of the encoder through residual connections, each layer of the encoder can learn the residual information between the input features and the output of the previous layer of the encoder. Specifically, in each layer of the encoder, first obtain the intermediate feature representation through a non-linear transformation:

[0068] z b l = σ b (W b l x l + b b l ) (3)

[0069] After that, perform a residual connection between the intermediate feature representation and the input features to obtain the final encoded output:

[0070] h l = z b l + x l (4)

[0071] In the formula, h l represents the output of the encoder in the l-th layer of the asymmetric deep autoencoder, z b l represents the intermediate feature of the encoder in the l-th layer of the asymmetric deep autoencoder, the subscript b is used to distinguish the encoder, x l represents the input of the encoder in the l-th layer of the asymmetric deep autoencoder, σ b (·) represents the non-linear transformation operation of the encoder in the l-th layer of the asymmetric deep autoencoder, W b l represents the weight of the encoder in the l-th layer of the asymmetric deep autoencoder, b b l represents the bias of the encoder in the l-th layer of the asymmetric deep autoencoder. This way of residual connection enables each layer of the encoder to not only learn the residual information between the input features and the output of the previous layer of the encoder, but also retain the original information of the input features, enhancing the model's ability to extract deep features, helping to alleviate the vanishing gradient problem in deep networks, and promoting the deep learning of the model.

[0072] In the decoder, an attention mechanism is adopted to weight the output of the encoder. Specifically, in each layer of the decoder, obtain the intermediate feature representation through a non-linear transformation:

[0073] z j l = σj (W j l h l +b j l ) (5)

[0074] After introducing the attention mechanism, calculate the similarity score between the encoder output features and the current decoder features:

[0075] s l =z j l +h l (6)

[0076] And normalize it through the softmax function to obtain the attention weights:

[0077] a l =softmax(s l ) (7)

[0078] Finally, perform a weighted sum of the attention weights and the encoder output features to obtain the final decoded output:

[0079]

[0080] In the formula, z j l represents the intermediate feature of the decoder in the l-th layer of the asymmetric deep autoencoder. The subscript j is used to distinguish the encoder. σ j (·) represents the non-linear transformation operation of the decoder in the l-th layer of the asymmetric deep autoencoder. W j l represents the weight of the decoder in the l-th layer of the asymmetric deep autoencoder. b j l represents the bias of the decoder in the l-th layer of the asymmetric deep autoencoder. s l represents the similarity score between the intermediate feature of the encoder and the input of the encoder. softmax(·) represents the softMax function. a l represents the attention weight. x l+1 represents the output of the decoder in the l-th layer of the asymmetric deep autoencoder, that is, the input of the encoder in the (l + 1)-th layer of the asymmetric deep autoencoder. q represents the q-th dimension. represents the value of the q-th dimension in the attention weight a l . represents the value of the q-th dimension in the input h l of the decoder in the l-th layer of the asymmetric deep autoencoder.

[0081] This attention mechanism calculates the similarity weights between the encoder output features and the decoder current layer features, enabling the model to pay more attention to the key parts in the packet features, thereby improving the accuracy of feature reconstruction and the robustness of the model, and enabling the autoencoder to better capture the internal structure and abnormal patterns of the packet features.

[0082] (3) SVM discrimination: Input the encoded features into the SVM classifier, and the SVM classifier outputs the intrusion detection result. If the intrusion detection result is that the packet is an attack packet, then cut off all communications of the IoT device where it is located through the communication module to timely mitigate the impact caused by the attack; otherwise, maintain the normal communication of the IoT device where it is located. Attack detection is mainly divided into two stages:

[0083] I. Discriminate attacks: The SVM classifier is a powerful machine learning model. By learning the features of normal packets and attack datagrams, it can classify new datagrams with high accuracy to determine whether the packet is a normal packet or an attack packet.

[0084] II. Block attacks: Once the SVM classifier determines that a certain packet is an attack packet, then use the communication module to block the communication. One of the methods to block the attack is to intercept all communications of the source IP address, which means that any packet initiated from this source IP will be blocked, thus effectively cutting off the attacker's communication channel.

[0085] In the description of the present invention, "a plurality of" means at least two, such as two, three, etc., unless otherwise clearly and specifically defined.

[0086] The technical features of the above-described embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above-described embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0087] The above-described embodiments only express several implementation manners of the present invention, and their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the invention. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the appended claims.

Claims

1. An efficient intrusion detection method for Internet of Things network based on deep learning network, characterized in that: The communication module is used to manage all IoT devices in the IoT network. The IoT network efficient intrusion detection method based on deep learning network is implemented in the IoT devices, including: Extracting data features based on data packets sent by the communication module and converting the data features into feature vectors; Using a stacked asymmetric deep autoencoder to output encoding features according to a feature vector, and inputting the encoding features into an SVM classifier, the SVM classifier outputs an intrusion detection result; the encoder in the stacked asymmetric deep autoencoder connects the input and output of the encoder through a residual, and the decoder in the stacked asymmetric deep autoencoder uses an attention mechanism to weight the output of the encoder; If the intrusion detection result is that the data packet is an attack data packet, all communications of the IoT device are cut off through the communication module; otherwise, the normal communication of the IoT device is maintained.

2. According to claim 1, the method for efficient intrusion detection of the Internet of Things network based on deep learning network is characterized in that: The communication module includes a connection module, a network simulation module and an interface module; The connection module receives an original bit stream from the Internet of Things network, converts the original bit stream into a data packet, and sends the data packet to the network simulation module; it is also used to receive a data packet from the network simulation module, convert the data packet into an original bit stream, and send the original bit stream to the Internet of Things network; The network simulation module receives data packets from the connection module and forwards the data packets to the interface module; it is also used to receive data packets from the interface module and forward the data packets to the connection module; The interface module creates a data packet switching interface and implements data interaction between the network simulation module and the Internet of Things device through the data packet switching interface.

3. According to claim 1, the method for efficient intrusion detection of the Internet of Things network based on deep learning network is characterized in that: The data features include features in six dimensions, namely source IP, target IP, data value, IoT device activity time, transmission rate and receiving rate.

4. The method for efficiently detecting intrusion in an Internet of Things network based on a deep learning network according to claim 2 is characterized in that: The step of converting the data features into feature vectors includes: Use probability distribution to process source IP, target IP, IoT device activity time, transmission rate, and receiving rate respectively to obtain corresponding eigenvalues; Use the word embedding model to process the data value and obtain the corresponding feature value; The eigenvalues ​​corresponding to the features of the six dimensions are combined to obtain the eigenvector.

5. According to claim 1, the method for efficient intrusion detection of the Internet of Things network based on deep learning network is characterized in that: The loss function in the SVM classifier training process is defined as follows: Where LossFunction represents the function function, λ represents the regularization parameter, w represents the weight vector of the SVM classifier to be trained, ||·|| 2 represents the L2 norm, n represents the total number of training samples, y i represents the true label of the i-th training sample, <x i ,w> represents the predicted value calculated by the SVM classifier using the weight vector w and the encoded features of the i-th training sample.

6. The method for efficient intrusion detection of the Internet of Things network based on deep learning network according to claim 1 is characterized in that: The stacked asymmetric deep autoencoder comprises multiple layers of asymmetric deep autoencoders; The encoder in each layer of the asymmetric deep autoencoder connects the input and output of the encoder through a residual connection, including: z b l =σ b (W b l x l +b b l ) h l =z b l +x l In the formula, h l represents the output of the encoder in the l-th layer asymmetric deep autoencoder, z b l represents the intermediate features of the encoder in the l-th layer asymmetric deep autoencoder, x l represents the input of the encoder in the l-th layer asymmetric deep autoencoder, σ b (·) represents the nonlinear transformation operation of the encoder in the l-th layer asymmetric deep autoencoder, W b l represents the weight of the encoder in the l-th layer asymmetric deep autoencoder, b b l represents the bias of the encoder in the l-th layer asymmetric deep autoencoder; The decoder in each layer of the asymmetric deep autoencoder uses an attention mechanism to weight the encoder output, including: z j l =σ j (W j l h l +b j l ) s l =z j l +h l a l =softmax(s l ) In the formula, z j l represents the intermediate features of the decoder in the l-th layer asymmetric deep autoencoder, σ j (·) represents the nonlinear transformation operation of the decoder in the l-th layer asymmetric deep autoencoder, W j l represents the weight of the decoder in the l-th layer asymmetric deep autoencoder, b j l represents the bias of the decoder in the l-th layer asymmetric deep autoencoder, s l represents the similarity score between the intermediate features of the encoder and the input of the encoder, softmax(·) represents the softMax function, and a l represents the attention weight, x l+1 represents the output of the decoder in the l-th layer asymmetric deep autoencoder, that is, the input of the encoder in the l+1-th layer asymmetric deep autoencoder, q represents the q-th dimension, represents the attention weight a l The value of the qth dimension in , represents the input h of the decoder in the l-th layer asymmetric deep autoencoder l The value of the qth dimension in .