Flow detection method and system based on spiking nerve-bidirectional LSTM network
Through the traffic detection method based on the pulsed neural-bidirectional LSTM network, combined with the characteristics of the pulsed neural network and bidirectional LSTM, a traffic anomaly detection model is built, which solves the problems of new attack detection lag and high false alarm rate in encrypted traffic detection, and achieves efficient and accurate encrypted traffic detection.
Patent Information
- Application Number
- CN202510704652.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-29
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2045-05-29
AI Technical Summary
The existing technology has problems with new attack detection lag, false alarms and high false alarms in encrypted traffic detection, making it difficult to effectively identify malicious traffic that is disguised as well, and deep learning models have high demand for computing resources and poor interpretability.
The traffic detection method based on the pulsed neural-bidirectional LSTM network is adopted, and the traffic anomaly detection model is constructed through the feature input module, the timing modeling module, the pulsed neural network module, the self-attention mechanism module and the global average pooling layer. Combining the dynamic characteristics of the pulsed neural network and the timing-dependent feature capture capability of the bidirectional LSTM, efficient detection of encrypted traffic is achieved.
It significantly improves the accuracy and efficiency of encrypted traffic detection, can extract timing characteristics and behavior patterns more accurately, reduce false alarm rates, improves the detection ability of traffic of multiple encryption protocols, and improves detection efficiency through modular design.
Smart Images

Figure CN120238371A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a traffic detection method and system based on a pulsed neural-bi-directional LSTM network, and belongs to the technical field of abnormal traffic detection. Background Art
[0002] With the increasing attention of users and enterprises to Internet communication security, protecting the security of communication information has become a core requirement. For this reason, encrypting traffic during communication has become a mainstream security measure. Among them, HTTPS (Hypertext Transfer Protocol Secure) is the most widely used encryption protocol at present. Based on the traditional Hypertext Transfer Protocol (HTTP), HTTPS combines SSL (Secure Sockets Layer) and TLS (Transport Layer Security) to effectively ensure the security of data transmission.
[0003] After the encryption of ordinary Internet security traffic, it can protect the confidentiality and integrity of private information to a certain extent, but it also provides shelter for malicious behaviors on the network, enabling them to perform destructive behaviors more covertly. Traditional traffic detection and analysis technologies mainly rely on the inspection of plaintext data packets, and achieve traffic classification, anomaly detection, and threat analysis by parsing transmission content, protocol fields, and behavior patterns. However, as data traffic is gradually encrypted, traditional methods cannot directly access the data content, and the accuracy and efficiency of traffic detection are severely affected.
[0004] Malicious traffic detection is an important research direction in the field of network security, and its goal is to identify and prevent malicious activities that may threaten users, enterprises, and critical infrastructure. In the prior art, the method based on feature matching detects known attack behaviors through rules or feature libraries, but has limited ability to cope with unknown threats; the behavior analysis method uses the dynamic features of traffic for anomaly detection, which is suitable for the analysis of encrypted traffic, but faces the problem of a high false alarm rate.
[0005] With the development of machine learning technology, traffic classification methods based on statistical features have been widely used. Traditional machine learning algorithms such as support vector machines and random forests perform well in capturing complex patterns, while deep learning methods further improve the detection accuracy by modeling multi-dimensional features of traffic. However, the high computational resource requirements and interpretability problems of deep learning models limit their practical applications. Although certain progress has been made in the prior art, challenges still remain in terms of the accuracy, efficiency, and adaptability of encrypted traffic detection:
[0006] (1)Detection lag of new attacks. Traditional methods based on rules and feature matching have limited response capabilities to unknown threats, and machine learning models may also require training with a large amount of new data to adapt to new attacks.
[0007] (2)High false positive and false negative rates. Behavior analysis and machine learning methods are prone to being interfered by normal behaviors in the determination of traffic anomalies, which may result in a large number of false positives. At the same time, for malicious traffic with good camouflage, these methods may not be able to effectively identify it, leading to false negatives. Summary of the Invention
[0008] The technical problem to be solved by the present invention is to provide a traffic detection method based on a spiking neural-bi-directional LSTM network. With a brand-new model structure design, it can effectively improve the detection efficiency of abnormal traffic.
[0009] The present invention adopts the following technical solutions to solve the above technical problems: The present invention designs a traffic detection method based on a spiking neural-bi-directional LSTM network, and performs the following steps A to C to obtain a traffic anomaly detection model, and then applies the traffic anomaly detection model to perform anomaly detection on the traffic to be detected;
[0010] Step A. Obtain each sample traffic with a preset number of known corresponding traffic anomaly labels or traffic non-anomaly labels respectively, and then enter Step B;
[0011] Step B. Sequentially connect in series a feature input module, a temporal modeling module, a max pooling layer, a spiking neural network module, a self-attention mechanism module, a global average pooling layer, a fully connected layer, and a classification output module from the input end to the output end to construct a network to be trained, and then enter Step C;
[0012] Step C. Based on each sample traffic, using the sample traffic as the input and the label corresponding to the sample traffic as the output, train the network to be trained to obtain a traffic anomaly detection model.
[0013] As a preferred technical solution of the present invention: The feature input module is used to receive traffic. First, for each packet in the traffic in sequence, extract the feature values corresponding to each preset feature category of the packet, and then perform normalization processing and update on the feature values corresponding to each packet respectively to form feature vectors corresponding to each packet, and output them.
[0014] As a preferred technical solution of the present invention: the timing modeling module includes a forward LSTM group and a reverse LSTM group. Both the forward LSTM group and the reverse LSTM group each include three LSTM modules connected in series in sequence from the input end to the output end. The input ends of the LSTM modules in the reverse LSTM group in sequence are respectively connected one-to-one to the input ends of the LSTM modules in the forward LSTM group in reverse order, constituting the three input ends of the timing modeling module. The output ends of the LSTM modules in the reverse LSTM group in sequence are respectively connected one-to-one to the output ends of the LSTM modules in the forward LSTM group in reverse order, constituting the three output ends of the timing modeling module;
[0015] Based on the positions of the first and last data packets in the sequential data packets in the traffic being connected, the three input ends of the timing modeling module sequentially receive the feature vectors corresponding to the sequential data packets output by the feature input module. For each feature vector, the following steps a1 to a3 are respectively executed under the LSTM module in the forward LSTM group and under the LSTM module in the reverse LSTM group to obtain the forward hidden state and the reverse hidden state of the data packet, and then step a4 is executed to obtain the high-dimensional feature vector corresponding to the data packet, that is, the high-dimensional feature vectors corresponding to each data packet are obtained and output;
[0016] Step a1. For the feature vector corresponding to the th data packet , according to the following formula: ; ; ; ;
[0017] Obtain the output of the forget gate corresponding to the th data packet, the output of the input gate corresponding to the th data packet, the output of the output gate corresponding to the th data packet, and the result of the combined forget gate output and input gate output corresponding to the th data packet, that is, the candidate memory content , where , represents the number of data packets in the traffic, represents the Sigmoid activation function, represents the hyperbolic tangent function, represents the unidirectional hidden state of the th data packet, represents the weight corresponding to the forget gate, represents the offset corresponding to the forget gate, represents the weight corresponding to the input gate, represents the offset corresponding to the input gate, represents the weight corresponding to the output gate, represents the offset corresponding to the output gate, represents the weight corresponding to the candidate memory, represents the offset corresponding to the candidate memory, and then enter step a2;
[0018] Step a2. According to the following formula: ; Obtain the result of the combined forget gate output and input gate output of the th data packet , where, represents the result of the combined forget gate output and input gate output of the th data packet, and then enter step a3;
[0019] Step a3. According to the following formula: ; Obtain the unidirectional hidden state of the th data packet ;
[0020] Step a4. According to the following formula: ;
[0021] Obtain the hidden state of the th data packet , that is, the high-dimensional feature vector corresponding to the th data packet ; where, represents the forward hidden state of the th data packet, that is, the unidirectional hidden state obtained by the th data packet executing steps a1 to a3 under the LSTM module in the forward LSTM group , represents the backward hidden state of the th data packet, that is, the unidirectional hidden state obtained by the th data packet executing steps a1 to a3 under the LSTM module in the backward LSTM group .
[0022] As a preferred technical solution of the present invention: the max pooling layer performs pooling update on the high-dimensional feature vectors corresponding to each data packet output by the time series modeling module, and further transmits them to the spiking neural network module. The spiking neural network module respectively executes the following steps b1 to b4 for each eigenvalue in the high-dimensional feature vector corresponding to each data packet, and obtains the activation state of the input pulse signal of each neuron corresponding to each data packet. , forming an activation state matrix , and output;
[0023] Step b1. The pulse coding layer in the spiking neural network module calculates according to the following formula: ; Obtain the spike firing rate corresponding to the th feature in the high-dimensional feature vector corresponding to the th data packet, , represents the number of preset feature categories, represents the th eigenvalue in the high-dimensional feature vector corresponding to the th data packet, represents the weight corresponding to the pulse coding layer, represents the offset corresponding to the pulse coding layer, and then enters step b2;
[0024] Step b2. For the th eigenvalue in the high-dimensional feature vector corresponding to the th data packet , randomly activate and generate corresponding input pulse signal, that is about the activation state of its corresponding input pulse signal, and the input pulse signal is emitted at the corresponding spike firing rate , or activate and not generate corresponding input pulse signal, that is about the activation state
[0025] of its corresponding input pulse signal, and then enter step b3; ;
[0026] Obtain the membrane potential of the th neuron corresponding to the th data packet, where represents the preset leakage coefficient, represents the A data packet corresponds to the membrane potential of the neuron, indicating the synaptic weight from the th feature to the neuron, then enter step b4;
[0027] Step b4. According to the following formula: ;
[0028] Obtain the activation state of the input pulse signal of the th data packet corresponding to the th neuron , indicating that the activation generates the input pulse signal of the th data packet corresponding to the th neuron, indicating that the activation does not generate the input pulse signal of the th data packet corresponding to the th neuron, indicating the preset membrane potential threshold.
[0029] As a preferred technical solution of the present invention: The self-attention mechanism module receives the activation state matrix from the spiking neural network module , and performs the following steps c1 to c2 to obtain a high-dimensional feature matrix and output it;
[0030] Step c1. For the activation state matrix , according to the following formula: ;
[0031] Obtain the corresponding query vector matrix , key vector matrix , value vector matrix , where represents the weight matrix of the query vector, represents the weight matrix of the key vector, represents the weight matrix of the value vector; then enter step c2;
[0032] Step c2. According to the following formula: ;
[0033] Obtain the corresponding attention score , then according to , that is, obtain the high-dimensional feature matrix , where represents the scaling factor, Denotes the dimension of the key vector. Denotes the normalized attention function.
[0034] As a preferred technical solution of the present invention: The global average pooling layer is for the high-dimensional feature matrix output by the self-attention mechanism module , and performs dimensionality reduction according to the following formula; ;
[0035] Obtain the average value corresponding to each feature , form the global feature vector , and output; where Denotes the high-dimensional feature matrix In the rd data packet corresponds to the th activation state of the high-dimensional feature;
[0036] The fully connected layer is for the global feature vector output by the global average pooling layer , according to the following formula: ;
[0037] Obtain the output result , where Denotes the weight matrix of the fully connected layer, Denotes the offset matrix of the fully connected layer;
[0038] The classification output module is for the output result of the fully connected layer , according to the following formula: ;
[0039] Obtain the probability that the traffic corresponds to the traffic anomaly label , Denotes the weight of the classification output module, Denotes the offset of the classification output module, where .
[0040] Corresponding to the above, the technical problem to be solved by the present invention is to provide a system for the traffic detection method based on the spiking neural-bi-directional LSTM network, modularize the network structure, and improve the working efficiency of the network for abnormal traffic detection applications.
[0041] To solve the above technical problems, the present invention adopts the following technical solutions: The present invention designs a system for a traffic detection method based on a pulsed neural-bi-directional LSTM network. The feature input module includes a traffic reading module, a traffic feature extraction module, and a data normalization and standardization module connected in series in sequence from the input end to the output end, which sequentially implement traffic reading, extracting the feature values corresponding to the preset respective feature categories of the data packets, and performing normalization processing and updating on the respective feature values corresponding to the respective data packets, to form feature vectors corresponding to the respective data packets.
[0042] The time series modeling module includes a bi-directional sequence modeling module, a feature sequence extraction module, and a time feature characterization module connected in series in sequence from the input end to the output end. The bi-directional sequence modeling module realizes the construction of a forward LSTM group and a reverse LSTM group. The feature sequence extraction module executes steps a1 to a3, and the time feature characterization module executes step a4.
[0043] The pulsed neural network module includes a model parameter reading module, a pulsed neuron modeling module, a signal conversion module, and a pulse processing and feature enhancement module connected in series in sequence from the input end to the output end. Among them, the model parameter reading module is used to read each feature value in the high-dimensional feature vectors corresponding to the respective data packets output by the max pooling layer. The pulsed neuron modeling module is used to execute steps b1 and b3. The signal conversion module is used to execute step b2 and obtain the activation state of the input pulse signal of each neuron corresponding to the respective data packets in step b4. The pulse processing and feature enhancement module is used to perform feature integration on the activation state of the input pulse signal of each neuron corresponding to the respective data packets to construct an activation state matrix. ;
[0044] The self-attention mechanism module includes an attention weight calculation module and a weighted feature generation module connected in series in sequence from the input end to the output end. The attention weight calculation module is used to execute steps c1 and c2, and the weighted feature generation module is used to execute step c3.
[0045] For the traffic detection method and system based on the pulsed neural-bi-directional LSTM network of the present invention, compared with the prior art by adopting the above technical solutions, it has the following technical effects:
[0046] The present invention designs a traffic detection method based on a spiking neural-bi-directional LSTM network, introduces a time series modeling module, a spiking neural network module, and a self-attention mechanism module, constructs a network to be trained, and trains it with various sample traffic to obtain a traffic anomaly detection model. By combining the dynamic characteristic modeling ability of the spiking neural network and the time series dependence feature capturing ability of the bi-directional long short-term memory network, it can more accurately extract the time series features and behavior patterns of encrypted traffic. And in the network, the parameters are optimized through global average pooling and fully connected layers, which can significantly improve the classification performance and generalization ability, and achieve efficient detection of various encrypted protocol traffic. The present invention also designs a corresponding system, modularizes the network structure design, realizes the modular application of each link of the detection method, and further improves the detection efficiency of abnormal traffic under actual application. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] Figure 1 is a schematic diagram of the data processing flow of the traffic anomaly detection model in the design of the present invention;
[0048] Figure 2 is a schematic diagram of the architecture of the system for implementing the encrypted traffic detection method in the design of the present invention;
[0049] Figure 3 is an application flow chart of the feature input module in the design of the present invention;
[0050] Figure 4 is an application flow chart of model training in the design of the present invention;
[0051] Figure 5 is an application flow chart of traffic classification in the design of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0052] The following further details the specific embodiments of the present invention with reference to the accompanying drawings of the specification.
[0053] The present invention designs a traffic detection method based on a spiking neural-bi-directional LSTM network. In actual application, the specific design is carried out in the following steps A to C to obtain a traffic anomaly detection model, and then the traffic anomaly detection model is used to detect anomalies in the traffic to be detected.
[0054] Step A. Obtain various sample traffic with a preset number of known corresponding traffic anomaly labels or traffic non-anomaly labels respectively, and then proceed to step B.
[0055] Step B. As Figure 1As shown, from the input end to the output end, a feature input module, a temporal modeling module (BiLSTM module), a max pooling layer, a spiking neural network module (SNN module), a self-attention mechanism module (Self-Attention Block), a global average pooling layer (Global Average Pooling), a fully connected layer (FullyConnected Layer), and a classification output module are connected in series in sequence to construct the network to be trained, and then proceed to step C.
[0056] Step C. Based on each sample traffic, using the sample traffic as the input and the label corresponding to the sample traffic as the output, train the network to be trained to obtain a traffic anomaly detection model.
[0057] In terms of specific data processing in the above-designed network structure, the feature input module is used to receive traffic. First, for each packet in the traffic in sequence, extract the feature values corresponding to each preset feature category of the packet, and then perform normalization processing and update on the feature values corresponding to each packet to form the feature vector corresponding to each packet, and output it.
[0058] Regarding each preset feature category, in practical applications, since the encrypted traffic data itself cannot directly extract content layer information, the design mainly obtains effective information from the temporal behavior characteristics and statistical features of the traffic, such as the packet size Size of the packet , arrival time Time , packet direction Direction , and in practical applications, perform normalization processing and update according to the following formula.
[0059]
[0060] Among them, represents the feature value of the th packet corresponding to the th feature category, represents the average feature value of the th feature category for each packet, represents the standard deviation of the feature values of the th feature category for each packet.
[0061] In practical applications, assume that each packet corresponds to 5 feature categories, and the temporal length of each packet is 100, then the input shape is (batch_size, 100, 5).
[0062] Considering that network traffic is a dynamic process, after the feature vectors corresponding to each data packet output by the feature input module, the time series modeling module extracts the time dependencies of traffic features based on a bidirectional long short-term memory network (BiLSTM), and generates high-dimensional time features by capturing context information in both the forward and reverse directions. Specifically, the time series modeling module is designed to include a forward LSTM group and a reverse LSTM group. The forward LSTM group extracts the dependencies from the past to the future, and the reverse LSTM group captures the time features from the future to the past. Both the forward LSTM group and the reverse LSTM group each include three LSTM modules connected in series from the input end to the output end. Each LSTM module dynamically updates the hidden state and memory cell through the forget gate, input gate, and output gate. The input ends of the LSTM modules in the reverse LSTM group in sequence are respectively connected one-to-one to the input ends of the LSTM modules in the forward LSTM group in reverse order, forming the three input ends of the time series modeling module. The output ends of the LSTM modules in the reverse LSTM group in sequence are respectively connected one-to-one to the output ends of the LSTM modules in the forward LSTM group in reverse order, forming the three output ends of the time series modeling module.
[0063] Based on the fact that the positions of the first and last data packets in each sequential data packet in the traffic are connected, the three input ends of the time series modeling module sequentially receive the feature vectors corresponding to each sequential data packet output by the feature input module. For each feature vector, the following steps a1 to a3 are respectively executed under the LSTM module in the forward LSTM group and under the LSTM module in the reverse LSTM group to obtain the forward hidden state and reverse hidden state of the data packet, and then step a4 is executed to obtain the high-dimensional feature vector corresponding to the data packet, that is, the high-dimensional feature vectors corresponding to each data packet are obtained and output.
[0064] Step a1. For the feature vector corresponding to the th data packet, according to the following formulas: ; ; ; ;
[0065] obtain the output of the forget gate corresponding to the th data packet, the output of the input gate corresponding to the th data packet, the output of the output gate corresponding to the th data packet, and the result of the combined forget gate output and input gate output corresponding to the th data packet, which is the candidate memory content corresponding to it , where , represents the number of data packets in the traffic, represents the Sigmoid activation function, represents the hyperbolic tangent function, represents the th one-way hidden state of the data packet, represents the weight corresponding to the forget gate, represents the offset corresponding to the forget gate, represents the weight corresponding to the input gate, represents the offset corresponding to the input gate, represents the weight corresponding to the output gate, represents the offset corresponding to the output gate, represents the weight corresponding to the candidate memory, represents the offset corresponding to the candidate memory, and then enter step a2.
[0066] Step a2. According to the following formula: ;
[0067] Obtain the result of the th data packet's combined forget gate output and input gate output , where represents the result of the th data packet's combined forget gate output and input gate output, and then enter step a3.
[0068] Step a3. According to the following formula: ;
[0069] Obtain the th one-way hidden state of the data packet .
[0070] Step a4. According to the following formula: ;
[0071] Obtain the th hidden state of the data packet , that is, the th high-dimensional feature vector corresponding to the data packet ; where represents the th positive hidden state of the data packet, that is, the one-way hidden state obtained by the data packet th in the LSTM module under the positive LSTM group by executing steps a1 to a3 , represents the The reverse hidden state of a data packet, i.e., the unidirectional hidden state obtained by the data packet in the LSTM module of the reverse LSTM group by performing steps a1 to a3 .
[0072] The high-dimensional feature vectors corresponding to each data packet form a matrix that contains the global context features of the time series, with an input shape of (batch_size, seq_length, feature_size), i.e., (batch_size, 100, 5). The output dimension of the BiLSTM is 2 * hidden_size. Assuming hidden_size = 64, the output shape is (batch_size, seq_length, 128). Then, a max pooling layer is further applied to reduce the time series length and retain the most significant features. That is, the max pooling layer performs pooling updates on the high-dimensional feature vectors corresponding to each data packet output by the time series modeling module and further conveys them to the spiking neural network module. In practical applications, the pooling window size of the max pooling layer can be 2, and the stride is 2, which will reduce the time series length by half. After pooling, the shape of the feature tensor is (batch_size, 50, 128).
[0073] The spiking neural network module (SNN) is a computational model of a biological neural network that mimics the spike discharge mechanism of neurons and is a neural network with strong spatio-temporal characteristics. The spiking neural network module in the present invention is mainly used to capture the time series and dynamic characteristics of encrypted traffic data, so as to provide higher-quality feature inputs for subsequent processing. The spiking neural network module further models the time features extracted by the BiLSTM to capture the burst behavior of malicious traffic. Among them, the SNN is based on the Leaky Integrate-and-Fire (LIF) model to model the time dynamics of the input signal.
[0074] The spiking neural network module respectively performs the following steps b1 to b4 on each eigenvalue in the high-dimensional feature vector corresponding to each data packet to obtain the activation state of the input pulse signal of each neuron corresponding to each data packet , forming an activation state matrix , and outputs it.
[0075] Spiking neural networks take discrete events (spikes) as inputs, so it is necessary to encode the eigenvalue at each time step. Common encoding methods include: Threshold Coding: When the eigenvalue exceeds a certain threshold, a spike is generated; Rate Coding: According to the magnitude of the eigenvalue, spike signals with different frequencies are generated; Temporal Coding: The eigenvalue is expressed by the time interval of the spikes.
[0076] Step b1. The spike coding layer in the spiking neural network module adopts Rate Coding, according to the following formula: ;
[0077] Obtain the spike firing rate corresponding to the th feature in the high-dimensional feature vector corresponding to the th data packet, , , represents the number of preset feature categories, represents the th eigenvalue in the high-dimensional feature vector corresponding to the th data packet, represents the weight corresponding to the spike coding layer, represents the offset corresponding to the spike coding layer, and then enter step b2.
[0078] Step b2. For the th eigenvalue in the high-dimensional feature vector corresponding to the th data packet , randomly activate to generate the corresponding input spike signal, that is, about the activation state of its corresponding input spike signal , and the input spike signal is emitted at the corresponding spike firing rate , or activate without generating the corresponding input spike signal, that is, about the activation state of its corresponding input spike signal , and then enter step b3.
[0079] Step b3. According to the following formula: ;
[0080] Obtain the membrane potential of the th neuron corresponding to the th data packet , where represents the preset leakage coefficient, Indicates that the th data packet corresponds to the membrane potential of the th neuron, indicates the synaptic weight from the th feature to the th neuron, and then enters step b4.
[0081] Step b4. According to the following formula: ;
[0082] Obtain the activation state of the input pulse signal of the th data packet corresponding to the th neuron , indicates that the activation generates the th data packet corresponding to the th neuron's input pulse signal, indicates that the activation does not generate the th data packet corresponding to the th neuron's input pulse signal, indicates the preset membrane potential threshold.
[0083] The spiking neural network module effectively improves the modeling ability of malicious traffic behavior sensitive to time characteristics through the capture of burst signals. Set the number of time steps as t_steps = 10, that is, the activities of neurons are simulated at each time step. Assume that pool_size = 2 and stride = 2 are used, and the dimension of the features after pooling is (batch_size, seq_length / / 4, 128). The spiking neural network module outputs features after pooling, with a shape of (batch_size, 25, 128).
[0084] The self-attention mechanism module enhances the focusing ability of the model by calculating the relationships between different features, enabling the model to capture important temporal patterns in traffic data. The self-attention mechanism module dynamically weights each time step by calculating the correlations between input features. This module weights the features extracted by the spiking neural network module using attention weights to highlight the key features of malicious traffic, thereby improving the classification accuracy.
[0085] The self-attention mechanism module receives the activation state matrix from the spiking neural network module, and performs the following steps c1 to c2 to obtain a high-dimensional feature matrix and output it.
[0086] Step c1. For the activation state matrix , according to the following formula: ;
[0087] Obtain the corresponding query vector matrix , key vector matrix , and value vector matrix , where represents the weight matrix of the query vector, represents the weight matrix of the key vector, represents the weight matrix of the value vector; then proceed to step c2.
[0088] Step c2. According to the following formula: ;
[0089] Obtain the corresponding attention scores , then according to , that is, obtain the high-dimensional feature matrix , where represents the scaling factor, represents the dimension of the key vector, represents the normalized attention function.
[0090] The global average pooling layer reduces the dimension of the high-dimensional feature matrix generated by the self-attention mechanism module . Its main function is to integrate the information in the time dimension and channel dimension, thereby reducing the data dimension, avoiding parameter redundancy, and retaining the global feature information. Specifically, design the global average pooling layer for the high-dimensional feature matrix output by the self-attention mechanism module, and reduce the dimension according to the following formula; ;
[0091] Obtain the average value corresponding to each feature , form the global feature vector , and output it. Through the dimension reduction operation, the global average pooling layer not only effectively reduces the number of parameters, but also avoids the overfitting problem and improves the calculation efficiency. Among them, represents the activation state of the th high-dimensional feature corresponding to the th data packet in the high-dimensional feature matrix .
[0092] The fully connected layer further maps the low-dimensional features after the global average pooling layer into the hidden layer representation for the non-linear combination of features. Specifically, design the fully connected layer for the global feature vector output by the global average pooling layer, according to the following formula: ;
[0093] Obtain the output result , where represents the weight matrix of the fully connected layer, represents the bias matrix of the fully connected layer.
[0094] While introducing non-linear representation ability, the fully connected layer avoids the problem of gradient disappearance. The output of the fully connected layer is a low-dimensional feature representation that fully captures the feature information required for the classification task. Among them, the first fully connected layer: the output dimension is 64, and the activation function uses ReLU; the second fully connected layer: the output dimension is 32, and the activation function uses ReLU. For the classification task, the output shape is (batch_size, num_classes), where num_classes is the number of classes.
[0095] The classification output module is responsible for mapping the hidden features generated by the fully connected layer to the classification results, which is specifically completed through a fully connected mapping and an activation function. Among them, the classification output module for the output result of the fully connected layer ;
[0096] obtains the probability of the traffic corresponding to the traffic anomaly label , and further converts the probability value into a specific detection result according to a preset classification threshold such as 0.5 to achieve the anomaly detection of the traffic. Among them, represents the weight of the classification output module, represents the offset of the classification output module, where .
[0097] In actual applications, for the specific implementation of the above-designed network, a corresponding system is designed modularly for actual implementation and application. As Figure 2 shown, the designed modules cooperate with each other to form a complete malicious encrypted traffic detection system. The feature input module preprocesses the data and generates a feature representation. The time series modeling module captures the long-term and short-term time series dependencies of the traffic. The spiking neural network module further strengthens the time dynamics of the traffic. The self-attention mechanism module highlights the key features. The classification output module finally detects and classifies the traffic.
[0098] The feature input module is the input module of the entire system. Its function is to extract core features from the original encrypted network traffic data. These features are mainly statistical and have nothing to do with the encrypted content. They can provide necessary context information for the model to help distinguish different types of encrypted traffic patterns. The specific design of the feature input module includes a traffic reading module, a traffic feature extraction module, and a data normalization and standardization module, which are connected in series from the input end to the output end. They sequentially implement traffic reading, extracting the feature values corresponding to the preset feature categories of each data packet, and normalizing and updating the feature values corresponding to each data packet respectively to form feature vectors corresponding to each data packet. The practical application of the feature input module is as follows.
[0099] Input: Original encrypted traffic data (such as Pcap format files or traffic logs), which contains a sequence of encrypted data packets.
[0100] Traffic data reading: Parse the original traffic file and extract key information (source / destination IP addresses, port numbers, protocol types, etc.) in the traffic session.
[0101] Data stream parsing: Statistically analyze the traffic session data, such as traffic duration, number of forward / backward data packets, data packet length statistics (such as maximum value, minimum value, mean value, standard deviation), number of bytes and data packets per second of traffic, traffic arrival time interval statistics (such as mean value, standard deviation, maximum value, minimum value), and TCP flags (such as FIN, SYN, ACK, etc.).
[0102] Traffic feature statistics: Combine the above statistical results into a feature vector with a fixed dimension to represent the overall characteristics of each traffic session.
[0103] Output: Feature vector , in the training stage, these statistical features will be normalized to the same numerical range (for example, through z-score standardization) to ensure that the features have equal weights in the model. Subsequently, these feature vectors will be used as inputs and passed to the subsequent deep learning modules.
[0104] The time series modeling module aims to model the time series information of traffic features through BiLSTM (Bidirectional Long Short-Term Memory Network), capture the time dependence of encrypted traffic features, and thus identify the changing trends of traffic patterns. The time series modeling module includes a bidirectional sequence modeling module, a feature sequence extraction module, and a time feature characterization module connected in series from the input end to the output end. The bidirectional sequence modeling module builds the forward LSTM group and the reverse LSTM group. The feature sequence extraction module executes steps a1 to a3, and the time feature characterization module executes step a4. In practical applications, the parameters of the time series modeling module (BiLSTM network) are optimized through backpropagation. The model updates the weights of the forward and reverse LSTMs by calculating the prediction error of the time series features (such as the cross-entropy loss in classification tasks), and thus gradually learns the time dependence patterns in the features.
[0105] The neuromorphic feature enhancement module is one of the core modules of the system. It aims to further enhance the dynamic and time series information in traffic features by simulating the behavior of a biological neural network (SNN, Spiking Neural Network). Different from traditional neural networks, the spiking neural network module (SNN) processes data in an event-driven manner and can efficiently capture sparse and dynamic feature patterns, especially suitable for analyzing the key burst characteristics in time series data. The introduction of this module further improves the modeling ability for complex encrypted traffic patterns.
[0106] The specific design of the spiking neural network module includes a model parameter reading module, a spiking neuron modeling module, a signal conversion module, and a pulse processing and feature enhancement module connected in series from the input end to the output end. Among them, the model parameter reading module is used to read each eigenvalue in the high-dimensional feature vectors corresponding to each data packet output by the max pooling layer. The spiking neuron modeling module is used to execute steps b1 and b3. The signal conversion module is used to execute step b2 and obtain the activation states of the input pulse signals of each neuron corresponding to each data packet in step b4. The pulse processing and feature enhancement module is used to perform feature integration on the activation states of the input pulse signals of each neuron corresponding to each data packet and construct an activation state matrix. .
[0107] For the dynamic feature sequence enhanced by the spiking neural network module (SNN), the feature representation at each time step pays more attention to the dynamic and burst characteristics in the traffic pattern. Through this module, the system can not only model static features but also more accurately analyze the time series dynamics in encrypted traffic, thus providing a more reliable feature representation for the subsequent attention mechanism and classification module.
[0108] The self-attention mechanism module includes an attention weight calculation module and a weighted feature generation module connected in series from the input end to the output end. The attention weight calculation module is used to execute step c1 and step c2, and the weighted feature generation module is used to execute step c3.
[0109] Applying the designed encrypted traffic detection method and system of the present invention to practice, such as Figure 3 As shown, the feature input module is the basic link of the entire encrypted traffic detection system, responsible for converting the original network traffic data into structured analyzable data. Through key steps such as traffic segmentation, duplicate removal and filtering, recombination, and feature extraction, this module eliminates redundancy and noise, extracts important features related to encrypted traffic behavior, and provides high-quality input data for subsequent feature enhancement and classification modules.
[0110] First, in the traffic data segmentation stage, the original data packets in the network can be divided into independent flows based on the five-tuple (source IP, destination IP, source port, destination port, protocol type) to ensure the uniqueness of each traffic flow. At the same time, the data can also be divided based on a time window, splitting continuous network traffic into smaller time segments for subsequent processing. Through the segmentation operation, the system can effectively process long-term network traffic and convert it into small-scale traffic units.
[0111] Next, in the traffic duplicate removal and filtering stage, it is necessary to remove network packets unrelated to the analysis, such as broadcast traffic and multicast traffic, and filter out protocol traffic that does not fall within the analysis scope (such as IPv6, ARP, etc.). In the analysis scenario for encrypted traffic, usually only data of common encrypted protocols such as TLS, SSH, and IPSec are retained, while non-encrypted traffic is excluded to ensure the effectiveness and relevance of the input data.
[0112] In the traffic recombination stage, the system recombines multiple data packets belonging to the same flow through the five-tuple and timestamp to restore the complete traffic session. Especially when processing TCP traffic, the system sorts the data packets in the order of sequence numbers to ensure the logical integrity of the recombined data. In addition, the system can also distinguish forward traffic (client to server) and backward traffic (server to client), and can even comprehensively process two-way traffic to further enrich the feature information.
[0113] Finally, the traffic processed through the above steps will enter the feature extraction stage. Since the content of encrypted traffic cannot be directly decoded, the focus of feature extraction lies in the extraction of traffic behavior and pattern features, including the temporal features of traffic (such as traffic duration, packet interval time, etc.), distribution features (such as the number of forward / backward packets, number of bytes, etc.), protocol features (such as the statistical distribution of TCP flag bits), and statistical features (such as packet length statistics, number of bytes of traffic per second, etc.). These features can effectively reflect the behavior patterns of encrypted traffic and provide rich information input for subsequent classification models.
[0114] The input of the feature input module is the original encrypted network traffic data, which contains an uninterrupted stream of consecutive packets. The output is the preprocessed structured traffic data, including the complete traffic sessions within the time window and their statistical features. These output data lay a solid foundation for the subsequent feature enhancement and classification modules.
[0115] Through the preprocessing process of the original traffic data, the system can not only remove irrelevant data and noise, but also extract multi-dimensional features, providing comprehensive and standardized input for the classification of encrypted traffic, significantly improving the training and prediction effects of subsequent models.
[0116] Regarding the actual training process of the network to be trained, as Figure 4 shown, the first stage of encrypted traffic detection is the modeling and feature extraction of temporal information. First, the original traffic features (such as traffic duration, packet length, and arrival time interval) are input into the temporal modeling module, namely the bidirectional long short-term memory network (BiLSTM). The bidirectional structure of BiLSTM can extract the time series information of traffic features from both the forward and backward directions, fully retaining the context relevance of the data. Internally, it uses a gating mechanism to screen the features at different time steps, highlighting the key features and filtering out the irrelevant data.
[0117] Next, the system uses the spiking neural network module (SNN) to dynamically encode and deeply mine the temporal features. The spiking neural network module (SNN) is a key part of the entire system, aiming to capture the time series features in the encrypted traffic data by simulating the dynamic characteristics of biological neurons. The process of this module mainly includes spike encoding, SNN model construction, model training, model prediction, and model verification. Through this series of steps, the SNN module can effectively process the input encrypted traffic data and provide strong support for subsequent classification and detection.
[0118] During the pulse coding stage, the original encrypted traffic features (such as packet length, traffic duration, arrival time interval, etc.) are converted into a spike train to adapt to the input requirements of the SNN. The coding methods mainly include spike frequency coding and time coding. In spike frequency coding, spikes with corresponding frequencies are generated according to the magnitude of the feature value, while in time coding, the time interval of spike emission is controlled by the magnitude of the feature value. The coded spike train can effectively represent the temporal pattern of the data and input signals to the subsequent spiking neural network module.
[0119] In the SNN model construction stage, the LIF (Leaky Integrate-and-Fire) model is used to simulate the dynamic behavior of neurons, and a spiking neural network module including an input layer, a hidden layer, and an output layer is built. The input layer receives the spike train signal, the hidden layer extracts and fuses the temporal features through neuron connections, and the output layer generates the feature signal. Through this structure, the SNN can simulate the response characteristics of biological neurons to dynamic pulse signals and effectively extract the time series information in the traffic features.
[0120] In the model training stage, the SNN model is optimized with spike train data and traffic label data. During the training process, the STDP (Spike-Timing-Dependent Plasticity) rule is used to adjust the weights between neurons, and through multiple rounds of iterative training, the loss function of the model gradually converges, and finally a stable SNN model with the ability to extract temporal features is obtained.
[0121] In the model prediction and testing stage, the model performs end-to-end inference on the preprocessed traffic data: BiLSTM and SNN extract spatio-temporal features, the self-attention module focuses on key nodes, and finally the detection results are output through the classifier. In the verification link, the performance is comprehensively evaluated through indicators such as accuracy, false alarm rate, and miss rate, and a visualization report is generated to provide a basis for model optimization. This process ensures the reliability and adaptability of the detection system in actual deployment.
[0122] Overall, the SNN module provides an efficient and accurate solution for the encrypted traffic detection task with its powerful time series processing ability, and further improves the detection performance and robustness of the system through combination with the subsequent BiLSTM module.
[0123] After the extraction of temporal features and dynamic coding are completed, the features of BiLSTM and SNN are further fused to form a comprehensive feature representation with both temporal dependence and dynamic expression ability. These fused features can fully characterize the complex patterns of encrypted traffic and lay a solid foundation for subsequent classification or other tasks.
[0124] Through a phased system design, the model has achieved in-depth modeling of encrypted traffic characteristics while taking into account both time dependence and dynamic response capabilities, significantly improving the accuracy and robustness of the detection task.
[0125] Traffic classification is also crucial for the entire system and is responsible for the final classification and judgment of encrypted traffic data. As Figure 5 shown, this module combines the functions of the Global Average Pooling (GAP) layer and the Fully Connected (FC) layer to complete the entire process from feature extraction to classification output through dimensionality reduction, feature integration, and classification mapping.
[0126] The main role of the global average pooling layer is to perform dimensionality reduction and information integration on the high-dimensional temporal features output by the BiLSTM network. The features generated by the BiLSTM model contain rich temporal information, but directly using these high-dimensional features will lead to too high computational complexity and increase the risk of overfitting. The global average pooling layer compresses the complex temporal features into a global feature representation of a fixed dimension by taking the average of the features on the time axis. This not only retains the global information of the features but also significantly reduces the feature dimension and computational cost, preparing for the next classification task.
[0127] The dimensionality-reduced features are fed into the fully connected layer to further complete feature integration and classification. The fully connected layer maps the features to prediction values for each category through linear transformation and non-linear activation functions. Subsequently, these prediction values are transformed into a categorical probability distribution through the Softmax function, and finally, the category corresponding to the highest probability is used as the classification result. The fully connected layer not only integrates the features but also plays a key role in the classification task, providing support for the final model performance.
[0128] Overall, the encrypted traffic classification module extracts global information through the global average pooling layer, reduces the feature dimension, and avoids the overfitting problem; while the fully connected layer completes the key mapping from features to classification results, providing a basis for evaluating system performance (such as accuracy, false alarm rate, etc.). The cooperation of the two ensures the efficiency and accuracy of the classification module in the entire system, providing a reliable guarantee for encrypted traffic detection.
[0129] The above technical solution designs a traffic detection method based on a pulsed neural-bi-directional LSTM network, introduces a time series modeling module, a pulsed neural network module, and a self-attention mechanism module, constructs a network to be trained, and uses each sample traffic for training to obtain a traffic anomaly detection model. By combining the dynamic characteristic modeling ability of the pulsed neural network with the time series dependence feature capture ability of the bi-directional long short-term memory network, it can more accurately extract the time series features and behavior patterns of encrypted traffic. Moreover, the parameters are optimized through global average pooling and fully connected layers in the network, which can significantly improve the classification performance and generalization ability, and achieve efficient detection of various encrypted protocol traffic. The present invention also designs a corresponding system, conducts modular design for the network structure, realizes the modular application of each link of the detection method, and further improves the detection efficiency of abnormal traffic under actual application.
[0130] The embodiments of the present invention have been described in detail above in conjunction with the accompanying drawings. However, the present invention is not limited to the above embodiments. Within the scope of knowledge possessed by those of ordinary skill in the art, various changes can be made without departing from the gist of the present invention.
Claims
1. A traffic detection method based on a pulsed neural - bidirectional LSTM network, characterized in that: Perform the following steps A to C to obtain a traffic anomaly detection model, and then apply the traffic anomaly detection model to perform anomaly detection on the traffic to be detected; Step A. Obtain each sample traffic with a preset number of known corresponding traffic anomaly labels or traffic non - anomaly labels respectively, and then proceed to Step B; Step B. Sequentially connect a feature input module, a temporal modeling module, a max - pooling layer, a spiking neural network module, a self - attention mechanism module, a global average pooling layer, a fully - connected layer, and a classification output module in series from the input end to the output end to construct a network to be trained, and then proceed to Step C; Step C. Based on each sample traffic, with the sample traffic as the input and the label corresponding to the sample traffic as the output, train the network to be trained to obtain a traffic anomaly detection model.
2. The flow detection method based on a pulsed neural-bi-directional LSTM network according to claim 1, wherein: The feature input module is used to receive traffic. First, for each packet in the traffic in sequence, extract the feature values of the preset feature categories corresponding to the packet, and then update the normalization process for each feature value corresponding to each packet, construct the feature vector corresponding to each packet, and output it.
3. The flow detection method based on the pulsed neural-bi-directional LSTM network according to claim 2, characterized in that: The temporal modeling module includes a forward LSTM group and a backward LSTM group. Both the forward LSTM group and the backward LSTM group each include three LSTM modules connected in series from the input end to the output end. The input ends of the LSTM modules in sequence in the backward LSTM group are respectively connected to the input ends of the LSTM modules in reverse order in the forward LSTM group one by one to form the three input ends of the temporal modeling module. The output ends of the LSTM modules in sequence in the backward LSTM group are respectively connected to the output ends of the LSTM modules in reverse order in the forward LSTM group one by one to form the three output ends of the temporal modeling module; Based on the connection of the head and tail packet positions in each packet in the traffic in sequence, the three input ends of the temporal modeling module sequentially receive the feature vectors corresponding to each packet output by the feature input module. For each feature vector under the LSTM modules in the forward LSTM group and under the LSTM modules in the backward LSTM group, perform the following steps a1 to a3 respectively to obtain the forward hidden state and the backward hidden state of the packet, and then perform Step a4 to obtain the high - dimensional feature vector corresponding to the packet, that is, obtain the high - dimensional feature vectors corresponding to each packet respectively, and output them; Step a1. For the eigenvector corresponding to the th data packet , according to the following formula: ; ; ; ; Obtain the output of the forget gate corresponding to the -th data packet, the output of the input gate corresponding to the -th data packet, the output of the output gate corresponding to the -th data packet, and the result of combining the output of the forget gate and the output of the input gate corresponding to the -th data packet, which is the candidate memory content corresponding to , where , represents the number of data packets in the traffic, represents the Sigmoid activation function, represents the hyperbolic tangent function, represents the unidirectional hidden state of the -th data packet, represents the weight corresponding to the forget gate, represents the offset corresponding to the forget gate, represents the weight corresponding to the input gate, represents the offset corresponding to the input gate, represents the weight corresponding to the output gate, represents the offset corresponding to the output gate, represents the weight corresponding to the candidate memory, represents the offset corresponding to the candidate memory, and then proceed to step a2; Step a2. According to the following formula: ; Obtain the result of the combined forget gate output and input gate output of the th data packet, where represents the result of the combined forget gate output and input gate output of the th data packet, and then proceed to step a3; Step a3. According to the following formula: ; Obtain the one-way hidden state of the th data packet; Step a4. According to the following formula: ; Obtain the hidden state of the th data packet, that is, the high-dimensional feature vector corresponding to the th data packet ; where represents the forward hidden state of the th data packet, that is, the single-direction hidden state obtained by the th data packet when executing steps a1 to a3 under the LSTM module in the forward LSTM group , represents the backward hidden state of the th data packet, that is, the single-direction hidden state obtained by the th data packet when executing steps a1 to a3 under the LSTM module in the backward LSTM group .
4. The flow detection method based on a pulsed neural-bi-directional LSTM network according to claim 3, wherein: The max pooling layer performs pooling updates on the high-dimensional feature vectors corresponding to each data packet output by the temporal modeling module, and further transmits them to the spiking neural network module. The spiking neural network module executes the following steps b1 to b4 for each eigenvalue in the high-dimensional feature vector corresponding to each data packet to obtain the activation states of the input pulse signals of each neuron corresponding to each data packet. , forming an activation state matrix , and outputs it; Step b1. By the pulse coding layer in the spiking neural network module according to the following formula: ; Obtain the firing rate corresponding to the th feature in the high-dimensional feature vector corresponding to the th data packet. Here, represents the number of preset feature categories, represents the th eigenvalue in the high-dimensional feature vector corresponding to the th data packet, represents the weight corresponding to the pulse coding layer, represents the offset corresponding to the pulse coding layer, and then enter step b2; Step b2. For the th data packet corresponding to the th eigenvalue in the high-dimensional feature vector , randomly activate to generate the corresponding input pulse signal, that is, regarding the activation state of the corresponding input pulse signal , and the input pulse signal is emitted at the corresponding pulse firing rate , or activate without generating the corresponding input pulse signal, that is, regarding the activation state of the corresponding input pulse signal , and then proceed to step b3; Step b3. According to the following formula: ; Obtain the th data packet corresponding to the membrane potential of the th neuron, where , in which, represents a preset leakage coefficient, represents the membrane potential of the th data packet corresponding to the th neuron, represents the synaptic weight from the th feature to the th neuron, represents a preset reset decay factor, and then enter step b4; Step b4. According to the following formula: ; Get the The data packet corresponds to The activation state of the input pulse signal of a neuron , Indicates activation of the generated The data packet corresponds to The input pulse signal of a neuron, Indicates that activation does not generate The data packet corresponds to The input pulse signal of a neuron, Indicates the preset membrane potential threshold.
5. The flow detection method based on the pulsed neural-bi-directional LSTM network according to claim 4, wherein: The self-attention mechanism module receives the activation state matrix from the spiking neural network module , and performs the following steps c1 to c2 to obtain a high-dimensional feature matrix and output it; Step c1. For the activation state matrix , according to the following formula: ; Obtain the corresponding query vector matrix , key vector matrix , value vector matrix , where represents the weight matrix of the query vector, represents the weight matrix of the key vector, represents the weight matrix of the value vector; then proceed to step c2; Step c2. According to the following formula: ; Obtain the corresponding attention score , then according to , that is, obtain the high-dimensional feature matrix , where represents the scaling factor represents the dimension of the key vector represents the normalized attention function 6. The flow detection method based on a pulsed neural - bidirectional LSTM network according to claim 5, wherein: The global average pooling layer is for the high-dimensional feature matrix output by the self-attention mechanism module , and performs dimensionality reduction according to the following formula; ; Obtain the average value corresponding to each feature , and form a global feature vector , and output it; where represents the activation state of the th high-dimensional feature corresponding to the th data packet in the high-dimensional feature matrix ; The fully connected layer is for the global feature vector output by the global average pooling layer , according to the following formula: ; Obtain the output result , where represents the weight matrix of the fully connected layer, represents the bias matrix of the fully connected layer; The classification output module is directed at the output result of the fully connected layer , according to the following formula: ; Probability of obtaining a traffic corresponding traffic anomaly label , represents the weight of the classification output module, represents the offset of the classification output module, where, .
7. A system for implementing the traffic detection method based on the pulsed neural-bi-directional LSTM network according to claim 6, characterized in that: The feature input module includes a traffic reading module, a traffic feature extraction module, and a data normalization and standardization module connected in series from the input end to the output end, which sequentially implement traffic reading, extracting the feature values of the preset feature categories corresponding to the packet, and updating the normalization process for each feature value corresponding to each packet to construct the feature vector corresponding to each packet; The timing modeling module includes a bidirectional sequence modeling module, a feature sequence extraction module, and a time feature characterization module connected in series from the input end to the output end. The bidirectional sequence modeling module implements the construction of a forward LSTM group and a backward LSTM group. The feature sequence extraction module executes steps a1 to a3, and the time feature characterization module executes step a4; The spiking neural network module includes a model parameter reading module, a spiking neuron modeling module, a signal conversion module, and a pulse processing and feature enhancement module that are connected in series from the input end to the output end. Among them, the model parameter reading module is used to read each eigenvalue in the high-dimensional feature vectors corresponding to each data packet output by the max pooling layer. The spiking neuron modeling module is used to execute step b1 and step b3. The signal conversion module is used to execute step b2 and obtain the activation states of the input pulse signals of each neuron corresponding to each data packet in step b4. The pulse processing and feature enhancement module is used to perform feature integration on the activation states of the input pulse signals of each neuron corresponding to each data packet and construct an activation state matrix ; The self-attention mechanism module includes an attention weight calculation module and a weighted feature generation module connected in series from the input end to the output end. The attention weight calculation module is used to execute steps c1 and c2, and the weighted feature generation module is used to execute step c3.
Citation Information
Patent Citations
CNN-BiLSTM and SVM fused industrial Internet of Things intrusion detection system and method
CN115550009A
Abnormal flow detection method and device, and medium
CN115712857A
Nervous system signal processing method based on spiking neural network
CN118013395A
Chinese electronic medical record named entity identification method based on multiple attention mechanisms and SNN network
CN119538927A
Long-short term memory (LSTM) cells on spiking neuromorphic hardware
US20180232631A1
Cited By
Encrypted stream attack detection method and system based on spiking nerve and bidirectional LSTM
CN121530755A
A method and system for encrypted stream attack detection based on pulse neural and bidirectional LSTM
CN121530755B