Intrusion detection system and method based on machine learning

Through the edge-cloud collaboration method of dynamic feature selection, lightweight detection and incremental learning, the existing network intrusion detection system has solved the problem of large size and high latency, and low latency and efficient intrusion detection capabilities are achieved, adapting to new attacks and reducing computing overhead.

CN120342777APending Publication Date: 2025-07-18GUANGXI UNIVERSITY OF TECHNOLOGY
View PDF 0 Cites 5 Cited by

Patent Information

Application Number
CN202510777043.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-11
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The existing network intrusion detection system is too large, has high latency and insufficient protection performance, which cannot meet the needs of industrial control or other real-time scenarios, and static feature engineering is difficult to adapt to the new attack mode.

Method used

The dynamic feature selection module is used to generate feature masks through the reinforcement learning policy network, combined with the lightweight detection module and the incremental learning engine, and the deep separable convolutional structure and hybrid precision quantization are used to realize homomorphic encryption and differential privacy processing of the edge-cloud collaboration module, and the global model is updated through a robust federated aggregation algorithm.

Benefits of technology

It realizes lightweight, low latency and better protection performance intrusion detection, can adapt to new attack modes in real time and reduce computing overhead, improving the robustness and protection capabilities of the model.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342777A_ABST
    Figure CN120342777A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, in particular to an intrusion detection system and method based on machine learning, and the system comprises a dynamic feature selection module which dynamically generates a feature mask through a reinforcement learning strategy network, and selects an optimal feature subset in real time according to an action return function # imgabs0 #; the lightweight detection module adopts a depth separable convolution structure, implements mixed precision quantization and structured pruning, and takes dynamic ReLU as an activation function; the incremental learning engine is used for restraining the weight through dynamic regularization based on a Fisher information matrix on the basis of a local cache data online fine tuning model; and the edge-cloud collaboration module is used for performing homomorphic encryption and differential privacy processing on model parameter differences, and updating a global model through a robust federated aggregation algorithm. Based on lightweight edge deployment and real-time incremental learning, the calculation overhead is reduced, and the robustness is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and particularly relates to an intrusion detection system and method based on machine learning. Background Art

[0002] With the rapid development of Internet of Things (IoT), 5G network and artificial intelligence technology, the applications of edge computing and machine learning in real-time data processing and intelligent decision-making are becoming increasingly widespread. In the process of using these technologies, it is necessary to pay attention to dealing with network intrusion. The current mainstream network intrusion detection system (NIDS) usually adopts a machine learning architecture based on the cloud center. Such a system collects the whole network traffic data centrally, trains complex models (such as deep neural network, random forest, etc.) in the cloud, relies on manually defined feature engineering rules, and distributes the trained model to the edge nodes for inference, that is, adopts a static model deployment mode.

[0003] However, centralized processing in the cloud will lead to end-to-end detection delay, which cannot meet the requirements of industrial control or other real-time scenarios, and the transmission of all features will incur high bandwidth overhead. More importantly, static feature engineering is difficult to adapt to new attack patterns, and it takes a lot of time to readjust the feature extraction logic and lacks the ability of online evolution.

[0004] Therefore, there is a need for an intrusion detection system and method with light weight, low latency and better protection performance. Summary of the Invention

[0005] The main object of the present invention is to provide an intrusion detection system and method based on machine learning, aiming to solve the problems of large size, high latency and insufficient protection performance in the existing intrusion detection technology.

[0006] To achieve the above object, the present invention proposes an intrusion detection system based on machine learning, including: A dynamic feature selection module that dynamically generates a feature mask through a reinforcement learning policy network and selects the optimal feature subset in real time according to the action reward function ; A lightweight detection module that adopts a depthwise separable convolution structure and implements mixed-precision quantization and structured pruning, with dynamic ReLU as the activation function; An incremental learning engine that fine-tunes the model online based on local cached data and constrains the weights through dynamic regularization based on the Fisher information matrix; An edge-cloud collaboration module that performs homomorphic encryption and differential privacy processing on the model parameter differences and updates the global model through a robust federated aggregation algorithm.

[0007] Further, the parameters of the activation function of the dynamic ReLU are generated by the lightweight quantum network based on the statistical characteristics of the current batch of data, and the input values of the lightweight quantum network include the mean, variance, and kurtosis of the current batch of data.

[0008] Further, the structured pruning is based on channel importance scores, and the pruning ratio is dynamically adjusted according to the model inference latency.

[0009] Further, the policy network of the dynamic feature selection module adopts the Twin Delayed Deep Deterministic Policy Gradient (TD3) algorithm, and the state space is the entropy value of the current network traffic, protocol type, and packet length distribution.

[0010] The present invention also proposes a machine learning-based intrusion detection method. The machine learning-based intrusion detection method is based on the machine learning-based intrusion detection system described in any one of the above technical solutions, and includes: Real-time traffic feature extraction and dynamic selection, parsing the network traffic header and payload, extracting the original feature vector, generating a feature mask through a reinforcement learning policy network, and screening the optimal feature subset; Lightweight model inference and confidence-level classification response, inputting the features into the lightweight detection model, outputting the attack probability confidence level, and triggering alarm, blocking, or release operations according to the threshold classification; Trigger condition-driven local incremental learning, when the confidence level is lower than the threshold or a new attack pattern is detected, start the incremental learning engine, and fine-tune the model based on the local cached data; Secure encryption of model parameter aggregation and global update, encrypting the parameter differences and uploading them to the cloud, performing robust joint aggregation, and then distributing the updated global model to the edge nodes.

[0011] Further, the step of generating a feature mask through a reinforcement learning policy network and screening the optimal feature subset further includes: Inputting the original feature vector into the policy network to output the feature retention probability ; Generating a binary mask M through Gumbel-Softmax sampling.

[0012] Further, the step of performing robust joint aggregation includes: Receiving the encrypted parameter differences from the edge devices ; Calculating the Euclidean distance of the parameter differences; Excluding abnormal nodes with distances exceeding the threshold, and aggregating the remaining parameter differences.

[0013] Further, the step of performing robust joint aggregation further includes: Add noise to the parameter differences in the cloud, where the noise follows a Laplace distribution.

[0014] In the intrusion detection system based on machine learning of the present invention, network traffic is captured in real time through edge devices, and a key feature subset is selected through a dynamic feature selection module to eliminate redundant data; then, a lightweight detection module uses depthwise separable convolution and hybrid quantization technology to infer the attack probability and output a confidence-level classification response; meanwhile, during the detection process, an incremental learning engine triggers incremental learning and fine-tunes the global model based on local cached data to achieve lightweight, low-latency, and better protection performance for intrusion detection. Specific implementation manners

[0015] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0016] It should be noted that all directional indications (such as up, down, left, right, front, back...) in the embodiments of the present invention are only used to explain the relative positional relationship and movement conditions between components in a specific posture. If the specific posture changes, the directional indication will also change accordingly.

[0017] In addition, the descriptions involving "first", "second", etc. in the present invention are only for descriptive purposes, and cannot be understood as indicating or implying their relative importance or implicitly indicating the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one of such features. In addition, the technical solutions between various embodiments may be combined with each other, but it must be based on the fact that those of ordinary skill in the art can implement them. When the combination of technical solutions conflicts with each other or cannot be implemented, it should be considered that such a combination of technical solutions does not exist and is not within the protection scope required by the present invention.

[0018] It can be understood that a distributed firewall is an internal firewall, and its working principle is to directly embed security services into the network structure. Especially in each host or virtual environment, the distributed firewall has the advantage of decentralization, can implement security policies finely, and avoid the low anti-risk ability caused by guiding all traffic through a central firewall. However, the distributed firewall has the problem of difficult management caused by frequent complex multi-source information interaction.

[0019] In the prior art, feature selection relies on statistical methods (such as chi-square detection) or fixed rules, and mostly focuses on a single compression technique (usually only quantization or only pruning). It can be understood that in the present invention, a reinforcement learning policy network is introduced, and an action reward function ( ), which jointly optimizes the detection performance and feature sparsity, is different from the feature selection based on genetic algorithms in the prior art. In the present invention, a composite compression method of depthwise separable convolution, mixed-precision quantization, and structured pruning is also disclosed, and the amount of computation is significantly reduced by the dynamic ReLU parameters generated by the lightweight neural network.

[0020] Based on this, a machine learning-based intrusion detection system provided by the present invention specifically includes: A dynamic feature selection module that dynamically generates a feature mask through a reinforcement learning policy network and selects the optimal feature subset in real time according to the action reward function ; A lightweight detection module that adopts a depthwise separable convolution structure and implements mixed-precision quantization and structured pruning, with dynamic ReLU as the activation function; An incremental learning engine that fine-tunes the model online based on local cached data and constrains the weights dynamically based on the Fisher information matrix; An edge-cloud collaboration module that performs homomorphic encryption and differential privacy processing on the model parameter differences and updates the global model through a robust federated aggregation algorithm.

[0021] It can be understood that the specific technical solution of the mixed-precision quantization in the present invention is to use numerical representations with different bit widths for the model weights and activation values. The weights are stored as 8-bit integers, and the activation values are calculated as 16-bit floating-point numbers, maintaining the accuracy and being able to balance the model compression rate and inference accuracy. Structured pruning is a model compression technique that prunes redundant parameters in units of channels and / or layers instead of randomly deleting individual weights. Specifically, homomorphic encryption is an encryption algorithm that directly performs calculations on ciphertext, and differential privacy ensures that the change of a single data point will not significantly affect the algorithm output by adding noise (Laplace noise in the present invention), preventing the reverse inference of the original data through parameter differences during the federated aggregation process.

[0022] The Fisher information matrix measures the sensitivity of the model parameters to the change of the data distribution, is used to calculate the parameter importance (i.e., quantify the importance of the parameters for the old tasks in incremental learning), and guides the elastic weight constraint. The dynamic regularization (i.e., elastic weight constraint) based on the Fisher information matrix involved in the present invention needs to dynamically adjust the constraint strength in combination with the local data distribution, and is used to solve the catastrophic forgetting problem that occurs when the neural network learns tasks, avoid model drift while reducing the risk of overfitting.

[0023] Specifically, existing federated learning systems are relatively vulnerable to various errors, including some non-malicious errors (such as vulnerabilities in the preprocessing process, overly noisy training labels, or incorrect user operations), as well as some explicit attacks aimed at disrupting the system training process and deployment process. The present invention defends through the Krum algorithm (Krum aggregation), which is a robust federated aggregation method. After the server receives the parameters of all clients, it calculates the Euclidean distance between each client's model parameters and the model parameters of other clients, and then, by calculating the Euclidean distance of the parameter differences, eliminates the abnormal nodes that deviate from the population distribution, and can effectively resist data poisoning attacks.

[0024] In this embodiment, the dynamic feature selection module collects network traffic data in real time, extracts initial feature vectors, including protocol type, packet length distribution, traffic entropy value, etc., and normalizes them into a state vector s T ; The s T is input into the reinforcement learning policy network, and the feature retention probability is output ; Then is converted into a binary feature mask M to meet the sparsity constraint (K is the preset maximum number of features); The policy is dynamically adjusted according to the action reward function.

[0025] More specifically, in this embodiment, the incremental learning engine retains 1000 recently detected data (including normal and attack samples), divides the training and validation sets in a ratio of 7:3, and then calculates the parameter importance based on the Fisher information matrix to perform constrained weight update. The formula for the constrained weight update amplitude is as follows:

[0026] where L is the total loss function, L new is the loss function of the new task, is the regularization strength is the i-th parameter in the current model, is the parameter of the diagonal value of the Fisher information matrix of is the value of the i-th parameter after the old task training is completed. By adjusting the regularization strength to balance the learning weights between the old and new tasks, is usually between 0.1 and 10, when it is larger, the parameter changes are strictly restricted, and the knowledge of the old task is preferentially protected; when it is smaller, more parameter updates are allowed, focusing on adapting to the new task.

[0027] In one embodiment, the parameters of the activation function of the dynamic ReLU are generated by a lightweight quantum network based on the statistical features of the current batch of data. The input values of the lightweight quantum network include the mean, variance, and kurtosis of the current batch of data.

[0028] In this embodiment, ReLU in Dynamic ReLU refers to the rectified linear unit and is a commonly used unit in deep neural networks. Dynamic ReLU refers to ReLU determined dynamically according to the input. The activation function refers to the non-linear transformation function in the neural network and is the core component of the neural network, determining the non-linear ability of the model. In the present invention, the parameters α and β of the dynamic ReLU involved are dynamically adjusted with the input data. Among them, the parameter α is the slope parameter, controlling the strength of the linear transformation in the negative interval, and β is the intercept parameter, used to adjust the translation amount in the negative interval.

[0029] The specific expression is:

[0030] where, ;

[0031] Specifically, is the mean of the current batch of data, is the variance of the current batch of data, is the kurtosis of the current batch of data, , are the fully connected layer mapping functions of the lightweight quantum network. The dynamic ReLU can automatically adjust the shape of the activation function according to the traffic characteristics, enhance the model's expressive ability when detecting new attacks, and can effectively enhance the accuracy and reduce the computational overhead compared with the prior art.

[0032] In one embodiment, the structured pruning is based on the channel importance score, and the pruning ratio is dynamically adjusted according to the model inference latency.

[0033] In this embodiment, the channel importance score on which the structured pruning is based is as follows:

[0034] where, is the importance score of the c-th channel, is the weight parameter of the -th channel, and N is the total number of weights in the channel. The larger the absolute value of the weight, the more important the channel is in feature extraction.

[0035] In the present invention, the pruning ratio is dynamically adjusted according to the real-time inference latency , and the specific formula is as follows:

[0036] Among them, is the basic pruning ratio, is the target inference latency, is the proportionality coefficient, which can automatically increase the pruning ratio to achieve acceleration when device resources are scarce.

[0037] Specifically, the steps of the pruning process involved in the present invention include: S10. Score and sort the importance of all channels, calculate the S c of all channels, and sort them in ascending order; S20. Determine the dynamic threshold and retain the first channels, where C is the total number of channels; S30. Model reconstruction, remove the low-scoring channels, and re-stitch the remaining channels; S40. Fine-tuning recovery, fine-tune the model for 1 to 3 epochs on the validation set to recover the accuracy loss.

[0038] In one embodiment, the policy network of the dynamic feature selection module adopts the Twin Delayed Deep Deterministic Policy Gradient (TD3) algorithm, and the state space is the entropy value of the current network traffic, the protocol type, and the packet length distribution.

[0039] In this embodiment, the Twin Delayed Deep Deterministic Policy Gradient (TD3) algorithm improves the stability of action decision-making through a dual Critic network, delayed policy update, and target policy smoothing.

[0040] The present invention also proposes a machine learning-based intrusion detection method. The machine learning-based intrusion detection method is based on the machine learning-based intrusion detection system of any one of the above technical solutions, and includes the following steps: S1. Real-time traffic feature extraction and dynamic selection, parse the network traffic header and payload, extract the original feature vector, generate a feature mask through the reinforcement learning policy network, and screen the optimal feature subset; S2. Lightweight model inference and confidence-level classification response, input the features into the lightweight detection model, output the attack probability confidence, and trigger alarm, block, or release operations according to the threshold classification; S3. Trigger condition-driven local incremental learning, when the confidence is lower than the threshold or a new attack pattern is detected, start the incremental learning engine and fine-tune the model based on the local cached data; S4. Secure encryption of model parameter aggregation and global update, encrypt the parameter differences and upload them to the cloud, perform robust joint aggregation, and then download the updated global model to the edge nodes.

[0041] In this embodiment, the hierarchical response of the confidence level is divided into three levels: alarm, block, and release. The thresholds corresponding to the three levels are , , , respectively. Among them, is the alarm threshold, is the block threshold, is the release threshold; When the attack probability P ≥ , the connection is immediately blocked and an alarm is issued; When the attack probability > P ≥ , the log is recorded and the bandwidth is restricted; When the attack probability > P, the traffic is released.

[0042] In one embodiment, the steps of generating a feature mask through a reinforcement learning policy network and screening the optimal feature subset further include: Input the original feature vector into the policy network to output the feature retention probability ; Generate a binary mask M through Gumbel-Softmax sampling.

[0043] Specifically, Gumbel-Softmax sampling is a differentiable discrete distribution sampling method that allows optimizing discrete actions through gradient descent in reinforcement learning, satisfying (K is the maximum number of features), where the specific formula for the sampling probability is:

[0044] Among them, is the Gumbel noise, is the temperature coefficient.

[0045] In one embodiment, the steps of performing robust joint aggregation include: Receive the encrypted parameter difference from the edge device; Calculate the Euclidean distance of the parameter difference; Exclude the abnormal nodes whose distance exceeds the threshold and aggregate the remaining parameter differences.

[0046] In this embodiment, the Paillier homomorphic encryption algorithm is used to encrypt the encrypted parameter difference of the edge device, and then the Krum algorithm is executed in the cloud to calculate the Euclidean distance of all parameter differences, exclude the abnormal nodes whose distance from the median exceeds the threshold , and aggregate the remaining parameters. The specific formula is as follows:

[0047] In one embodiment, the steps of performing robust joint aggregation further include: Adding noise to the parameter differences in the cloud, where the noise follows a Laplace distribution.

[0048] Specifically, the noise follows a Laplace distribution , where specifically:

[0049] is the sensitivity, is the privacy budget; In anomaly node exclusion, it is necessary to calculate the median of the Euclidean distances of the parameter differences . If node i satisfies (j is other nodes), then it is determined as an anomaly and excluded. In this embodiment, the Laplace noise scale b = 0.01, .

[0050] It should be understood that the various parts disclosed in the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in a suitable manner in any one or more embodiments or examples.

[0051] The above is only the specific implementation manner of the present invention, but the protection scope of this application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed in this application, and all should be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

[0052] Combining all the above embodiments, the present invention provides an intrusion detection system and method based on machine learning. The present invention captures network traffic in real time through edge devices, filters out key feature subsets through a dynamic feature selection module, and eliminates redundant data; then, through a lightweight detection module, depthwise separable convolution and hybrid quantization technology are used to perform attack probability inference and output a confidence level classification response (block / alert / response); at the same time, during the detection process, an incremental learning engine triggers incremental learning based on local cached data, dynamically adjusts the global model through elastic weight constraints, prevents catastrophic forgetting, and uploads the encrypted parameter differences to the cloud to perform anti-interference federated aggregation and update the global model. The present invention realizes lightweight, low-latency, and better protection performance intrusion detection.

[0053] The above are only the preferred embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. Any equivalent structural transformation made by using the specification of the present invention under the inventive concept of the present invention, or direct / indirect application in other related technical fields, is included in the patent protection scope of the present invention.

Claims

1. An intrusion detection system based on machine learning, characterized in that, Including: The dynamic feature selection module dynamically generates a feature mask through a reinforcement learning policy network and selects the optimal feature subset in real time according to the action reward function ; A lightweight detection module, which adopts a depthwise separable convolution structure, implements mixed-precision quantization and structured pruning, and uses dynamic ReLU as the activation function; An incremental learning engine, which fine-tunes the model online based on local cached data and constrains the weights through dynamic regularization based on the Fisher information matrix; An edge-cloud collaboration module, which performs homomorphic encryption and differential privacy processing on the model parameter differences and updates the global model through a robust federated aggregation algorithm.

2. The machine learning-based intrusion detection system according to claim 1, characterized in that, The parameters of the activation function of the dynamic ReLU are generated by the lightweight quantum network based on the statistical characteristics of the current batch of data. The input values of the lightweight quantum network include the mean, variance, and kurtosis of the current batch of data.

3. The machine learning-based intrusion detection system according to claim 1, wherein The structured pruning is based on channel importance scoring, and the pruning ratio is dynamically adjusted according to the model inference latency.

4. The machine learning-based intrusion detection system according to claim 1, wherein The policy network of the dynamic feature selection module adopts the Twin Delayed Deep Deterministic Policy Gradient (TD3) algorithm, and the state space is the entropy value of the current network traffic, the protocol type, and the packet length distribution.

5. An intrusion detection method based on machine learning, characterized in that, The machine learning-based intrusion detection method is based on the machine learning-based intrusion detection system described in any one of claims 1-4, and includes: Real-time traffic feature extraction and dynamic selection, parsing the network traffic header and payload, extracting the original feature vector, generating a feature mask through a reinforcement learning policy network, and screening the optimal feature subset; Lightweight model inference and confidence-level classification response, inputting the features into the lightweight detection model, outputting the attack probability confidence level, and triggering alarm, blocking, or releasing operations according to the threshold classification; Trigger condition-driven local incremental learning, when the confidence level is lower than the threshold or a new attack pattern is detected, start the incremental learning engine and fine-tune the model based on local cached data; Secure encryption of model parameter aggregation and global update, encrypting the parameter differences and uploading them to the cloud, and after performing robust joint aggregation, sending the updated global model to the edge nodes.

6. The machine learning-based intrusion detection system according to claim 5, wherein The step of generating a feature mask through a reinforcement learning policy network and screening the optimal feature subset further includes: Input the original feature vector into the policy network to output the feature retention probability ; Generating a binary mask M through Gumbel-Softmax sampling.

7. The machine learning-based intrusion detection system according to claim 6, wherein, The step of performing robust joint aggregation includes: Receive the encrypted parameter differences from the edge device ; Calculating the Euclidean distance of the parameter differences; Excluding abnormal nodes whose distance exceeds the threshold and aggregating the remaining parameter differences.

8. The machine learning-based intrusion detection system according to claim 7, characterized in that, The step of performing robust joint aggregation further includes: Adding noise to the parameter differences in the cloud, and the noise follows a Laplace distribution.

Citation Information

Cited By

  • Distributed data collaboration method and device based on federal control

    CN121396643A

  • A distributed data collaboration method and device based on federal control

    CN121396643B

  • Lightweight model edge deployment optimization method based on incremental learning

    CN121660113A

  • Real-time intrusion intelligent detection method and system for distributed network environment

    CN122160192A

  • Big language model access security method based on federated learning and privacy calculation

    CN122204449A