Data anomaly detection method and device, equipment and storage medium
Through the iterative processing of hypergraph data, adjusting node weights and hyper-edges, the problem of unbalanced detection and instability of traffic data generated by different data protocols is solved, the detection accuracy is improved, and the security of cloud data is ensured.
Patent Information
- Application Number
- CN202410064428.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-16
- Publication Date
- 2025-07-18
AI Technical Summary
In the prior art, due to the differences in data representation of traffic data generated by different data protocols, the detection classifier has high detection accuracy for traffic data generated by certain data protocols, while the detection accuracy for traffic data generated by other data protocols is low, resulting in problems of detection imbalance and unstable accuracy.
By obtaining hypergraph data containing multiple nodes and each node's hyper-edge, using hypergraph data for iterative processing, adjusting the node weight and hyper-edge degree, in order to mine the correlation relationship between traffic data generated by different data protocols and improve detection accuracy.
It has achieved the improvement of detection accuracy and stability of traffic data generated by different data protocols, effectively avoiding cloud data leakage caused by network attacks, and ensuring cloud data security.
Smart Images

Figure CN120342643A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and in particular, to a method, device, equipment and storage medium for data anomaly detection. Background Art
[0002] In the field of information security technology, in order to improve the detection efficiency of network attacks, a detection classifier relying on artificial intelligence technology to detect abnormal traffic data has emerged as the times require.
[0003] Under the related technology, sample traffic data and its corresponding real data categories (such as: abnormal, normal, etc.) are used to iteratively train the detection classifier to be trained, and a trained detection classifier is obtained. Then, the trained detection classifier is used to classify the traffic data to be detected, and the corresponding predicted data category is obtained as the data detection result.
[0004] However, through creative labor, the inventor found that there are deviations in the data representation forms of traffic data generated by different data protocols, that is: for the same data packet, the traffic data 1 generated based on data protocol 1 and the traffic data 2 generated based on data protocol 2 have different data representation forms; furthermore, when most of the sample traffic data used to train the detection classifier to be trained is generated based on data protocol 1 and a small part is generated based on data protocol 2, it will result in higher detection accuracy for each traffic data to be detected generated by data protocol 1 and lower detection accuracy for each traffic data to be detected generated by data protocol 2 when using the trained classifier subsequently.
[0005] In view of this, there is an urgent need for a data anomaly detection method to solve the problems of unbalanced detection and unstable detection accuracy existing between the traffic data to be detected generated by different data protocols. Summary of the Invention
[0006] The present application provides a method, device, equipment and storage medium for data anomaly detection to solve the problems of unbalanced detection and unstable detection accuracy existing between the traffic data to be detected generated by different data protocols, so as to improve the accuracy of data anomaly detection.
[0007] In a first aspect, the present application provides a method for data anomaly detection, including:
[0008] Obtain hypergraph data including multiple nodes and hyperedges of each node; wherein, the multiple nodes include: M sample nodes representing M pieces of sample traffic data, and N nodes to be detected representing N pieces of traffic data to be detected, and each hyperedge represents: the connection relationship between the corresponding node and other nodes;
[0009] Perform at least one round of iterative processing on the hypergraph data, wherein, in each round of iteration:
[0010] Obtain prediction data categories of the traffic data represented by each node respectively, at least based on the node weights of each node and the degrees of each hyperedge; wherein, each node weight represents the correlation between the traffic data represented by the corresponding node and the abnormal data category, and the degree of each hyperedge represents the contribution of each node connected by the corresponding hyperedge to obtaining the corresponding prediction data category;
[0011] Adjust the node weights of the M sample nodes and the degrees of the corresponding hyperedges respectively based on the differences between the prediction data categories of the M sample traffic data and the corresponding true data categories;
[0012] When a preset iteration termination condition is met, regard the traffic data to be inspected with the prediction data category being the abnormal data category as the target abnormal data.
[0013] In a second aspect, the present application provides a data anomaly detection device, including:
[0014] An acquisition unit, configured to acquire hypergraph data including a plurality of nodes and hyperedges of each node; wherein, the plurality of nodes include M sample nodes representing M sample traffic data and N nodes to be inspected representing N traffic data to be inspected, and each hyperedge represents the connection relationship between the corresponding node and other nodes;
[0015] A processing unit, configured to perform at least one round of iterative processing on the hypergraph data. Wherein, in each round of iteration: obtain prediction data categories of the traffic data represented by each node respectively, at least based on the node weights of each node and the degrees of each hyperedge; wherein, each node weight represents the correlation between the traffic data represented by the corresponding node and the abnormal data category, and the degree of each hyperedge represents the contribution of each node connected by the corresponding hyperedge to obtaining the corresponding prediction data category; adjust the node weights of the M sample nodes and the degrees of the corresponding hyperedges respectively based on the differences between the prediction data categories of the M sample traffic data and the corresponding true data categories; when a preset iteration termination condition is met, regard the traffic data to be inspected with the prediction data category being the abnormal data category as the target abnormal data.
[0016] In a third aspect, the present application provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, it implements any one of the data anomaly detection methods in the first aspect above.
[0017] In a fourth aspect, the present application provides a computer storage medium, in which computer program instructions are stored, and the computer program instructions are executed by the processor to implement any one of the data anomaly detection methods in the first aspect above.
[0018] Fifth aspect, a computer program product provided by an embodiment of the present application includes computer program instructions, which when executed by a processor implement any one of the data anomaly detection methods in the first aspect above.
[0019] The beneficial effects of the present application are as follows:
[0020] In the embodiment of the present application, first, hypergraph data including multiple nodes and hyperedges of each node is obtained. That is, M sample traffic data representing M sample nodes, N to-be-detected traffic data representing N to-be-detected nodes, and each hyperedge representing the connection relationship between the corresponding node and other nodes are obtained. Thus, based on the hyperedges of each node, a quantitative representation of the data association between the M sample traffic data and the N to-be-detected traffic data, and the data association between the obtained multiple traffic data is realized, so as to facilitate subsequent mining of the association relationship between traffic data generated based on different data protocols to solve the problem of unbalanced data anomaly detection of different data protocols.
[0021] Then, at least one round of iterative processing is performed on the hypergraph data. In each round of iteration: at least based on the node weights of each node and the degrees of each hyperedge, the predicted data categories of the traffic data represented by each node are obtained respectively, and then based on the differences between the predicted data categories of the M sample traffic data and the corresponding true data categories, the node weights of the M sample nodes and the degrees of the corresponding hyperedges are adjusted. Wherein, each node weight represents the association relationship between the traffic data represented by the corresponding node and the abnormal data category, and the degree of each hyperedge represents the contribution degree of the nodes connected by the corresponding hyperedge to obtaining the corresponding predicted data category. Thus, it is easy to understand that the above iterative processing process adjusts the association relationship between traffic data generated by different data protocols by updating the node weights of each node and the degrees of each hyperedge; that is, by continuously mining the association relationship between each traffic data itself and between each traffic data, the attention to the abnormal data category is increased to continuously improve the accuracy of the predicted data category of each to-be-detected traffic data.
[0022] Finally, when the preset iteration termination condition is met, the to-be-detected traffic data with the predicted data category of the abnormal data category obtained from the last iterative processing is used as the target abnormal data to implement data anomaly detection, solve the problems of unbalanced detection and unstable detection accuracy existing between the to-be-detected traffic data generated by different data protocols, improve the accuracy of data anomaly detection, be used to ensure data security, especially applied to the cloud computing field, improve the accuracy of anomaly detection for cloud traffic data, thereby ensuring the data security of the cloud, and effectively avoiding the problem of leakage of cloud privacy data caused by network attacks.
[0023] Other features and advantages of the present application will be set forth in the following description, and in part will be obvious from the description, or may be learned by practice of the present application. The objectives and other advantages of the present application may be realized and attained by the structure particularly pointed out in the written description, claims, as well as the drawings. Description of the Drawings
[0024] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:
[0025] Figure 1 It is a schematic diagram of an optional application scenario in an embodiment of the present application;
[0026] Figure 2 It is a schematic diagram of an optional specific application scenario in an embodiment of the present application;
[0027] Figure 3 It is a schematic flowchart of a data anomaly detection method provided in an embodiment of the present application;
[0028] Figures 4A to 4B It is a schematic diagram of possible hypergraph data in an embodiment of the present application;
[0029] Figure 5 It is a schematic diagram of a process for obtaining hypergraph data that may be in an embodiment of the present application;
[0030] Figure 6 It is a schematic diagram of a process for performing at least one round of iterative processing on hypergraph data in an embodiment of the present application;
[0031] Figure 7 It is a schematic diagram of a process for performing multiple rounds of hypergraph learning on hypergraph data in an embodiment of the present application;
[0032] Figure 8 It is a schematic diagram of the predicted class probabilities corresponding to multiple nodes in an embodiment of the present application;
[0033] Figure 9 It is a schematic flowchart of a data anomaly detection method provided in an embodiment of the present application;
[0034] Figure 10 It is a schematic structural diagram of a data anomaly detection device provided in an embodiment of the present application;
[0035] Figure 11 It is a schematic structural diagram of a computer device provided in an embodiment of the present application. Detailed Description of the Embodiments
[0036] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the following will clearly and completely describe the technical solutions in the embodiments of this application with reference to the accompanying drawings in the embodiments of this application.
[0037] In the embodiments of this application, the term "module" or "unit" refers to a computer program with a predetermined function or a part of a computer program, which works together with other related parts to achieve a predetermined goal, and can be fully or partially implemented by using software, hardware (such as a processing circuit or a memory), or a combination thereof. Similarly, one processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be a part of the overall module or unit that includes the functions of that module or unit.
[0038] In the embodiments of this application, the processing of the collection, storage, use, processing, transmission, provision, and disclosure of the user's personal information complies with the provisions of relevant laws and regulations and does not violate public order and good customs.
[0039] The embodiments of this application relate to artificial intelligence technology, mainly involving natural language processing technology and machine learning technology in artificial intelligence technology.
[0040] Artificial Intelligence (AI) is the theory, method, technology, and application system that uses a digital computer or a machine controlled by a digital computer to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use knowledge to obtain the best results. In other words, artificial intelligence is a comprehensive technology in computer science. It attempts to understand the essence of intelligence and produce a new intelligent machine that can respond in a way similar to human intelligence. Artificial intelligence also studies the design principles and implementation methods of various intelligent machines, enabling the machines to have the functions of perception, reasoning, and decision-making.
[0041] Artificial intelligence technology is an interdisciplinary subject, involving a wide range of fields, including both hardware-level technologies and software-level technologies. The basic technologies of artificial intelligence generally include sensors, dedicated artificial intelligence chips, cloud computing, distributed storage, big data processing technology, pre-trained model technology, operation / interaction systems, mechatronics, etc. Among them, the pre-trained model, also known as the large model or the basic model, can be widely applied to the downstream tasks in various directions of artificial intelligence after fine-tuning. The software technologies of artificial intelligence mainly include several major directions such as computer vision technology, speech processing technology, natural language processing technology, and machine learning / deep learning.
[0042] Natural Language Processing (NLP) is an important direction in the fields of computer science and artificial intelligence. It studies various theories and methods that can enable effective communication between humans and computers in natural language. Natural language processing involves natural language, that is, the language people use in daily life, and is closely related to linguistic research; at the same time, it involves computer science and mathematics. The pre-trained model, an important technology for model training in the field of artificial intelligence, has evolved from the large language model (LLM) in the NLP field. After fine-tuning, the large language model can be widely applied to downstream tasks. Natural language processing technologies usually include text processing, semantic understanding, machine translation, robot question answering, knowledge graphs, and other technologies.
[0043] Machine Learning (ML) is an interdisciplinary subject that involves multiple disciplines such as probability theory, statistics, approximation theory, convex analysis, and algorithm complexity theory. It specifically studies how computers simulate or implement human learning behaviors to acquire new knowledge or skills and reorganize the existing knowledge structure to continuously improve their own performance. Machine learning is the core of artificial intelligence and the fundamental way to make computers intelligent, and its applications cover all fields of artificial intelligence. Machine learning and deep learning usually include technologies such as artificial neural networks, belief networks, reinforcement learning, transfer learning, inductive learning, and rote learning. The pre-trained model is the latest development result of deep learning, integrating the above technologies.
[0044] Autonomous driving technology refers to the vehicle's ability to drive itself without driver operation. It usually includes technologies such as high-precision maps, environmental perception, computer vision, behavior decision-making, path planning, and motion control. Autonomous driving includes multiple development paths such as single-vehicle intelligence, vehicle-road cooperation, and networked cloud control. Autonomous driving technology has broad application prospects. Currently, in addition to the fields of logistics, public transportation, taxis, and intelligent transportation, it will be further developed in the future.
[0045] With the research and progress of artificial intelligence technology, artificial intelligence technology has been studied and applied in multiple fields. For example, common ones include Artificial Intelligence Generated Content (AIGC), conversational interaction, intelligent healthcare, intelligent customer service, game AI, smart home, smart wearable devices, virtual assistants, smart speakers, intelligent marketing, driverless, autonomous driving, drones, digital twins, virtual humans, robots, etc. It is believed that with the development of technology, artificial intelligence technology will be applied in more fields and play an increasingly important role.
[0046] In the embodiments of the present application, artificial intelligence technology is applied to the field of information security technology to detect abnormal traffic data and improve the detection accuracy and stability of network attacks. Especially when applied to the field of cloud technology, it can be used to improve the detection accuracy of abnormal traffic data in the cloud and solve the problem of data leakage caused by cloud attacks (such as privacy leakage). Here, it mainly involves the field of cloud security technology in cloud technology.
[0047] Cloud technology refers to a hosting technology that unifies a series of resources such as hardware, software, and networks within a wide area network or a local area network to achieve data computing, storage, processing, and sharing.
[0048] Cloud technology is the general term for network technology, information technology, integration technology, management platform technology, application technology, etc. applied based on the cloud computing business model. It can form a resource pool, be used on demand, and is flexible and convenient. Cloud computing technology will become an important support. The back-end services of technical network systems require a large amount of computing and storage resources, such as video websites, picture websites, and more portal websites. With the highly developed and applied Internet industry, in the future, each item may have its own identification mark and needs to be transmitted to the back-end system for logical processing. Data at different levels will be processed separately, and various industry data requires a powerful system support, which can only be achieved through cloud computing.
[0049] Cloud Security refers to the general term for security software, hardware, users, organizations, and security cloud platforms applied based on the cloud computing business model. Cloud Security integrates emerging technologies and concepts such as parallel processing, grid computing, and unknown virus behavior judgment. Through the abnormal monitoring of software behaviors in the network by a large number of client ends in a mesh structure, the latest information about Trojans and malicious programs in the Internet is obtained and sent to the server for automatic analysis and processing. Then, the solutions for viruses and Trojans are distributed to each client end.
[0050] The main research directions of cloud security include: 1. Cloud computing security, mainly studying how to ensure the security of the cloud itself and various applications on the cloud, including cloud computer system security, secure storage and isolation of user data, user access authentication, information transmission security, network attack protection, compliance audit, etc.; 2. Cloudification of security infrastructure, mainly studying how to use cloud computing to build and integrate security infrastructure resources and optimize the security protection mechanism, including building a super-large-scale security event, information collection and processing platform through cloud computing technology to achieve the collection and correlation analysis of massive information, and improving the overall network security event control ability and risk control ability; 3. Cloud security services, mainly studying various security services provided for users based on the cloud computing platform, such as anti-virus services, etc.
[0051] To facilitate the understanding of the technical solutions provided by the embodiments of the present application, some key terms used in the embodiments of the present application are first explained.
[0052] Hypergraph: A concept in graph theory, which is a data structure that extends the traditional graph structure and allows edges to connect multiple vertices. In a traditional graph, an edge connects two vertices, while in a hypergraph, an edge can connect any number of vertices.
[0053] Hypergraph structure: The basic components of a hypergraph include nodes (Vertices) and hyperedges. Vertices represent entities or objects in the graph, while hyperedges represent relationships or connections that connect multiple vertices. Hyperedges can connect two or more vertices, which enables hypergraphs to represent complex relationships and connection patterns more flexibly.
[0054] The design concept of the embodiments of the present application is briefly introduced below.
[0055] In the existing traffic data anomaly detection methods, usually a detection classifier is trained based on data samples, and then the traffic data to be detected is input into the trained detection classifier to obtain the corresponding predicted data category, so as to realize the detection of abnormal traffic data.
[0056] However, in the above method, although the automatic detection of abnormal traffic data is realized, the inventor creatively found that when the data samples for training the detection classifier are unbalanced, affected by the unbalanced data samples, the detection of the trained detection classifier for the traffic data to be detected is unbalanced, that is, there is a problem of inaccurate data anomaly detection.
[0057] Furthermore, through creative work, the inventor considered that traffic data can be generated based on different data protocols, and there are differences in the data presentation forms standardized by different data protocols. Then, the problem of optimizing the accuracy of abnormal data detection can be transformed into mining the data associations between the traffic data corresponding to different data protocols, so as to combine the data associations to improve the detection stability and detection accuracy of data anomaly detection.
[0058] In view of this, the embodiments of the present application provide a data anomaly detection method. In this method, a way to obtain traffic data is provided, that is, hypergraph data including multiple nodes and the hyperedges of each node is obtained. The nodes are used to represent sample traffic data or traffic data to be detected, and the hyperedges are used to represent the connection relationships between the corresponding nodes and other nodes. In this way, the obtained hypergraph data can realize the representation of each traffic data and also the representation of the association relationships between each traffic data (such as: sample traffic data and traffic data to be detected, and also: traffic data corresponding to different data protocols), so as to facilitate the subsequent mining of the foregoing association relationships, thereby improving the accuracy and stability of data anomaly detection.
[0059] In addition, an embodiment of the present application further provides a method for detecting traffic data, that is, performing at least one round of iterative processing on the obtained hypergraph data until a preset iterative termination condition is met, and using the traffic data to be detected whose predicted data category is the abnormal data category obtained in the last iteration as the target abnormal data. By iterative processing, the correlation between each traffic data is further mined, so as to improve the detection accuracy of the target abnormal data.
[0060] Specifically, in the process of each round of iterative processing, the predicted data category of each traffic data is obtained respectively based on at least the node weight corresponding to each traffic data (that is, each node) and the degree of each correlation (that is, each hyperedge). Then, based on the difference between the true data category of M sample traffic data and the corresponding predicted data category, the node weights corresponding to the M sample traffic data and the degrees of the relevant correlations are adjusted accordingly. In this way, based on the M sample traffic data, by updating the corresponding node weights and the degrees of the corresponding correlations, the accuracy of obtaining the predicted data category is improved, that is, the correlation between the corresponding traffic data and the abnormal data category is mined, and the contribution degree of the corresponding traffic data to obtaining the corresponding predicted data category is mined. In this way, not only the correlation between the traffic data itself and the abnormal data category can be mined, but also the correlation between different data protocols and the obtained corresponding predicted data category can be mined, so as to solve the problem of unbalanced detection of abnormal data caused by different data protocols and improve the detection accuracy of the target abnormal data.
[0061] The following briefly introduces the application scenarios applicable to the technical solution of the embodiment of the present application. It should be noted that the application scenarios introduced below are only used to illustrate the embodiment of the present application rather than to limit it. In the specific implementation process, the technical solution provided by the embodiment of the present application can be flexibly applied according to actual needs.
[0062] The solution provided by the embodiment of the present application can be applied to the target detection scenarios of most physical objects; for example, in the industrial quality inspection scenario, for the defect detection of lithium batteries; for example, in the intelligent driving scenario, for the obstacle detection of roads; and for example, in the field of robot navigation, for the category detection of roads.
[0063] Refer to Figure 1 As shown, it is a schematic diagram of an application scenario provided by the embodiment of the present application. In this scenario, it may include a terminal device 110 and a server 120.
[0064] In the embodiments of the present application, the terminal device 110 may be, for example, a mobile phone, a tablet computer (PAD), a notebook computer, a desktop computer, a smart TV, a smart vehicle-mounted device, and a smart wearable device, etc.; a client for data anomaly detection (such as a target detection platform) may be installed on the terminal device, and the client may be software (such as a browser, an image processing software, etc.), or a web page, a small program, etc., and the server 120 is a background server corresponding to the software or the web page, the small program, etc., or a server dedicated to image processing, and the present application does not make specific limitations.
[0065] The server 120 may be an independent physical server, or a server cluster or a distributed system composed of multiple physical servers, or may be a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, Content Delivery Network (CDN), and big data and artificial intelligence platforms. The terminal may be a smart phone, a tablet computer, a notebook computer, a desktop computer, a smart speaker, a smart watch, etc., but is not limited thereto. The terminal and the server may be directly or indirectly connected through wired or wireless communication means, and the present application does not make limitations herein.
[0066] In an alternative embodiment, the terminal device 110 and the server 120 may be directly or indirectly communicatively connected through one or more networks 130. The network 130 may be a wired network or a wireless network. For example, the wireless network may be a mobile cellular network or a Wireless-Fidelity (WIFI) network. Of course, it may also be other possible networks, and the embodiments of the present invention do not make limitations thereto.
[0067] It should be noted that, in the embodiments of the present application, the number of terminal devices 110 may be one or multiple. Similarly, the number of servers 120 may also be one or multiple. That is to say, the number of terminal devices 110 or servers 120 is not limited.
[0068] In a possible application scenario, in order to facilitate reducing the communication delay of retrieval, the server 120 may be deployed in each region, or for load balancing, different servers 120 may respectively serve terminal devices 110 in different regions. For example, the terminal device 110 is located at location a and establishes a communication connection with the server 120 serving location a, and the terminal device 110 is located at location b and establishes a communication connection with the server 120 serving location b. Multiple servers 120 form a data sharing system, and data sharing is realized through a blockchain.
[0069] For each server 120 in the data sharing system, there is a node identifier corresponding to the server 120. Each server 120 in the data sharing system can store the node identifiers of other servers 120 in the data sharing system, so as to broadcast the generated block to other servers 120 in the data sharing system according to the node identifiers of other servers 120 subsequently. A node identifier list can be maintained in each server 120, and the server 120 name and the node identifier are stored in the node identifier list correspondingly. Among them, the node identifier can be an Internet Protocol (IP) address for interconnection between networks and any other information that can be used to identify the node.
[0070] Exemplarily, in the embodiments of the present application, when the number of servers is multiple, the multiple servers can form a blockchain, and the servers are nodes on the blockchain; as in the object detection method disclosed in the embodiments of the present application, various feature map sizes, color feature maps and depth feature maps corresponding to the images to be detected, each fused feature map, initial object features, fused object features, object detection results, etc. involved can all be saved on the blockchain.
[0071] In addition, it should be noted that the hypergraph data acquisition method, hypergraph data processing method, hypergraph data learning method, and target abnormal traffic data detection method in each embodiment of the present application can be executed by an electronic device, which can be a terminal device 110 or a server 120. That is, the method can be executed independently by the terminal device 110 or the server 120, or jointly executed by the terminal device 110 and the server 120. For example, when jointly executed by the terminal device 110 and the server 120, N pieces of traffic data to be inspected are obtained through the terminal device 110 and sent to the server 120, or the Uniform Resource Locator (URL) of the N pieces of traffic data to be inspected is sent to the server 120 for the server 120 to download by itself, etc.; furthermore, through the target detection platform deployed on the server 120, based on M pieces of sample traffic data and in combination with N pieces of traffic data to be inspected, hypergraph data including multiple nodes and hyperedges of each node is obtained, and at least one round of iterative processing is performed on the hypergraph data. During each round of iterative processing, at least based on the node weights of each node and the degrees of each hyperedge, the predicted data categories of the traffic data represented by each node are obtained respectively, and based on the differences between the predicted data categories of the M pieces of sample traffic data and the corresponding true data categories respectively, the node weights of the M sample nodes and the degrees of the corresponding hyperedges are adjusted until a preset iterative termination condition is met. The traffic data to be inspected with the predicted data category being the abnormal data category is used as the target abnormal data; then, the server 120 sends the detected target abnormal data to the terminal device 110. Finally, the terminal device 110 performs visual display.
[0072] Exemplarily, the solution provided in the embodiments of the present application is applicable to various abnormal detection application scenarios of traffic data, such as: application scenarios for abnormal detection of cloud data, application scenarios for abnormal detection of offline data, application scenarios for abnormal detection and analysis of data, etc.
[0073] Refer to Figure 2 As shown, it is a schematic diagram of a possible application scenario for abnormal detection of cloud data provided in the embodiments of the present application. In this scenario, the cloud server 120 is used as the background server of the target detection platform, and the terminal device 110 is used as the main body for the target detection platform to interact with the user. As Figure 2As shown in the figure, User 1 is interacting with User 2 in a chat. During the information interaction process, Cloud Server 120 will obtain in real time the online traffic data to be inspected, which is traffic data that may constitute a network attack, including but not limited to: external traffic data sent by other devices (other terminal devices 110, other servers 120), interactive traffic data sent by terminal devices 110 with the consent of the user, etc.; correspondingly, through the target detection platform deployed on Cloud Server 120, based on M sample traffic data and combined with N traffic data to be inspected, hypergraph data containing multiple nodes and hyperedges for each node is obtained. At least one round of iterative processing is performed on the hypergraph data. During each round of iterative processing, at least based on the node weights of each node and the degrees of each hyperedge, the predicted data categories of the traffic data represented by each node are obtained respectively, and based on the differences between the predicted data categories of the M sample traffic data and the corresponding true data categories respectively, the node weights of the M sample nodes and the degrees of the corresponding hyperedges are adjusted until the preset iterative termination condition is met. The traffic data to be inspected with the predicted data category being the abnormal data category is used as the target abnormal data; then, the detected target abnormal data is sent by Server 120 to the corresponding terminal device 110. Finally, the corresponding terminal device 110 performs visual display.
[0074] It should be noted that the above client can be a mini-program client, a browser client, etc., and the mini-program client and the browser client can be deployed in different backend servers respectively.
[0075] Of course, the method provided in the embodiments of the present application is not limited to Figure 1 or Figure 2 the application scenarios shown. It can also be used in other possible application scenarios, and the embodiments of the present application do not limit this. For Figure 1 or Figure 2 the functions that can be achieved by each device in the application scenarios shown will be described together in the subsequent method embodiments, and will not be elaborated here too much.
[0076] In addition, the process of jointly performing the data anomaly detection method by the terminal device 110 and the server 120 listed above is only a feasible implementation manner. In fact, any process of the terminal device 110 and the server 120 performing this method is applicable to the embodiments of the present application, and will not be elaborated one by one here.
[0077] In addition, the embodiments of the present application can be applied to various scenarios, including but not limited to scenarios such as cloud technology, artificial intelligence, intelligent transportation, assisted driving, and autonomous driving.
[0078] Next, in combination with the above-described application scenarios, the method provided by the exemplary embodiments of the present application will be described with reference to the accompanying drawings. It should be noted that the above application scenarios are only shown for the convenience of understanding the spirit and principle of the present application, and the embodiments of the present application are not limited in this regard. And it should be noted that the following method can be executed by the above terminal device or server, or can be jointly executed by the terminal device and the server. Here, it is specifically shown taking the server execution as an example.
[0079] Refer to Figure 3 As shown, it is a flowchart of the implementation of a data anomaly detection method provided by an embodiment of the present application. Taking a computing device characterized as a terminal device or a server as the execution subject, the specific implementation process of the method is as follows:
[0080] Step 301: Obtain hypergraph data including multiple nodes and hyperedges of each node; wherein, the multiple nodes include: M sample nodes representing M pieces of sample traffic data, and N to-be-detected nodes representing N pieces of to-be-detected traffic data, and each hyperedge represents: the connection relationship between the corresponding node and other nodes.
[0081] In the embodiments of the present application, the obtained hypergraph data can be used to represent: multiple pieces of traffic data and their corresponding connection relationships.
[0082] The above-mentioned multiple pieces of traffic data can be traffic data generated based on multiple different data protocols, and the multiple pieces of traffic data can include M pieces of sample traffic data and N pieces of to-be-detected traffic data. The M pieces of sample traffic data can be generated based on M (or less than M) data protocols, and the N pieces of to-be-detected traffic data can be generated based on N (or less than N) data protocols. Each piece of sample traffic data is historical traffic data that has undergone historical anomaly detection. Then, in addition to obtaining the hypergraph data, the historical detection results of each of the M pieces of sample traffic data can also be obtained as the corresponding true data types. Optionally, the foregoing historical detection results can be obtained by means of expert detection. Of course, other detection methods that meet the actual detection requirements can also be used, and no specific limitation is made here. Each piece of to-be-detected traffic data is traffic data that has not undergone historical anomaly detection. In combination with the embodiments of the present application, at least based on the M pieces of sample traffic data, the N pieces of to-be-detected traffic data are detected to obtain the predicted data category of each piece of to-be-detected traffic data, so as to achieve the detection of target anomaly data.
[0083] The above connection relationship can be the connection relationship between one piece of traffic data and K pieces of other traffic data, where K is generally an integer greater than 1. Of course, K can also be set to 1 based on the actual application situation, and the embodiments of the present application do not make specific limitations in this regard.
[0084] Refer to Figure 4AAs shown, it is a schematic diagram of a possible hypergraph data in an embodiment of the present application. The hypergraph data can represent: multiple traffic data and their corresponding connection relationships. For example Figure 4A As shown, taking the example that each traffic data has a connection relationship with another traffic data; it can be seen that there are 4 sample nodes (representing 4 sample traffic data) and 2 to-be-tested nodes (representing 2 sample traffic data) in the figure, and 6 hyperedges (6 connection relationships) are formed between them. Each hyperedge corresponds to a node. For example, the sample hyperedge 1 representing the connection relationship between the sample hyperedge 1 and the sample node 1 corresponds to the sample node 1. Another example is the to-be-tested hyperedge 1 representing the connection relationship between the to-be-tested node 1 and the sample node 1, which corresponds to the to-be-tested node 1. The relationships of other hyperedges can be obtained in the same way and will not be repeated here.
[0085] It should be noted that in an embodiment of the present application, a traffic data can also have a connection relationship with multiple other traffic data; for example, referring to Figure 4B As shown, it is a schematic diagram of a possible hypergraph data in an embodiment of the present application. Taking the example that the sample node 4 has a connection relationship with the to-be-tested node 1 and the sample node 3, the corresponding sample hyperedge 4 includes the sample node 4, the to-be-tested node 1, and the sample node 3, and represents the connection relationship between the sample node 4 and the other two nodes.
[0086] In an optional embodiment, a possible way to obtain hypergraph data is also provided. Specifically, M sample traffic data and N to-be-tested traffic data are respectively abstracted into M sample nodes and N to-be-tested nodes to obtain multiple nodes. Then, a reference node of the reference traffic data representing the abnormal data category is obtained. Based on the node differences between each node and the reference node, the belonging degree of each node to the abnormal data category is obtained, and based on the obtained belonging degrees, the following operations are respectively performed for each node: based on the belonging degree difference between the belonging degree of one node and the belonging degrees of other nodes, multiple belonging degree differences are obtained, and then from the multiple belonging degree differences, a specified number of nodes corresponding to the belonging degree differences are selected in ascending order as the associated nodes of one node, and the connection relationship between one node and the corresponding associated nodes is constructed to obtain the hyperedge of one node.
[0087] Referring to Figure 5As shown in the figure, it is a schematic diagram of the process of obtaining hypergraph data in an embodiment of the present application. Among them, each membership degree can be obtained based on the node distance between the corresponding node and the reference node. Taking the example of obtaining the hyperedge of sample node 4, first, based on the reference node, obtain the membership degrees of the 6 nodes shown in the figure, which are D1 to D6 respectively. Further, based on the membership degree difference between D5 (corresponding to sample node 4) and other membership degrees, arrange the other membership degrees in ascending order, and obtain the corresponding node sorting as follows: sample node 3, test node 1, sample node 1, test node 2, sample node 2. When the specified number is 2, select two nodes in ascending order, which are: sample node 3, test node 1, as the associated nodes of sample node 4, and construct the connection relationship between them to obtain the corresponding sample hyperedge 4.
[0088] It should be noted that the above node distance can be obtained by using the Euclidean distance, or the Euclidean distance, Manhattan distance, Chebyshev distance can be used. Here, the specific method of obtaining the node distance is not specifically limited. Based on different node distance methods, different hyperedges of a node can be obtained correspondingly; for example, based on t node distance calculation methods, t hyperedges of a node can be obtained correspondingly. For M + N nodes, the number of obtained hyperedges is t * (M + N), where t is the number of adopted node distance calculation methods, and M + N is the number of nodes in the obtained hypergraph data.
[0089] Further, the above reference node can also be obtained through the following method: based on the true data categories of M sample traffic data respectively, select at least one sample abnormal data belonging to the abnormal data category from the M sample traffic data, then perform clustering processing on the sample nodes corresponding to the at least one sample abnormal data, and use the clustering center as the reference node to represent the reference traffic data belonging to the abnormal data category.
[0090] It should be noted that in the process of obtaining the above reference node, multiple historical abnormal data can also be obtained, combined with the selected sample abnormal data from the M sample traffic data, and clustering processing is performed to obtain the corresponding reference node. In this way, the versatility of the obtained reference node can be improved. In addition, the above clustering processing can specifically adopt the K-means clustering algorithm, or other clustering algorithms can also be used. Here, the specific clustering method is not specifically limited.
[0091] Step 302: Perform at least one round of iterative processing on the hypergraph data. Among them, in each round of iteration process, the following steps 3021 to 3022 are included.
[0092] In the embodiments of the present application, in order to obtain the predicted data categories of N pieces of traffic data to be inspected, iterative processing is performed on the hypergraph data. Each iterative processing is performed on the hypergraph data, and the predicted data category of each piece of traffic data can be obtained.
[0093] Referring to Figure 6 As shown, it is a schematic diagram of the process of performing at least one round of iterative processing on the hypergraph data in the embodiments of the present application. Among them, the obtained hypergraph data includes M sample nodes (corresponding to M true data categories respectively), N nodes to be inspected, and M + N hyperedges. In the first round of iterative process, M + N node weights 1 and the degrees 1 of M + N hyperedges are obtained accordingly. Then, based on this, the hypergraph data is processed to obtain the predicted data category 1 of each node. Then, based on the difference between the M predicted data categories 1 corresponding to the M sample nodes and the corresponding M true data categories, M + N node weights 1 and the degrees 1 of M + N hyperedges are updated to obtain the M + N node weights 2 and the degrees 2 of M + N hyperedges in the second round of iteration.
[0094] Further, the detailed process of each round of iterative processing can be seen in steps 3021 to 3022, specifically as follows:
[0095] Step 3021: Obtain the predicted data category of the traffic data represented by each node at least based on the node weight of each node and the degree of each hyperedge; among them, each node weight represents the correlation between the traffic data represented by the corresponding node and the abnormal data category, and the degree of each hyperedge represents the contribution degree of the nodes connected by the corresponding hyperedge to obtaining the corresponding predicted data category.
[0096] Specifically, in the first round of iterative process, first obtain the node weights of each node in the first round of iteration and the degrees of each hyperedge in the first round of iteration. Then, at least based on the node weights of each node and the degrees of the hyperedges in the first round of iteration, perform multiple rounds of hypergraph learning on the hypergraph data, and obtain the predicted data categories of the traffic data represented by each node by predicting the probability that each node belongs to the abnormal data category. Subsequently, the difference between the i-th (i is an integer greater than 1) round of iteration and the first round of iteration is: obtain the node weights updated by each node in the (i - 1)-th round of iteration and the degrees of each hyperedge updated by each hyperedge in the (i - 1)-th round of iteration, and then obtain the predicted data categories of the traffic data represented by each node at least based on the node weights of each node and the degrees of the hyperedges in the i-th round of iteration.
[0097] In an alternative embodiment, to obtain the node weights of each node in the first round of iteration, before performing the first round of iteration processing, first obtain the reference nodes of the reference traffic data representing the abnormal data categories, and then, based on each difference index, calculate the node differences between each node and the reference nodes respectively, to obtain the respective membership degrees of each node for each abnormal data category. Then, based on the respective membership degrees of each node, generalize the association relationship between the traffic data represented by the corresponding node and the abnormal data category, to obtain the node weights of each node.
[0098] Among them, each obtained node weight corresponds to a difference index, and each difference index represents: a calculation method of a node difference; this calculation method can be obtained by calculating the distance between nodes; the calculation method of the node distance and the calculation method of each membership degree can refer to the relevant description in step 301, and will not be repeated here.
[0099] Optionally, after obtaining the node weights of each node in the first round of iteration, the obtained node weights can also be concatenated based on the concatenation order of each node, to obtain a concatenated node weight matrix; for example: based on the sample nodes, the nodes to be inspected, and the concatenation order of each node obtained in combination with the data protocol order, the corresponding node weight matrix can be shown as follows:
[0100] u = (u11, u10, u21, u20, …, uM1, uM0, u1test, u2test, …, uNtest);
[0101] Among them, u11 is the node weight of sample node 1 representing sample abnormal data, u10 is the node weight of sample node 1 representing sample normal data, uM1 is the node weight of sample node M representing sample abnormal data, uM0 is the node weight of sample node M representing sample normal data, u1test is the node weight of test node 1 representing the traffic data to be inspected, and uNtest is the node weight of test node N representing the traffic data to be inspected.
[0102] It should be noted that in the process of obtaining the above node weights, the method of isolation forest can also be used to generalize the association relationship between the traffic data represented by the corresponding node and the abnormal data category based on the respective membership degrees of each node, to obtain the node weights of each node. Briefly speaking, a threshold is randomly selected, so that the membership degrees greater than this threshold among the membership degrees are farther away from the reference node, thereby obtaining the probability that each node belongs to the abnormal data category, and further obtaining the node weights of each node based on the obtained probability values, which will not be elaborated here.
[0103] In an alternative embodiment, in order to obtain the degree of each hyperedge in the first round of iteration, before performing the first-round iteration processing, for each hyperedge, the following operations are respectively performed: Sum the node weights of the nodes connected by a hyperedge to obtain the degree of a hyperedge.
[0104] Exemplarily, the relationship between the degree of a hyperedge and the corresponding nodes can be referred to as follows:
[0105]
[0106] Among them, e is a hyperedge, delta(e) is the degree of a hyperedge, V is the set of nodes included in a hyperedge, v is a node in the node set, U(v) is the node weight of a node, and H(v,e) is the incidence matrix between nodes and hyperedges, used to represent the inclusion relationship between a node and each hyperedge. Each element value is used to identify whether a corresponding node is associated with a hyperedge (or whether a corresponding hyperedge contains a node). The incidence matrix can be specifically referred to as follows:
[0107]
[0108] Among them, v is any node, and e is the above-mentioned hyperedge; v∈e means that this hyperedge e contains this node v, then the value of H(v,e) is 1, indicating that this node v is associated with this hyperedge e; means that this hyperedge e does not contain this node v, then the value of H(v,e) is 0, indicating that this node v is not associated with this hyperedge e.
[0109] It should be noted that the above situations that meet the preset iteration termination conditions can include any one or a combination of the following situations: Situation 1, the number of iteration rounds for the hypergraph data is greater than or equal to the preset round threshold; Situation 2, the difference value between the node weights corresponding to the current round of iteration and the previous round of iteration is less than or equal to the preset difference threshold.
[0110] Furthermore, the embodiments of the present application also disclose a method for obtaining predicted data categories, that is: based at least on each node weight and the degree of hyperedges, perform multiple rounds of hypergraph learning on the hypergraph data, and obtain the predicted data categories of the traffic data represented by each node by predicting the probability that each node belongs to the abnormal data category.
[0111] In a possible implementation, multi-round hypergraph learning is performed on hypergraph data based at least on the node weights of each node and the degrees of each hyperedge. During one round of learning: based on the node weights of each node and the degrees of each hyperedge, combining the hyperedge weights of each hyperedge and the degrees of each node, obtain the prediction loss values of each candidate data category for predicting the traffic data representation of each node; when the prediction loss value does not meet the preset learning termination condition, based on the prediction loss value, adjust the hyperedge weights of each hyperedge and the degrees of each node; when the prediction loss value meets the preset learning termination condition, obtain the predicted data category of the traffic data represented by each node.
[0112] Wherein, each hyperedge weight represents: the association relationship between the nodes connected by the corresponding hyperedge. The degree of each node represents: the contribution degree of the connection relationship on which the corresponding node depends to obtaining the corresponding predicted data category.
[0113] Refer to Figure 7 As shown, it is a schematic diagram of the process of performing multi-round hypergraph learning on hypergraph data in an embodiment of the present application. As Figure 7 As shown, the obtained hypergraph data includes M sample nodes (corresponding to M real data categories respectively), N nodes to be inspected, and M + N hyperedges. In the first round of learning process, M + N hyperedge weights 1 and the degrees 1 of M + N nodes are obtained correspondingly. Then, based on this, the hypergraph data is processed to obtain the candidate data categories 1 of M + N nodes. Then, based on the candidate data categories 1 of M + N nodes, the prediction loss value 1 of the first round of learning process is obtained. When the prediction loss value 1 does not meet the preset learning termination condition, based on the prediction loss value 1, update the M + N hyperedge weights 1 and the degrees 1 of M + N nodes to obtain the M + N hyperedge weights 2 and the degrees 2 of M + N nodes in the second round of learning. When the prediction loss value i obtained in the i-th (i is any positive integer) round of learning meets the preset learning termination condition, obtain the candidate data categories i of M + N nodes as the predicted data categories of the corresponding traffic data.
[0114] Optionally, in the first round of learning in the first iteration, the hyperedge weights of each hyperedge are the same. For example, the hyperedge weights are all set to 1; then in the first round of learning in the first iteration, the hyperedge weights of specified values will also be obtained, and the specified data can be set according to the actual application situation, so as to ensure that the association relationship between the nodes connected by the corresponding hyperedge is balanced.
[0115] Optionally, in the first round of learning in the first iteration, the degrees of each node can be obtained in the following way, that is, for each node, the following operations are performed respectively: sum the hyperedge weights of each hyperedge connected to a node to obtain the degree of a node.
[0116] Exemplarily, the degree of a node and the association relationship with the corresponding hyperedge can be referred to as follows:
[0117]
[0118] Among them, v is a node, d(v) is the degree of a node, E is the hyperedge set of the hyperedges corresponding to a node, e is a hyperedge in the hyperedge set, W(e) is the hyperedge weight of a hyperedge, and H(v, e) is the incidence matrix of the node and the hyperedge, used to represent the inclusion relationship between a node and each hyperedge. Each element value is used to identify whether a node is associated with a hyperedge (or whether a hyperedge contains a node). The incidence matrix can be specifically referred to as follows:
[0119]
[0120] Among them, v is the above-mentioned node, and e is any hyperedge; v ∈ e means that the hyperedge e contains this node v, then the value of H(v, e) is 1, indicating that the node v is associated with the hyperedge e; means that the hyperedge e does not contain this node v, then the value of H(v, e) is 0, indicating that the node v is not associated with the hyperedge e.
[0121] It should also be noted that the satisfaction of the above learning termination condition can include any one or a combination of the following situations: Situation 1, the number of learning rounds for the hypergraph data is greater than or equal to a preset learning threshold; Situation 2, the difference value between the hyperedge weights corresponding to the current round of learning and the previous round of learning is less than or equal to a preset difference threshold.
[0122] Step 3022: Adjust the node weights of the M sample nodes and the degrees of the corresponding hyperedges respectively based on the difference between the predicted data category and the corresponding true data category of the M sample traffic data.
[0123] In the embodiments of the present application, based on the difference between the predicted data category and the corresponding true data category of the M sample traffic data, the loss value of the corresponding sample nodes (i.e., the corresponding sample traffic data) is calculated, and then a preset loss value function is used to adjust the node weights of the M sample nodes accordingly. Then, based on the adjusted node weights of the M nodes, the degrees of the M hyperedges are adjusted accordingly.
[0124] Furthermore, in order to explore the importance of different data protocols for generating the corresponding final predicted data category, for the M sample traffic data generated based on multiple data protocols, by combining the data protocols corresponding to each sample traffic data, the corresponding loss value is calculated, and the adjustment of the node weights and the degrees of the hyperedges is realized to solve the problem of unbalanced final abnormal data detection caused by unbalanced data protocols.
[0125] Specifically, based on the differences between the predicted data categories and the corresponding true data categories of M sample traffic data respectively, the loss values of each of the M sample nodes are obtained. Then, for each sample traffic data generated by each data protocol, under the preset node weight constraint conditions, based on the sum of the products of the corresponding loss values and the corresponding node weights, the positive influence on obtaining the corresponding predicted data category is used to adjust the corresponding node weights. Then, based on the adjusted node weights, the degrees of the corresponding hyperedges are adjusted respectively.
[0126] In an alternative implementation, the loss values of each of the M sample nodes can use a logarithmic function to calculate the predicted category probability corresponding to the corresponding predicted data category and the abnormal category probability corresponding to the corresponding abnormal data category, and take the negative value of the calculation result.
[0127] Exemplarily, the relationship between the predicted category probability F[pre + j][1] (i.e., the hypergraph learning result of the corresponding sample traffic data) of the jth sample traffic data generated based on data protocol i and corresponding to the true data category of abnormal data category and the corresponding loss value can be specifically referred to as follows:
[0128] loss i_j_1 =-math.log(F[pre + j][1]);
[0129] where loss i_j_1 represents the loss value of the jth sample traffic data corresponding to the abnormal data category corresponding to data protocol 1, i represents the corresponding data protocol i, pre represents the total amount of sample traffic data corresponding to the i - 1 types of data protocols between data protocol i, j represents the jth sample traffic data corresponding to data protocol i, [1] represents the abnormal category probability of the abnormal data category, and math.log() is the logarithmic function.
[0130] In another alternative implementation, the loss values of each of the M sample nodes can use a logarithmic function to calculate the predicted category probability corresponding to the corresponding predicted data category and the normal category probability corresponding to the corresponding normal data category, and take the negative value of the calculation result.
[0131] Exemplarily, the relationship between the predicted category probability F[pre + j][0] (i.e., the hypergraph learning result of the corresponding sample traffic data) of the jth sample traffic data generated based on data protocol i and corresponding to the true data category of normal data category and the corresponding loss value can be specifically referred to as follows:
[0132] loss i_j_0 =-math.log(F[pre + j][0]);
[0133] Among them, loss i_j_0 represents the loss value corresponding to the normal data category of the j-th sample traffic data corresponding to data protocol 1. i represents the corresponding data protocol i, pre represents the total amount of sample traffic data corresponding to the i-1 data protocols between data protocols i, j represents the j-th sample traffic data corresponding to data protocol i, [0] represents the normal category probability of the normal data category, and math.log() is the logarithmic function.
[0134] It should be noted that, as shown in Figure 8 a schematic diagram of the predicted category probabilities corresponding to multiple nodes in the embodiment of the present application, that is, the predicted category probabilities of the true data categories (the corresponding true category probabilities are 0) and abnormal data categories (the corresponding abnormal data categories are 1) corresponding to multiple nodes. It is worth mentioning that in the process of obtaining the predicted data category shown in step 2031, multiple rounds of hypergraph learning will also be performed. The results of these multiple rounds of hypergraph learning can be represented as a vector matrix F (F can correspond to the Figure 8 table shown), and the vector matrix F contains M + N rows of data, and each row of data corresponds to the traffic data represented by a node.
[0135] As shown in Figure 8As shown, it can be seen that the data in the first column are the node traffic data arranged in sequence according to the traffic data belonging to the same data protocol, and the sample traffic data are listed above the traffic data to be inspected. Thus, in the first row data of the vector matrix F (except for the first row attribute representation), for the first sample traffic data 1_1 corresponding to data protocol 1: F[1][1] corresponds to the data in the first row and the second column, which represents the predicted class probability of the abnormal data class (abnormal class probability is 1); F[1][0] corresponds to the data in the first row and the third column, which represents the predicted class probability of the normal data class (normal class probability is 0). In the (pre + j)-th row data of the vector matrix F (except for the first row attribute representation), for the j-th sample traffic data i_j corresponding to data protocol i: F[pre + j][1] corresponds to the data in the (pre + j)-th row and the second column, which represents the predicted class probability of the abnormal data class (abnormal class probability is 1); F[pre + j][0] corresponds to the data in the (pre + j)-th row and the third column, which represents the predicted class probability of the normal data class (normal class probability is 0). In addition, in the (train + j)-th row data of the vector matrix F (except for the first row attribute representation), where the value of train is the total number M of sample traffic data, for the j-th training traffic data test_j: F[train + j][1] corresponds to the data in the (train + j)-th row and the second column, which represents the predicted class probability of the abnormal data class (abnormal class probability is 0.5, which can be preset according to the actual situation); F[train + j][0] corresponds to the data in the (train + j)-th row and the third column, which represents the predicted class probability of the normal data class (normal class probability is 0.5, which can be preset according to the actual situation).
[0136] Further, after obtaining the loss values of each of the M sample nodes, for each sample traffic data generated for each data protocol, under the preset node weight constraint conditions, based on the sum of the products of the corresponding loss value and the corresponding node weight, for the positive impact on obtaining the corresponding predicted data class, adjust the corresponding node weight, and then based on the adjusted node weights of each, adjust the degrees of the corresponding hyperedges respectively.
[0137] In an alternative implementation, for each sample traffic data generated for each data protocol, the following operations are performed respectively: for each sample traffic data generated for a data protocol, calculate the difference between the product of the loss value corresponding to each sample traffic data and the corresponding node weight and the weighted value of the square of the corresponding node weight, and then sum the obtained differences to obtain the preference degree of a data protocol for obtaining the corresponding predicted data class, and then under the preset node weight constraint conditions, based on the preference degree corresponding to a data protocol, for the positive impact on obtaining the corresponding predicted data class, adjust the corresponding node weight.
[0138] Exemplarily, the association relationship between the preference degree for obtaining the corresponding predicted data category and the corresponding loss value of the above data protocol can be characterized as follows:
[0139]
[0140] Among them, represents the preference degree of data protocol i for obtaining the corresponding predicted data category, loss i_j represents the loss value of the j-th sample traffic data corresponding to data protocol i, u i,j is the node weight corresponding to the j-th sample traffic data of data protocol i, u i,j *loss i,j is the product of the corresponding loss value and the corresponding node weight. j = 1 indicates starting the summation calculation from the i-th sample traffic data corresponding to data protocol i, and len(i) represents the total amount of sample traffic data corresponding to data protocol i up to which the above summation calculation is performed.
[0141] Furthermore, the association relationship between the above preset node weight constraint conditions and the corresponding node weights can be referred to as follows;
[0142] Σu i,j = c, u i ≥ 0;
[0143] Among them, u i,j is the node weight corresponding to the j-th sample traffic data of data protocol i, c is a specified value preset according to the actual application situation, and Σu i,j is the sum value of the node weights corresponding to all sample traffic data of data protocol i.
[0144] Overall, under the preset node weight constraint conditions, based on the preference degree corresponding to a data protocol, the corresponding node weights are adjusted for the positive impact on obtaining the corresponding predicted data category. The adjustment idea is to ensure the balance between traffic data from different data protocols and the balance between abnormal sample traffic data and normal sample traffic data corresponding to the same data protocol by making the sum of the node weights corresponding to each data protocol a constant c through the preset node weight constraint conditions. Then, a larger node weight needs to be assigned to the sample node corresponding to the sample traffic data with a larger loss value.
[0145] Exemplarily, for the node weights of each sample node of data protocol i, its adjustment process can be specifically characterized as follows:
[0146] Under the condition of satisfying Σu i,j = c, u i ≥ 0, make the preference degree corresponding to data protocol i the largest, that is: Among them, the meanings represented by the respective parameters refer to the explanations in the previous formulas and will not be repeated here.
[0147] Furthermore, in order to focus on more sample traffic data that is mispredicted, prevent the node weight of the sample node corresponding to individual sample traffic data from being too high, and also make the adjustment process of the node weight convergent, the embodiments of the present application also provide a method for adjusting the node weight, which is specifically as follows;
[0148] When Σu i,j = c, u i ≥ 0, make the preference degree corresponding to the data protocol i the largest, that is:
[0149] It should be noted that there are some differences between the preference degree corresponding to the above data protocol i and the previous description. The difference lies in that the preset α * ||u i || 2 is used to reduce the adjusted node weight, where α is a parameter threshold preset according to the actual situation, and u i is a processed value obtained based on the respective node weights corresponding to the data protocol i (such as: mean value, sum value, etc., which are not specifically limited here).
[0150] Subsequently, based on the adjusted node weights of each of the M sample nodes, the corresponding hyperedge weights are adjusted, which will not be elaborated here.
[0151] In this way, it is easy to understand that in this step 302, by performing the above iterative processing on the hypergraph data, the association relationship between the traffic data generated by different data protocols is adjusted by updating the node weights of each node and the degrees of each hyperedge; that is, by continuously mining the association relationship between each traffic data itself and between each traffic data, the attention to abnormal data categories is increased to continuously improve the accuracy of the predicted data categories of each traffic data to be detected.
[0152] Step 303: When the preset iteration termination condition is satisfied, the traffic data to be detected with the predicted data category being the abnormal data category is used as the target abnormal data.
[0153] In the embodiments of the present application, when the number of iterative rounds for the hypergraph data is greater than or equal to the preset round threshold; or the difference value between the respective node weights corresponding to the current round of iteration and the previous round of iteration is less than or equal to the preset difference threshold, the respective predicted data categories corresponding to the last round of iteration are obtained, and from the N predicted data categories corresponding to the N traffic data to be detected, the traffic data to be detected corresponding to the abnormal data category is selected as the target abnormal data.
[0154] Exemplarily, the association relationship characterized by the difference value between the respective node weights corresponding to the current round of iteration and the previous round of iteration being less than or equal to a preset difference threshold can be specifically referred to as follows;
[0155] ∑(U i -U i ′) 2 ≤0.0001;
[0156] Wherein, ∑(U i -U i ′) 2 is the difference value between the respective node weights corresponding to the current round of iteration and the previous round of iteration, U i ′ is the respective node weight corresponding to the current iteration, U i is the respective node weight corresponding to the previous round of iteration, and 0.0001 is the preset difference threshold; of course, 0.0001 here is an example value, which can be specifically preset according to actual situations, and the embodiments of the present application do not make specific limitations on this.
[0157] In summary, the embodiments of the present application use hypergraph data to realize the abstraction of sample traffic data, to-be-detected traffic data, and their connection relationships, and then perform at least one round of iterative processing on the hypergraph data. By adjusting the node weights and the degrees of hyperedges, the adjustment of the foregoing connection relationships is realized, and then the deep associations between the traffic data of different data protocols are mined to realize data anomaly detection, so as to solve the problems of unbalanced detection and unstable detection accuracy existing between the to-be-detected traffic data generated by different data protocols, improve the accuracy of data anomaly detection, ensure data security, especially in the field of cloud computing, improve the anomaly detection accuracy for cloud traffic data, thereby ensuring the data security of the cloud, and effectively avoiding the problem of leakage of cloud privacy data caused by network attacks.
[0158] Based on the above embodiments, an example involving data anomaly detection is used below to illustrate the process of detecting target anomaly data in the embodiments of the present application. Refer to Figure 9 As shown, it is a schematic diagram of the process of data anomaly detection in the embodiments of the present application, which specifically includes:
[0159] Step 901: Obtain hypergraph data.
[0160] Among them, the hypergraph data includes multiple nodes and multiple hyperedges. The specific acquisition method can refer to the description in the relevant part above and will not be repeated here.
[0161] It should be noted that the obtained hypergraph data may also include: the node weight and degree of each node, and the hyperedge weight and degree of each hyperedge. The specific acquisition method can also refer to the description in the relevant part above and will not be repeated here.
[0162] Step 902: In the i-th (i≥1) iteration process, perform multiple rounds of hypergraph learning on the hypergraph data.
[0163] Wherein, i is an integer greater than or equal to 0.
[0164] It should be noted that after obtaining the hypergraph data, the first iteration process is executed; and the result of the i-th iteration process, after being judged in step 905, then step 902 is executed, and for the hypergraph data, the (i + 1)-th iteration process is executed. For the specific iteration process and the multiple rounds of hypergraph learning process in each iteration process, reference can be made to the description in the relevant part above, and no repeated elaboration will be made here.
[0165] Step 903: Based on the node weights of each node and the degrees of each hyperedge, obtain the predicted data categories representing the traffic data of each node.
[0166] It should be noted that in one iteration process, the results of multiple rounds of hypergraph learning of the hypergraph data are obtained based on the node weights of each node and the degrees of each hyperedge, and its manifestation form can be the predicted data categories representing the traffic data of each node.
[0167] Step 904: Based on the predicted data categories corresponding to the sample nodes, adjust the node weights of the sample nodes and the degrees of the corresponding hyperedges.
[0168] It should be noted that the above adjustment process can refer to the description in the relevant part above, and no repeated elaboration will be made here.
[0169] Step 905: Determine whether the preset iteration termination condition is satisfied?
[0170] Specifically, if it is determined that the preset iteration termination condition is not satisfied, then step 902 is executed; if it is determined that the preset iteration termination condition is satisfied, then step 906 is executed.
[0171] It should be noted that the above preset iteration termination condition can refer to the description in the relevant part above, and no repeated elaboration will be made here.
[0172] Step 906: Obtain the target abnormal data among the N traffic data to be detected.
[0173] Briefly summarized, the data anomaly detection solution provided by the embodiments of the present application can be used to improve the accuracy and stability of detecting target abnormal data.
[0174] See Figure 10 As shown, based on the same inventive concept, the embodiments of the present application also provide a data anomaly detection device 1000, and the device includes:
[0175] An acquisition unit 1001, configured to acquire hypergraph data including a plurality of nodes and hyperedges of each node; wherein, the plurality of nodes include: M sample nodes representing M pieces of sample traffic data, and N to-be-inspected nodes representing N pieces of to-be-inspected traffic data, and each hyperedge represents: the connection relationship between the corresponding node and other nodes;
[0176] A processing unit 1002, configured to perform at least one round of iterative processing on the hypergraph data, wherein, in each round of iteration: at least based on the node weights of each node and the degrees of each hyperedge, respectively obtain the predicted data categories of the traffic data represented by each node; wherein, each node weight represents: the correlation between the traffic data represented by the corresponding node and the abnormal data category, and the degree of each hyperedge represents: the contribution of each node connected by the corresponding hyperedge to obtaining the corresponding predicted data category; respectively based on the difference between the predicted data category of the M pieces of sample traffic data and the corresponding true data category, adjust the node weights of the M sample nodes and the degrees of the corresponding hyperedges; when the preset iteration termination condition is satisfied, use the to-be-inspected traffic data with the predicted data category being the abnormal data category as the target abnormal data.
[0177] Optionally, the acquisition unit 1001 is specifically configured to:
[0178] Abstract the M pieces of sample traffic data and the N pieces of to-be-inspected traffic data into M sample nodes and N to-be-inspected nodes respectively, so as to obtain a plurality of nodes;
[0179] Acquire a reference node of reference traffic data representing the abnormal data category, and obtain the attribution degree of each node to the abnormal data category based on the node difference between each node and the reference node;
[0180] Based on the obtained attribution degrees, respectively perform the following operations for each node:
[0181] Based on the attribution degree difference between the attribution degree of one node and the attribution degrees of other nodes, obtain a plurality of attribution degree differences;
[0182] Select the nodes corresponding to a specified number of attribution degree differences in ascending order from the plurality of attribution degree differences as the associated nodes of the one node;
[0183] Construct the connection relationship between the one node and the corresponding associated nodes, and obtain the hyperedge of the one node.
[0184] Optionally, if the reference node is obtained in the following manner, the acquisition unit 1001 is specifically configured to:
[0185] Select at least one sample abnormal data belonging to the abnormal data category from the M sample traffic data based on the respective true data categories of the M sample traffic data;
[0186] Perform clustering processing on the sample nodes corresponding to the at least one sample abnormal data, and use the clustering center as a reference node, where the reference node represents reference traffic data belonging to the abnormal data category.
[0187] Optionally, in the first round of iteration process, if the node weights of the respective nodes are obtained in the following manner, then the obtaining unit 1001 is further configured to:
[0188] Obtain a reference node representing reference traffic data of the abnormal data category;
[0189] Based on each difference index, calculate the node difference between each node and the reference node respectively, and obtain the respective belonging degrees of each node to the abnormal data category; where one difference index represents: a calculation method of a node difference;
[0190] Based on the respective belonging degrees of each node, summarize the association relationship between the traffic data represented by the corresponding node and the abnormal data category, and obtain the node weights of each node.
[0191] Optionally, in the first round of iteration process, if the degrees of the respective hyperedges are obtained in the following manner, then the obtaining unit 1001 is further configured to:
[0192] For each hyperedge, perform the following operations respectively: sum the node weights of the nodes connected by a hyperedge to obtain the degree of the hyperedge.
[0193] Optionally, the M sample traffic data are generated corresponding to multiple data protocols; then the processing unit 1002 is specifically configured to:
[0194] Respectively obtain the loss values of the M sample nodes based on the differences between the predicted data categories and the corresponding true data categories of the M sample traffic data;
[0195] For each sample traffic data generated by each data protocol respectively, under the preset node weight constraint conditions, based on the sum of the products of the corresponding loss value and the corresponding node weight, adjust the corresponding node weight for the positive impact of obtaining the corresponding predicted data category;
[0196] Based on the adjusted node weights of each node, adjust the degrees of the corresponding hyperedges respectively.
[0197] Optionally, the processing unit 1002 is configured to, for each sample traffic data generated for each data protocol, under the preset node weight constraint condition, based on the sum of the products of the corresponding loss value and the corresponding node weight, adjust the corresponding node weight for the positive impact on obtaining the corresponding predicted data category, specifically:
[0198] For each sample traffic data generated for each data protocol, perform the following operations respectively:
[0199] For each sample traffic data generated for one data protocol, calculate the difference between the product of the loss value corresponding to each sample traffic data and the corresponding node weight and the weighted value of the square of the corresponding node weight;
[0200] Sum the obtained differences to obtain the preference degree of the one data protocol for obtaining the corresponding predicted data category;
[0201] Under the preset node weight constraint condition, based on the preference degree corresponding to the one data protocol, adjust the corresponding node weight for the positive impact on obtaining the corresponding predicted data category.
[0202] Optionally, the processing unit 1002 is configured to obtain the predicted data category of the traffic data represented by each node at least based on the node weight of each node and the degree of each hyperedge, specifically:
[0203] Perform multiple rounds of hypergraph learning on the hypergraph data at least based on the node weight of each node and the degree of each hyperedge. In one round of learning process:
[0204] Based on the node weight of each node and the degree of each hyperedge, combine the hyperedge weight of each hyperedge and the degree of each node to obtain the predicted loss value of each candidate data category predicted for the traffic data represented by each node; where each hyperedge weight represents the association relationship between the nodes connected by the corresponding hyperedge, and the degree of each node represents the contribution degree of the connection relationship on which the corresponding node depends to obtaining the corresponding predicted data category;
[0205] When the predicted loss value does not meet the preset learning termination condition, adjust the hyperedge weight of each hyperedge and the degree of each node based on the predicted loss value;
[0206] When the predicted loss value meets the preset learning termination condition, obtain the predicted data category of the traffic data represented by each node.
[0207] Optionally, in the first round of learning process, the hyperedge weights of the hyperedges are the same.
[0208] Optionally, during the first round of learning, if the degrees of the nodes are obtained in the following manner, the obtaining unit 1001 is further configured to:
[0209] For each node, perform the following operations respectively: Sum up the hyperedge weights of the hyperedges connected to a node to obtain the degree of the node.
[0210] Optionally, if the preset iteration termination condition is satisfied, including any one of the following cases, the processing unit 1002 is further configured to determine whether the preset iteration termination condition is satisfied, specifically:
[0211] The number of iteration rounds for the hypergraph data is greater than or equal to a preset round threshold;
[0212] The difference value between the node weights corresponding to the current round of iteration and the previous round of iteration is less than or equal to a preset difference threshold.
[0213] This device can be used to execute the methods shown in the embodiments of the present application. Therefore, for the functions that can be realized by each functional module of this device, reference can be made to the description of the foregoing embodiments, and details are not repeated here.
[0214] Please refer to Figure 11 As shown, based on the same inventive concept, an embodiment of the present application further provides a computer device 1100, which can be Figure 1 or Figure 2 the terminal device or server shown. The computer device 1100 may include a memory 1101 and a processor 1102.
[0215] The so-called memory 1101 is used to store the computer program executed by the processor 1102. The memory 1101 mainly includes a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function, etc.; the data storage area can store data created according to the use of the computer device, etc. The processor 1102 can be a central processing unit (CPU), or a digital processing unit, etc. In the embodiments of the present application, the specific connection medium between the above-mentioned memory 1101 and the processor 1102 is not limited. In the embodiments of the present application Figure 11 it is shown that the memory 1101 and the processor 1102 are connected through a bus 1103. The bus 1103 is shown as a thick line in Figure 11 The connection manners of other components are only for illustrative purposes and are not to be construed as limiting. The so-called bus 1103 can be divided into an address bus, a data bus, a control bus, etc. For the convenience of representation, Figure 11It is represented by only one thick line, but it does not mean that there is only one bus or one type of bus.
[0216] The memory 1101 can be a volatile memory, such as a random-access memory (RAM); the memory 1101 can also be a non-volatile memory, such as a read-only memory, a flash memory, a hard disk drive (HDD), or a solid-state drive (SSD), or the memory 1101 is any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 1101 can be a combination of the above memories.
[0217] The processor 1102 is configured to execute the methods performed by the devices in the embodiments of the present application when calling the computer programs stored in the so-called memory 1101.
[0218] In some possible implementation manners, each aspect of the method provided in the present application can also be implemented in the form of a program product, which includes program code. When the so-called program product runs on a computer device, the so-called program code is used to cause the so-called computer device to execute the steps in the methods according to various exemplary implementation manners of the present application described above in this specification. For example, the so-called computer device can execute the methods performed by the devices in the embodiments of the present application.
[0219] The so-called program product can adopt any combination of one or more readable media. The readable media can be a readable signal medium or a readable storage medium. The readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the readable storage medium include: an electrical connection having one or more wires, a portable disk, a hard disk, a random-access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0220] Although the preferred embodiments of the present application have been described, those skilled in the art can make additional changes and modifications once they learn the basic creative concepts. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications falling within the scope of the present application.
[0221] Obviously, those skilled in the art can make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalent technologies, this application is also intended to include these modifications and variations.
Claims
1. A method for detecting data anomalies, characterized in that Including: Obtaining hypergraph data including multiple nodes and hyperedges for each node; wherein, the multiple nodes include: M sample nodes representing M pieces of sample traffic data, and N to-be-inspected nodes representing N pieces of to-be-inspected traffic data, and each hyperedge represents: the connection relationship between a corresponding node and other nodes; Performing at least one round of iterative processing on the hypergraph data, wherein, in each round of iteration: Obtaining, at least based on the node weights of each node and the degrees of each hyperedge, the predicted data categories of the traffic data represented by each node; wherein, each node weight represents: the correlation relationship between the traffic data represented by the corresponding node and the abnormal data category, and the degree of each hyperedge represents: the contribution degree of each node connected by the corresponding hyperedge to obtaining the corresponding predicted data category; Adjusting the node weights of the M sample nodes and the degrees of the corresponding hyperedges respectively based on the differences between the predicted data categories of the M pieces of sample traffic data and the corresponding true data categories; When a preset iteration termination condition is satisfied, the to-be-inspected traffic data with the predicted data category being the abnormal data category is used as the target abnormal data.
2. The method according to claim 1, characterized in that, The obtaining of the hypergraph data including multiple nodes and hyperedges for each node includes: Abstracting the M pieces of sample traffic data and the N pieces of to-be-inspected traffic data into M sample nodes and N to-be-inspected nodes respectively to obtain multiple nodes; Obtaining a reference node for the reference traffic data representing the abnormal data category, and obtaining the belonging degree of each node to the abnormal data category based on the node differences between each node and the reference node; Based on the obtained belonging degrees of each node, the following operations are respectively performed for each node: Obtaining multiple belonging degree differences based on the belonging degree differences between the belonging degree of one node and the belonging degrees of other nodes; Selecting, from the multiple belonging degree differences, the nodes corresponding to a specified number of belonging degree differences in ascending order as the associated nodes of the one node; Constructing the connection relationship between the one node and the corresponding associated nodes to obtain the hyperedge of the one node.
3. The method according to claim 2, characterized in that The reference node is obtained through the following manner: Based on the true data categories of the M pieces of sample traffic data respectively, selecting at least one piece of sample abnormal data belonging to the abnormal data category from the M pieces of sample traffic data; Performing clustering processing on the sample nodes corresponding to the at least one piece of sample abnormal data, and using the clustering center as the reference node, and the reference node represents the reference traffic data belonging to the abnormal data category.
4. The method according to claim 1, wherein In the first round of iteration process, the node weights of each node are obtained through the following manner: Obtaining a reference node for the reference traffic data representing the abnormal data category; Calculating the node differences between each node and the reference node respectively based on various difference indicators to obtain the respective belonging degrees of each node to the abnormal data category; wherein, one difference indicator represents: one calculation method of node difference; Based on the respective belonging degrees of each node, generalizing the correlation relationship between the traffic data represented by the corresponding node and the abnormal data category to obtain the node weights of each node.
5. The method according to claim 1, wherein In the first-round iteration process, the degrees of the respective hyperedges are obtained in the following manner: For each hyperedge, the following operations are respectively performed: The node weights of the nodes connected by a hyperedge are summed to obtain the degree of the hyperedge.
6. The method according to any one of claims 1 to 5, characterized in that, The M sample traffic data are generated corresponding to multiple data protocols; Then, adjusting the node weights of the M sample nodes and the degrees of the corresponding hyperedges respectively based on the differences between the predicted data categories of the M sample traffic data and the corresponding true data categories includes: Respectively obtaining the loss values of the M sample nodes based on the differences between the predicted data categories of the M sample traffic data and the corresponding true data categories; For each sample traffic data generated for each data protocol, under the preset node weight constraint conditions, based on the sum of the products of the corresponding loss value and the corresponding node weight, for the positive influence on obtaining the corresponding predicted data category, adjust the corresponding node weight; Based on the adjusted node weights of each node, respectively adjust the degrees of the corresponding hyperedges.
7. The method according to claim 6, wherein The step of, for each sample traffic data generated for each data protocol, under the preset node weight constraint conditions, based on the sum of the products of the corresponding loss value and the corresponding node weight, for the positive influence on obtaining the corresponding predicted data category, adjust the corresponding node weight includes: For each sample traffic data generated for each data protocol, the following operations are respectively performed: For each sample traffic data generated for a data protocol, respectively calculate the difference between the product of the loss value corresponding to each sample traffic data and the corresponding node weight and the weighted value of the square of the corresponding node weight; Sum the obtained differences to obtain the preference degree of the data protocol for obtaining the corresponding predicted data category; Under the preset node weight constraint conditions, based on the preference degree corresponding to the data protocol, for the positive influence on obtaining the corresponding predicted data category, adjust the corresponding node weight.
8. The method according to any one of claims 1 to 5, characterized in that, The step of respectively obtaining the predicted data categories of the traffic data represented by each node based on at least the node weights of each node and the degrees of each hyperedge includes: Based on at least the node weights of each node and the degrees of each hyperedge, perform multiple rounds of hypergraph learning on the hypergraph data, where, in one round of learning process: Based on the node weights of each node and the degrees of each hyperedge, in combination with the hyperedge weights of each hyperedge and the degrees of each node, obtain the predicted loss values of each candidate data category predicted for the traffic data represented by each node; where each hyperedge weight represents the association relationship between the nodes connected by the corresponding hyperedge, and the degree of each node represents the contribution degree of the connection relationship on which the corresponding node depends to obtaining the corresponding predicted data category; When the predicted loss value does not satisfy the preset learning termination condition, based on the predicted loss value, adjust the hyperedge weights of each hyperedge and the degrees of each node; When the predicted loss value satisfies the preset learning termination condition, obtain the predicted data categories of the traffic data represented by each node.
9. The method according to claim 8, wherein In the first-round learning process, the hyperedge weights of the respective hyperedges are the same.
10. The method according to claim 8, characterized in that In the first-round learning process, the degrees of the respective nodes are obtained in the following manner: For each node, the following operations are respectively performed: The hyperedge weights of the hyperedges connected to a node are summed to obtain the degree of the said one node.
11. The method according to any one of claims 1 to 5, characterized in that, The satisfaction of the preset iteration termination condition includes any one of the following cases: The number of iteration rounds performed on the hypergraph data is greater than or equal to a preset round threshold; The difference value between the node weights corresponding to the current round of iteration and the previous round of iteration is less than or equal to a preset difference threshold.
12. A data anomaly detection device, characterized in that, It includes: An acquisition unit for acquiring hypergraph data including multiple nodes and the hyperedges of each node; wherein, the multiple nodes include: M sample nodes representing M sample traffic data, and N to-be-inspected nodes representing N to-be-inspected traffic data, and each hyperedge represents: the connection relationship between the corresponding node and other nodes; A processing unit for performing at least one round of iterative processing on the hypergraph data, wherein, in each round of iteration: at least based on the node weights of each node and the degrees of each hyperedge, the predicted data categories of the traffic data represented by each node are respectively obtained; wherein, each node weight represents: the correlation relationship between the traffic data represented by the corresponding node and the abnormal data category, and the degree of each hyperedge represents: the contribution degree of the nodes connected by the corresponding hyperedge to obtaining the corresponding predicted data category; respectively based on the difference between the predicted data categories of the M sample traffic data and the corresponding real data categories, the node weights of the M sample nodes and the degrees of the corresponding hyperedges are adjusted; when the preset iteration termination condition is satisfied, the to-be-inspected traffic data with the predicted data category being the abnormal data category is used as the target abnormal data.
13. A computer device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the computer program, the steps of the method according to any one of claims 1 to 11 are implemented.
14. A computer storage medium, on which computer program instructions are stored, wherein when the computer program instructions are executed by a processor, the steps of the method according to any one of claims 1 to 11 are implemented.
15. A computer program product, comprising computer program instructions, wherein when the computer program instructions are executed by a processor, the steps of the method according to any one of claims 1 to 11 are implemented.