Malicious domain name detection method and device based on meta learning and comparative learning
The integration of meta-learning and contrastive learning enhances malicious domain name detection by optimizing feature encoders and performing data augmentation, addressing robustness and accuracy issues in small sample scenarios, thereby improving detection of rare domain name families.
Patent Information
- Application Number
- CN202510745836.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-05
- Publication Date
- 2025-07-15
AI Technical Summary
The detection accuracy of existing malicious domain name detection methods has significantly decreased in the face of dynamic domain name generation algorithms and adversarial perturbations, and the generalization ability is insufficient in small sample scenarios, especially when new malicious domain name samples are scarce, it is difficult for traditional methods to effectively identify them.
The malicious domain name detection method based on meta-learning and contrast learning is adopted, and the metadata set of malicious domain name classification tasks is constructed, hard positive examples and negative sample pairs are generated, and the in-class diversity comparison loss optimization is used to optimize the in-class diversity comparison, freeze the feature encoder parameters, perform in-class obfuscation data enhancement, optimize the classifier decision boundaries, and realize cross-task generalization capabilities.
It significantly improves the recognition accuracy of families with sparse samples, alleviates the problem of model overfitting, and provides a high robust and adaptable lightweight detection system, which can maintain high detection accuracy in extreme small sample scenarios.
Smart Images

Figure CN120321028A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical fields of network security and malicious software domain name detection, and in particular to a malicious domain name detection method and device based on meta-learning and contrastive learning. Background Art
[0002] With the rapid development of Internet technology, malicious domain names have become the core carriers of network attacks. Approximately 35% of network attacks globally are carried out through malicious domain names. However, when facing the Domain Generation Algorithm (DGA) and adversarial perturbations, the detection accuracy of traditional detection methods drops significantly. There are currently two major challenges in malicious domain name detection: First, attackers can bypass feature engineering-based detection systems through means such as character addition and deletion, synonym replacement, etc. Existing machine learning methods based on feature engineering have poor robustness against adversarial perturbations. Second, new malicious domain name labeled samples are scarce (for example, there are only dozens of samples of new DGA variants). Traditional deep learning models have insufficient generalization ability in small-sample scenarios due to their dependence on large-scale data.
[0003] Existing DGA detection methods are mainly divided into two categories: machine learning methods based on feature engineering and deep learning methods for automatically extracting features. Among them, the core of machine learning methods based on feature engineering lies in manually designing quantifiable domain name statistical features to build a classification model. The feature dimensions are clear, the model is highly interpretable, and it has high detection efficiency when there is sufficient labeled data. However, this method has significant defects: First, feature engineering relies on expert experience, and the design process is time-consuming and difficult to cover complex attack patterns (such as DGA variants with dynamically adjusted character distributions). Second, attackers can bypass model detection through targeted perturbations (for example, reducing character randomness to avoid entropy detection and adding common suffixes of legitimate domain names to interfere with N-gram statistics). Third, static features cannot effectively capture the dynamic generation rules and temporal evolution characteristics of malicious domain names, resulting in insufficient adaptability to new attacks.
[0004] Deep learning methods for automatically extracting features automatically learn the abstract feature expressions of domain name character sequences through neural networks, getting rid of the limitations of manual feature design and being able to mine the deep semantic features of domain names. However, its limitations are also significant: First, the model performance highly depends on large-scale labeled data. When the sample size of new malicious domain names is insufficient, that is, in the small-sample detection problem, the network parameters are difficult to converge, prone to overfitting and reducing the detection accuracy. Second, deep models are sensitive to input perturbations. Attackers only need to modify a small number of characters to cause feature space deviation and classification errors. In addition, model training consumes a large amount of computing resources and it is difficult to meet the deployment requirements of real-time detection scenarios. Summary of the Invention
[0005] To solve the problems of unbalanced sample distribution of domain name families and insufficient detection accuracy for small samples in the existing technology, the primary objective of the present invention is to provide a malicious domain name detection method based on meta-learning and contrast learning that can significantly improve the recognition accuracy of families with scarce samples and still maintain a high detection accuracy in extremely small sample scenarios.
[0006] To achieve the above objective, the present invention adopts the following technical solutions: A malicious domain name detection method based on meta-learning and contrast learning, the method comprising the following steps in sequence:
[0007] (1) Construct a meta-dataset for the malicious domain name classification task: Given a dataset , where is a domain name sample set, is a class label set, and each sample corresponds to a label ; Divide the dataset into a meta-training dataset and a meta-test dataset , where is the support set in the training stage, is the support set in the test stage, is the query set in the training stage, is the query set in the test stage;
[0008] (2) Generate a binary training set based on the meta-training dataset : Screen hard positive example sample pairs through keyword differences and randomly generate negative sample pairs, and generate the binary training set from the hard positive example sample pairs and negative sample pairs;
[0009] (3) Input the binary training set into a siamese neural network and perform joint optimization based on the intra-class diversity contrast loss, where the intra-class diversity contrast loss includes a contrast loss, a margin loss, and a diversity regularization term;
[0010] (4) Synchronously update the parameters of the feature encoder and the classifier in the siamese neural network through backpropagation to obtain a feature encoder with cross-task generalization ability;
[0011] (5) Freeze the parameters of the feature encoder, calculate the cosine distance for the support set in the test stage, and iteratively select representative samples covering the intra-class distribution boundary through a quantile threshold to form an optimized support set , and merge the optimized support sets of all classes to form a global support set ;
[0012] (6) For the global support set Perform intra-class confusion data augmentation to generate an augmented support set by weighted mixing of the embedding vectors of samples in the same class , and expand intra-class diversity;
[0013] (7) Use the augmented support set to train a classifier, optimize the decision boundary based on the cross-entropy loss function, and finally output the domain name category, i.e., the final prediction result, on the query set in the test phase .
[0014] Step (2) includes the following steps in sequence:
[0015] (2a) Generation of hard positive sample pairs: For the data in the support set during the training phase , use the KeyBERT model to extract keyword features from malicious domain names in the same class, and obtain the semantic keyword set for each domain name; for two domain name samples and belonging to the same malicious domain name family, determine whether the keyword sets of and satisfy the mutual exclusion condition:
[0016] If , then construct the positive sample pair triple ; is an empty set; are the keywords obtained by the KeyBERT model for the sample , are the keywords obtained by the KeyBERT model for the sample ;
[0017] Filter out domain name pairs with significant intra-class semantic differences through the mutual exclusion condition to form a hard positive sample pair set ; where and represent the class labels of the samples and respectively, is the current class, represents that the samples and belong to the same malicious domain name class;
[0018] (2b) Generation of negative sample pairs: For the data in the training set , randomly sample sample pairs from different malicious domain name families, satisfying ;
[0019] Construct the negative sample pair triple , to form a negative sample pair set ; where and respectively represent the samples and the class labels of, is the current class, indicating that the samples and do not belong to the same malicious domain name class;
[0020] (2c)Combine the set of hard positive sample pairs with the set of negative sample pairs to generate a binary training set .
[0021] Step (3) includes the following steps in sequence:
[0022] (3a)Feature embedding and similarity calculation: Through a feature encoder with shared parameters map the input sample pairs in the binary training set to normalized 768-dimensional embedding vectors and ;
[0023] Calculate the cosine similarity matrix of the sample pairs: ;
[0024] (3b)Dynamic hard sample screening:
[0025] Define the set of hard positive samples :
[0026] where, is the minimum similarity threshold for all negative sample pairs; represents the set of hard positive sample pairs in the binary training set , and are the feature vectors extracted from the samples and through the feature encoder respectively;
[0027] Define the set of hard negative samples :
[0028] where, is the maximum similarity threshold for all positive sample pairs; represents the set of negative sample pairs in the binary training set ;
[0029] (3c)Construct an intra-class diversity contrast loss :
[0030] Apply margin loss to hard negative samples : , where is the preset lower threshold of inter-class similarity;
[0031] Apply contrastive loss to hard positive samples : ;
[0032] Introduce a diversity regularization term : , where is the weight coefficient, is the similarity decay factor;
[0033] Intra-class diversity contrast loss is: .
[0034] Step (4) specifically refers to: Based on the intra-class diversity contrast loss perform backpropagation on the parameters of the feature encoder of the siamese neural network, and synchronously update the parameters of the classifier ; Through iterative optimization by the gradient descent algorithm, the embedding space of similar samples covers a wider intra-class distribution, and the embedding distance of dissimilar samples is at least maintained interval, is the preset lower threshold of inter-class similarity; Similar samples are sample pairs in the hard positive sample set , and dissimilar samples are sample pairs in the hard negative sample set .
[0035] Step (5) includes the following steps in sequence:
[0036] (5a) Initialize the optimization support set: Freeze the parameters of the feature encoder obtained in the meta-training stage, and perform feature embedding on the support set in the test stage; For each class initialize the optimization support set , and randomly select a sample of this class from the meta-test dataset , where represents the first domain name sample selected into under class , is is the corresponding class label, indicating that belongs to the malicious domain name class ; Embed the embedded representation and add it to , where represents the sample and is a vector representation obtained by mapping through a feature encoder with parameter ; ;
[0037] (5b) Perform iterative sample selection on : The k-th iteration operation ; The is the preset number of sample selections, satisfying , where represents the total number of samples in class in the meta-test dataset ; (5b1) Calculate the mean vector of all sample embeddings in the current ; (5b2) Calculate the cosine distance between the embeddings of the remaining samples in class that are not included in this class and :
[0038] ;
[0039] where represents the -th sample in class that has not been selected into , is the embedded representation obtained by through the feature encoder , and calculate the cosine similarity of the two vectors; (5b3) Filter samples according to the dynamic quantile threshold , where the hyperparameter is used to control the upper limit of ; The hyperparameter is used to control the growth rate of ; (5b4) Select samples that satisfy , that is, samples with the cosine distance closest to the -th quantile, and add to , where represents the distance value at the -th percentile of all , that is, the distances of
[0040] (5c) Optimized support set generation: Repeat steps (5b1) to (5b4) until completion Minor sample addition, finally obtaining the optimized support set for each category ; Merge the optimized support sets of all categories to form a global support set where is the total number of malicious domain name categories;
[0041] (5d) Hyperparameter constraint: The and take values from a discrete set in grid search to determine the optimal parameter combination through cross-validation.
[0042] Step (6) includes the following steps in sequence:
[0043] (6a) Sampling of same-class samples: Randomly select two sample embedding vectors of the same category from the global support set and where and belong to the same malicious domain name category;
[0044] (6b) Dynamic weight mixing: Generate a mixed weight parameter to dynamically control the mixing ratio;
[0045] Synthesize the enhanced sample embedding vector according to the following formula :
[0046] ;
[0047] Keep the enhanced sample label unchanged:
[0048] ;
[0049] where represents that the category label of the enhanced sample embedding vector is the same as the embedding vectors of the original samples and and is category to ensure that the malicious domain name category attribute of the sample is not changed during the data augmentation process;
[0050] (6c) Batch augmentation generation: Repeat steps (6a) to (6b) times to generate the augmented support set where is the preset number of augmented samples, used to control the number of artificial samples generated for each category to expand the scale of the support set.
[0051] Step (7) includes the following steps in sequence:
[0052] (7a) Classifier training: Using the enhanced support set to train a classifier and updating the parameters by optimizing the cross-entropy loss function :
[0053] ;
[0054] Wherein: is the total number of samples in the enhanced support set, is the total number of malicious domain name categories, , is the true label: when the sample belongs to the current malicious domain name category , otherwise ;
[0055] (7b) Prediction probability calculation: Using the softmax function to calculate the probability that the sample belongs to the current malicious domain name category : :
[0056] ;
[0057] Wherein: and respectively represent the transposes of the classifier parameter vectors corresponding to the current malicious domain name category and the category ; is the feature vector extracted from the sample through the feature encoder ;
[0058] (7c) Decision boundary optimization: Minimizing through the gradient descent algorithm and updating the classifier parameters to optimize the decision boundary;
[0059] (7d) Query set inference: Applying the trained classifier to the query set in the test phase and outputting the class probability distribution of each sample: ; Selecting the domain name category corresponding to the maximum probability as the final prediction result: .
[0060] Another object of the present invention is to provide an electronic device, including:
[0061] A processor; and
[0062] A memory stores computer program instructions, and when the computer program instructions are run by the processor, the processor is caused to execute the malicious domain name detection method based on meta-learning and contrast learning as described above.
[0063] The present invention also provides a computer-readable storage medium, on which computer program instructions are stored, and when the computer program instructions are run by a processor, the processor is caused to execute the malicious domain name detection method based on meta-learning and contrast learning as described above.
[0064] As can be seen from the above technical solutions, the beneficial effects of the present invention are as follows: First, for the problem of unbalanced sample distribution, the present invention uses the task adaptation mechanism of meta-learning to force the contribution degrees of samples of each family to be balanced during the model training stage, so that while the model maintains the detection performance of the mainstream families, it significantly improves the recognition accuracy for families with few samples (such as new DGA variants with only dozens of samples), realizes balanced detection performance under long-tail distribution, and alleviates the problems of model overfitting and insufficient generalization ability caused by insufficient data in the small-sample scenario of traditional deep learning methods; Second, for the problem of insufficient detection accuracy in small samples, a dual optimization design of contrast learning and siamese network structure is introduced: (1) hard positive sample pairs strengthen the compactness of intra-class features to ensure that an effective feature space can be established with a small number of samples; (2) negative sample pairs expand and enhance the inter-class discriminability, so that the model still maintains a high detection accuracy in the extremely small-sample scenario; In addition, the present invention replaces manual feature engineering with automated feature optimization, which reduces the algorithm deployment cost while providing a highly robust and adaptive lightweight detection system for dynamically evolving malicious domain name threats. Description of the Drawings
[0065] Figure 1 is the flowchart of the method of the present invention;
[0066] Figure 2 is the framework diagram of the siamese neural network in the present invention;
[0067] Figure 3 is the framework diagram of the meta-training stage;
[0068] Figure 4 is the framework diagram of the meta-testing stage. Detailed Embodiments
[0069] As Figure 1 shown, a malicious domain name detection method based on meta-learning and contrast learning, the method includes the following steps in sequence:
[0070] (1) Construct a meta-dataset for the malicious domain name classification task: Given a dataset where is a domain name sample set, is a class label set, and each sample Corresponding label ; Divide the dataset into a meta-training dataset and a meta-testing dataset , where is the support set for the training phase, is the support set for the testing phase, is the query set for the training phase, is the query set for the testing phase;
[0071] (2) Generate a binary training set based on the meta-training dataset : Screen hard positive example pairs through keyword differences and randomly generate negative sample pairs, and generate a binary training set from the hard positive example pairs and negative sample pairs ;
[0072] (3) Input the binary training set into a siamese neural network and perform joint optimization based on the intra-class diversity contrast loss, where the intra-class diversity contrast loss includes a contrast loss, a margin loss, and a diversity regularization term;
[0073] (4) Synchronously update the parameters of the feature encoder and classifier in the siamese neural network through backpropagation to obtain a feature encoder with cross-task generalization ability;
[0074] (5) Freeze the parameters of the feature encoder, calculate the cosine distance for the support set in the testing phase , and iteratively select representative samples covering the intra-class distribution boundary through a quantile threshold to form an optimized support set , and merge the optimized support sets of all classes to form a global support set ;
[0075] (6) Perform intra-class confusion data augmentation on the global support set , and generate an augmented support set by weighted mixing of the embedding vectors of samples of the same class , expanding the intra-class diversity;
[0076] (7) Use the augmented support set to train the classifier, optimize the decision boundary based on the cross-entropy loss function, and finally output the domain name category, i.e., the final prediction result, on the query set in the testing phase.
[0077] Steps (1), (2), (3), and (4) are the meta-training phase, and steps (5), (6), and (7) are the meta-testing phase.
[0078] Step (2) includes the following steps in sequence: To train the feature encoder in the Siamese neural network, it is necessary to construct reasonable positive sample pairs and negative sample pairs so that the model can fully learn the intra-class feature similarity and inter-class feature difference. Therefore, the present invention designs a sample pair generation method, including negative sample pair generation and hard positive example sample pair generation.
[0079] (2a) Hard positive example sample pair generation: For the data in the support set during the training phase , use the KeyBERT model to extract keyword features for malicious domain names of the same category, and obtain the semantic keyword set for each domain name; for two domain name samples and belonging to the same malicious domain name family, determine and whether the keyword sets satisfy the mutual exclusion condition:
[0080] If , then construct the positive sample pair triple ; is an empty set; is the keyword obtained by the KeyBERT model for the sample , is the keyword obtained by the KeyBERT model for the sample ;
[0081] Screen out domain name pairs with significant intra-class semantic differences through the mutual exclusion condition to form a hard positive example sample pair set ; where and respectively represent the class labels of the samples and , is the current class, represents that the samples and belong to the same malicious domain name class;
[0082] In contrastive learning, traditional positive samples usually select samples with high intra-class similarity. However, this may cause the model to only focus on local patterns and make it difficult to learn the diversity of categories. Therefore, the present invention designs a method for generating hard positive sample pairs to enhance intra-class diversity. By using a keyword matching strategy, hard positive sample pairs with large differences in domain name text content but belonging to the same category are screened out. Specifically, the present invention uses KeyBERT to extract the main keywords of the domain name and selects domain name sample pairs that do not contain the same keywords within the same category as hard positive sample pairs. KeyBERT is a variant of the BERT model. By calculating the embedding vector of the domain name and selecting the token that best matches the overall semantics as the main keyword. During the process of selecting positive samples, if the main keywords of two texts do not overlap, their similarity in the embedding space is low, thereby enhancing the diversity of intra-class data.
[0083] (2b) Generation of negative sample pairs: For the data in the training set sample pairs of different malicious domain name families are randomly sampled , satisfying ;
[0084] Construct negative sample pair triples to form a set of negative sample pairs ; where and respectively represent the class labels of samples and , is the current class, indicates that samples and do not belong to the same malicious domain name category;
[0085] (2c) Combine the set of hard positive sample pairs with the set of negative sample pairs to generate a binary training set .
[0086] Step (2) can increase the variability of intra-class data while maintaining intra-class consistency, enabling the model to adapt to more complex intra-class distributions. In the case of small-sample domain name detection with limited data, the model can learn richer intra-class information, thereby enhancing the generalization ability for unseen tasks.
[0087] Step (3) includes the following steps in sequence:
[0088] (3a) Feature embedding and similarity calculation: Through a feature encoder with shared parameters map the input sample pairs in the binary training set to normalized 768-dimensional embedding vectors and ;
[0089] Calculate the cosine similarity matrix of sample pairs: ;
[0090] (3b)Dynamic hard sample screening:
[0091] Define the hard positive sample set :
[0092] where is the minimum similarity threshold for all negative sample pairs; represents the set of hard positive example sample pairs in the binary training set , and are the feature vectors extracted from samples and through the feature encoder respectively;
[0093] Define the hard negative sample set :
[0094] where is the maximum similarity threshold for all positive sample pairs; represents the set of negative sample pairs in the binary training set ;
[0095] (3c)Construct the intra-class diversity contrast loss :
[0096] Apply the margin loss to the hard negative samples : , where is the preset lower threshold for inter-class similarity;
[0097] Apply the contrast loss to the hard positive samples : ;
[0098] Introduce the diversity regularization term : where is the weight coefficient, is the similarity decay factor;
[0099] The intra-class diversity contrast loss is: .
[0100] The feature encoder is optimized by intra-class diversity contrast loss, so that it can effectively expand the range of intra-class representation while maintaining inter-class discrimination, and improve the model's adaptability to unseen tasks. The intra-class diversity contrast loss enables the feature encoder to narrow the distance between pairs of difficult positive samples, while moderately pushing away easy positive samples and negative samples, to achieve the coordinated optimization of intra-class diversity modeling and inter-class discrimination. While ensuring the ability to distinguish between classes, the intra-class structural information is fully mined, so that the embedding space can accommodate more potential meaningful features, providing stronger generalization capabilities for the domain name detection task in the subsequent meta-test phase.
[0101] Step (4) specifically refers to: based on intra-class diversity contrast loss Feature Encoder for Siamese Neural Networks Parameters Perform back propagation and update the classifier synchronously Parameters Through iterative optimization of the gradient descent algorithm, the embedding space of the same type of samples covers a wider intra-class distribution, and the embedding distance of heterogeneous samples is kept at least interval, is the preset lower limit threshold of inter-class similarity; samples of the same type are hard positive sample sets The sample pairs in , heterogeneous samples are hard negative sample sets The sample pairs in .
[0102] Step (5) comprises the following steps in the following order:
[0103] (5a) Initialize the optimized support set: Freeze the feature encoder obtained in the meta-training phase Parameters , support set for the testing phase Perform feature embedding; for each category Initialize the optimization support set , from the meta-test dataset Randomly select a sample of this category ,in Indicates category The first one under A sample of domain names, yes The corresponding category label indicates Belongs to the malicious domain category ;Will Embedding Representation Add to ,in, Representation sample Through the parameters The feature encoder The vector representation obtained by mapping;
[0104] (5b) Perform iterative sample selection: The k-th iteration operation ; The ; The is the preset sample selection quantity, satisfying , where represents the total number of samples of class in the meta-test dataset ; (5b1) Calculate the mean vector of all sample embeddings in the current ; (5b2) Calculate the cosine distance between the embeddings of the remaining samples in class that are not included in this class and :
[0105] ;
[0106] where represents the -th sample in class that has not been selected into , is the embedding representation obtained by the feature encoder , calculate the cosine similarity of the two vectors; (5b3) Filter samples according to the dynamic quantile threshold , where the hyperparameter is used to control the upper limit of to prevent the classifier convergence effect from decreasing due to overly diverse data selection; the hyperparameter is used to control the growth rate of ; (5b4) Select the samples that satisfy , that is, the samples with the cosine distance closest to the -th quantile, and add to , where represents the distance value at the -th percentile of all , that is, the distance of
[0107] (5c) Optimize the support set generation: Repeat steps (5b1) to (5b4) until sample additions are completed, and finally obtain the optimized support set for each class; Combine all class optimized support sets to form the global support set , where is the total number of malicious domain name categories;
[0108] (5d) Hyperparameter constraint: The and takes values in a discrete set in grid search , and the optimal parameter combination is determined through cross-validation.
[0109] Step (6) includes the following steps in sequence:
[0110] (6a) Sampling of same-class sample pairs: Randomly select two sample embedding vectors of the same class from the global support set , where and , and and belong to the same malicious domain name category;
[0111] (6b) Dynamic weight mixing: Generate a mixed weight parameter to dynamically control the mixing ratio;
[0112] Synthesize the enhanced sample embedding vector according to the following formula:
[0113] ;
[0114] Keep the enhanced sample label unchanged:
[0115] ;
[0116] where represents that the class label of the enhanced sample embedding vector is the same as that of the original sample's embedding vector and , both being class , ensuring that the malicious domain name category attribute of the sample is not changed during the data augmentation process;
[0117] Since the feature distributions of malicious domain names often vary greatly, and the finiteness of the support set under the small sample condition will lead to insufficient class representation, which in turn affects the learning ability of the classifier for the class decision boundary. Through intra-class confusion data augmentation, the distribution range of intra-class samples can be effectively extended, the sparse regions in the embedding space can be filled, making the support set more representative, thereby enhancing the robustness of the model under the small sample condition. In addition, it can alleviate the overfitting problem caused by insufficient support set data, enabling the classifier to better learn the discriminative features between classes.
[0118] (6c) Batch augmentation generation: Repeat steps (6a) to (6b) times to generate the enhanced support set , where is the preset number of enhanced samples, used to control the number of artificial samples generated for each category to expand the size of the support set.
[0119] Step (7) includes the following steps in sequence:
[0120] (7a) Classifier training: Use the enhanced support set to train the classifier , and update the parameters by optimizing the cross-entropy loss function :
[0121] ;
[0122] Where: is the total number of samples in the enhanced support set, is the total number of malicious domain name categories, , is the true label: when the sample belongs to the current malicious domain name category , otherwise ;
[0123] (7b) Prediction probability calculation: Use the softmax function to calculate the probability that the sample belongs to the current malicious domain name category :
[0124] ;
[0125] Where: and respectively represent the transposes of the classifier parameter vectors corresponding to the current malicious domain name category and the category ; is the feature vector extracted from the sample through the feature encoder ; the softmax function normalizes the category scores calculated by the classifier into a probability distribution, so that each sample has a unique maximum probability value for the predicted category.
[0126] (7c) Decision boundary optimization: Minimize through the gradient descent algorithm, and update the classifier parameters to optimize the decision boundary;
[0127] (7d) Query set inference: Apply the trained classifier to the query set in the test phase , and output the category probability distribution of each sample: ; Select the domain name category corresponding to the maximum probability as the final prediction result: .
[0128] like Figure 2 As shown in the figure, the core of the twin neural network architecture consists of two weight-shared feature encoders, namely feature encoder 1 and feature encoder 2, which respectively decode the input samples. , Positive samples Or negative samples Through contrast loss calculation, the discriminative feature representation between positive and negative sample pairs can be effectively learned, thereby enhancing the robustness and generalization ability of the model in small sample scenarios.
[0129] like Figure 3 As shown in the figure, the left side constructs sample pairs through hard positive sampling, and the right side uses intra-class diversity contrast loss to shorten the distance between positive sample pairs and push away the distance between negative sample pairs.
[0130] like Figure 4 As shown, through Figure 4 The sample selection mechanism (1) based on the cosine distance quantile selects representative samples that cover the boundaries of the intra-class distribution, namely the blue dots, and Figure 4 In the (2) intra-class obfuscation data enhancement stage, the selected samples are enhanced with intra-class obfuscation data to generate mixed samples, i.e., red dots, to expand intra-class diversity. In the present invention, the model refers to a twin neural network. In the meta-test stage, in order to effectively distinguish multiple categories of malicious domain names under small sample conditions, the present invention proposes an intra-class diversity optimization method to improve the representativeness of the support set and enhance the ability to distinguish categories, such as As shown in the figure, this method mainly includes two core parts: sample selection based on cosine distance difference and intra-class confusion data enhancement.
[0131] The present invention solves the problem of scarcity of new malicious domain name annotations and adversarial disturbances through the dual stages of meta-training and meta-testing. In the meta-training stage, a multi-task learning scenario across malicious domain name families is first constructed, and hard positive sample pairs are screened based on keyword differences. The contrast loss and intra-class diversity loss are jointly optimized through the twin neural network, forcing the encoder to capture the essential characteristics of samples within the family and enhance the inter-class separability; at the same time, a meta-learning strategy is used to iteratively update the classifier parameters so that the model can quickly adapt to unknown tasks. In the meta-testing stage, the encoder is frozen, and only a small number of support set samples of the target family are used to optimize the classifier: representative samples covering the intra-class distribution boundaries are selected through the cosine distance quantile, and the selected samples are enhanced with intra-class confusion data to generate mixed samples to expand the intra-class diversity; finally, the domain name to be detected is input into the optimized model, and the domain name category probability is output.
[0132] In summary, to address the issue of unbalanced sample distribution, the present invention uses a task adaptation mechanism in meta-learning to force the contribution of samples from each family to be balanced during the model training phase. This enables the model to maintain the detection performance of the mainstream families while significantly improving the recognition accuracy for families with scarce samples (such as new DGA variants with only dozens of samples), achieving balanced detection performance under long-tail distributions and alleviating the problems of model overfitting and insufficient generalization ability caused by insufficient data in small-sample scenarios. To address the issue of insufficient detection accuracy for small samples, a dual optimization design of contrastive learning and siamese network structure is introduced: (1) hard positive sample pairs enhance the intra-class feature compactness, ensuring that an effective feature space can be established with a small number of samples; (2) negative sample pairs expand and enhance the inter-class discriminability, enabling the model to maintain a high detection accuracy even in extremely small-sample scenarios. In addition, the present invention replaces manual feature engineering with automated feature optimization, providing a highly robust and adaptive lightweight detection system for dynamically evolving malicious domain name threats while reducing the algorithm deployment cost.
[0133] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments. The above embodiments and the descriptions in the specification only illustrate the principles of the present invention. Without departing from the spirit and scope of the present invention, various changes and improvements will occur to the present invention, and these changes and improvements all fall within the scope of the present invention claimed. The scope of protection claimed by the present invention is defined by the appended claims and their equivalents.
Claims
1. A malicious domain name detection method based on meta-learning and contrastive learning, characterized in that: The method includes the following steps in sequence: (1)Construct the meta-dataset for the malicious domain classification task: Given a dataset , where is the domain name sample set, is the class label set, and each sample corresponds to the label ; Divide the dataset into a meta-training dataset and a meta-test dataset , where is the support set in the training stage, is the support set in the test stage, is the query set in the training stage, is the query set in the test stage; (2) Based on the meta-training dataset Generate a binary training set : Screen hard positive example pairs through keyword differences, randomly generate negative sample pairs, and generate a binary training set from the hard positive example pairs and negative sample pairs ; (3)Input the binary training set into the Siamese neural network and perform joint optimization based on the intra-class diversity contrast loss, where the intra-class diversity contrast loss includes a contrast loss, a margin loss, and a diversity regularization term; (4) Synchronously update the feature encoder and classifier parameters in the twin neural network through backpropagation to obtain a feature encoder with cross-task generalization ability; (5) Freeze the parameters of the feature encoder, and for the support set in the test phase Calculate the cosine distance, and iteratively select representative samples that cover the intra-class distribution boundary through the quantile threshold to form an optimized support set , and merge the optimized support sets of all classes to form a global support set ; (6) For the global support set perform intra-class confusion data augmentation to generate an augmented support set by weighted mixing of the embedding vectors of samples of the same class to expand intra-class diversity; (7) Utilize the enhanced support set to train a classifier, optimize the decision boundary based on the cross-entropy loss function, and finally output the domain name category, i.e., the final prediction result, on the query set during the test phase.
2. The malicious domain name detection method based on meta-learning and contrastive learning according to claim 1, characterized in that: Step (2) includes the following steps in sequence: (2a) Generation of hard positive example pairs: For the data in the support set during the training phase , use the KeyBERT model to extract keyword features from malicious domain names of the same category, and obtain the semantic keyword set for each domain name; for two domain name samples and belonging to the same malicious domain name family, determine and whether the keyword sets satisfy the mutual exclusion condition: If , then construct the positive sample pair triples ; is an empty set; is the keyword obtained by the KeyBERT model for the sample , is the keyword obtained by the KeyBERT model for the sample ; Filter out domain name pairs with significant intra-class semantic differences through the mutual exclusion condition to form a set of hard positive example sample pairs ; where and represent the class labels of samples and respectively, is the current malicious domain name class, represents that samples and belong to the same malicious domain name class; (2b) Negative sample pair generation: For the data in the training set samples of different malicious domain name families are randomly sampled that satisfy ; Construct negative sample pair triples , to form a set of negative sample pairs ; among them, and respectively represent the class labels of samples and , is the current class, indicating that samples and do not belong to the same malicious domain name class; (2c) Combine the set of hard positive sample pairs with the set of negative sample pairs to generate a binary training set .
3. The malicious domain name detection method based on meta-learning and contrast learning according to claim 1, characterized in that: Step (3) includes the following steps in sequence: (3a) Feature Embedding and Similarity Calculation: Through a feature encoder with shared parameters Map the input sample pairs in the binary training set to normalized 768-dimensional embedding vectors and ; Calculate the cosine similarity matrix of sample pairs: ; (3b) Dynamic hard sample screening: Define the set of hard positive samples : ; wherein, is the minimum similarity threshold for all negative sample pairs; represents the binary training set in the set of hard positive sample pairs, and are respectively the samples and extracted feature vectors through the feature encoder ; Define the set of hard negative samples : ; Among them, is the maximum similarity threshold for all positive sample pairs; represents the binary training set in the set of negative sample pairs; (3c) Constructing the within-class diversity contrast loss : Apply a margin loss to hard negative samples : , where is a preset lower threshold for inter-class similarity; Apply contrastive loss to hard positive samples : ; Introduce the diversity regularization term : , where is the weight coefficient is the similarity decay factor; Intra-class diversity contrast loss is as follows: .
4. The malicious domain name detection method based on meta - learning and contrastive learning according to claim 1, characterized in that: Step (4) specifically refers to: based on the intra-class diversity contrast loss perform backpropagation on the parameters of the feature encoder of the Siamese neural network and synchronously update the parameters of the classifier ; through iterative optimization by the gradient descent algorithm, make the embedding space of similar samples cover a wider intra-class distribution, and the embedding distance of dissimilar samples is at least maintained interval, where is the preset lower threshold of inter-class similarity; similar samples are sample pairs in the hard positive sample set ; dissimilar samples are sample pairs in the hard negative sample set ; . 5. The malicious domain name detection method based on meta-learning and contrastive learning according to claim 1, characterized in that: Step (5) includes the following steps in sequence: (5a) Initialize the optimized support set: Freeze the feature encoder obtained in the meta-training phase Parameters , support set for the testing phase Perform feature embedding; for each category Initialize the optimization support set , from the meta-test dataset Randomly select a sample of this category ,in, Indicates category The first one under Domain name samples; yes The corresponding category label indicates Belongs to the malicious domain category ;Will Embedding Representation Add to ,in, Representation sample Through the parameters The feature encoder The vector representation obtained by mapping; (5b) For perform iterative sample selection: the k-th iteration operation ; the is the preset sample selection quantity, satisfying , where represents the total number of samples of class in the meta-test dataset ; (5b1) Calculate the current mean vector of all sample embeddings in ; Calculation category (5b2) The embeddings of the remaining samples not included in this category and cosine distance : ; Among them, represents the category in the th sample not selected into is the embedded representation obtained by the feature encoder and calculate the cosine similarity of the two vectors; (5b3) Screen samples according to the dynamic quantile threshold where the hyperparameter is used to control the upper limit of ; the hyperparameter is used to control the growth rate of . Select samples that satisfy i.e., samples with the cosine distance closest to the quantile, and add to where represents the distance value at the th percentile in all i.e., the distances of samples are less than this value. (5c) Optimized support set generation: Repeat steps (5b1) to (5b4) until completion Minor sample addition, finally obtaining the optimized support set for each category ; Merge the optimized support sets of all categories to form a global support set , where is the total number of malicious domain name categories; (5d) Hyperparameter constraint: The and takes values from a discrete set in grid search , and determines the optimal parameter combination through cross-validation.
6. The malicious domain name detection method based on meta-learning and contrast learning according to claim 1, characterized in that: Step (6) includes the following steps in sequence: (6a) Sampling of similar samples: Randomly select two sample embedding vectors of the same category from the global support set among which are of the same category and , where and belong to the same malicious domain name category; (6b) Dynamic weight mixing: Generate mixed weight parameters , dynamically control the mixing ratio; Synthesize the enhanced sample embedding vector according to the following formula : ; Keep the enhanced sample labels unchanged: ; Among them, represents the enhanced sample embedding vector whose class label is the same as that of the embedding vector of the original sample and remains consistent, both being the class , ensuring that the data augmentation process does not change the malicious domain name class attribute of the sample; (6c) Batch enhancement generation: Repeat steps (6a) to (6b) times to generate an enhanced support set , where is a preset number of enhanced samples, which is used to control the number of artificial samples generated for each category to expand the scale of the support set.
7. The malicious domain name detection method based on meta-learning and contrast learning according to claim 1, wherein: Step (7) includes the following steps in sequence: (7a) Classifier training: Use the enhanced support set to train a classifier by optimizing the cross-entropy loss function Update the parameters: ; Wherein: is the total number of samples in the enhanced support set, is the total number of malicious domain name categories, , is the true label: when the sample belongs to the current malicious domain name category , otherwise ; (7b) Prediction probability calculation: Use the softmax function to calculate the probability that the sample belongs to the current malicious domain name category of : ; Wherein: and respectively represent the transpose of the classifier parameter vectors corresponding to the current malicious domain name category and the category ; is the sample feature vector extracted through the feature encoder ; (7c) Decision boundary optimization: Minimize through the gradient descent algorithm and update the classifier parameters to optimize the decision boundary; (7d)Query set inference: Apply the trained classifier to the query set in the test phase , and output the class probability distribution of each sample: ; Select the domain name class corresponding to the maximum probability as the final prediction result: .
8. An electronic device, comprising: Processor; And a memory, in which computer program instructions are stored, and when the computer program instructions are run by the processor, the processor is caused to execute the malicious domain name detection method based on meta-learning and contrast learning according to any one of claims 1-7.
9. A computer-readable storage medium, on which computer program instructions are stored, and when the computer program instructions are run by a processor, the processor is caused to execute the malicious domain name detection method based on meta-learning and contrast learning according to any one of claims 1-7.
Citation Information
Cited By
Remote sensing image feature extraction and classification method based on comparative learning method
CN121121482A
Acoustic emission signal classification method, system and equipment based on comparative learning and medium
CN121234165A