Lightweight flow detection method based on migration active learning

By adopting a lightweight traffic detection method based on migration active learning in the Internet of Things malicious traffic detection, the dependence problem of feature selection and large amount of labeled data in the prior art is solved, and more efficient malicious traffic detection accuracy and lower sample labeling cost are achieved.

CN120200861AActive Publication Date: 2025-06-24CHINA UNIV OF MINING & TECH (BEIJING)
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510686470.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-06-24
Estimated Expiration
2045-05-27

AI Technical Summary

Technical Problem

The prior art relies on feature selection and a large number of labeled samples in the detection of malicious traffic in IoT, resulting in poor detection performance and high sample labeling costs.

Method used

A lightweight traffic detection method based on transfer active learning is adopted. By pre-training malicious traffic detection models outside the target domain, the dependence on large-scale annotation data is reduced, and some samples are selected for annotation using active learning strategies to avoid overfitting.

Benefits of technology

It improves the detection accuracy of malicious traffic detection models for malicious traffic, reduces sample annotation costs, and avoids the problem of quickly fitting the model on small sample data sets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200861A_ABST
    Figure CN120200861A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of malicious traffic detection, and provides a lightweight traffic detection method based on migration active learning. In the method, a selection sample set and a test sample set are constructed based on a target domain traffic packet, samples are randomly selected from the selection sample set to construct a first labeled sample set, and other samples construct an unlabeled sample set; in a first training period, circularly training a malicious traffic detection model # imgabs0 # which is generated based on source domain traffic packet pre-training and migrated to a target domain until a model index of the malicious traffic detection model # imgabs1 # on the test sample set meets a first condition, and migrating training samples in the first marked sample set to a second marked sample set; and in a second training period, circularly updating the model parameters of the malicious traffic detection model # imgabs2 # trained in the first training period until the model indexes of the malicious traffic detection model # imgabs3 # on the test sample set meet a second condition, and performing malicious traffic detection through the trained malicious traffic detection model # imgabs4 #.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of malicious traffic detection, and particularly to a lightweight traffic detection method based on transfer active learning. Background Art

[0002] With the rapid development of technologies such as wireless communication, edge computing, and intelligent sensing, the Internet of Things (IoT) and various IoT devices have been widely used, enabling efficient communication and data exchange. Interacting with the IoT through mobile devices has provided convenience for various fields such as healthcare, transportation, and smart homes. However, with the rapid development and popularization of the IoT, IoT security issues have become increasingly prominent, among which malicious program propagation, vulnerability risks, malicious attacks, etc. are particularly prominent.

[0003] For IoT malicious traffic detection, since technologies based on ports and the like have started to fail, methods such as machine learning and deep learning have been planned and summarized as the mainstream of malicious traffic detection. However, the performance of machine learning-based methods depends on the effectiveness of feature selection, which in turn depends on expert experience and requires a large amount of time. Although deep learning-based methods can automatically extract features from raw data without relying on manual feature selection, the training of deep learning models depends on a large number of labeled samples, and it is extremely difficult to train a high-performance model using a small number of labeled samples. In a real IoT environment, the cost of sample annotation is extremely high, and deep learning models with a large number of model parameters are prone to quickly fitting the data when trained on a small sample dataset and perform poorly in the prediction set. Summary of the Invention

[0004] The purpose of this application is to provide a lightweight traffic detection method based on transfer active learning to solve or alleviate the problems existing in the above-mentioned prior art.

[0005] To achieve the above purpose, this application provides the following technical solutions: This application provides a lightweight traffic detection method based on transfer active learning, including: Construct a selected sample set and a test sample set based on the target domain Pcap traffic packets, and randomly select multiple training samples from the selected sample set to construct a first labeled sample set , and the remaining samples are used to construct an unlabeled sample set ; In the first training cycle, continuously train the malicious traffic detection model pre-trained based on the source domain Pcap traffic packets and migrated to the target domain , until the model metrics of the malicious traffic detection model meet the first condition on the test sample set, and transfer the training samples in the first labeled sample set to the second labeled sample set ; In a single cycle of the first training period: Based on the first labeled sample set The trained malicious traffic detection model Obtain a batch of unlabeled samples from the unlabeled sample set through entropy sampling and update the first labeled sample set and the unlabeled sample set respectively, and use the updated first labeled sample set to train the malicious traffic detection model ; among them, the malicious traffic detection model is a lightweight model of the malicious traffic detection model ; In the second training period, cyclically update the model parameters of the malicious traffic detection model trained in the first training period until the model metrics of the malicious traffic detection model on the test sample set meet the second condition, and perform malicious traffic detection through the trained malicious traffic detection model ; In a single cycle of the second training period: Based on the malicious traffic detection model Obtain a batch of unlabeled samples from the updated unlabeled sample set through confidence sampling and update the second labeled sample set and use the updated second labeled sample set to train the malicious traffic detection model .

[0006] Preferably, convert both the malicious traffic and the benign traffic included in the preprocessed target domain Pcap traffic packet into grayscale images, divide them into a selection sample set and a test sample set, and randomly select multiple grayscale images from the selection sample set to construct the first labeled sample set , and construct the unlabeled sample set from the remaining grayscale images in the selection sample set .

[0007] Preferably, convert both the malicious traffic and the benign traffic included in the preprocessed source domain Pcap traffic packet into grayscale images to construct a source domain training set; In the source domain, pre-train the malicious traffic detection model through the source domain training set, and transfer the obtained malicious traffic detection model with pre-trained weight parameters to the target domain.

[0008] Preferably, in a single cycle of the first training period, in the target domain, Based on the first labeled sample set The trained malicious traffic detection model Calculate the entropy value of the prediction result of each sample in the unlabeled sample set, and select the samples with entropy value greater than the first threshold to label them and add them to the first labeled sample set to update the first labeled sample set; Use the updated first labeled sample set to train the malicious traffic detection model with pre-trained weight parameters and calculate its model metrics on the test sample set. Preferably, in a single cycle of the first training period: When updating the first labeled sample set

[0009] synchronously subtract the corresponding samples from the unlabeled sample set to update the unlabeled sample set; Responding to the model metrics of the malicious traffic detection model with pre-trained weight parameters not meeting the first condition, update the model parameters of the malicious traffic detection model through the updated first labeled sample set; Based on the malicious traffic detection model with updated model parameters obtain a batch of unlabeled samples from the updated unlabeled sample set again through entropy sampling to update the updated first labeled sample set and retrain the malicious traffic detection model with pre-trained weight parameters through the first labeled sample set after the second update, and calculate its model metrics on the test sample set.

[0010] Preferably, in a single cycle of the second training period: Train the malicious traffic detection model through the second labeled sample set and calculate the confidence of the prediction result of each sample in the updated unlabeled sample set based on the obtained malicious traffic detection model and select the samples with confidence less than the second threshold to label them and add them to the second labeled sample set to update the second labeled sample set; Use the updated second labeled sample set ​Retrain the malicious traffic detection model and calculate its model metrics on the test sample set.

[0011] Preferably, in a single cycle of the second training period: When updating the second labeled sample set subtract the corresponding number of samples from the updated unlabeled sample set simultaneously to re-update the updated unlabeled sample set ; In response to the model metrics of the malicious traffic detection model not meeting the second condition on the test sample set, update the model parameters of the malicious traffic detection model through the updated second labeled sample set ; Based on the malicious traffic detection model with updated model parameters obtain a batch of unlabeled samples again from the re-updated unlabeled sample set by confidence sampling to update the updated second labeled sample set again, and retrain the malicious traffic detection model through the second labeled sample set after the re-update and calculate its model metrics on the test sample set.

[0012] Preferably, the malicious traffic detection model and the malicious traffic detection model are constructed based on the same network architecture and both include: a convolutional layer, a batch normalization layer (Batch Normalization, abbreviated as BN), a rectified linear unit layer (Rectified Linear Unit, abbreviated as Relu), an attention mechanism module (CA), a depthwise convolutional layer DWConv (Depthwise Convolution), a max pooling layer, a global average pooling layer, a fully connected layer, and a Softmax activation function.

[0013] Preferably, in the malicious traffic detection model the input feature successively passes through a convolutional layer with a kernel size of 3, a stride of 1, a padding of 1, and 16 channels, a BN layer, and a Relu layer to obtain an output feature ; the output feature then passes through a CA attention module to obtain an output feature ; the output feature Then, it successively passes through a depthwise convolutional layer DWConv with a kernel size of 3, a stride of 1, a padding of 1, and 16 channels, a BN layer, and a Relu layer to obtain the output feature ; The output feature Then, it successively passes through a convolutional layer with a kernel size of 1, a stride of 1, no padding, and 32 channels, a BN layer, and a Relu layer to obtain the output feature ; The output feature Then, it passes through a CA attention module to obtain the output feature ; The output feature Then, it successively passes through a depthwise convolutional layer DWConv with a kernel size of 3, a stride of 1, a padding of 1, and 32 channels, a BN layer, and a Relu layer to obtain the output feature ; The output feature Then, it successively passes through a convolutional layer with a kernel size of 1, a stride of 1, no padding, and 64 channels, a BN layer, and a Relu layer to obtain the output feature ; The output feature Then, it passes through a max pooling layer with a pooling window of 2 to obtain the output feature ; The output feature Then, it successively passes through a global average pooling layer, a fully connected layer, and a Softmax activation function layer to obtain the output result of whether it is benign traffic or malicious traffic.

[0014] Preferably, in the malicious traffic detection model the input feature successively passes through a convolutional layer with a kernel size of 3, a stride of 1, a padding of 1, and 16 channels, a BN layer, and a Relu layer to obtain the input feature ; The input feature Then, it passes through a CA attention module to obtain the input feature ; The input feature Then, it successively passes through a depthwise convolutional layer DWConv with a kernel size of 3, a stride of 1, a padding of 1, and 16 channels, a BN layer, and a Relu layer to obtain the input feature ; The input feature Then, it successively passes through a convolutional layer with a kernel size of 1, a stride of 1, no padding, and 32 channels, a BN layer, and a Relu layer to obtain the input feature ; The input feature Then, it passes through a CA attention module to obtain the input feature ; The input feature Then, it successively passes through a depthwise convolutional layer DWConv with a convolutional kernel size of 3, a stride of 1, a padding of 1, and 32 channels, a BN layer, and a Relu layer to obtain the input features ; The input features Then, it successively passes through a convolutional layer with a convolutional kernel size of 1, a stride of 1, no padding, and 64 channels, a BN layer, and a Relu layer to obtain the input features ; The input features Then, it passes through a max-pooling layer with a pooling window of 2 to obtain the input features ; The input features Then, it passes through a CA attention module to obtain the input features ; The input features Then, it successively passes through a depthwise convolutional layer DWConv with a convolutional kernel size of 3, a stride of 1, a padding of 1, and 64 channels, a BN layer, and a Relu layer to obtain the input features ; The input features Then, it successively passes through a convolutional layer with a convolutional kernel size of 1, a stride of 1, no padding, and 128 channels, a BN layer, and a Relu layer to obtain the input features ; The input features Then, it passes through a max-pooling layer with a pooling window of 2 to obtain the input features ; The input features Then, it passes through a CA attention module to obtain the input features ; The input features Then, it successively passes through a depthwise convolutional layer DWConv with a convolutional kernel size of 3, a stride of 1, a padding of 1, and 128 channels, a BN layer, and a Relu layer to obtain the input features ; The input features Then, it passes through a convolutional layer with a convolutional kernel size of 1, a stride of 1, no padding, and 256 channels, a BN layer, and a Relu layer to obtain the input features ; The input features Then, it successively passes through a global average pooling layer, a fully connected layer, and a Softmax activation function layer to obtain the output result of whether it is benign traffic or malicious traffic

[0015] Beneficial effects: In the lightweight traffic detection method based on transfer active learning provided by the embodiments of the present application, a selection sample set and a test sample set are constructed based on the target domain Pcap traffic packets, and multiple training samples are randomly selected from the selection sample set to construct the first labeled sample set , and the remaining samples are used to construct the unlabeled sample set ; In the first training cycle, repeatedly train the malicious traffic detection model that is pre-trained based on source domain Pcap traffic packets and migrated to the target domain , until the model metrics of the malicious traffic detection model on the test sample set meet the first condition, and transfer the training samples in the first labeled sample set to the second labeled sample set ; In a single loop cycle of the first training cycle: Based on the malicious traffic detection model trained on the first labeled sample set (the lightweight model of the malicious traffic detection model ), obtain a batch of unlabeled samples from the unlabeled sample set through entropy sampling to update the first labeled sample set and the unlabeled sample set respectively, and use the updated first labeled sample set to train the malicious traffic detection model ; In the second training cycle, repeatedly update the model parameters of the malicious traffic detection model trained in the first training cycle , until the model metrics of the malicious traffic detection model on the test sample set meet the second condition, and perform malicious traffic detection through the trained malicious traffic detection model ; In a single loop cycle of the second training cycle: Based on the malicious traffic detection model , obtain a batch of unlabeled samples from the updated unlabeled sample set through confidence sampling to update the second labeled sample set , and use the updated second labeled sample set to train the malicious traffic detection model .

[0016] Thus, by pre-training the malicious traffic detection model B outside the target domain to learn the general feature representation of traffic, the learning process of the malicious traffic detection model B pre-trained and migrated to the target domain becomes more efficient, effectively reducing the dependence on a large amount of labeled data during the training process; through the lightweight model of the malicious traffic detection model B (the malicious traffic detection model A), after selecting some samples for annotation based on the active learning strategy, and using these samples to adjust the pre-training parameters of the malicious traffic detection model pre-trained and migrated to the target domain, effectively avoiding the overfitting problem of the malicious traffic detection model during the training process.

[0017] The lightweight model of the malicious traffic detection model B (malicious traffic detection model A) is used for active learning to select high-information samples, and the model parameters of the pre-trained malicious traffic detection model B migrated to the target domain are cyclically updated, enabling the malicious traffic detection model B to quickly adapt to the detection task of the target domain.

[0018] Furthermore, by training the malicious traffic detection model outside the target domain and migrating it to the target domain, the model parameters of the malicious traffic detection model B migrated to the target domain are cyclically updated using the samples actively learned and selected by the lightweight model of the malicious traffic detection model B (malicious traffic detection model A). By combining transfer learning, deep learning, and active learning to select a small number of samples for annotation, the problems of difficult sample annotation during the training process of the malicious traffic detection model B and easy overfitting during training on a small sample dataset are effectively solved, and the detection accuracy of the malicious traffic detection model B for malicious traffic is effectively improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The accompanying drawings forming a part of this application are used to provide a further understanding of this application. The schematic embodiments and descriptions thereof of this application are used to explain this application and do not constitute an improper limitation of this application. Among them: Figure 1 FIG. is a schematic flowchart of a lightweight traffic detection method based on transfer active learning provided by some embodiments of this application; Figure 2 FIG. is a schematic diagram of sample selection of a malicious traffic detection model provided by some embodiments of this application; Figure 3 FIG. is a schematic diagram of the network structure of the malicious traffic detection model A provided by some embodiments of this application; Figure 4 FIG. is a schematic diagram of the network structure of the malicious traffic detection model B provided by some embodiments of this application; Figure 5 FIG. is a schematic diagram of the prediction accuracy of the malicious traffic detection model B provided by an embodiment of this application ; Figure 6 FIG. is a schematic diagram of the F1 score of the malicious traffic detection model B provided by an embodiment of this application ; DETAILED DESCRIPTION OF THE EMBODIMENTS

[0020] The present application will be described in detail below with reference to the accompanying drawings and in conjunction with embodiments. Each example is provided by way of explanation of the present application rather than a limitation thereof. In fact, those skilled in the art will appreciate that modifications and variations can be made to the present application without departing from the scope or spirit thereof. For example, features shown or described as part of one embodiment can be used in another embodiment to yield yet another embodiment. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the embodiments of the present invention shall fall within the scope of protection of the embodiments of the present invention.

[0021] In the existing Internet of Things (IoT) malicious traffic detection process, the cost of sample annotation in a real IoT environment is extremely high. Deep learning model training relies on a large number of labeled samples. It is very difficult to train a high-performance detection model with a small number of labeled samples, and a deep learning model with a large number of model parameters is prone to overfitting quickly when trained on a dataset with a small number of labeled samples, resulting in poor detection performance of the model.

[0022] Based on this, the embodiments of the present application provide a lightweight traffic detection method based on transfer active learning, as Figures 1 to 6 shown. The method includes: Step S101, constructing a selection sample set and a test sample set based on the target domain Pcap traffic packets, and randomly selecting a plurality of training samples from the selection sample set to construct a first labeled sample set , and constructing an unlabeled sample set for the remaining samples .

[0023] The target domain Pcap traffic packets contain malicious traffic packets and benign traffic packets. By converting the preprocessed target domain Pcap traffic packets into grayscale images, the grayscale images are divided into a selection sample set and a test sample set according to a ratio of 9:1. In the selection sample set, a plurality of grayscale images of each malicious traffic type and benign traffic type are randomly selected and labeled to construct a first labeled sample set ; the grayscale images of the remaining malicious traffic types and benign traffic types in the selection sample set are used to construct an unlabeled sample set .

[0024] Specifically, when preprocessing the target domain Pcap traffic packets, the target domain Pcap traffic packets are segmented into multiple session data according to IP, source port, destination IP, destination port, and transport layer protocol, the duplicate data and blank data in the session data are deleted, and the information (such as: mac address) that affects the traffic classification result is deleted, thereby obtaining the preprocessed traffic data.

[0025] The preprocessed Pacp traffic packet is processed to obtain traffic data. The traffic data is intercepted according to a fixed length of 784 bytes, and each byte of the intercepted traffic data is converted into a decimal number. Then, the 784 converted decimal numbers are converted into a two-dimensional array. Next, the two-dimensional array is converted into a grayscale image with a size of Finally, the grayscale image is divided into a selected sample set and a test sample set according to a ratio of 9:1.

[0026] Step S102: In the first training cycle, continuously train the malicious traffic detection model pre-trained based on the source-domain Pcap traffic packet and migrated to the target domain until the model metrics of the malicious traffic detection model on the test sample set meet the first condition, and transfer the training samples in the first labeled sample set to the second labeled sample set .

[0027] In this application, the malicious traffic detection model A and the malicious traffic detection model B are built based on the same network architecture, and the malicious traffic detection model is a lightweight model of the malicious traffic detection model . Both the malicious traffic detection model A and the malicious traffic detection model B can detect malicious traffic, and both include a convolutional layer, a batch normalization layer (BatchNormalization, abbreviated as BN), a rectified linear unit layer (Rectified Linear Unit, abbreviated as Relu), an attention mechanism module (CA), a depthwise convolution layer DWConv (Depthwise Convolution), a max pooling layer, a global average pooling layer, a fully connected layer, and a Softmax activation function.

[0028] For the malicious traffic detection model , the input feature (traffic to be detected) sequentially passes through a convolutional layer with a kernel size of 3, a stride of 1, a padding of 1, and 16 channels, a BN layer, and a Relu layer to obtain an output feature ; the output feature then passes through a CA attention module to obtain an output feature ; the output feature then sequentially passes through a depthwise convolution layer DWConv with a kernel size of 3, a stride of 1, a padding of 1, and 16 channels, a BN layer, and a Relu layer to obtain an output feature ; the output feature Then, it successively passes through a convolutional layer with a kernel size of 1, a stride of 1, no padding, and 32 channels, a BN layer, and a Relu layer to obtain the output features ; The output features Then pass through a CA attention module to obtain the output features ; The output features Then, it successively passes through a depthwise convolutional layer DWConv with a kernel size of 3, a stride of 1, padding of 1, and 32 channels, a BN layer, and a Relu layer to obtain the output features ; The output features Then, it successively passes through a convolutional layer with a kernel size of 1, a stride of 1, no padding, and 64 channels, a BN layer, and a Relu layer to obtain the output features ; The output features Then pass through a max pooling layer with a pooling window of 2 to obtain the output features ; The output features Then, it successively passes through a global average pooling layer, a fully connected layer, and a Softmax activation function layer to obtain the output result of whether it is benign traffic or malicious traffic.

[0029] For the malicious traffic detection model , The input features (traffic to be detected) successively pass through a convolutional layer with a kernel size of 3, a stride of 1, padding of 1, and 16 channels, a BN layer, and a Relu layer to obtain the input features ; The input features Then pass through a CA attention module to obtain the input features ; The input features Then, it successively passes through a depthwise convolutional layer DWConv with a kernel size of 3, a stride of 1, padding of 1, and 16 channels, a BN layer, and a Relu layer to obtain the input features ; The input features Then, it successively passes through a convolutional layer with a kernel size of 1, a stride of 1, no padding, and 32 channels, a BN layer, and a Relu layer to obtain the input features ; The input features Then pass through a CA attention module to obtain the input features ; The input features Then, it successively passes through a depthwise convolutional layer DWConv with a kernel size of 3, a stride of 1, padding of 1, and 32 channels, a BN layer, and a Relu layer to obtain the input features ; The input features Then, it successively passes through a convolutional layer with a kernel size of 1, a stride of 1, no padding, and 64 channels, a BN layer, and a Relu layer to obtain the input features ; The input features Then pass through a max pooling layer with a pooling window of 2 to obtain the input features ; The input features Then pass through a CA attention module to obtain the input features ; The input features Then it successively passes through a depthwise convolutional layer DWConv with a kernel size of 3, a stride of 1, padding of 1, and 64 channels, a BN layer, and a Relu layer to obtain the input features ; The input features Then it successively passes through a convolutional layer with a kernel size of 1, a stride of 1, no padding, and 128 channels, a BN layer, and a Relu layer to obtain the input features ; The input features Then pass through a max pooling layer with a pooling window of 2 to obtain the input features ; The input features Then pass through a CA attention module to obtain the input features ; The input features Then it successively passes through a depthwise convolutional layer DWConv with a kernel size of 3, a stride of 1, padding of 1, and 128 channels, a BN layer, and a Relu layer to obtain the input features ; The input features Then it passes through a convolutional layer with a kernel size of 1, a stride of 1, no padding, and 256 channels, a BN layer, and a Relu layer to obtain the input features ; The input features Then it successively passes through a global average pooling layer, a fully connected layer, and a Softmax activation function layer to obtain the output result of whether it is benign traffic or malicious traffic.

[0030] In this application, both the malicious traffic and benign traffic included in the preprocessed source domain Pcap traffic packets are converted into grayscale images to construct the source domain training set. Among them, according to the same method as the target domain Pcap traffic packets, the preprocessed source domain Pcap traffic packets are converted into grayscale images to construct the source domain training set. Then, in the source domain, the constructed malicious traffic detection model is pre-trained to obtain a malicious traffic detection model with pre-trained weight parameters And migrate it to the target domain. By pre-training the malicious traffic detection model B outside the target domain, the general feature representation of the traffic is learned, making the learning process of the malicious traffic detection model B pre-trained and generated in the target domain more efficient and effectively reducing the dependence on a large amount of labeled data during the training process.

[0031] The malicious traffic detection model with pre-trained weight parameters After migrating it to the target domain, based on the active learning strategy, the lightweight model (malicious traffic detection model A) of the malicious traffic detection model B selects some samples for annotation, and uses the annotated samples to adjust the parameters of the malicious traffic detection model with pre-trained weight parameters for the first time, effectively preventing overfitting of the malicious traffic detection model during training. Among them, in a single cycle of the first training period: based on the first labeled sample set The trained malicious traffic detection model Obtains a batch of unlabeled samples from the unlabeled sample set through entropy sampling to update the first labeled sample set and the unlabeled sample set respectively, and uses the updated first labeled sample set to train the malicious traffic detection model .

[0032] Specifically, first, in the target domain, through the active learning of the malicious traffic detection model A, the first labeled sample set is updated. Among them, based on the first labeled sample set the malicious traffic detection model is trained; based on the first labeled sample set the trained malicious traffic detection model calculates the entropy value of the prediction result of each sample in the unlabeled sample set , and sorts the entropy values of the prediction results of each sample from largest to smallest, and selects the samples with entropy values greater than the preset entropy value (i.e., the first threshold) to be labeled and added to the first labeled sample set to update the first labeled sample set . Here, it should be noted that when updating the first labeled sample set , the corresponding samples are synchronously subtracted from the unlabeled sample set to update the unlabeled sample set .

[0033] Then, use the updated first labeled sample set For a malicious traffic detection model with pre-trained weight parameters Train it and calculate its model metrics on the test sample set. That is, use the updated first labeled sample set To initially adjust the model parameters of the malicious traffic detection model with pre-trained weight parameters And test the malicious traffic detection model after the initial adjustment of the model parameters through the test sample set That is, calculate the model metrics of the malicious traffic detection model after the initial adjustment of the model parameters On the test sample set.

[0034] In a specific example, input the unlabeled samples In the unlabeled sample set Into the malicious traffic detection model A, and predict the unlabeled samples through the malicious traffic detection model A The probability of being of class Is ; According to the formula:

[0035] Calculate the entropy value of the prediction result of the unlabeled sample Wherein, Represents the serial number of the traffic type, Is a positive integer, Indicates that the unlabeled sample is predicted by the malicious traffic detection model A Is the Th Traffic type. For example, Indicates that the unlabeled sample is predicted by the malicious traffic detection model A Is the Traffic type (benign), Indicates that the unlabeled sample is predicted by the malicious traffic detection model A Is the Traffic type (malicious). It should be noted that in this application, malicious traffic can be divided into multiple different types, that is, there can be multiple malicious traffic types, while there is only one benign traffic type.

[0036] In another specific example, test the malicious traffic detection model after the initial adjustment of the model parameters with the test sample set And calculate its prediction accuracy And F1 score When the prediction accuracy And F1 score At least one is less than or equal to 50%, then through the updated first labeled sample set Update the model parameters of the malicious traffic detection model A. That is, when the model metrics of the malicious traffic detection model with pre-trained weight parameters on the test sample set do not meet the first condition, update the first labeled sample set to update the model parameters of the malicious traffic detection model .

[0037] Then, based on the malicious traffic detection model with updated model parameters obtain a batch of unlabeled samples again from the updated unlabeled sample set through entropy sampling to update the updated first labeled sample set again, and use the first labeled sample set after the second update to retrain the malicious traffic detection model with pre-trained weight parameters and calculate its model metrics on the test sample set. That is, use the first labeled sample set after the second update to initially adjust the model parameters of the malicious traffic detection model with pre-trained weight parameters again, and calculate the prediction accuracy of the malicious traffic detection model after the second initial adjustment on the test sample set and the F1 score . Loop in this way until the prediction accuracy and the F1 score are both greater than 50%, and the initial adjustment of the model parameters of the malicious traffic detection model with pre-trained weight parameters migrated to the target domain is completed.

[0038] Here, it should be noted that in the first training cycle, each time the model parameters of the malicious traffic detection model are adjusted using the updated first labeled sample set , it is based on the pre-trained parameters of the malicious traffic detection model with pre-trained weight parameters migrated to the target domain . That is, the adjustment results of the model parameters of the malicious traffic detection model by the previous first labeled sample set are not retained, but the initial adjustment is made based on the pre-trained parameters of the malicious traffic detection model with pre-trained weight parameters migrated to the target domain .

[0039] Therefore, after the lightweight model (malicious traffic detection model A) of the malicious traffic detection model B selects some samples for annotation based on the active learning strategy, and uses these samples to pre-train and migrate the malicious traffic detection model to the target domain​ The pre-trained parameters are initially adjusted to effectively avoid overfitting problems of the malicious traffic detection model during the training process.

[0040] Step S103: In the second training cycle, the model parameters of the malicious traffic detection model trained in the first training cycle are cyclically updated until the model metrics of the malicious traffic detection model B on the test sample set meet the second condition, and malicious traffic detection is performed using the trained malicious traffic detection model B.

[0041] In the first training cycle, by using active learning of the lightweight model (malicious traffic detection model A) of the malicious traffic detection model B to select high-information samples, the model parameters of the malicious traffic detection model B generated by pre-training transferred to the target domain are initially updated (i.e., initially adjusted), enabling the malicious traffic detection model B to quickly adapt to the detection tasks in the target domain.

[0042] Then, the training samples in the first labeled sample set are transferred to the constructed empty sample set to generate a second labeled sample set , and the cyclic update of the second labeled sample set is used to achieve cyclic adjustment (i.e., cyclic update) of the model parameters of the malicious traffic detection model trained in the first training cycle . Among them, in a single cycle of the second training cycle: Based on the malicious traffic detection model B, a batch of unlabeled samples are obtained through confidence sampling from the updated unlabeled sample set to update the second labeled sample set , and the malicious traffic detection model is trained using the updated second labeled sample set .

[0043] Specifically, within a single cycle of the second training cycle, the malicious traffic detection model obtained in the first training cycle is trained using the second labeled sample set , and based on the obtained malicious traffic detection model , the confidence of the prediction results of each sample in the unlabeled sample set is calculated, and samples with a confidence less than the second threshold are selected and labeled and added to the second labeled sample set to update the second labeled sample set . Then, the malicious traffic detection model is trained using the updated second labeled sample set Retrain and calculate the model index on the test sample set. When updating, synchronize the updated unlabeled sample set Subtract the corresponding samples to update the unlabeled sample set Update again.

[0044] That is, use the updated second labeled sample set For the second labeled sample set before updating Trained malicious traffic detection model The model parameters are adjusted twice, and the malicious traffic detection model after the model parameters are adjusted twice is tested through the test sample set , that is, the malicious traffic detection model after the calculation model parameters are adjusted twice Model metrics on the test set.

[0045] In a specific example, the unlabeled sample set Unlabeled samples in Input the malicious traffic detection model B, and use the malicious traffic detection model B to predict the unlabeled samples For the Traffic categories The probability of . According to the formula:

[0046] Calculate unlabeled samples The traffic category predicted to have the highest probability by malicious traffic detection model B Probability .in, Indicates that unlabeled samples are predicted by malicious traffic detection model B For the For example, three types of malicious traffic are classified, so there are 3 types of malicious traffic. hour, , indicating the sample The probability of being classified as the first type of malicious traffic is 0.1; hour, , indicating the sample The probability of being classified as the second type of malicious traffic is 0.7; hour, , indicating the sample The probability of being classified as the third type of malicious traffic is 0.2. Therefore, the probability of sample x being predicted as the second type of malicious traffic is the largest. For the second type of malicious traffic,

[0047] In another specific example, the malicious traffic detection model with adjusted model parameters is tested using a test sample set to calculate its prediction accuracy and F1 score When the prediction accuracy and F1 score are at least one less than or equal to 99%, then the malicious traffic detection model trained using the second labeled sample set before update has its model parameters adjusted again. That is, when the model metrics of the malicious traffic detection model on the test sample set do not meet the second condition, the model parameters of the malicious traffic detection model are updated using the updated second labeled sample set .

[0048] Then, based on the malicious traffic detection model with updated model parameters a batch of unlabeled samples are obtained again through confidence sampling from the further updated unlabeled sample set to update the updated second labeled sample set again, and the malicious traffic detection model is retrained using the second labeled sample set after the second update, and its model metrics on the test sample set are calculated .

[0049] That is, the malicious traffic detection model with the model parameters updated in the previous time has its model parameters adjusted again using the second labeled sample set after the second update , and the prediction accuracy of the malicious traffic detection model with the model parameters adjusted again on the test sample set and F1 score are calculated. This cycle continues until both the prediction accuracy and F1 score are greater than 99% or all samples in the unlabeled sample set are labeled, and the finally obtained malicious traffic detection model is output for IoT malicious traffic detection

[0050] Thus, by training the malicious traffic detection model outside the target domain ​And migrate it to the target domain. Use the lightweight model of the malicious traffic detection model B (malicious traffic detection model A) to cyclically update the model parameters of the malicious traffic detection model B migrated to the target domain by actively learning the selected samples. Combine transfer learning, deep learning, and active learning to select a small number of samples for annotation, effectively solving the problems of difficult sample annotation during the training process of the malicious traffic detection model B and easy overfitting during training on a small sample dataset, and effectively improving the detection accuracy of the malicious traffic detection model B for malicious traffic.

[0051] In the description of the present invention, the terms "first" and "second" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include at least one of such features. In the description of the present invention, "a plurality of" means at least two, such as two, three, etc., unless otherwise specifically defined.

[0052] In the present invention, the terms "an embodiment", "some embodiments", "example", "specific example", or "some examples", etc. mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in any one or more embodiments or examples in a suitable manner.

[0053] The foregoing is only the preferred embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.

Claims

1. A lightweight traffic detection method based on transfer active learning, characterized in that Including: Construct a selected sample set and a test sample set based on the target domain Pcap traffic packets, and randomly select multiple training samples from the selected sample set to construct the first labeled sample set , and construct an unlabeled sample set from the remaining samples ; In the first training cycle, the malicious traffic detection model pre-trained based on source-domain Pcap traffic packets and migrated to the target domain is cyclically trained until the model metrics of the malicious traffic detection model on the test sample set meet the first condition, and the training samples in the first labeled sample set are migrated to the second labeled sample set ; In a single cycle of the first training period: Based on the first labeled sample set The trained malicious traffic detection model Obtain a batch of unlabeled samples from the unlabeled sample set by entropy sampling for the first labeled sample set and the unlabeled sample set and update them respectively, and use the updated first labeled sample set to train the malicious traffic detection model ; where the malicious traffic detection model is a lightweight model of the malicious traffic detection model ; In the second training cycle, the malicious traffic detection model trained in the first training cycle has its model parameters updated iteratively until the malicious traffic detection model meets the second condition in terms of the model metrics on the test sample set. The trained malicious traffic detection model is then used for malicious traffic detection; In a single cycle of the second training period: Based on the malicious traffic detection model Obtain a batch of unlabeled samples from the updated unlabeled sample set to update the second labeled sample set through confidence sampling and use the updated second labeled sample set to train the malicious traffic detection model .

2. The lightweight traffic detection method based on transfer active learning according to claim 1, characterized in that Convert both malicious traffic and benign traffic contained in the preprocessed target domain Pcap traffic packets into grayscale images, divide them into a selected sample set and a test sample set, and randomly select multiple grayscale images from the selected sample set to construct a first labeled sample set , and construct an unlabeled sample set from the remaining grayscale images in the selected sample set .

3. The lightweight traffic detection method based on transfer active learning according to claim 1, characterized in that Both the malicious traffic and the benign traffic included in the preprocessed source domain Pcap traffic packets are converted into grayscale images to construct a source domain training set; In the source domain, the malicious traffic detection model is pre-trained with the source domain training set and the obtained malicious traffic detection model with pre-trained weight parameters is migrated to the target domain.

4. The lightweight traffic detection method based on transfer active learning according to claim 1, characterized in that In a single cycle of the first training cycle, in the target domain Based on the first labeled sample set The trained malicious traffic detection model Calculate the entropy values of the prediction results of each sample in the unlabeled sample set, and select the samples whose entropy values are greater than the first threshold and label them, then add them to the first labeled sample set to update the first labeled sample set ; ​ With the updated first labeled sample set Train a malicious traffic detection model with pre-trained weight parameters and calculate its model metrics on the test sample set.

5. The lightweight traffic detection method based on transfer active learning according to claim 4, wherein In a single cycle of the first training cycle: When updating the first labeled sample set synchronously subtract the corresponding number of samples from the unlabeled sample set to update the unlabeled sample set ; In response to a malicious traffic detection model with pre-trained weight parameters the model metrics on the test sample set do not meet the first condition, and the updated first labeled sample set is used to update the model parameters of the malicious traffic detection model; Malicious traffic detection model based on updated model parameters From the updated unlabeled sample set Another batch of unlabeled samples is obtained again through entropy sampling for the updated first labeled sample set For re-updating, and through the first labeled sample set after re-updating The malicious traffic detection model with pre-trained weight parameters Is retrained, and its model metrics on the test sample set are calculated.

6. The lightweight traffic detection method based on transfer active learning according to claim 1, wherein In a single cycle of the second training cycle: Through the second labeled sample set Train the malicious traffic detection model And based on the obtained malicious traffic detection model Calculate the confidence of the prediction results of each sample in the updated unlabeled sample set And select the samples with a confidence less than the second threshold Label them and add them to the second labeled sample set To update the second labeled sample set ; With the updated second labeled sample set retrain the malicious traffic detection model and calculate its model metrics on the test sample set.

7. The lightweight traffic detection method based on transfer active learning according to claim 6, characterized in that, In a single cycle of the second training cycle: For the second labeled sample set when updating, synchronously subtract the corresponding number of samples from the updated unlabeled sample set to re-update the updated unlabeled sample set ; In response to the malicious traffic detection model The model metrics on the test sample set do not meet the second condition, and the updated second labeled sample set is used to update the model parameters of the malicious traffic detection model; Malicious traffic detection model based on updated model parameters From the re-updated unlabeled sample set A batch of unlabeled samples are obtained again through confidence sampling for the updated second labeled sample set For re-updating, and through the re-updated second labeled sample set For the malicious traffic detection model For retraining, and calculate its model metrics on the test sample set.

8. The lightweight traffic detection method based on transfer active learning according to any one of claims 1-7, characterized in that Malicious traffic detection model and malicious traffic detection model are constructed based on the same network architecture and both include: convolutional layer, batch normalization layer, rectified linear unit layer, attention mechanism module, depthwise convolutional layer DWConv, max pooling layer, global average pooling layer, fully connected layer, and Softmax activation function.

9. The lightweight traffic detection method based on transfer active learning according to claim 8, characterized in that Malicious traffic detection model In the input features are successively passed through a convolutional layer with a kernel size of 3, a stride of 1, a padding of 1, and 16 channels, a BN layer, and a Relu layer to obtain output features ; Output feature The output feature is obtained after passing through a CA attention module again ; Output feature Then, it passes through a depthwise convolutional layer DWConv with a convolutional kernel size of 3, a stride of 1, a padding of 1, and 16 channels, a BN layer, and a Relu layer in sequence to obtain the output feature ; Output feature Then, it passes through a convolutional layer with a kernel size of 1, a stride of 1, no padding, and 32 channels, a BN layer, and a Relu layer in sequence to obtain the output feature ; Output feature The output feature is obtained after passing through a CA attention module ; Output feature Then, it passes through a depthwise convolution layer DWConv with a convolution kernel size of 3, a stride of 1, a padding of 1, and 32 channels, a BN layer, and a Relu layer in sequence to obtain the output feature ; Output feature Then, it passes through a convolutional layer with a kernel size of 1, a stride of 1, no padding, and 64 channels, a BN layer, and a Relu layer in sequence to obtain the output feature ; Output feature The output feature is obtained by passing through a max pooling layer with a pooling window of 2 ; Output feature Then, it passes through a global average pooling layer, a fully connected layer, and a Softmax activation function layer in sequence to obtain the output result indicating whether it is benign traffic or malicious traffic.

10. The lightweight traffic detection method based on transfer active learning according to claim 8, characterized in that Malicious traffic detection model In the input feature The input features are obtained by passing through a convolution layer with a convolution kernel size of 3, a step size of 1, a padding of 1, and a channel number of 16, a BN layer, and a Relu layer. ; Input features Then pass through a CA attention module to get the input features ; Input features Then, the input features are obtained by passing through a deep convolution layer DWConv with a convolution kernel size of 3, a step size of 1, a padding of 1, and a channel number of 16, a BN layer, and a Relu layer. ; Input feature Then, it passes through a convolutional layer with a kernel size of 1, a stride of 1, no padding, and 32 channels, a BN layer, and a Relu layer in sequence to obtain the input feature ; Input features Then, the input features are obtained through a CA attention module ; Input feature Then, it passes through a depthwise convolutional layer DWConv with a convolutional kernel size of 3, a stride of 1, a padding of 1, and 32 channels, a BN layer, and a Relu layer in sequence to obtain the input feature ; Input features Then, it passes through a convolutional layer with a kernel size of 1, a stride of 1, no padding, and 64 channels, a BN layer, and a Relu layer in sequence to obtain the input features ; The input features Then, it passes through a max-pooling layer with a pooling window of 2 to obtain the input features ; The input features Then, it passes through a CA attention module to obtain the input features ; Input feature Then, it successively passes through a depthwise convolution layer DWConv with a convolution kernel size of 3, a stride of 1, a padding of 1, and 64 channels, a BN layer, and a Relu layer to obtain the input feature ; Input feature Then, it passes through a convolutional layer with a kernel size of 1, a stride of 1, no padding, and 128 channels, a BN layer, and a Relu layer in sequence to obtain the input feature ; Input features The input features are obtained through a max-pooling layer with a pooling window of 2 ; Input feature Then, through a CA attention module, the input feature is obtained ; The input feature Then, it successively passes through a depthwise convolution layer DWConv with a convolution kernel size of 3, a stride of 1, a padding of 1, and 128 channels, a BN layer, and a Relu layer to obtain the input feature ; Input feature The input feature is obtained by passing through a convolutional layer with a kernel size of 1, a stride of 1, no padding, and 256 channels, a BN layer, and a Relu layer ; Input features Then, it successively passes through a global average pooling layer, a fully connected layer, and a Softmax activation function layer to obtain the output result indicating whether it is benign traffic or malicious traffic.

Citation Information

Patent Citations

  • Metalearning-based small sample malicious network traffic detection method

    CN115174272A

  • Small sample malicious traffic classification method and system based on deep migration

    CN116049749A

  • Malicious traffic detection method and system based on transfer learning and knowledge distillation

    CN118540117A

  • Method and system for carrying out maching learning under data privacy protection

    EP3839790A1