Network intrusion detection method based on federal map neural network

By using the method of federated graph neural network and Dirichlet distribution partitioning local subgraphs in network intrusion detection, the problem of insufficient data privacy protection and model generalization capabilities is solved, efficient network intrusion detection is achieved, and detection accuracy and real-time performance are improved.

CN120223360APending Publication Date: 2025-06-27SHANGHAI UNIVERSITY OF ELECTRIC POWER

Patent Information

Application Number
CN202510254067.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-05
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

The existing technology has problems with insufficient data privacy protection and model generalization capabilities in network intrusion detection, especially in cross-organizational collaboration scenarios, data island phenomenon is serious, limiting the real-time detection effect of the model.

Method used

Using a network intrusion detection method based on federated graph neural network, the global graph data is divided into local subgraphs through Dirichlet distribution. Each client conducts model training locally and performs federated aggregation through the server. The GAT model is used to capture the topological relationship of network traffic, and combined with multi-dimensional features such as HTTP dual-stream byte distribution features to enhance detection accuracy.

Benefits of technology

It effectively protects data privacy, improves the generalization ability of the model and real-time detection effect, avoids the risks of single point of failure and data leakage, and improves the accuracy and accuracy of intrusion detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223360A_ABST
    Figure CN120223360A_ABST
Patent Text Reader

Abstract

The invention provides a network intrusion detection method based on a federated graph neural network, which comprises the following steps: carrying out graph structure modeling on network flow data, constructing a local sub-graph of each client, adopting a federated learning framework, carrying out graph neural network model training by the client locally through the local sub-graph, and obtaining a network intrusion detection result; and the encrypted data and model parameters are uploaded to the server, so that the potential safety hazard of data sharing is avoided. And the server aggregates the encrypted remainder set and the model parameter from each client, generates a global model parameter and an aggregated encrypted remainder set, and feeds back the global model parameter and the aggregated encrypted remainder set to the client to realize cross-client collaborative training. The encrypted data is decrypted by introducing the Chinese remainder theorem, so that the security and privacy of the data are ensured, and the feature reconstruction precision is improved at the same time. According to the method, the problem of data islands in cross-organization cooperation is effectively solved, and the real-time performance and accuracy of an intrusion detection system are improved on the premise of ensuring privacy protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of network security technology, and particularly relates to a network intrusion detection method based on a federated graph neural network. Background Art

[0002] With the acceleration of digital transformation, network attack means have become increasingly complex and concealed, and traditional network intrusion detection technologies are facing severe challenges. The current mainstream intrusion detection methods rely on centralized data processing. Although deep learning-based models can effectively capture the non-linear correlations of traffic features, the mode of relying on large-scale labeled data sets for centralized training has significant defects. Especially in cross-organization collaboration scenarios, the network traffic data of each entity cannot be shared due to privacy protection or compliance requirements, resulting in a serious data island phenomenon, which limits the generalization ability and real-time detection effect of the model.

[0003] Although the existing intrusion detection methods based on graph neural networks can improve the detection accuracy by modeling the topological relationships between traffic flows, they usually assume that the data is stored in a single server, ignoring the distributed characteristics of data in the actual network. At the same time, centralized training is prone to the risk of single-point failure and there are potential data leakage hazards, making it difficult to meet the requirements of regulations such as the Cybersecurity Law for local data storage and processing.

[0004] Some existing technologies introduce federated learning to solve the problem of data privacy. For example, Chinese Patent Application CN118018177A discloses a federated network intrusion detection method based on local graph expansion, including the steps of: using the source address and destination address in network traffic data as the endpoints of network traffic, and the remaining traffic data as edge features to construct a graph of network traffic data; constructing a general graph neural network federated learning architecture based on a self-noise mechanism and a homomorphic encryption method; performing secure federated training on the general graph neural network federated learning architecture; and expanding the local graph structure of the client. However, different from the conventional network intrusion detection methods of federated learning and graph neural networks, the simple model parameters and weights cannot achieve the coordination of client model training, and there are model synchronization problems caused by the lack of node interaction. Although the existing technologies have proposed network intrusion detection methods based on federated learning and graph neural networks, they have certain disadvantages. First, the construction of the graph structure is relatively simple, and the complex multi-dimensional features of traffic data are not fully considered, resulting in weak capture ability for complex topological relationships in network traffic. Second, although a self-noise mechanism and homomorphic encryption are used to protect data privacy, the negative values of the noise are added to the parameters of each layer of the local graph neural network model. Although this approach helps to increase privacy through the differential privacy protection mechanism, the introduction of noise will directly affect the accuracy of the model. Adding noise to the parameters of each layer of the model may make the training process of the model more difficult. Especially in multiple rounds of training, the convergence of the model may be disturbed, which in turn affects the final effect of the model, resulting in insufficient coordination effect in the federated learning process. In addition, the aggregation method of the client model does not fully consider dynamic optimization, which may affect the performance of the final model and the real-time detection effect. Summary of the Invention

[0005] The purpose of the present invention is to provide a network intrusion detection method based on a federated graph neural network to overcome the above-mentioned defects existing in the prior art.

[0006] The purpose of the present invention can be achieved by the following technical solutions:

[0007] On the one hand, the present invention provides a network intrusion detection method based on a federated graph neural network, including the following steps:

[0008] Obtain an open network intrusion detection traffic data set, perform feature extraction and screening on the data set to obtain the feature data of each traffic data in the network intrusion detection traffic data set, and the feature data includes HTTP two-stream byte distribution features, source IP address, destination IP address, and traffic type label;

[0009] Construct the global graph data according to the feature data of the network intrusion detection traffic dataset, divide the global graph data into local subgraphs by using the Dirichlet distribution for each client, each client constructs a GAT model, and train the GAT model of each client according to the divided local subgraphs and the server. Each client obtains the trained GAT model, and each client performs network intrusion detection through the trained GAT model.

[0010] Further, the HTTP two-stream byte distribution feature is used to describe the data distribution between requests and responses in network communication, and the traffic type labels include secure traffic and malicious traffic.

[0011] Further, the construction of the global graph data according to the feature data of the network intrusion detection traffic dataset specifically includes:

[0012] Normalize the HTTP two-stream byte distribution feature to keep the feature dimensions the same, and convert the traffic type labels into numerical codes through LabelEncoder;

[0013] Take the source IP address and destination IP address in the feature data as node identifiers respectively, and each node represents a communication entity as a node in the global graph data;

[0014] Take the normalized HTTP two-stream byte distribution feature vector and the numerically encoded traffic type labels as node feature vectors;

[0015] Establish edge connections between nodes according to the communication records in the network traffic data;

[0016] Quantify the interaction frequency between nodes through the adjacency matrix, and the elements in the adjacency matrix represent the interaction weight A ij , and the calculation formula is as follows:

[0017] A ij =n ij / N i

[0018] where, A ij is the interaction weight between source node i and node j, n ij represents the number of interactions between source node i and node i, and N i represents the total number of interactions of source node i;

[0019] When the source node interacts with multiple destination nodes, the node feature vectors of the destination nodes are weighted and accumulated according to the interaction weights in the adjacency matrix to generate the node feature vector of the source node, and the calculation formula is as follows:

[0020]

[0021] Among them, X i is the node feature vector of the source node i, N(i) is the set of destination nodes with interactions of the source node i, and X j is the node feature vector of node j;

[0022] Obtain the global graph data G:

[0023] G = (V, E, X, A)

[0024] Among them, V is the set of nodes, E is the set of edges, X is the node feature vector matrix, and A is the adjacency matrix.

[0025] Furthermore, partitioning the global graph data into local subgraphs for each client by using the Dirichlet distribution specifically includes:

[0026] According to the number of clients K, generate the Dirichlet distribution vector set β = (β1, β2,..., β i .., β K ), where Randomly assign the node set V in the global graph data G to each client according to the Dirichlet distribution vector β i ;

[0027] Construct the local subgraph of each client according to the node assignment situation. The local subgraph only includes the nodes assigned to the client and the edge connections between them, and the edges between cross-client nodes do not appear in the local subgraph;

[0028] The process of generating edges in the local subgraph is as follows:

[0029] For each pair of nodes, determine whether they belong to the same type of nodes. If the source node and the destination node belong to the secure traffic, they are the same type of nodes; if the source node and the destination node are of the malicious traffic type, they are cross-type nodes;

[0030] Set the generation thresholds for same-type node edges and cross-type node edges. The generation threshold for same-type node edges is The generation threshold for cross-type node edges is K, the number of clients. Generate a probability s randomly for each pair of nodes. If s > τ, generate an edge between the two nodes;

[0031] Obtain the local subgraph G k :

[0032] G k = (V k , E k , X k , A k )

[0033] Among them, G k is the local subgraph of client k, V k is the set of nodes assigned to client k, and E k is the edge set in the local subgraph generated according to the label types of homogeneous nodes and cross - type nodes and the set generation thresholds τ1 and τ2. X k is the node feature vector matrix of client k, and A k is the local adjacency matrix, representing the interaction weights of the edge connections between nodes in the local subgraph.

[0034] Furthermore, training the GAT models of each client based on the partitioned local subgraph and the server specifically includes:

[0035] The client initializes the trainable attention weight vector α and the trainable weight matrix W for the GAT model. Among them, W is used for linear transformation of the input features, and α is used to calculate the attention weights between neighbor nodes;

[0036] Each client performs feature propagation on the local subgraph, dynamically calculates the attention weights between nodes, and aggregates the neighbor node features. Specifically, it includes:

[0037] Calculate the attention weight of node i to neighbor node j:

[0038]

[0039] Among them, α ij is the attention weight of node i to neighbor node j, W is the trainable weight matrix, || is the vector concatenation operation, N(i) is the neighbor set of node i, and X i is the node feature vector of node i;

[0040] Perform weighted aggregation on the neighbor node features to obtain the hidden feature representation of node i:

[0041]

[0042] Among them, h i represents the hidden feature representation of node i, and σ is the non - linear activation function;

[0043] Each client performs vertical encrypted aggregation on the node hidden feature representations after the local subgraph feature propagation, and uploads them together with the local GAT model parameters θ k to the server. The server aggregates the encrypted remainder sets uploaded by all clients to obtain an aggregated remainder set, and performs federated aggregation on the client model parameters to obtain global model parameters;

[0044] The server returns the aggregated remainder set and the aggregated global model parameters to each client;

[0045] The client updates the local GAT model using the aggregated global model parameters, and reconstructs the node feature vectors of each node in the local subgraph of each client based on the aggregated remainder set according to the Chinese Remainder Theorem to obtain the reconstructed local subgraph;

[0046] Each client performs local gradient descent training on the locally updated GAT model according to the reconstructed local subgraph;

[0047] The client uploads the trained model parameters and encrypted features to the server again for the next round of federated aggregation until the GAT models of all clients converge.

[0048] Furthermore, the clients perform vertical encrypted aggregation on the node hidden feature representations after feature propagation in the local subgraph, specifically including:

[0049] The server generates a set of relatively prime large integers p1, p2, … p k …, p K , and distributes p k to the corresponding client k;

[0050] For the hidden feature representation h i =(h i,1 , h i,2 , …, h i,d ) of the i-th node in the client's local subgraph, encrypt each dimension of the feature vector according to the modulus set, where d is the feature dimension of the hidden feature representation, and the specific calculation formula is as follows:

[0051] c i,j,k =h i,j mod p k

[0052] where c i,j,k represents the encrypted remainder of the j-th dimension of the feature vector of node i under the modulus p k , k = 1, 2, ..., K, j = 1, 2, ..., d;

[0053] After encrypting all the node feature representations in the client's local subgraph, generate the encrypted remainder set of client k:

[0054] C k ={c i,j,k |i = 1, 2, …, n k ; j = 1, 2, …, d}

[0055] where n k is the number of nodes in the local subgraph of client k.

[0056] Further, the server aggregates the encrypted remainder sets uploaded by all clients to obtain an aggregated remainder set, which specifically includes:

[0057] After the server receives the encrypted remainder sets uploaded by each client, it vertically aggregates the remainders of all clients according to the same dimensional position and takes the modulus. The specific calculation formula is as follows:

[0058]

[0059] Wherein, represents the aggregated remainder of the j-th dimensional feature under the modulus p k , and K represents the number of clients;

[0060] The client returns the aggregated remainder set to each client.

[0061] Further, the federated aggregation of the client model parameters to obtain the global model parameters specifically includes:

[0062] After each client completes the local GAT model training, it uploads the local GAT model parameter set θ (k) to the server. The model parameter set includes the trainable weight matrix W and the trainable attention vector α;

[0063] The server calculates the cosine similarity between the local model parameters uploaded by the client and the global model parameters θ t-1 global after the previous round of aggregation. The specific formula is as follows:

[0064]

[0065] Wherein, s k represents the cosine similarity score of the k-th client, indicating the degree of consistency between the client model parameters and the global model parameters;

[0066] The server generates a dynamic aggregation weight w k based on the cosine similarity score s k , and the specific formula is as follows:

[0067]

[0068] Wherein, τ is the temperature coefficient, controlling the smoothness of the weight distribution, and K is the number of clients, satisfying:

[0069]

[0070] The server performs weighted summation on the local model parameters uploaded by each client based on the dynamic aggregation weight w k to obtain the aggregated global model parameters:

[0071]

[0072] Among them, θ t global is the updated global model parameter;

[0073] The server distributes the aggregated global model parameter θ t global to each client.

[0074] Furthermore, the client uses the aggregated global model parameter to update the local GAT model, including:

[0075] The client receives the aggregated global model parameter θ t global returned by the server, and synchronizes the global model parameter to the local GAT model to update the trainable weight matrix W and the trainable attention vector α.

[0076] Furthermore, reconstructing the node feature vectors of each node of the local subgraph of each client according to the aggregated remainder set based on the Chinese Remainder Theorem to obtain the reconstructed local subgraph specifically includes:

[0077] The client receives the aggregated global model parameter θ t global returned by the server, and synchronizes the global model parameter to the local GAT model to update the trainable weight matrix W and the trainable attention vector α;

[0078] After each client receives the aggregated remainder set returned by the server, it uses the Chinese Remainder Theorem for decryption and reconstruction:

[0079]

[0080] Among them, is the aggregated feature representation of node i in the j-th dimension, N = p1p1…p K is the product of all moduli, y k is the multiplicative inverse, satisfying: represents the aggregated remainder of the j-th dimensional feature under the modulus p k ;

[0081] The client updates the feature representations of each node in the local subgraph according to the decrypted and reconstructed aggregated feature representation to obtain the reconstructed local subgraph.

[0082] Compared with the prior art, the present invention has the following advantages:

[0083] (1) The present invention utilizes the federated learning framework to avoid the privacy issues of centralized data storage. Each client completes data processing and model training locally and only uploads model parameters instead of raw data, effectively protecting data privacy. Through this distributed training method, it can meet the regulatory requirements for local data storage and processing, and avoid the risks of single-point failure and data leakage.

[0084] (2) The present invention uses the graph neural network GAT to model the topological relationship of network traffic, which can effectively capture the complex non-linear correlations between traffic flows. Compared with the prior art, the present invention enhances the expression ability of complex traffic relationships by introducing multi-dimensional features such as HTTP two-stream byte distribution characteristics, source IP addresses, and destination IP addresses, thereby improving the accuracy and precision of intrusion detection.

[0085] (3) The present invention divides the global graph data into local subgraphs by using the Dirichlet distribution, enabling each client to train on its local data and forming a global model by aggregating local models. This method can improve the training efficiency while ensuring privacy protection, effectively avoid the problem of cross-client data leakage, and enhance the collaborative effect of federated learning.

[0086] (4) When aggregating client models, the present invention adopts a dynamic weighted aggregation method based on cosine similarity, which can perform differential weighting according to the similarity between each client and the global model, effectively improving the accuracy of aggregation and the performance of the final model, and thus enhancing the real-time performance and accuracy of network intrusion detection.

[0087] (5) The present invention uses the Chinese Remainder Theorem to encrypt and aggregate and reconstruct the node features of client models, effectively protecting the privacy of data and models, while ensuring the correct update of model parameters and the efficient training of the global model. The process of encrypted aggregation does not lose the contribution information of clients and the data will not be leaked. Therefore, the global model can more accurately reflect the data characteristics of all participating clients. Through this encrypted aggregation and reconstruction, the accuracy of the global model of the entire federated learning is improved, the collaborative effect of each client is enhanced, and thus it better supports tasks such as intrusion detection. BRIEF DESCRIPTION OF THE DRAWINGS

[0088] Figure 1 is the training flow chart of the federated graph neural network model of the present invention;

[0089] Figure 2 is the structural block diagram of the federated graph neural network of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0090] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0091] Embodiment 1:

[0092] A network intrusion detection method based on a federated graph neural network includes the following steps:

[0093] Obtain a publicly available network intrusion detection traffic dataset, perform feature extraction and screening on the dataset to obtain the feature data of each traffic data in the network intrusion detection traffic dataset. The feature data includes HTTP two-stream byte distribution characteristics, source IP address, destination IP address, and traffic type label;

[0094] Construct global graph data according to the feature data of the network intrusion detection traffic dataset, use the Dirichlet distribution to divide the global graph data into local subgraphs for each client. Each client constructs a GAT model, and trains the GAT model of each client according to the divided local subgraphs and the server. Each client obtains the trained GAT model, and each client performs network intrusion detection through the trained GAT model.

[0095] Further, the HTTP two-stream byte distribution characteristic is used to describe the data distribution situation between requests and responses in network communication, and the traffic type label includes secure traffic and malicious traffic.

[0096] Further, the construction of the global graph data according to the feature data of the network intrusion detection traffic dataset specifically includes:

[0097] Perform normalization processing on the HTTP two-stream byte distribution characteristic to keep the feature dimensions of the HTTP two-stream byte distribution characteristic the same, and perform numerical encoding conversion on the traffic type label through LabelEncoder.

[0098] The HTTP two-stream byte distribution characteristics refer to the byte stream information corresponding to the source port and destination port in network traffic, which have an important impact on the accuracy of intrusion detection. These characteristics may essentially vary greatly in terms of numerical magnitude and range. The purpose of normalization is to eliminate possible dimensional inconsistencies between different feature dimensions, that is, to make these features within the same quantization range, so as to facilitate the model to learn effectively. For example, if some feature values have a large range while others have a small range, the model may tend to rely on the features with a large range during the training process, resulting in an unbalanced training effect of the model. Through normalization, all feature values are compressed into a relatively unified range, so that the contributions of all features to the model are more balanced, avoiding the excessive influence of certain features. The traffic type labels represent different network intrusion types or traffic categories, and these labels usually exist in text form, such as "normal traffic", "DoS attack", etc. Since most machine learning models, especially graph neural networks and deep learning models, cannot directly process text data, these labels need to be numerically encoded. LabelEncoder is a common encoding method that converts text labels into numerical labels, usually by assigning a unique integer value to each label. This conversion helps to transform the classification task into a numerical task that the model can handle, facilitating calculation and optimization.

[0099] Take the source IP address and destination IP address in the feature data as node identifiers respectively, and each node represents a communication entity, serving as a node in the global graph data;

[0100] Use the normalized HTTP two-stream byte distribution feature vector and the numerically encoded traffic type label as the node feature vector;

[0101] Using the source IP address and the destination IP address as node identifiers is based on the thinking mode of graph neural networks. Graph neural networks can efficiently process data with topological structures, and network traffic usually involves multiple different communication entities. Each communication entity is distinguished by the source IP address and the destination IP address. By using these two addresses as node identifiers respectively, each pair of communication entities can be regarded as a node in the graph. In this way, the source IP and the destination IP become key nodes in the graph, and the connections between them reflect the communication relationships. Each node in the graph represents a communication entity in the network, and the connection relationships between nodes can reflect the transmission paths of data packets and the frequency of data interaction. Using the source IP and the destination IP as node identifiers is because they are the unique identifiers for distinguishing different entities in the network and are usually closely related to network attack types (such as DDoS, port scanning, etc.). Through these identifiers, the interaction patterns between different communication entities can be effectively captured, thus revealing the potential rules and abnormal behaviors of network traffic. The HTTP two-stream byte distribution feature represents the content information of network traffic, while the traffic type label reveals the category of traffic (such as normal traffic, attack traffic, etc.). Combining these two features with the node identifiers can make each node not only represent a communication entity but also reflect the traffic pattern and behavior characteristics of this communication entity.

[0102] Establish edge connections between nodes according to the communication records in the network traffic data;

[0103] Quantify the interaction frequency between nodes through the adjacency matrix. The elements in the adjacency matrix represent the interaction weight A between the source node and the destination node ij , and the calculation formula is as follows:

[0104] A ij =n ij / N i

[0105] Among them, A ij is the interaction weight between the source node i and the node j, n ij represents the number of interactions between the source node i and the node i, and N i represents the total number of interactions of the source node i;

[0106] When the source node has interactions with multiple destination nodes, the node feature vector of the destination nodes is weighted and accumulated according to the interaction weights in the adjacency matrix to generate the node feature vector of the source node. The calculation formula is as follows:

[0107]

[0108] Among them, X i is the node feature vector of the source node i, N(i) is the set of destination nodes with interactions of the source node i, Xj is the node feature vector of node j;

[0109] Obtain the global graph data G:

[0110] G = (V, E, X, A)

[0111] where V is the set of nodes, E is the set of edges, X is the node feature vector matrix, and A is the adjacency matrix.

[0112] Furthermore, partitioning the global graph data into local subgraphs for each client by using the Dirichlet distribution specifically includes:

[0113] According to the number of clients K, generate the Dirichlet distribution vector set β = (β1, β2,..., β i .., β K ), where Randomly assign the node set V in the global graph data G to each client according to the Dirichlet distribution vector β i ; The structural block diagram of the federated graph neural network of the present invention is as Figure 2 shown.

[0114] Construct the local subgraph of each client according to the node assignment situation. The local subgraph only contains the nodes assigned to the client and the edge connections between them, and the edges between cross-client nodes do not appear in the local subgraph;

[0115] In this way, the tasks of the global graph can be effectively processed in a distributed manner while ensuring data privacy and security. The use of the Dirichlet distribution provides a balanced and random way for node assignment, ensuring that each client can receive a certain proportion of the global data, while avoiding the over-concentration or over-assignment of nodes in some clients. This not only ensures the balanced distribution of the training tasks, but also avoids the training bias that may be caused by data imbalance. The random assignment of nodes increases the diversity of the training data of each client, thereby improving the generalization ability of the model and ensuring better adaptability and robustness.

[0116] In addition, the construction method of the local subgraph helps to reduce cross-client computing and data transmission, improving the computing efficiency. Each client only needs to process its local subgraph and does not need to access cross-client data, avoiding the bandwidth consumption and privacy leakage problems that may occur during cross-client data transmission. The local subgraph only contains the nodes assigned to this client and the edges connecting them, localizing the computing process of each client, thus greatly reducing the dependence on global data and ensuring the protection of data privacy. Such a design effectively avoids the single-point failure risk brought by centralized storage and processing, improving the robustness and scalability of the system. Through distributed computing, each client can independently train on its local subgraph, thus avoiding the computing bottleneck problem that may be caused by centralized training and improving the overall training efficiency.

[0117] Overall, through reasonable node allocation and local subgraph construction, this step not only enhances data privacy protection and the training efficiency of the model, but also strengthens the reliability of the distributed system, avoids the limitations of data storage and processing brought by the centralized method, and further improves the generalization ability of the model and its ability to adapt to different network environments.

[0118] The process of generating edges in the local subgraph is as follows:

[0119] For each pair of nodes, determine whether they belong to the same type of nodes. If the source node and the destination node belong to safe traffic, they are of the same type; if the types of the source node and the destination node are malicious traffic, they are of different types;

[0120] Set the generation thresholds for edges between nodes of the same type and edges between nodes of different types. The generation threshold for edges between nodes of the same type is The generation threshold for edges between nodes of different types is K, the number of clients. For each pair of nodes, randomly generate a probability s. If s > τ, generate an edge between the two nodes;

[0121] This means that interactions between malicious traffic nodes are more likely to generate edges. The purpose of doing this is to make the connections between malicious traffic nodes closer, so that the model can focus on the potential dependencies and interaction patterns between these malicious traffic nodes during the training process. In this way, the generated local subgraph will emphasize the interactions between malicious traffic nodes more, which is crucial for the training of the model. By weighting the generated edges, it is easier to connect the nodes of malicious traffic, helping the model to capture the potential patterns of malicious traffic, thereby improving the detection accuracy of these traffic. Malicious traffic usually has specific attack patterns or abnormal traffic behaviors, and by enhancing the interactions between these malicious nodes, the model can better identify and distinguish malicious traffic.

[0122] According to the generated edge information, obtain the local subgraph G k:

[0123] G k = (V k , E k , X k , A k )

[0124] where G k is the local sub - graph of client k, V k is the set of nodes assigned to client k, E k is the edge set in the local sub - graph generated according to the label types of homogeneous nodes and cross - type nodes and the set generation thresholds τ1 and τ2, X k is the node feature vector matrix of client k, and A k is the local adjacency matrix, representing the interaction weights of the edge connections between nodes in the local sub - graph.

[0125] Furthermore, training the GAT models of each client according to the divided local sub - graphs and the server is as Figure 1 shown, and specifically includes:

[0126] The client initializes the trainable attention weight vector α and the trainable weight matrix W for the GAT model. Among them, W is used for linear transformation of the input features, and α is used to calculate the attention weights between neighbor nodes;

[0127] Each client performs feature propagation on the local sub - graph, dynamically calculates the attention weights between nodes and aggregates the neighbor node features, specifically including:

[0128] Calculate the attention weight of node i to neighbor node j:

[0129]

[0130] where α ij is the attention weight of node i to neighbor node j, W is the trainable weight matrix, || is the vector concatenation operation, N(i) is the neighbor set of node i, and X i is the node feature vector of node i;

[0131] Weighted aggregation of neighbor node features to obtain the hidden feature representation of node i:

[0132]

[0133] where h i represents the hidden feature representation of node i, and σ is the non - linear activation function;

[0134] Each client passes its local subgraph to the GAT model for training. During the training process, the model performs feature propagation and calculates the attention weights between nodes through the following steps. First, for each pair of nodes i and neighbor node j, calculate the attention weight of node i to node j. This attention weight is calculated based on the feature values of node i and node j (after linear transformation) and the strength of their relationship. Specifically, first linearly transform the features of node i and node j through the weight matrix W and concatenate them to form a new vector. Then, use the LeakyReLU activation function to calculate the non-linear representation of this vector, and then perform normalization through softmax. The final obtained α ij represents the attention weight of node i to neighbor node j. The higher the weight, the stronger the dependence of node i on node j.

[0135] In this way, the model can automatically learn which neighbor nodes are more important for the representation of the current node, avoiding the situation in traditional methods where all neighbor nodes are regarded as equal. This adaptive weight assignment mechanism enables the GAT model to better capture the complex relationships between nodes, especially in graph data with irregular topological structures. For each node i, the GAT model performs weighted aggregation on the features of its neighbor nodes to obtain the hidden feature representation of node i. The process of weighted aggregation is to calculate the features of each neighbor node (features adjusted by the attention weight) and sum them up to obtain the new feature representation of node i. Specifically, first obtain the attention weights of each neighbor node through the above calculation, then perform weighted summation on the features of the neighbor nodes (features transformed by the weight matrix W) according to the weights, and activate them through a non-linear activation function (such as ReLU) to obtain the hidden feature representation of node i. This feature representation is a weighted aggregation of the interaction information of node i with its neighbor nodes, which can better reflect the complex relationships between nodes. Through this aggregation method, the GAT model can not only capture the features of the node itself, but also enrich its representation according to the features of the neighbor nodes. This method is particularly suitable for processing graph-structured data, where the interaction between nodes affects the final representation of the nodes. In the network intrusion detection task, the final feature representation of the nodes is crucial for identifying malicious traffic and abnormal behaviors. In this way, the client can train based on the information of the local subgraph to obtain accurate node representations, which provides strong feature support for subsequent global model aggregation and attack detection. The advantage of the GAT model lies in its ability to adaptively learn the dependence relationships between nodes and process the complex interactions of the nodes in the graph through weighted aggregation, which makes it have higher accuracy and robustness in complex network traffic detection tasks.

[0136] Each client performs vertical encryption aggregation on the node hidden feature representations after local subgraph feature propagation and combines it with the local GAT model parameter θ k and uploads it to the server. The server aggregates the encrypted remainder sets uploaded by all clients to obtain an aggregated remainder set, and performs federated aggregation on the client model parameters to obtain global model parameters;

[0137] The server returns the aggregated remainder set and the aggregated global model parameters to each client;

[0138] The client updates the local GAT model using the aggregated global model parameters and reconstructs the node feature vectors of each node in the local subgraph of each client based on the aggregated remainder set according to the Chinese Remainder Theorem to obtain the reconstructed local subgraph;

[0139] Each client performs local gradient descent training on the locally updated GAT model according to the reconstructed local subgraph;

[0140] The client uploads the trained model parameters and encrypted features to the server again for the next round of federated aggregation until the GAT models of all clients converge.

[0141] In this process, the client, the server, and encryption technology work together to improve the training efficiency, privacy protection ability, and global model optimization of the network intrusion detection model. The client performs vertical encryption aggregation on the node hidden feature representations after feature propagation and uploads them to the server together with the local GAT model parameter θk. Here, "vertical encryption aggregation" means that the client aggregates their respective encrypted data into an encrypted remainder set, ensuring the privacy of the data during the upload process. The node feature information of the local subgraph of each client is uploaded together with the local model parameters, ensuring that the data received by the server is encrypted and does not disclose private information.

[0142] After receiving the encrypted remainder sets from each client, the server performs aggregation to generate a global aggregated remainder set. At the same time, the server also performs federated aggregation on the model parameters uploaded by the clients. This process determines the weights of each client model by comprehensively calculating the consistency between the parameters uploaded by each client and the global model parameters of the previous round, and finally obtains the updated global model parameters. The core of this step is to ensure data privacy while enabling efficient global model training through encrypted data aggregation. After the encrypted data and model parameters are uploaded to the server, the server does not directly access the specific data of the client, but trains the model based on the encrypted information, ensuring data privacy.

[0143] Then, the server returns the aggregated global model parameters and the set of aggregation remainders to each client. At this time, the client will use these updated global model parameters to synchronize the local GAT model and decrypt and reconstruct the node feature vectors of the local subgraph based on the Chinese Remainder Theorem. The application of the Chinese Remainder Theorem ensures that the client can decrypt the relevant information of the global model when updating the model parameters, while protecting the data privacy of each client. By reconstructing the node features in the local subgraph, the client can update the feature representation of the local model to make it more accurate.

[0144] On this basis, each client will use the reconstructed local subgraph to continue training its local GAT model and further optimize the model parameters using the local gradient descent method. At this time, the local model of the client will obtain more accurate optimization results after feature propagation, global model parameter update, and local subgraph reconstruction. Through local gradient descent training, each client model can adapt to the characteristics of its local data and continuously improve the prediction performance of the model.

[0145] Finally, the client will upload the model parameters after local training and the encrypted features to the server again. This process realizes the information sharing between clients under the condition of privacy protection, and gradually optimizes the global model through multiple rounds of aggregation and update. As each round of training progresses, the server continuously updates the global model parameters until the GAT models of all clients finally converge.

[0146] The advantages of this series of steps are as follows: The upload of all data and model parameters is encrypted, ensuring the privacy of the client is not leaked. This encryption process ensures that even if the data is intercepted during transmission, the specific content cannot be interpreted. Through federated learning, the client does not need to directly share data, but only shares model parameters, which greatly improves the efficiency of model training and avoids the problems of data silos and cross-organizational data sharing. By aggregating the local model parameters of the clients, the server can obtain the global model and gradually optimize the model performance. Each client trains based on the global model, and the finally obtained global model can better adapt to the needs of all clients. Each client trains the model according to its own local data, which enables the model of each client to better adapt to its specific data distribution. By combining the global model update, the local model will become more accurate, further improving the generalization ability of the model. Each client trains on its own local data and is guided by the global model parameters, which can effectively avoid overfitting problems and improve the robustness of the model. The Chinese Remainder Theorem enables the encrypted features to be decrypted while ensuring security, restoring the original features. This technology application improves the computational efficiency of the system and ensures that the encryption and decryption of the entire process can be completed efficiently. Through multiple rounds of federated aggregation until the model converges, it ensures that the model can be optimized to the best state on the data of different clients and finally achieves a good generalization effect.

[0147] Further, the longitudinal encryption aggregation of the node hidden feature representations after the local subgraph feature propagation by each client specifically includes:

[0148] The server generates a set of relatively prime large integers p1, p2, … p k …, p K , and distributes p k to the corresponding client k;

[0149] For the hidden feature representation h i =(h i,1 , h i,2 , …, h i,d ) of the i-th node in the client local subgraph, encrypt each dimension of the feature vector according to the modulus set, where d is the feature dimension of the hidden feature representation, and the specific calculation formula is as follows:

[0150] c i,j,k =h i,j mod p k

[0151] where c i,j,k represents the encrypted remainder of the j-th dimension of the feature vector of node i under the modulus p k , k = 1, 2, …, K, c = 1, 2, …, d;

[0152] After encrypting all the node feature representations in the client's local subgraph, an encrypted remainder set for client k is generated:

[0153] C k ={c i,j,k |i = 1, 2, …, n k ; j = 1, 2, …, d}

[0154] where n k is the number of nodes in the local subgraph of client k.

[0155] By using the modulus p generated by the server k to encrypt the node features, data privacy protection is achieved. The data of each client (i.e., the feature vector of the node) has been encrypted before being transmitted to the server, thus avoiding the risk of data leakage. In addition, using modular arithmetic for encryption also ensures that the encrypted features can be safely aggregated during model training without affecting the accuracy of the training results. This encryption method also ensures data privacy among multiple clients. Even in the federated learning framework, the server and other clients cannot directly access the original data of a certain client. This is of great significance for the processing of sensitive data, especially in scenarios involving privacy protection and compliance requirements. Through vertical encrypted aggregation, clients can not only protect their own data privacy but also participate in the training of the global model, improving the overall detection accuracy and model performance while complying with the requirements of data privacy protection regulations.

[0156] Furthermore, the server aggregates the encrypted remainder sets uploaded by all clients to obtain an aggregated remainder set, which specifically includes:

[0157] After the server receives the encrypted remainder sets uploaded by each client, it vertically aggregates the remainders of all clients according to the same dimensional position and takes the modulus. The specific calculation formula is as follows:

[0158]

[0159] where represents the aggregated remainder of the j - th dimensional feature under the modulus p k , and K represents the number of clients;

[0160] The client returns the aggregated remainder set to each client.

[0161] The server vertically aggregates the encrypted remainders of all clients along the same dimension. That is, the server adds up the encrypted remainders of all clients on the same dimension and uses modular arithmetic to ensure the correctness and security of the encrypted features. The purpose of this aggregation process is to merge the encrypted feature values of all clients, thereby generating a global set of aggregated remainders. This set of aggregated remainders contains information contributed by all clients, but due to the encryption process, the original feature values are not leaked to the server or other clients. The set of aggregated remainders can effectively retain all client information while protecting the data privacy of each client. By encrypting the features uploaded by each client and aggregating them on the server side, direct access by any party to the original data of the client is avoided. Even in a multi-party cooperation scenario, participants cannot obtain sensitive information of other clients. The server only processes encrypted data, avoiding the risk of exposing the original data. At the same time, through the encrypted aggregation method, it can efficiently summarize multi-party data and update the global model. Modular arithmetic and encrypted aggregation can ensure that even during the aggregation process, the privacy and security of the data are effectively protected, while avoiding the leakage of any sensitive information during the aggregation process. This step ensures that each client can participate in the training of the global model through encryption without exposing its own data. In this way, even if different organizations or institutions collaborate on model training, they can still achieve collaborative learning and knowledge sharing under strict data privacy requirements.

[0162] Furthermore, the federated aggregation of the client model parameters to obtain the global model parameters specifically includes:

[0163] After each client completes the local GAT model training, it uploads the local GAT model parameter set θ (k) to the server. The model parameter set includes the trainable weight matrix W and the trainable attention vector α;

[0164] The server calculates the cosine similarity between the local model parameters uploaded by the client and the global model parameters θ t-1 global from the previous round of aggregation. The specific formula is as follows:

[0165]

[0166] where s k represents the cosine similarity score of the k-th client, indicating the degree of consistency between the client model parameters and the global model parameters;

[0167] The server generates the dynamic aggregation weight w k based on the cosine similarity score s k , and the specific formula is as follows:

[0168]

[0169] Among them, τ is the temperature coefficient that controls the smoothness of the weight distribution, and K is the number of clients, satisfying:

[0170]

[0171] The server performs a weighted sum of the local model parameters uploaded by each client based on the dynamic aggregation weight w k to obtain the aggregated global model parameters:

[0172]

[0173] where θ t global is the updated global model parameter;

[0174] The server distributes the aggregated global model parameter θ t global to each client.

[0175] By calculating the cosine similarity, it can be ensured that clients with a high similarity to the global model contribute more in model training, thus avoiding over-reliance on a single client and making the global model more accurate and stable. There may be differences in the local data and training effects of different clients. The cosine similarity and dynamic aggregation weight mechanism can dynamically adjust their weights in the global model according to the training quality of the clients. This approach can ensure that the actual contributions of each client are reasonably reflected in the training of the global model. Although the server can calculate the cosine similarity and generate dynamic aggregation weights during the aggregation process, it does not access any raw data or local model weights of the clients. All operations are carried out within the framework of encryption and privacy protection, ensuring the protection of data privacy. By dynamically adjusting the weights of the clients, the efficiency of global model training can be effectively improved, and the problem of training imbalance caused by data differences between clients can be avoided. In addition, the similarity-based aggregation method also reduces the influence of noise in training, enabling the global model to converge quickly.

[0176] Furthermore, the client updates the local GAT model using the aggregated global model parameters, including:

[0177] The client receives the aggregated global model parameter θ t global returned by the server and synchronizes the global model parameter to the local GAT model to update the trainable weight matrix W and the trainable attention vector α.

[0178] Further, based on the aggregated remainder set, the node feature vectors of each node in the local subgraphs of each client are reconstructed according to the Chinese Remainder Theorem to obtain the reconstructed local subgraphs, which specifically includes:

[0179] The client receives the aggregated global model parameters θ returned by the server t global and synchronizes the global model parameters to the local GAT model to update the trainable weight matrix W and the trainable attention vector α;

[0180] After each client receives the aggregated remainder set returned by the server, it uses the Chinese Remainder Theorem for decryption and reconstruction:

[0181]

[0182] where is the aggregated feature representation of node i in the j-th dimension, N = p1p1…p K is the product of all moduli, y k is the multiplicative inverse, satisfying: represents the aggregated remainder of the j-th dimensional feature under the modulus p k ;

[0183] The client updates the feature representations of each node in the local subgraph according to the decrypted and reconstructed aggregated feature representation to obtain the reconstructed local subgraph.

[0184] By synchronizing the global model parameters and combining the decryption and reconstruction of the encrypted remainders, the client can effectively update the weight information of its local GAT model, thereby strengthening the consistency of the local model with the global model and further improving the accuracy and robustness of the global model. By using the Chinese Remainder Theorem, the client can efficiently decrypt the aggregated remainders and reconstruct the features. This method can ensure the accuracy and consistency of model aggregation among different clients while guaranteeing the computational efficiency, and avoid the cost of directly transmitting a large number of model parameters. Each client updates its local GAT model according to its local data, ensuring that each client can optimize on its specific data distribution. At the same time, with the help of global model aggregation, the client can obtain cross-client data knowledge and improve the generalization ability of the model.

[0185] Example 2:

[0186] This embodiment provides an electronic device, including a memory and a processor. A computer program is stored on the memory, and when the processor executes the program, it implements the network intrusion detection method based on the federated graph neural network as described in any one of the above.

[0187] This embodiment also provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the network intrusion detection method based on the federated graph neural network described in any one of the above.

[0188] If the above functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the essence of the technical solution of the present invention, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.

[0189] The above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of various equivalent modifications or substitutions, and these modifications or substitutions should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

Claims

1. A network intrusion detection method based on a federated graph neural network, characterized in that: The following steps are involved: Obtain a public network intrusion detection traffic data set, extract and filter the data set, and obtain the characteristic data of each traffic data in the network intrusion detection traffic data set, wherein the characteristic data includes HTTP dual-stream byte distribution characteristics, source IP address, destination IP address, and traffic type label; The global graph data is constructed according to the characteristic data of the network intrusion detection traffic data set, and the global graph data is divided into local subgraphs for each client using Dirichlet distribution. Each client constructs a GAT model, and the GAT model of each client is trained based on the divided local subgraph and the server. Each client obtains the trained GAT model, and each client performs network intrusion detection through the trained GAT model.

2. According to claim 1, a network intrusion detection method based on a federated graph neural network is characterized in that: The HTTP dual-stream byte distribution feature is used to describe the data distribution between requests and responses in network communications, and the traffic type label includes safe traffic and malicious traffic.

3. According to claim 1, a network intrusion detection method based on a federated graph neural network is characterized in that: The step of constructing global graph data based on the characteristic data of the network intrusion detection traffic data set specifically includes: The HTTP dual-stream byte distribution feature is normalized, the feature dimension of the HTTP dual-stream byte distribution feature is kept the same, and the traffic type label is converted into a numerical code through LabelEncoder; The source IP address and the destination IP address in the feature data are used as node identifiers, and each node represents a communication entity as a node in the global graph data; The normalized HTTP dual-stream byte distribution feature vector and the numerically encoded traffic type label are used as the node feature vector; Establish edge connections between nodes based on communication records in network traffic data; The interaction frequency between nodes is quantified by the adjacency matrix. The elements in the adjacency matrix represent the interaction weight A between the source node and the destination node. ij , the calculation formula is as follows: A ij =n ij / N i Among them, A ij is the interaction weight between source node i and node j, n ij represents the number of interactions between source node i and node i, N i represents the total number of interactions of source node i; When a source node interacts with multiple destination nodes, the node feature vector of the destination node is weighted and accumulated according to the interaction weight in the adjacency matrix to generate the node feature vector of the source node. The calculation formula is as follows: Among them, X i is the node feature vector of source node i, N(i) is the set of destination nodes with which source node i interacts, X j is the node feature vector of node j; Get the global graph data G: G=(V,E,X,A) Among them, V is the node set, E is the edge set, X is the node feature vector matrix, and A is the adjacency matrix.

4. According to claim 1, a network intrusion detection method based on a federated graph neural network is characterized in that: The method of using Dirichlet distribution to divide the global graph data into local subgraphs for each client specifically includes: According to the number of clients K, a Dirichlet distribution vector set β = (β1, β2, β i ..,β K ),in The node set V in the global graph data G is distributed according to the Dirichlet distribution vector β i Randomly assigned to each client; According to the node allocation, a local subgraph of each client is constructed. The local subgraph only contains the nodes allocated to the client and the edge connections between them, and the edges between nodes across clients do not appear in the local subgraph; The process of generating edges in a local subgraph is as follows: For each pair of nodes, determine whether they belong to the same type of nodes. If the source node and the destination node belong to safe traffic, they are the same type of nodes; if the source node and the destination node type are malicious traffic, they are cross-class nodes; Set the generation threshold of the same type of node edges and cross-type node edges. The generation threshold of the same type of node edges is The generation threshold of cross-class node edges is The number of K clients is to randomly generate a probability s for each pair of nodes. If s>τ, an edge is generated between the two nodes; According to the generated edge information, the local subgraph G is obtained k : G k =(V k ,E k ,X k ,A k ) Among them, G k is the local subgraph of client k, V k The node set assigned to client k, E k To generate the edge set in the local subgraph according to the label types of the same-class nodes and cross-class nodes and the set generation thresholds τ1 and τ2, X k is the node feature vector matrix of client k, A k is the local adjacency matrix, which represents the interaction weights of the edge connections between nodes in the local subgraph.

5. According to claim 1, a network intrusion detection method based on a federated graph neural network is characterized in that: The training of the GAT model of each client according to the divided local subgraphs and the server specifically includes: The client initializes the trainable attention weight vector α and the trainable weight matrix W for the GAT model, where W is used to perform linear transformation on the input features and α is used to calculate the attention weights between neighboring nodes; Each client propagates features of the local subgraph, dynamically calculates the attention weights between nodes, and aggregates the features of neighboring nodes, including: Calculate the attention weight of node i to neighbor node j: Among them, α ij is the attention weight of node i to neighbor node j, W is the trainable weight matrix, || is the vector concatenation operation, N(i) is the neighbor set of node i, X i is the node feature vector of node i; Perform weighted aggregation on neighbor node features to obtain the hidden feature representation of node i: Among them, h i represents the hidden feature representation of node i, σ is a nonlinear activation function; Each client performs vertical encryption aggregation on the node hidden feature representation after local subgraph feature propagation, and compares it with the local GAT model parameter θ k Upload to the server, the server aggregates the encrypted remainder sets uploaded by all clients to obtain the aggregate remainder set, and performs federated aggregation on the client model parameters to obtain the global model parameters; The server returns the aggregated remainder set and the aggregated global model parameters to each client; The client uses the aggregated global model parameters to update the local GAT model, and reconstructs the node feature vectors of each node of the local subgraph of each client based on the aggregate remainder set and the Chinese remainder theorem to obtain the reconstructed local subgraph; Each client performs local gradient descent training on the local GAT model with updated parameters based on the reconstructed local subgraph; The client re-uploads the trained model parameters and encrypted features to the server for the next round of federated aggregation until the GAT models of each client converge.

6. According to claim 5, a network intrusion detection method based on a federated graph neural network is characterized in that: Each client performs vertical encryption aggregation on the node hidden feature representation after the local subgraph feature propagation, specifically including: The server generates a set of relatively prime large integers p1, p2, ... p k …,p K , and p k Distribute to the corresponding client k; For the hidden feature representation h of the i-th node in the client local subgraph i =(h i,1 ,h i,2 ,…,h i,d ), encrypt the feature vector dimension by dimension according to the modulus set, where d is the feature dimension of the hidden feature representation. The specific calculation formula is as follows: c i,j,k =h i,j modp k Among them, c i,j,k Indicates that the jth dimension of the feature vector of node i is in modulus p k The encrypted remainder under , k=1,2,...,K, j=1,2,...,d; After encrypting the feature representations of all nodes in the client's local subgraph, the encrypted remainder set of client k is generated: C k ={c i,j,k |i=1,2,…,n k ;j=1,2,…,d} Among them, n k is the number of nodes in the local subgraph of client k.

7. According to claim 5, a network intrusion detection method based on a federated graph neural network is characterized in that: The server aggregates the encrypted remainder sets uploaded by all clients to obtain an aggregate remainder set, which specifically includes: After receiving the encrypted remainder set uploaded by each client, the server aggregates the remainders of all clients vertically according to the same dimensional position and takes the modulus. The specific calculation formula is as follows: in, Indicates that the j-th dimension feature is modulo p k The aggregate remainder under , K represents the number of clients; The client will aggregate the remainder set Return to each client.

8. According to claim 5, a network intrusion detection method based on a federated graph neural network is characterized in that: The client model parameters are federated and aggregated to obtain global model parameters, specifically including: After completing the local GAT model training, each client sets the local GAT model parameter set θ (k) Upload to the server, the model parameter set includes a trainable weight matrix W and a trainable attention vector α; The server compares the local model parameters uploaded by the client with the global model parameters after the previous round of aggregation θ t-1 global Calculate the cosine similarity. The specific formula is as follows: Among them, s k represents the cosine similarity score of the kth client, indicating the degree of consistency between the client model parameters and the global model parameters; The server uses the cosine similarity score s k Generate dynamic aggregation weight w k , the specific formula is as follows: Among them, τ is the temperature coefficient, which controls the smoothness of the weight distribution, and K is the number of clients, satisfying: The server is based on the dynamic aggregation weight w k Perform weighted summation on the local model parameters uploaded by each client to obtain the aggregated global model parameters: Among them, θ t global is the updated global model parameter; The server will aggregate the global model parameters θ t global Distribute to each client.

9. According to claim 5, a network intrusion detection method based on a federated graph neural network is characterized in that: The client updates the local GAT model using the aggregated global model parameters, including: The client receives the aggregated global model parameters θ returned by the server t global , and synchronize the global model parameters to the local GAT model, updating the trainable weight matrix W and the trainable attention vector α.

10. A network intrusion detection method based on a federated graph neural network according to claim 5, characterized in that: The node feature vectors of each node of the local subgraph of each client are reconstructed based on the Chinese remainder theorem according to the aggregate remainder set to obtain the reconstructed local subgraph, specifically including: The client receives the aggregated global model parameters θ returned by the server t global , and synchronize the global model parameters to the local GAT model, updating the trainable weight matrix W and the trainable attention vector α; After receiving the aggregate remainder set returned by the server, each client uses the Chinese remainder theorem to decrypt and reconstruct: in, is the aggregate feature representation of node i in the jth dimension, N = p1p1…p K is the product of all moduli, y k is a multiplicative inverse element, satisfying: Indicates that the j-th dimension feature is modulo p k The aggregate remainder under ; The client updates the feature representation of each node in the local subgraph according to the decrypted and reconstructed aggregate feature representation to obtain the reconstructed local subgraph.

Citation Information

Patent Citations

  • Federated network intrusion detection method based on local graph expansion

    CN118018177A

Cited By

  • Electric hand drill maintenance data tracing management system

    CN120910626A