Graph anomaly detection method based on multi-view graph embedding and node prototype comparison
Through the method of multi-view graph embedding and node prototype comparison, the lack of detection of traditional graph neural networks under the assumption of homogeneity is solved, efficient identification of abnormal nodes is achieved, and the performance of graph abnormality detection is improved.
Patent Information
- Application Number
- CN202510749084.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-06
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2045-06-06
AI Technical Summary
Existing graph anomaly detection methods rely on the assumption of homogeneity, making it difficult to effectively distinguish between normal nodes and abnormal nodes, especially when facing abnormal nodes' camouflage behavior, the detection capability is insufficient.
Using the method of multi-view diagram embedding and node prototype comparison, an enhanced adjacency matrix is constructed through the KNN algorithm, combined with the BWGNN model and attention mechanism, learn node representation, and strengthen heterogeneity discrimination through prototype comparison learning to realize the identification of abnormal nodes.
It significantly improves the performance of graph abnormality detection, improves the distinction between abnormal nodes, and enhances the ability to identify camouflage behavior.
Smart Images

Figure CN120257029A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of Graph Anomaly Detection (GAD), and particularly relates to a graph anomaly detection method based on multi-view graph embedding and node prototype comparison. Background Art
[0002] A graph is a complex data structure composed of nodes and edges. Nodes represent entities, and edges describe the relationships between entities, which can effectively model various complex systems in the real world. Graph anomaly detection aims to identify nodes, edges, or subgraphs that deviate significantly from the normal pattern in graph data, such as fraudulent transaction nodes in a financial network, abnormal accounts on a social platform, etc. The core challenge lies in how to integrate node topological structure and attribute feature information while dealing with the sparsity, camouflage of abnormal samples, and the complexity of data scale.
[0003] Among the existing graph anomaly detection techniques, traditional methods such as statistical, density, or clustering-based algorithms are difficult to capture the non-linear relationships and local anomaly patterns in graph data due to their dependence on artificial features or global distribution assumptions. With the development of Graph Neural Networks (GNNs), GNN-based methods aggregate neighborhood information through a message passing mechanism to learn high-dimensional representations of graph data, significantly improving the detection performance. However, traditional GNN methods are generally limited by the "homophily assumption" - that is, assuming that adjacent nodes have similar features or labels. The low-frequency filtering characteristic of GNNs will smooth the key differences between abnormal nodes and normal nodes, resulting in insufficient ability to detect anomalies that disguise themselves by mimicking the structure or features of normal nodes.
[0004] Therefore, it is necessary to propose a new graph anomaly detection method to identify the noise patterns of abnormal nodes and edges in graph data, design a GNN architecture with heterogeneity awareness, and learn discriminative node representations to solve the technical problems existing in the existing graph anomaly detection methods. Summary of the Invention
[0005] Aiming at the problem that traditional graph neural networks are difficult to effectively distinguish normal nodes from abnormal nodes based on the homophily assumption, the present invention proposes an attribute graph abnormal node detection method based on multi-view graph embedding and node prototype comparison.
[0006] In a first aspect, a graph anomaly detection method based on multi-view graph embedding and node prototype comparison is provided, including the following steps: S1. Collection and preprocessing of the graph anomaly detection dataset, and construction of the dataset labels; S2. Construction of a graph anomaly detection model based on multi-view graph embedding and node prototype comparison; S3. Iteratively optimizing the model using the training set S4. Repeatedly execute S2 and S3 until the total loss value stabilizes; complete the training of the graph anomaly detection model.
[0007] S5. Predict the anomaly probability of nodes on the test set. If the probability exceeds the specified threshold, the node is regarded as an abnormal node.
[0008] Preferably, S1 includes: S1.1. Data acquisition and cleaning. For the original dataset containing node adjacency relationships and attribute features, remove noise data (such as isolated nodes), retain valid nodes, and obtain the adjacency matrix and the attribute feature matrix .
[0009] S1.2. Anomaly label injection. For the dataset with anomaly labels, directly use the existing labels. For the dataset without anomaly labels, generate artificial abnormal nodes by injecting structural anomalies (such as fully connected subgraphs) and attribute anomalies (such as replacing the feature vector with a high Euclidean distance vector). Finally, construct the graph data containing the adjacency matrix , node features and anomaly labels .
[0010] Preferably, S2 includes: S2.1. Generation of the KNN-enhanced adjacency matrix.
[0011] Calculate the attribute similarity between nodes through the KNN algorithm, and select the most similar neighbors of each node to construct the enhanced adjacency matrix.
[0012] S2.2. Feature extraction based on the BWGNN model.
[0013] Input the adjacency matrix and attribute feature matrix of the original graph and the enhanced graph into the customized spectral filter BWGNN model to obtain the node representation.
[0014] S2.3. Node representation fusion based on the attention mechanism.
[0015] Fuse the node representations of the original graph and the enhanced graph in two modalities through the weighted attention mechanism.
[0016] S2.4. Prototype contrast learning of node representations.
[0017] Calculate the average value of all normal and abnormal node embeddings as the prototypes of normal nodes and abnormal nodes, and minimize the distance between the node embeddings of a certain category and the corresponding prototypes.
[0018] S2.5. Abnormal node detection.
[0019] The node representation is input into a classifier to predict the anomaly probability of the node, thereby realizing the detection of anomalous nodes.
[0020] Preferably, S3 is specifically: By jointly optimizing the node classification loss and the prototype contrast loss the model parameters are updated. The total loss function is:
[0021] where is the loss weight parameter, and the parameters of the BWGNN model and the attention module are adjusted through backpropagation.
[0022] In a second aspect, a graph anomaly detection system based on multi-view graph embedding and node prototype contrast is provided for performing the method described in the first aspect, including: A data processing module for collecting and preprocessing a graph anomaly detection dataset and injecting anomalous nodes.
[0023] A model construction module for constructing a graph anomaly detection model based on multi-view graph embedding and node prototype contrast, including generating a KNN-enhanced adjacency matrix, feature extraction based on the BWGNN model, node representation fusion based on the attention mechanism, prototype contrast learning of node representations, and anomalous node detection; A calculation optimization module for updating the model parameters according to the node classification loss and the prototype contrast loss.
[0024] An inference and prediction module for predicting the anomaly probability of nodes.
[0025] In a third aspect, a computer storage medium is provided, in which a computer program is stored; when the computer program runs on a computer, the computer is enabled to execute the method described in the first aspect.
[0026] In a fourth aspect, an electronic device is provided, including: A memory for storing a computer program; A processor for executing the computer program to implement the method described in the first aspect.
[0027] The advantages and beneficial effects of the present invention are as follows: 1. Multi-dimensional information fusion enhances the anomaly representation ability. Traditional GNNs rely on the homophily assumption and are difficult to capture the camouflage behavior of anomalous nodes. The present invention constructs a multi-view adjacency matrix through the KNN algorithm, fuses the node attribute similarity with the original adjacency relationship, and generates an enhanced adjacency matrix reflecting the attribute similarity, providing richer inputs for the graph neural network.
[0028] 2. Prototype contrast learning enhances the discriminative power of heterogeneity. To address the problem of abnormal node noise interfering with model training, the present invention introduces a normal and abnormal node representation prototype contrast mechanism. By explicitly modeling the feature centers of the two types of nodes, it forces the embeddings of normal nodes to be close to the normal prototype and abnormal nodes to be close to the abnormal prototype, reducing the impact of misleading information caused by abnormal nodes disguising themselves. Through the learning of multi-view graph embeddings and the node prototype contrast strategy, the present invention significantly improves the distinguishability between normal nodes and abnormal nodes and effectively enhances the performance of graph anomaly detection. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] Figure 1 FIG. is a flowchart of a graph anomaly detection method based on multi-view graph embedding and node prototype contrast provided by an embodiment of the present invention.
[0030] Figure 2 FIG. is an architecture diagram of a graph anomaly detection method based on multi-view graph embedding and node prototype contrast provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0031] The present invention will be further described below in conjunction with specific embodiments and the accompanying drawings.
[0032] Aiming at the problem that traditional graph neural networks are difficult to effectively distinguish normal nodes from abnormal nodes based on the homogeneity assumption, the present invention proposes an innovative heterogeneity perception mechanism. By means of the KNN algorithm, an enhanced adjacency matrix is constructed to provide structural information from the perspective of node attribute similarity, thereby accurately extracting node features. Further, by introducing a contrast learning module for normal node and abnormal node representation prototypes, the model's ability to capture the heterogeneity relationship between nodes is strengthened.
[0033] Taking the publicly available graph anomaly detection datasets Yelp, Amazon, and Pubmed as examples, the process of the present invention will be specifically described.
[0034] The Yelp dataset contains review data of users on different businesses such as hotels and restaurants, consisting of approximately 1.6 million merchants and 8.63 million reviews from 8 metropolitan areas. The vertices represent reviews, and the edges represent the relationships between reviews (such as the same user posting or the same product being posted under the same rating or month). Spam reviews are regarded as abnormal vertices.
[0035] The Amazon dataset is a user review network under the Amazon music equipment category. The vertices are users, and the edges are the relationships between users (such as reviewing the same product or having the same star rating within the same week). Users who write false reviews are regarded as abnormal vertices.
[0036] The Pubmed dataset consists of a biomedical citation network, where scientific publications are vertices and citation relationships are edges. This dataset is used for node classification tasks. In the experiment, the category with the fewest published papers is regarded as the abnormal vertex. The specific information of the dataset is shown in Table 1: Table 1: Specific Information of the Dataset dataset number of nodes number of edges proportion of abnormal nodes Yelp 45954 8097302 14.5% Amazon 11944 9557648 6.9% Pubmed 19717 88651 20.8% A graph anomaly detection method based on multi-view graph embedding and node prototype contrast includes the following steps: S1. Collection and preprocessing of the graph anomaly detection dataset, and construction of dataset labels.
[0037] S1.1. Data acquisition and cleaning. For the original dataset containing node adjacency relationships and attribute features, noise data (such as isolated nodes) are removed, and valid nodes are retained to obtain the adjacency matrix and the attribute feature matrix .
[0038] S1.2. Abnormal label injection. For the dataset with abnormal labels, the existing labels are directly used. For the dataset without abnormal labels, artificial abnormal nodes are generated by injecting structural anomalies (such as fully connected subgraphs) and attribute anomalies (such as replacing the feature vector with a high Euclidean distance vector). Finally, graph data containing the adjacency matrix , node features and abnormal labels is constructed.
[0039] S2. Construction of a graph anomaly detection model based on multi-view graph embedding and node prototype contrast.
[0040] S2.1. Generation of the KNN-enhanced adjacency matrix. The original adjacency matrix directly reflects the real connection relationship between nodes in the graph and captures the original structural information. The KNN-enhanced adjacency matrix is obtained by calculating the attribute similarity between nodes using the KNN algorithm and selecting the most similar neighbors for each node to construct the enhanced adjacency matrix. The formula is: . This matrix strengthens the connections of nodes with similar attributes and is used to capture the feature homogeneity pattern.
[0041] S2.2. Feature extraction based on the BWGNN model. BWGNN refers to the Beta wavelet graph neural network. The BWGNN adopts multiple graph convolutional layers and uses wavelet kernels in parallel, and then aggregates the corresponding filtering results. The propagation process of the BWGNN is:
[0042]
[0043] Among them, represents a multi-layer perceptron, represents an aggregation function, corresponds to the beta wavelet, and the node embedding representation is obtained after aggregation , represents the node representation calculated by the -th beta wavelet, .
[0044] The adjacency matrix feature matrix of the original graph and the KNN-enhanced adjacency matrix , feature matrix are respectively input into the BWGNN to extract the multi-modal node representation, and the original graph features and the KNN graph features are obtained respectively.
[0045] S2.3. Node representation fusion based on the attention mechanism. The node representations of the two modalities are fused through a weighted attention mechanism, and the formula is: .
[0046] Among them, is the adaptive weight, which dynamically balances the contributions of the original structure and attribute similarity.
[0047] S2.4. Prototype contrast learning of node representations. Define the normal node prototype and the abnormal node prototype , and calculate the mean values of all normal and abnormal node embeddings:
[0048]
[0049] By minimizing the distance between the node embedding and the corresponding prototype, the clustering of normal and abnormal patterns is strengthened, and the loss function is:
[0050] S2.5. Abnormal node detection. The node representation is input into a feedforward neural network (Feedforward Neural Network, FFN) for classification, and the abnormal probability is output.
[0051] Let the parameters of the feedforward neural network be the weight matrix and the bias vector ( represents the number of network layers), then for the node representation , and its abnormal probability calculation process is as follows:
[0052]
[0053] where is an activation function (such as ReLU) for introducing non-linearity; maps the output to the interval to obtain the abnormal probability ( the closer it is to 1, the more likely the node is to be abnormal).
[0054] The classification loss uses the cross-entropy function:
[0055] S3. Use the training set to iteratively optimize the model. Finally, update the model parameters by jointly optimizing the node classification loss and the prototype comparison loss . The total loss function is:
[0056] where is the loss weight parameter, and the parameters of the BWGNN model and the attention module are adjusted through backpropagation.
[0057] S4. Repeatedly execute S2 and S3 until the total loss value tends to be stable; complete the training of the graph anomaly detection model.
[0058] S5. Predict the abnormal probability of nodes on the test set. If the probability exceeds the specified threshold, the node is regarded as an abnormal node.
[0059] The embodiment of the present invention also provides a graph anomaly detection system based on multi-view graph embedding and node prototype comparison, including the following modules: A data processing module for collecting and preprocessing the graph anomaly detection data set and injecting abnormal nodes.
[0060] A model construction module for constructing a graph anomaly detection model based on multi-view graph embedding and node prototype comparison, including generating an adjacency matrix enhanced by KNN, feature extraction based on the BWGNN model, node representation fusion based on the attention mechanism, prototype comparison learning of node representations, and abnormal node detection; A calculation and optimization module for updating the model parameters according to the node classification loss and the prototype comparison loss.
[0061] An inference and prediction module for predicting the abnormal probability of nodes.
[0062] An embodiment of the present invention also provides a graph anomaly detection device based on multi-view graph embedding and node prototype comparison, including: a memory for storing a computer program; a processor for executing the computer program to implement a graph anomaly detection method based on multi-view graph embedding and node prototype comparison as described in the above solution.
[0063] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A graph anomaly detection method based on multi-view graph embedding and node prototype contrast, characterized in that It includes the following steps: S1. Collect and preprocess the graph anomaly detection dataset, and construct the dataset labels; S2. Construct a graph anomaly detection model based on multi-view graph embedding and node prototype contrast; S3. Iteratively optimize the model using the training set; S4. Repeatedly execute S2 and S3 until the total loss value tends to be stable; complete the training of the graph anomaly detection model; S5. Predict the anomaly probability of nodes on the test set. If the probability exceeds the specified threshold, the node is regarded as an abnormal node.
2. The graph anomaly detection method based on multi-view graph embedding and node prototype comparison according to claim 1, wherein, S1 includes: S1.
1. Data acquisition and cleaning. For the original dataset containing node adjacency relationships and attribute features, noise data is removed and valid nodes are retained to obtain an adjacency matrix and an attribute feature matrix ; S1.
2. Inject anomaly labels. For the dataset with anomaly labels, directly use the existing labels; For the dataset without abnormal labels, artificial abnormal nodes are generated by injecting structural anomalies and attribute anomalies; finally, a graph data containing an adjacency matrix , node features and abnormal labels is constructed.
3. The graph anomaly detection method based on multi-view graph embedding and node prototype comparison according to claim 1, characterized in that S2 It includes: S2.
1. Generate an adjacency matrix enhanced by KNN Calculate the attribute similarity between nodes through the KNN algorithm, and select the most similar neighbors of each node to construct an enhanced adjacency matrix; S2.
2. Feature extraction based on the BWGNN model Input the adjacency matrices and attribute feature matrices of the original graph and the enhanced graph into the customized spectral filter BWGNN model to obtain node representations; S2.
3. Node representation fusion based on the attention mechanism Fuse the node representations of the original graph and the enhanced graph in two modalities through the weighted attention mechanism; S2.
4. Prototype contrast learning of node representations Calculate the average values of all normal and abnormal node embeddings as the prototypes of normal and abnormal nodes, and minimize the distance between the node embeddings of a certain category and the corresponding prototypes; S2.
5. Abnormal node detection Input the node representations into the classifier to predict the anomaly probability of the nodes and achieve abnormal node detection.
4. A graph anomaly detection system based on multi-view graph embedding and node prototype comparison, characterized in that For implementing the method described in any one of claims 1-3, it is characterized in that the detection system includes: A data processing module for collecting and preprocessing the graph anomaly detection dataset and injecting abnormal nodes; A model construction module for constructing a graph anomaly detection model based on multi-view graph embedding and node prototype contrast, including generating an adjacency matrix enhanced by KNN, feature extraction based on the BWGNN model, node representation fusion based on the attention mechanism, prototype contrast learning of node representations, and abnormal node detection; A calculation and optimization module for updating the model parameters according to the node classification loss and prototype contrast loss; An inference and prediction module for predicting the anomaly probability of nodes.
5. A computer storage medium, characterized in that, The computer storage medium stores a computer program; when the computer program runs on the computer, the computer executes the method described in any one of claims 1-3.
6. An electronic device, characterized in that, It includes: A memory for storing the computer program; A processor for executing the computer program to implement the method described in any one of claims 1-3.
Citation Information
Patent Citations
Neighborhood node structure coding-based graph neural network anomaly detection method and apparatus
CN115859143A
Small sample remote sensing image classification method based on restrictive prototype comparison network
CN115984621A
Equipment anomaly detection method and device, electronic equipment and storage medium
CN118349932A
Method, system and device for detecting abnormal node in blockchain and storage medium
US12052379B1
Method and apparatus for anomaly detection on graph
WO2023010502A1
Cited By
Abnormal node detection method for financial transaction information based on attribute enhancement
CN120597179A
Abnormal node detection method for financial transaction information based on attribute enhancement
CN120597179B
Unsupervised graph anomaly detection method and device, equipment and storage medium
CN121920454A
Open set-oriented graph-level anomaly detection method based on prototype boundary constraint
CN122310380A