Network anomaly detection method based on incremental learning graph neural network
By dividing molecular networks in parallel training graph neural networks on edge forwarding devices, using incremental learning and federated learning, the problems of low network edge detection efficiency and resource limitation are solved, and efficient and accurate network anomaly detection is achieved.
Patent Information
- Application Number
- CN202510463251.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-14
- Publication Date
- 2025-07-11
AI Technical Summary
Existing graph neural networks cannot perform abnormal detection on-site at the edge of the network, resulting in low detection efficiency, high privacy leakage risk and heavy transmission burden. At the same time, embedded system computing power and storage resources are limited and cannot run classic graph neural networks.
The computer network is divided into multiple subnets, each subnet is managed by an edge forwarding device. The graph neural network is trained on the edge forwarding device in the form of data parallelism and model parallelism, and the model is updated using incremental learning and federated learning, and lightweight model updates are performed through attention heat maps and knowledge distillation.
It realizes efficient and accurate network anomaly detection on resource-constrained network forwarding devices, reduces the burden of data transmission and privacy leakage risks, and avoids the problems of repeated training and insufficient memory.
Smart Images

Figure CN120301649A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network anomaly detection, and in particular relates to a network anomaly detection method based on incremental learning graph neural network. Background Art
[0002] GNN (graph neural network) has become one of the research hotspots of network anomaly detection because it is naturally suitable for representing computer networks. However, most of the current related studies use centralized servers to train graph neural networks. This training mode requires long-distance transmission and dumping of network flow data, so the execution efficiency is not high. At the same time, it is impossible to track network fact data in a timely manner, resulting in the lag of the detection model, and there is a risk of privacy leakage. At the same time, it also introduces additional transmission burden to the target network. If the network flow data can be detected based on graph neural networks at the edge of the network, it will be a more efficient method. This idea is similar to the design concept of content distribution networks (CDNs) to provide access services to users as close as possible; but similar CDN solutions such as the literature [Hao Yin, Liu Xuening, Min Geyong and Lin Chuang, "Content delivery networks: a bridge between emerging applications and future IP networks", IEEE Network, vol. 24, no. 4, 2010, pp. 52-56] require the establishment of dedicated networks, protocols, algorithms and servers, which are extremely expensive, which is unaffordable for network anomaly detection services.
[0003] At present, the main method to solve the problem of remote transmission of a large amount of training data is through sampling, such as the literature [B.Perozzi, R.Al-Rfou, and S.Skiena, "Deepwalk: Online learning of socialrepresentations", KDD, 2014, pp.701-710]. This solution does not collect all data when collecting network data, but periodically and randomly samples data from different locations in the network and uses these data as input for the anomaly detection model. This solution effectively reduces the remote transmission process of training data, improves the efficiency of model training, reduces the risk of privacy leakage to a certain extent, and reduces the transmission burden of the network. However, this method of collecting training data may miss some important data, resulting in deviation of the trained model; at the same time, this method still does not solve the problem of data in-situ training and reasoning, and the trained model still has lag.
[0004] A network forwarding device is the device closest to the network terminal. If data collection, model training, and inference can be performed locally on the network forwarding device, it is the most ideal method. However, most network forwarding devices are implemented based on embedded systems and are restricted by the limited computing power and storage resources of the embedded platform, making it impossible to run classical graph neural networks. Summary of the Invention
[0005] In view of the above, the present invention provides a network anomaly detection method based on an incremental learning graph neural network, which can solve the dilemma that existing graph neural networks cannot detect network anomalies locally at the network edge, helps improve the accuracy of graph neural networks, and avoids sensitive data leakage and increased network load caused by training data transmission.
[0006] A network anomaly detection method based on an incremental learning graph neural network includes the following steps:
[0007] (1) Divide the entire computer network into multiple subnets with an edge forwarding device as the subnet center. Each subnet corresponds to an edge forwarding device and consists of hosts directly connected to the edge forwarding device. The edge forwarding device directly obtains the network flow characteristics of each host in the subnet and forms a micro computing power network;
[0008] (2) Execute the AGGREGATE-COMBINE (aggregation-fusion) and training processes of the graph neural network on each edge forwarding device in a mode that combines data parallelism and model parallelism;
[0009] (3) Construct negative samples of the computer network through a destruction function, calculate the mutual information between local edge features and global information using a non-linear function, and use it as the score value of the discriminator in the graph neural network;
[0010] (4) Use the binary cross-entropy loss function to perform gradient descent on the graph neural network to iteratively update the parameters of the encoder and discriminator in the graph neural network. After training is completed, determine the attention heat map of the computer network;
[0011] (5) When the node features in the computer network change, purify the attention heat map, and input the node feature data in the corresponding area of the purified attention heat map into the graph neural network for incremental learning;
[0012] (6) Update the network anomaly detection models trained by each edge forwarding device in a federated learning manner. The edge forwarding device uses the updated model to detect anomalies in the nodes (i.e., hosts) in its subnet.
[0013] Further, in the step (2), for any edge forwarding device, when performing node neighbor aggregation at the 0th layer of the graph neural network, the edge forwarding device uses its computing power to aggregate the features of each node in the subnet centered on itself, obtains the aggregated features of the 0th layer of the graph neural network in the subnet where it is located, and sends them to other edge forwarding devices; when performing node neighbor aggregation at the ith layer of the graph neural network, the edge forwarding device merges the aggregated features of the (i - 1)th layer of the graph neural network in its subnet with the aggregated features of the (i - 1)th layer of the graph neural network in the corresponding subnets of other edge forwarding devices to generate the aggregated features of the ith layer of the graph neural network in the subnet where the edge forwarding device is located, where i is a natural number greater than 0.
[0014] Further, in the step (2), each edge forwarding device uses the node feature data in its subnet and the subnet node feature data from other edge forwarding devices to train the encoder of the graph neural network, aggregates the encoder parameters trained by each edge forwarding device in a federated learning manner to obtain global encoder parameters, and then uses the global encoder parameters to uniformly update the graph neural network encoder on each edge forwarding device.
[0015] The present invention decomposes the neighbor aggregation process of each node in the entire computer network by the graph neural network into neighbor aggregation of nodes in its own subnet on each edge forwarding device and sharing of aggregated data between edge forwarding devices; in the training process of the graph neural network encoder, node feature data is collected and aggregated distributively under the cooperation of each edge forwarding device in a data parallel manner, and at the same time, the graph neural network encoder is independently trained by each edge forwarding device in a model parallel manner.
[0016] Further, in the step (3), the sum of two node feature vectors is used as the feature vector of the edge between these two points, and the global information of the entire computer network is represented as the average value of the feature vectors of all edges; for any edge, the mutual information between the feature vector of the edge and the global information characterizes the importance degree of the edge in the entire computer network, and it is used as the score value of the graph neural network discriminator.
[0017] Further, in the step (4), the graph neural network is trained based on the binary cross-entropy loss function. After training, the score value of the discriminator represents the importance of the edge feature in the global information. At this time, the area composed of the edges with relatively high corresponding score values (greater than the set threshold) is used as the attention heat map of the computer network. The present invention uses the maximum mutual information algorithm for the by-products of training the graph neural network encoder, that is, the score values of the discriminator for each edge or node as the standard for identifying the importance of the edge or node in representing the entire computer network graph. Edges or nodes with scores higher than a specific value are classified as the attention heat map of the target computer network.
[0018] Further, if the characteristics of a node in the computer network change within one cycle in step (5), determine its subnet and take the intersection of this subnet and the attention heatmap to obtain a purified attention heatmap. Then, input the node feature data within the intersection area into the graph neural network, and perform incremental learning on the graph neural network based on the knowledge distillation method. Through the high-order context transfer of the graph neural network for the changes in node or edge features, the present invention truly represents the degree of change in other node features caused by the change in the features of each node or edge, thereby accurately capturing the parts in the network that have significant changes. The attention heatmap is purified using the attention heatmap and the subgraph with significant changes to obtain the subgraph that can best represent the changes in the entire computer network. By adopting the method of performing incremental learning on the purified attention heatmap, when the network changes, only update the parameters of the old model with the data on the purified attention heatmap to obtain a new model, instead of retraining the entire model.
[0019] Further, the knowledge distillation method is to use the network anomaly detection model based on the graph neural network at the previous moment as old knowledge, and combine the new data on the purified attention heatmap at the current moment to perform knowledge distillation on the old knowledge. At the same time, add an attention heatmap drift loss to the total loss function of incremental learning to ensure that the attention heatmap knowledge can also be updated synchronously during the update of model parameters. The present invention online mines the main change patterns of the network diagram, and then only uses the parts of the computer network with large changes as data for incremental learning based on knowledge distillation, without knowledge replay, which realizes model lightweight while avoiding the problem of insufficient memory of forwarding devices.
[0020] Further, the attention heatmap drift loss is calculated as the L1 (1-norm) difference after normalizing the node features within the region of the purified attention heatmap at two consecutive moments using L2 (2-norm), and then this L1 difference is accumulated over the number of nodes in the region.
[0021] Further, the total loss function includes the loss of the new data on the purified attention heatmap at the current moment on the model at the previous moment, the loss of knowledge distillation of the model at the previous moment, and the attention heatmap drift loss.
[0022] Further, in step (6), after each edge forwarding device completes incremental learning, use the federated learning method to aggregate the trained model parameters of each edge forwarding device to obtain global model parameters, and then use the global model parameters to uniformly update the network anomaly detection model on each edge forwarding device. The present invention uses the encrypted southbound interface of SDN for evolution towards federated learning, and adds a southbound protocol that supports the BSP parallel computing model to complete the distribution, synchronization, aggregation of distributed tasks, and the issuance and synchronization of model parameters.
[0023] The method of the present invention runs on edge forwarding devices. By using real-time network data, it conducts learning and inference on network anomaly detection through a graph neural network at the network edge. The graph neural network model is split into multiple distributed tasks in a data parallel and model parallel manner, that is, each edge forwarding device AGGREGATE-COMBINE the features of the Hosts or links connected to it, thereby achieving localized data collection and learning, reducing the computing burden of each edge forwarding device, and enabling the model to be offloaded to the computing power network for operation. At the same time, the present invention uses the network traffic flowing through the edge forwarding device to update the anomaly detection knowledge of the graph neural network model, and uses the existing computer network to connect the limited computing and storage resources on the edge forwarding device to form a micro computing power network composed of edge forwarding devices.
[0024] The present invention uses a computer network to connect the limited computing power on edge forwarding devices to form a computing power network, and then offloads the anomaly detection model based on the graph neural network to be distributed and run on edge forwarding devices in a model parallel manner, which can solve the contradiction between model localization and insufficient local computing power. In addition, the present invention uses the edge and node features of the computer network graph to mine the hot parts and significantly changing parts that can best represent the whole graph representation while training the encoder, generates a purified hot map, and updates the graph neural network model in a memoryless learning manner by refining the hot map, solving the problem that the memory of the network forwarding device is insufficient to run the graph neural network.
[0025] In summary, on the one hand, the present invention starts from algorithm lightweight, using an incremental learning method that does not record the historical data of the computer network, avoids data playback, and retrains the model, enabling the anomaly detection graph neural network to run on resource-constrained network forwarding devices; on the other hand, through the ideas of model parallelism and data parallelism, network forwarding devices with limited computing and storage resources are formed into a micro computing power network through the network, and the training of the entire model is completed in the form of distributed computing. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] Figure 1 It is a schematic diagram of the network anomaly detection system framework based on the incremental learning graph neural network of the present invention.
[0027] Figure 2 It is a schematic diagram of the network anomaly detection method flow based on the incremental learning graph neural network of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0028] To describe the present invention more specifically, the technical solutions of the present invention will be described in detail below in conjunction with the drawings and specific embodiments.
[0029] Such as Figure 1 And Figure 2As shown in the figure, the network anomaly detection method based on the incremental learning graph neural network of the present invention includes the following steps:
[0030] Step 1: Centering on the edge forwarding device and taking the hosts directly connected to the edge forwarding device as nodes, the computer network is divided into multiple subnets, as shown in part A of Figure 1 the figure.
[0031] At this time, the subgraphs representing these subnets can be obtained in the graph space, as shown in part B of Figure 1 the figure. Taking the edge forwarding device 1 as an example, as the edge forwarding device of hosts 1, 2, and 3, it can directly obtain the network flow characteristics of the above hosts.
[0032] In a computer network composed of m edge forwarding devices and n hosts. Taking to represent the subnet composed of the hosts directly connected by the kth edge forwarding device at time t, the graph of the network can be represented as For the subnet composed of the kth edge switching mechanism represents the edges within the subnet at time t, represents the nodes within the subnet at time t, represents the part of the network other than the subnet at time t, that is, the remote subnet, represents the edges in the remote subnet at time t, represents the nodes in the remote subnet at time t. Then, from the perspective of the kth edge forwarding device, the entire network can be represented as The edges within the network can be represented as The nodes can be represented as
[0033] Step 2: As shown in part C of Figure 1 the figure, in a mode that combines data parallelism and model parallelism, the AGGREGATE-COMBINE process of the GNN is executed on each edge forwarding device. For the feature aggregation of layer 0 of the graph neural network, if we use the computing power of the edge forwarding device to perform the feature aggregation of layer 0 of the graph neural network, since there are only a few nodes on the subgraph centered on this device, only a very small amount of computing power is required to aggregate the node features within the subgraph. As shown at layer 0 in part C of Figure 1 the figure, the edge forwarding device 1 only needs to aggregate hosts 1, 2, and 3, that is, nodes 1, 2, and 3 in sub Figure 1 the figure. Similarly, the edge forwarding devices 2 and 3 can also complete the feature aggregation of layer 0 within sub Figure 2 and subgraph 3 with very little computing power.
[0034] When the graph neural network performs feature aggregation at layer 1, since the neighbor devices of each edge forwarding device have independently completed the aggregation of layer 0 features of other subgraphs, for the edge forwarding device, when the graph neural network performs aggregation at layer 1, the edge forwarding device only needs to combine the features of the subgraph centered on itself obtained with the layer 0 aggregation of other edge forwarding devices to generate the layer 1 aggregation. As Figure 1 shown, when the GNN performs feature aggregation at layer 1, since Switch 1 and Switch 3 have independently completed the aggregation of layer 0 features of sub Figure 1 and layer 0 features of subgraph 3 respectively, for Switch 2, when the GNN performs aggregation at layer 1, Switch 2 only needs to combine the features of sub Figure 2 it obtained with the layer 0 aggregation of Switch 1 and Switch 3 to generate the layer 1 aggregation. Similarly, Switch 1 and 3 can also generate the features of layer 1 through the feature aggregation of the layer 0 of the other 2 switches. And so on, when Switch 1, 2, and 3 have respectively completed the three-layer AGGREGATE-COMBINE process, we can obtain the embeddings reflecting the features of the entire network from Switch 1, 2, and 3 respectively.
[0035] At the k-th switch, the information aggregated at node v can be expressed as shown in the following formula:
[0036]
[0037] Where: N(V k ), respectively represent the neighbor set of node v, the edge from the neighbor to v, and the embedding of node u at the (l - 1)-th layer from the perspective of edge forwarding device k at time t.
[0038] Aggregate the current embedding of the node and the embedding from the upper layer of node v . After passing the aggregated result through a non-linear activation function, the embedding of node v at the l-th layer at time t can be expressed as shown in the following formula:
[0039]
[0040] And the embedding of each edge uv can be obtained by combining the embeddings of the two nodes of the edge, and can be expressed as shown in the following formula:
[0041]
[0042] According to Equation 3, the normalized node embedding of the computer network topology graph can be expressed as:
[0043]
[0044] Step 3: Construct negative samples of the computer network graph through a disruption function, and then As the global representation, each edge embedding As the local representation of the graph, a non-linear sigmoid function is used to calculate the score of the local-global mutual information, and this mutual information score is used as the discriminator. With ψ k Representing the discriminator parameters, the discriminator can be expressed as:
[0045]
[0046] Where: The higher the score of the discriminator, the more The corresponding local representation contains graph-level information
[0047] Step 4: Use the binary cross-entropy loss function to perform gradient descent, iteratively update the encoder parameters and discriminator parameters to train the encoder and discriminator, and the objective function formula is as follows:
[0048]
[0049] When the minimum value of the objective function is found, the graph encoder training is completed. At this time, the graph embedding output by the encoder can comprehensively represent the computer network. Since the discriminator Describes the degree to which the edge embedding Contains graph-level information We can consider that the score value of the discriminator at this time represents the importance of the edge embedding In representing the information of the entire graph, and the area composed of edges with high discriminator scores is the attention heat map of the computer network graph. Then at time t, from the perspective of the edge switch k, the attention heat map composed of the set of edges with high discriminator scores is as follows:
[0050]
[0051] Where: γ is the threshold and hyperparameter. The larger γ is, the more nodes will be included in the attention heat map, and vice versa.
[0052] If the characteristics of the node v on the topology graph of the computer network change during the period Δt, then from the perspective of the switch k, the embedding of the characteristic change of the computer network topology graph is calculated by the following formula:
[0053]
[0054] That is, the embedding of the change in the computer network topology map is the combination of the embedding of the change of each node in the upper layer node on the period Δt and the embedding of the change of the current node at the current moment.
[0055] Step 5: After obtaining the attention heat map of graph G k and the significantly changed part in the graph, the intersection of the two can represent both the current network representation and the new change characteristics of the current network. At this time, the purified attention heat map is calculated by the following formula:
[0056]
[0057] Step 6: Use the network data on the purified attention heat map at the current moment as the input to perform incremental learning on the model.
[0058] Since the change of the computer network will inevitably cause the drift of the attention heat map of its topology map, we add the attention heat map drift loss function to the overall loss function of the incremental learning model to ensure that the attention heat map knowledge can also be updated synchronously during the model update process.
[0059] Then, for the edge forwarding device k, using to represent the message passing parameter of the old GNN model, to represent the classification parameter of the old graph neural network model, to represent the classification parameter after the update of the GNN model, to represent the edge embedding on the purified attention heat map at the previous moment and to represent the soft label at the current moment (defined by the model output with the highest confidence), to represent the output on the old GNN model, to represent updating the parameters and to and respectively, and the output of the old GNN model, to represent updating the parameters and to and respectively, and the output of the new GNN model, then there is an expression:
[0060]
[0061] Using to represent the classification loss function of the new data, to represent the knowledge distillation loss function of the old data, Denote the attention heatmap drift loss function, then the overall loss function of the model can be defined as:
[0062]
[0063] Continuously adjust the parameters through the stochastic gradient descent algorithm until L k is minimized, so as to obtain the optimal model on switch k. Among them, the cross-entropy loss is used for calculation and For we define it as the sum of the L1 differences between two attention heatmaps before and after Δt after L2 normalization, and the formula is as follows:
[0064]
[0065] After each edge forwarding device completes the above process, it will obtain a trained network anomaly detection model based on the graph neural network on the local machine, such as Figure 1 the models 1, 2, and 3 obtained by edge forwarding devices 1, 2, and 3 respectively.
[0066] Step 7: Take each edge forwarding device as a worker for federated learning, and bring the model parameters obtained on each edge forwarding device into the following formula for federated learning:
[0067]
[0068] Obtain the global model parameters Furthermore, obtain the global anomaly detection model. After updating these parameters to each edge forwarding device, each edge switch obtains the latest anomaly detection model. In the above calculation process, since the update of the model is driven by the purified attention heatmap, the input scale and storage requirements of the model are significantly reduced while taking into account the accuracy of the model.
[0069] The above description of the embodiments is for those of ordinary skill in the art of the present technology to understand and apply the present invention. Those who are familiar with the technology in the art can obviously make various modifications to the above embodiments easily, and apply the general principles described herein to other embodiments without creative labor. Therefore, the present invention is not limited to the above embodiments, and the improvements and modifications made by those skilled in the art to the present invention should be within the protection scope of the present invention.
Claims
1. A network anomaly detection method based on an incremental learning graph neural network, comprising the following steps: (1) Divide the entire computer network into multiple subnets with edge forwarding devices as the subnet centers. Each subnet corresponds to an edge forwarding device and consists of hosts directly connected to the edge forwarding device. The edge forwarding device directly obtains the network flow characteristics of each host within the subnet and constitutes a micro computing power network; (2) Execute the AGGREGATE-COMBINE and training processes of the graph neural network on each edge forwarding device in a mode that combines data parallelism and model parallelism; (3) Construct negative samples of the computer network through a destruction function, calculate the mutual information between local edge features and global information using a non-linear function, and use it as the score value of the discriminator in the graph neural network; (4) Perform gradient descent on the graph neural network using the binary cross-entropy loss function to iteratively update the parameters of the encoder and discriminator in the graph neural network. After training is completed, determine the attention heat map of the computer network; (5) When the node features in the computer network change, purify the attention heat map, and input the node feature data in the corresponding area of the purified attention heat map into the graph neural network for incremental learning; (6) Update the network anomaly detection models trained by each edge forwarding device in a federated learning manner. The edge forwarding device uses the updated model to detect anomalies in the nodes within its subnet.
2. The network anomaly detection method based on the incremental learning graph neural network according to claim 1, wherein: In step (2), for any edge forwarding device, when performing node neighbor aggregation at the 0th layer of the graph neural network, the edge forwarding device uses its computing power to aggregate the features of each node within the subnet centered on itself, obtains the aggregated features of the 0th layer of the graph neural network in its subnet, and sends them to other edge forwarding devices; when performing node neighbor aggregation at the ith layer of the graph neural network, the edge forwarding device combines the aggregated features of the (i-1)th layer of the graph neural network in its subnet with the aggregated features of the (i-1)th layer of the graph neural network in the corresponding subnets of other edge forwarding devices to generate the aggregated features of the ith layer of the graph neural network in its subnet, where i is a natural number greater than 0.
3. The network anomaly detection method based on an incremental learning graph neural network according to claim 1, wherein: In step (2), each edge forwarding device uses the node feature data within its subnet and the subnet node feature data from other edge forwarding devices to train the encoder of the graph neural network, aggregates the encoder parameters trained by each edge forwarding device in a federated learning manner to obtain global encoder parameters, and then uses the global encoder parameters to uniformly update the graph neural network encoder on each edge forwarding device.
4. The network anomaly detection method based on the incremental learning graph neural network according to claim 1, characterized in that: In step (3), the sum of two node feature vectors is used as the edge feature vector between these two points, and the global information of the entire computer network is represented as the average value of the edge feature vectors of all edges; for any edge, the mutual information between the edge feature vector and the global information characterizes the importance degree of the edge in the entire computer network, and it is used as the score value of the graph neural network discriminator.
5. The network anomaly detection method based on the incremental learning graph neural network according to claim 1, characterized in that: In step (4), the graph neural network is trained based on the binary cross-entropy loss function. After the training is completed, the score value of the discriminator represents the importance of the edge features in the global information. At this time, the area composed of the edges with higher corresponding score values is used as the attention heat map of the computer network.
6. The network anomaly detection method based on the incremental learning graph neural network according to claim 1, wherein: In step (5), if the features of a node in the computer network change within a period, determine its subnet and take the intersection of the subnet and the attention heat map to obtain the purified attention heat map. Then, input the node feature data in the intersection area into the graph neural network, and perform incremental learning on the graph neural network based on the knowledge distillation method.
7. The network anomaly detection method based on an incremental learning graph neural network according to claim 6, characterized in that: The knowledge distillation method is to use the network anomaly detection model based on the graph neural network at the previous moment as the old knowledge, and combine the new data on the purified attention heat map at the current moment to perform knowledge distillation on the old knowledge. At the same time, an attention heat map drift loss is added to the total loss function of incremental learning to ensure that the attention heat map knowledge can also be updated synchronously during the update of the model parameters.
8. The network anomaly detection method based on the incremental learning graph neural network according to claim 7, wherein: The attention heat map drift loss is obtained by calculating the L1 difference after L2 normalization of the node features in the purified attention heat map regions at two consecutive moments, and then accumulating the L1 difference over the number of nodes in the region.
9. The network anomaly detection method based on the incremental learning graph neural network according to claim 7, characterized in that: The total loss function includes the loss of the new data on the purified attention heat map at the current moment on the model at the previous moment, the loss of knowledge distillation of the model at the previous moment, and the attention heat map drift loss.
10. The network anomaly detection method based on the incremental learning graph neural network according to claim 1, characterized in that: In step (6), after each edge forwarding device completes incremental learning, the federated learning method is used to aggregate the model parameters trained by each edge forwarding device to obtain the global model parameters, and then the network anomaly detection model on each edge forwarding device is uniformly updated using the global model parameters.
Citation Information
Cited By
Vehicle collision risk prediction method and device and controller
CN121838522A