Propagation source positioning method and device

By constructing the fusion feature matrix and diffusion process of propagation cascade snapshots, using Gaussian noise to capture fine-grained features, directly inferring the propagation source from the observed data, solving the problem of insufficient adaptability and accuracy of existing methods in real scenarios, and achieving efficient propagation source positioning.

CN120342782AActive Publication Date: 2025-07-18NORTHWESTERN POLYTECHNICAL UNIV
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510789421.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-13
Publication Date
2025-07-18
Estimated Expiration
2045-06-13

AI Technical Summary

Technical Problem

Existing source positioning methods are difficult to adapt to real scenarios and cannot effectively capture propagation patterns. Relying on a large amount of data leads to insufficient generalization capabilities and poor prediction performance.

Method used

By obtaining the observation time-step infection status from the propagation cascade snapshot, a fusion feature matrix is constructed, combining the forward and reverse diffusion processes, the fine-grained features are accurately captured using non-zero mean Gaussian noise to directly infer the propagation source from the observed data.

Benefits of technology

It realizes the accuracy of dissemination source positioning and cross-scenario applicability without explicit source tag historical data, reduces deployment costs, and helps social media content governance and network security prevention and control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342782A_ABST
    Figure CN120342782A_ABST
Patent Text Reader

Abstract

The invention discloses a propagation source positioning method and device, relates to the technical field of network space security information traceability, and is used for solving the problems that an existing source positioning method cannot effectively capture a propagation mode and depends on a large amount of data in a source derivation process due to the fact that the existing source positioning method is difficult to adapt to a real scene. The generalization ability is insufficient; and the optimal prediction performance cannot be achieved. Comprising the following steps: according to a forward infection state and a fusion feature matrix, starting reverse iteration from the maximum time step until the time step is zero, sequentially determining a reverse infection state of each reverse iteration time step until an initial infection state is obtained, and obtaining a reverse infection state of each reverse iteration time step from vectors which are included in the initial infection state and are equal to the total number of nodes, and selecting the node with the maximum probability value as a predicted propagation source.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of cyber - space security information traceability, and more particularly to a method and device for locating a propagation source. Background Art

[0002] In recent years, with the rapid development of Internet technology and the wide popularity of devices such as mobile phones and computers, according to the "Facts and Figures 2024" annual report released by the International Telecommunication Union in 2024, it is estimated that by the end of 2024, the number of global Internet users will reach 5.5 billion. In today's information age, the information interaction mode of human society has increasingly shifted to virtual networks. Social media has become the core carrier for the public to obtain information and participate in public issues. However, various harmful information and security risks often spread rapidly through social media with rapid fission, bringing harm to user property, social stability, etc. In this context, timely and effectively locating the propagation source is of great significance for maintaining property security and social stability.

[0003] Currently, snapshot - based source - location methods have received extensive attention due to their ease of processing. In methods based on Bayesian theory, the location problem can be transformed into maximum a posteriori estimation or maximum likelihood estimation. Among them, the maximum a posteriori estimation branch focuses on inferring the most likely source based on observed data, while the maximum likelihood estimation method reconstructs the observed propagation scenario by selecting a specific source. Since the maximum likelihood estimation method involves high - complexity methods such as computationally intensive Monte Carlo simulations, current research mainly focuses on the MPE method, including centrality methods and deep - learning - based methods. However, many existing source - location methods rely heavily on the assumptions of specific propagation models, which limits their effectiveness and transfer ability in other propagation scenarios. Although some works do not rely on the underlying propagation dynamics for source location, many of these methods still fail to effectively capture the propagation pattern during source inference and lack sufficient consideration of the fine - grained characteristics of the propagation process, resulting in the model not achieving optimal prediction performance.

[0004] The performance of existing source - location methods highly depends on the preset propagation model assumptions and is only effective under specific models. It is difficult to adapt to the diverse propagation dynamics in real - world scenarios, resulting in insufficient generalization ability of the model. Moreover, during source inference, the propagation pattern cannot be effectively captured, and there is a lack of sufficient consideration of the fine - grained characteristics of the propagation process, leading to the model not achieving optimal prediction performance. At the same time, existing source - location methods rely on a large amount of historical data containing explicit source labels for training, resulting in failure in data - scarce scenarios and a significant decline in model performance. Summary of the Invention

[0005] An embodiment of the present invention provides a method and device for locating a propagation source, which are used to solve the problems that existing source location methods are difficult to adapt to real scenarios, cannot effectively capture propagation patterns in source inference, and have insufficient generalization ability and low prediction performance due to relying on a large amount of data.

[0006] An embodiment of the present invention provides a method for locating a propagation source, including:

[0007] Obtain the infection status of all nodes at the observation time step from the propagation cascade snapshot. According to the number of infected nodes and the total number of nodes in the infection status at the observation time step, combined with the maximum time step, judge the stage at which the current infection progress is in the entire diffusion process and the corresponding observation time step; according to the single-step attenuation coefficient, obtain the cumulative intensity for controlling noise in the diffusion process within the forward diffusion time step; determine the forward infection status of all nodes at the forward diffusion time step according to the cumulative intensity and the infection status of all nodes at the observation time step;

[0008] Concatenate the node attributes of each node included in the propagation cascade snapshot and the infection status at the observation time step to obtain a fusion feature matrix corresponding to the propagation cascade snapshot, where the fusion feature matrix is composed of fusion features obtained by each node;

[0009] According to the forward infection status and the fusion feature matrix, perform reverse iteration from the maximum time step to time step zero, and sequentially determine the reverse estimated infection status at each reverse iteration time step until the initial infection status is obtained;

[0010] Select the node with the largest probability value from the vector equal to the total number of nodes included in the initial infection status as the predicted propagation source.

[0011] An embodiment of the present invention provides a device for locating a propagation source, including:

[0012] A first determination unit, configured to obtain the infection status of all nodes at the observation time step from the propagation cascade snapshot. According to the number of infected nodes and the total number of nodes in the infection status at the observation time step, combined with the maximum time step, judge the stage at which the current infection progress is in the entire diffusion process and the corresponding observation time step; according to the single-step attenuation coefficient, obtain the cumulative intensity for controlling noise in the diffusion process within the forward diffusion time step; determine the forward infection status of all nodes at the forward diffusion time step according to the cumulative intensity and the infection status of all nodes at the observation time step;

[0013] A fusion unit, configured to splice the node attributes of each node included in the propagation cascade snapshot and the infection status at the observed time step, to obtain a fusion feature matrix corresponding to the propagation cascade snapshot, where the fusion feature matrix is composed of fusion features obtained by each node;

[0014] A second determination unit, configured to, according to the forward infection status and the fusion feature matrix, perform reverse iteration from the maximum time step to time step zero, and sequentially determine the reverse estimated infection status at each reverse iteration time step until the initial infection status is obtained;

[0015] A selection unit, configured to select, from the vectors included in the initial infection status that are equal in number to the total number of nodes, the node with the largest probability value as the predicted propagation source.

[0016] An embodiment of the present invention provides a computer device, where the computer device includes a memory and a processor, the memory stores a computer program, and when the computer program is executed by the processor, the processor is caused to execute the propagation source location method described in any one of the above.

[0017] An embodiment of the present invention provides a computer-readable storage medium, storing a computer program, and when the computer program is executed by a processor, the processor is caused to execute the propagation source location method described in any one of the above.

[0018] An embodiment of the present invention provides a propagation source location method and apparatus. The method is based on a diffusion framework of learnable propagation dynamics, breaking through the limitations of traditional methods that rely on assumptions of specific fixed propagation models. By flexibly adapting to various propagation dynamics characteristics, the applicability of the model is significantly extended, and the cross-scenario migration ability is enhanced; the forward diffusion process is redefined, and by introducing non-zero mean Gaussian noise, it converges to a full infection state consistent with the real propagation dynamics; this redefinition enables the model to derive unbiased noise that can encode the microscopic states of different propagation mechanisms, thereby accurately capturing the fine-grained features crucial for source location and improving the accuracy of source location; based on the unbiased noise learned in the forward diffusion process, the propagation source is accurately traced through an interpretable closed-form reverse diffusion process. It realizes the direct inference of the propagation source from the observed data without relying on historical data containing explicit source labels; the expected benefits and commercial value after the transformation of this method are: using the present invention to perform the propagation source location task under cyberspace security can quickly locate the propagation source of rumors or network viruses, contribute to the governance of social media content and the prevention and control of network public security, and reduce social and economic losses; at the same time, the general framework of the present invention reduces the multi-scenario deployment cost and does not require a large amount of historical data containing source labels, significantly saving time and economic investment, providing an important guarantee for the rapid deployment and practical application of the propagation source location technology, and having broad application prospects and commercial value. Brief Description of the Drawings

[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0020] Figure 1 Schematic flowchart of a propagation source localization method provided by an embodiment of the present invention;

[0021] Figure 2 Schematic structural diagram of a propagation source localization device provided by an embodiment of the present invention. Detailed Embodiments

[0022] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0023] Step 101: Obtain the infection status of all nodes at the observation time step from the propagation cascade snapshot. According to the number of infected nodes and the total number of nodes in the infection status at the observation time step, combined with the maximum time step, determine the stage of the current infection progress in the entire diffusion process and the corresponding observation time step; according to the single-step attenuation coefficient, obtain the cumulative intensity of noise control in the diffusion process within the forward diffusion time step; determine the forward infection status of all nodes at the forward diffusion time step according to the cumulative intensity and the infection status of all nodes at the observation time step;

[0024] Step 102: Concatenate the node attributes of each node included in the propagation cascade snapshot and the infection status at the observation time step to obtain a fusion feature matrix corresponding to the propagation cascade snapshot, where the fusion feature matrix is composed of fusion features obtained for each node;

[0025] Step 103: According to the forward infection status and the fusion feature matrix, perform reverse iteration from the maximum time step to time step zero, and sequentially determine the reverse estimated infection status at each reverse iteration time step until the initial infection status is obtained;

[0026] Step 104: Select the node with the largest probability value from the vector equal to the total number of nodes included in the initial infection status as the predicted propagation source.

[0027] It should be noted that in the embodiments of the present invention, the execution subject is a propagation data processing system.

[0028] Here, the data processing system can be understood as a computing framework or software platform that realizes functions such as restoring the infection status from the propagation cascade snapshot. For example, it can be a system built based on a deep learning framework (such as PyTorch or TensorFlow), which includes a series of functional modules such as model loading, data processing, forward propagation, and result output. It can also be a more specific application system, such as a system for infectious disease propagation simulation and analysis, which takes the noise predicted by the pre-trained denoising model and the propagation cascade snapshot as inputs to realize functions such as the analysis and prediction of the infectious disease propagation process.

[0029] In the propagation source location method provided by the embodiments of the present invention, selecting the propagation cascade snapshot from the dataset and the noise predicted by the pre-trained denoising model are the key pre-steps for the entire technical implementation.

[0030] Before step 101, it is necessary to first select a propagation cascade snapshot from the dataset and obtain the pre-training data (including real social network data collection and model propagation data generation); specifically, collect data from real social network platforms (such as Weibo, Twitter, etc.). Using web crawler technology, according to the rules allowed by the platform, obtain the propagation data of a specific topic or event within a certain time step. These data include node (user account) information, such as determining user ID (Identity), basic information, etc. as node attributes; edge (relationship between users) information, such as follow, forward, and comment relationships; and various infection statuses of users at different time steps (observed time step infection status, forward infection status, reverse estimated infection status, initial infection status). Determine whether to spread specific information according to various infection statuses. If it spreads, mark it as 1, and if it does not spread, mark it as 0.

[0031] Taking the dataset Twitter15 as an example, the Twitter15 dataset contains 1490 propagation cascades, 580593 relationship edges, 480987 user nodes and their node attributes. The node attributes include 7-dimensional features such as user description, blue label authentication status, and geographical location. In practical applications, a certain propagation cascade snapshot can be taken as an input. Suppose a certain observed time step of the propagation cascade .

[0032] Among them, the propagation cascade is , and its detailed content includes: represents the node set. For example, 5000 nodes can be represented as ; Represents the edge set. For example, 10,000 relationship edges can be represented as ; Represents the infection status at the observation time step. When the number of infected nodes is 1250, it can be represented as ; Represents the node attributes. The node attributes can include 7-dimensional features such as user description, blue label authentication status, geographical location, etc.

[0033] The pre-training of the denoising model includes model construction and initialization, determination of the loss function, and the training process. In practical applications, common pre-trained denoising models include the Denoising Auto–Encoder (DAE), Variational Auto–Encoder (VAE), etc. Taking DAE as an example, it consists of an encoder and a decoder. The encoder maps the input data to the latent space, and the decoder then reconstructs the original data from the latent space. The noise predicted by the pre-trained denoising model is the weight matrices, bias vectors, etc. learned during the training process. For example, in a simple fully-connected neural network structure DAE, there will be a weight matrix from the input layer to the hidden layer , a weight matrix from the hidden layer to the output layer , and the corresponding bias vectors , , etc. These are all the noises predicted by the pre-trained denoising model.

[0034] Furthermore, the propagation cascade snapshots selected from the dataset and the noise predicted by the pre-trained denoising model are input into the propagation data processing system.

[0035] In the embodiments of the present invention, the noise predicted by the pre-trained denoising model contains the knowledge and features learned by the denoising model during the previous training process. These parameters enable the propagation data processing system to have the ability to denoise and analyze the propagation cascade snapshots. Without these parameters, the denoising model in the propagation data processing system cannot function and cannot effectively process the input propagation cascade snapshots; the noise predicted by the pre-trained denoising model input into the propagation data processing system allows the propagation data processing system to operate in the manner of the trained model when processing new propagation cascade snapshots, avoiding unstable or inaccurate results caused by differences in model parameters.

[0036] In step 101, first, obtain the infection status at the observation time step of all nodes from the propagation cascade snapshots. According to the number of infected nodes, the total number of nodes, and the maximum time step in the infection status at the observation time step of all nodes, determine the observation time step through formula (1) , where the current infection progress stage in the entire diffusion process can be determined according to the observation time step.

[0037] (1)

[0038] Wherein, represents the observation time step, represents the maximum time step, represents the total number of nodes, represents the number of infected nodes in the current state.

[0039] Exemplarily, when the number of infected nodes in the above embodiment is 1250, then , If , then the observation time step . This value indicates that the infection progress at the observation time step corresponds to the first 25% stage of the diffusion process.

[0040] Secondly, according to the forward diffusion time step the determined forward attenuation coefficient , the forward diffusion time step to the observation time step is obtained through formula (2) to control the cumulative intensity of noise diffusion, which is determined by the following formula:

[0041] (2)

[0042] Wherein, represents the cumulative intensity from the forward diffusion time step to the observation time step , that is, the product of multiple single-step attenuation coefficients from the forward diffusion time step to the observation time step , representing the cumulative intensity of controlling noise in the diffusion process, represents the single-step attenuation coefficient of the forward diffusion time step .

[0043] In practical applications, the single-step attenuation coefficient corresponding to each time step may be different. In practical applications, the initial single-step attenuation coefficient ( ) is preset through experiments. For example, it is selected according to the cosine scheduling strategy , and the change of noise is simulated through the multiplication operation to ensure that the diffusion process gradually approaches the fully infected state. In the embodiments of the present invention, the fully infected state means that the infection state of all nodes is 1.

[0044] Exemplarily, in the above embodiment , , taking as an example, there is the single-step attenuation coefficient corresponding to the 1000th time step, ; similarly, the single-step attenuation coefficient corresponding to the 999th time step, ; the single-step attenuation coefficient corresponding to the 250th time step, . .

[0045] Furthermore, according to the cumulative intensity and the observed time step infection status of all nodes within the observed time step through formula (3), the forward infection status of all nodes at the forward diffusion time step can be determined:

[0046] (3)

[0047] where represents the forward infection status of all nodes at the forward diffusion time step , represents standard Gaussian noise, , represents the identity matrix with the same dimension as the number of nodes, represents the all-one vector, which is used to guide the forward diffusion process to converge to the fully infected state. When the forward diffusion time step is equal to the maximum time step, i.e., , the current fully infected state is obtained, that is, the fully infected state of all nodes at the forward diffusion time step , which means that all nodes are infected at the forward diffusion time step . represents the observed time step infection status of all nodes at the observed time step .

[0048] It should be noted that when calculating the forward infection status of all nodes at the forward diffusion time step , each node is taken as an object, and the forward infection status of each node is calculated separately, and then the forward infection statuses of all nodes are concatenated to obtain the forward infection status of all nodes at the forward diffusion time step.

[0049] Exemplarily, let the observed time step infection status of node A at the observed time step be . If it is forward diffused to , assuming , then: ; ; . Therefore, the forward infection status of node A at the forward diffusion time step is: .

[0050] It should be noted that in the above formula (3), represents retaining the observed infection status information, which decays with the cumulative intensity decay, represents guiding the state to converge towards full infection to ensure that the diffusion process ultimately covers all nodes. represents introducing Gaussian noise , , simulating the uncertainty in the propagation process and enhancing the robustness of the model.

[0051] In the embodiments of the present invention, in order for the denoising model to obtain more comprehensive and effective information for more accurate processing and analysis of the propagation cascade, it is necessary to construct fused features.

[0052] In step 102, the node attribute set is concatenated with the observed infection status row of the observation time step to form a fused feature matrix as shown below:

[0053] (4)

[0054] Where, represents the fused feature matrix, represents the set of attribute features of each node, represents the observation time step under which the observed infection status of all nodes is obtained by concatenating the set of multi-dimensional attribute features of each node with the observed infection status of all nodes (concatenating the attribute features of each node with the observed infection status by dimension), and the fused feature matrix of all nodes can be obtained, represents concatenation.

[0055] Exemplarily, for node A, if the set of attribute features it includes is 3, that is, node A includes 3-dimensional attribute features, assumed to be [1, 1, 1], and the observed infection status of node A at the observation time step , after concatenating the set of multi-dimensional attribute features of node A with the observed infection status, the single-node fused feature can be obtained: .

[0056] And so on, performing such operations on all the remaining nodes to obtain the single-node fused features of each node, and then combining the single-node fused features of all nodes, the fused feature matrix of all nodes can be obtained , , where the dimension of the fused feature matrix , and the fused feature matrix contains the 3-dimensional attribute information and 1-dimensional observed infection status information of each node, and 5000 represents the number of nodes. This fused feature matrix Will be used as the input parameters of the denoising model for subsequent calculation and analysis processes.

[0057] In practical applications, the initial infection state at the initial time step is crucial for locating the source of transmission because the initial infection state can reflect which nodes were initially infected at the start of the transmission process, i.e., the source nodes of transmission. Since noise is introduced during the forward diffusion process (forward diffusion time step ), it is necessary to gradually remove the noise through reverse iteration (reverse iteration time step ) to restore the true state.

[0058] In step 103, according to the forward infection states of all nodes at the forward diffusion time step , the fusion feature matrix , starting from the maximum time step, reverse iterate to the minimum time step (time step is zero), and sequentially determine the reverse estimated infection state at each reverse iteration time step until the initial infection state at time step zero is obtained.

[0059] Specifically, in each reverse iteration process, the variance of reverse diffusion, the optimal estimated mean of the previous state, and the reverse estimated infection state corresponding to each reverse iteration time step are sequentially determined through the following formulas, that is, the reverse estimated infection state at each reverse iteration time step:

[0060] (5)

[0061] (6)

[0062] (7)

[0063] Among them, represents the single-step attenuation coefficient of the reverse iteration time step (the physical meaning of the reverse attenuation coefficient is the same as that of the forward attenuation coefficient, only the representation of the same parameter in different stages), represents a preset parameter, , represents the variance of reverse diffusion; represents the optimal estimated mean of the previous state, represents the noise predicted by the denoising model, represents the learnable parameters of the denoising model, represents the reverse estimated infection state of the reverse iteration time step , represents the reverse iteration time step, represents the node set, represents the edge set, represents the fusion feature matrix, represents the all - one vector, which is used to guide the reverse iteration process to converge to the fully infected state. When the reverse iteration time step is equal to the minimum time step, that is , the reverse iteration time step for the infection status of all nodes can also be referred to as the initial infection status; represents the reverse - estimated infection status at the reverse iteration time step . When , represents being sampled from the standard normal distribution, , represents the identity matrix, with the dimension the same as the number of nodes; when , .

[0064] Specifically, starting from the maximum time step and performing reverse iteration until the time step is equal to zero. At each reverse iteration time step , the variance of reverse diffusion, the optimal estimated mean of the previous state, and the reverse - estimated infection status are determined successively through the following formulas.

[0065] Exemplarily, for the first iteration, from iterating to , specifically, ; to avoid division by zero, assume , , .

[0066] Determine the variance of reverse diffusion according to formula (5): .

[0067] Taking node A as an example, determine the optimal estimated mean of the previous state: Assume , then there is ; finally, according to formula (7), when , being sampled from the standard normal distribution , obtain the reverse - estimated infection status of node A at .

[0068] For the second iteration, iterating to , specifically, ; , .

[0069] Determine the variance of reverse diffusion according to formula (5): .

[0070] Using the result of the previous step, , it can be calculated . According to formula (7), we get the reverse estimated infection status of node A at .

[0071] Repeat the above iterative process until it iterates to , and obtain the initial infection status of all nodes , whose dimension is 5000*1, and each element represents the initial infection status of the corresponding node.

[0072] In step 104, according to the following formula, output the node with the highest probability in the initial infection status, and determine this node as the predicted source of propagation.

[0073] (8)

[0074] Among them, represents the initial infection status of node at the initial time step . In the embodiment of the present invention, the initial infection status, the infection status at the observation time step, the forward infection status, and the reverse estimated infection status of each node can all be represented by probabilities. Therefore, here can also be called the infection probability of node at the initial time step . The larger the infection probability value, the greater the probability of infection. represents the predicted source of propagation node, that is, the node with the highest infection probability. represents each node. .

[0075] Embodiment 1

[0076] Suppose in a small-scale social network, there are 5 nodes, respectively labeled as A . This network simulates a rumor propagation scenario. The following details the embodiment of source of propagation location based on the above method.

[0077] Step 201, environment and data preparation. The social network includes 5 nodes, and select W propagation cascade snapshots from the small-scale social network of 5 nodes .

[0078] In the propagation cascade snapshot , represents the node set. Here there are 5 nodes in total, that is , . represents the edge set. Here there are 5 nodes in total, so there are 8 relational edges corresponding. The edge represents the node information propagation path. The 8 relational edges here can be . Represents the set of node attributes. For example, each node contains 3 attributes (i.e., ), such as node activity (high / medium / low, encoded as [1, 0.5, 0]), authentication status (1 / 0), and geographical label (local / foreign, encoded as [1, 0]). Represents the observation time step The infection status of all nodes at the observation time step. At the observation time step If the infection status of two nodes at the observation time step is in the infected state (assuming A and C), then there is , ; Since the remaining nodes are not infected, so there is , , .

[0079] Through preliminary training, the noise predicted by the optimized denoising model is obtained.

[0080] Step 202. Input the selected propagation cascade snapshot in the dataset and the noise predicted by the pre-trained denoising model into the propagation data processing system;

[0081] Specifically, first calculate the observation time step according to formula (1). Assume the maximum time step . Because (node C and node A are infected), so according to the formula .

[0082] Determine the cumulative intensity from the forward diffusion time step to the observation time step . Taking as an example, first determine the single-step attenuation coefficient of the forward diffusion time step , , , , and then determine the cumulative intensity according to formula (3).

[0083] Furthermore, obtain the forward infection status of all nodes at the forward diffusion time step according to formula (3). Taking node A as an example, assume the noise component , then: ; ; . Therefore, the forward infection status of node A at the forward diffusion time step : .

[0084] Similarly, calculate the forward infection status of each node one by one according to the above method, and finally obtain 。

[0085] Step 203: Concatenate the node attribute set with the observed time-step infection status of all nodes at the observed time step to form a fused feature.

[0086] Taking node A as an example, when the attribute feature set of node A is 3, if the observed time-step infection status of node A is , then the fused feature of node A obtained is . At this time, has a dimension of 5 * 4 (5 nodes, each node has 3-dimensional attributes + 1-dimensional observed time-step infection status). Further, according to the above method, the fused features of the other 4 nodes are obtained in sequence, and the fused features of all nodes are combined to obtain the fused feature matrix of all nodes , , whose dimension is .

[0087] Step 204: Reverse diffusion denoising. In each reverse iteration process, calculate the variance of the reverse diffusion and the optimal estimated mean of the previous state according to formulas (5) and (6) respectively, and then determine the reverse estimated infection status of each node at each reverse iteration time step according to formula (7).

[0088] For the first iteration, from to , assuming ; , , . Then the variance of the reverse diffusion: .

[0089] The optimal estimated mean of the previous state (taking node A as an example), assuming , . According to formula (7), we can get: .

[0090] For the second iteration, from to ; assuming ; , , . Then the variance: ; use to calculate , and update the state .

[0091] Repeat the above iteration method until iterating to , and finally obtain the initial infection status vector

[0092] Step 205, output the predicted propagation source. After obtaining the initial infection status of all nodes , it is necessary to determine the predicted propagation source from the initial infection status . At this time, the is a vector with a length of (in this embodiment , that is, it contains nodes A, B, C, D, and E). Each element in the vector represents the probability that the corresponding node is infected at the initial moment.

[0093] The meaning of formula (8) is to find, among all nodes belonging to the set V , the node that makes (that is, the probability value at the corresponding position of node in the vector) the largest. This node is the predicted propagation source.

[0094] Assume that after iterating to , the initial infection status of all nodes obtained is ; compare these 5 probability values according to formula (8): Specifically, the probability value corresponding to node A is 0.6; the probability value corresponding to node B is 0.2; the probability value corresponding to node C is 0.7; the probability value corresponding to node D is 0.1; the probability value corresponding to node E is 0.1.

[0095] Obviously, 0.7 is the largest among these 5 probability values, and the corresponding node is C. Therefore, according to the above formula and comparison results, node C is determined as the predicted propagation source.

[0096] In summary, the embodiments of the present invention provide a method for locating a propagation source. Based on a diffusion framework of learnable propagation dynamics, this method breaks through the limitations of traditional methods that rely on assumptions of specific fixed propagation models. By flexibly adapting to various propagation dynamics characteristics, it significantly expands the applicability of the model and enhances the cross-scenario migration ability. It redefines the forward diffusion process. By introducing non-zero mean Gaussian noise, it converges to a fully infected state consistent with the true propagation dynamics. This redefinition enables the model to derive unbiased noise that can encode the microscopic states of different propagation mechanisms, thereby accurately capturing the fine-grained features crucial for source location and improving the accuracy of source location. Based on the unbiased noise learned in the forward diffusion process, the propagation source is accurately traced through an interpretable closed-form reverse diffusion process. It realizes the direct inference of the propagation source from the observed data without relying on historical data containing explicit source labels. The expected benefits and commercial values after the transformation of this method are as follows: Using the present invention to perform the task of locating the propagation source under cyberspace security can quickly locate the sources of rumors or network viruses, assist in the governance of social media content and the prevention and control of network public security, and reduce social and economic losses. At the same time, the general framework of the present invention reduces the multi-scenario deployment cost and does not require a large amount of historical data containing source labels, significantly saving time and economic investment, providing an important guarantee for the rapid deployment and practical application of source location technology, and having broad application prospects and commercial values.

[0097] Based on the same inventive concept, the embodiments of the present invention provide a device for locating a propagation source. Since the principle of this device for solving technical problems is similar to that of a method for locating a propagation source, the implementation of this device can refer to the implementation of the method, and the repeated parts will not be elaborated.

[0098] As Figure 2 shown, the device includes a first determination unit 201, a fusion unit 202, a second determination unit 203, and a selection unit 204.

[0099] The first determination unit 201 is configured to obtain the observed time step infection states of all nodes at the observed time step from the propagation cascade snapshot, and based on the number of already infected nodes and the total number of nodes in the observed time step infection state, in combination with the maximum time step, determine the stage at which the current infection progress is in the entire diffusion process and the corresponding observed time step; obtain the cumulative intensity for controlling the noise in the diffusion process within the forward diffusion time step according to the single-step attenuation coefficient; and determine the forward infection states of all nodes at the forward diffusion time step based on the cumulative intensity and the observed time step infection states of all nodes at the observed time step.

[0100] A fusion unit 202 is configured to splice the node attributes of each node included in the propagation cascade snapshot and the infection status at the observed time step to obtain a fusion feature matrix corresponding to the propagation cascade snapshot, where the fusion feature matrix is composed of the fusion features obtained for each node;

[0101] A second determination unit 203 is configured to, according to the forward infection status and the fusion feature matrix, perform reverse iteration from the maximum time step to a time step of zero, and sequentially determine the reverse estimated infection status at each reverse iteration time step until the initial infection status is obtained;

[0102] A selection unit 204 is configured to select, from the vectors included in the initial infection status that are equal in number to the total number of nodes, the node with the largest probability value as the predicted propagation source.

[0103] It should be understood that the units included in the above propagation source localization device are only logically divided according to the functions implemented by the device. In actual applications, the above units can be superimposed or split. Moreover, the functions implemented by the propagation source localization device provided in this embodiment correspond one by one to the propagation source localization method provided in the above embodiment. For the more detailed processing flow implemented by the device, it has been described in detail in the first method embodiment above and will not be described in detail here.

[0104] Another embodiment of the present invention further provides a computer device, which includes: a processor and a scenario database; the scenario database is used to store computer program code, and the computer program code includes computer instructions; when the processor executes the computer instructions, the electronic device executes each step of the propagation source localization method shown in the above method embodiment.

[0105] Another embodiment of the present invention further provides a computer-readable storage medium, in which computer instructions are stored. When the computer instructions run on a computer device, the computer device is caused to execute each step of the propagation source localization method shown in the above method embodiment.

[0106] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these changes and modifications.

Claims

1. A method for locating a propagation source, characterized in that, Including: Obtain the infection status of all nodes at the observation time step from the propagation cascade snapshot. According to the number of infected nodes and the total number of nodes in the infection status at the observation time step, combined with the maximum time step, determine the stage of the current infection progress in the entire diffusion process and the corresponding observation time step; According to the single-step attenuation coefficient, obtain the cumulative intensity used to control noise in the diffusion process within the forward diffusion time step; Determine the forward infection status of all nodes at the forward diffusion time step according to the cumulative intensity and the infection status of all nodes at the observation time step; Concatenate the node attributes of each node included in the propagation cascade snapshot and the infection status at the observation time step to obtain the fusion feature matrix corresponding to the propagation cascade snapshot, where the fusion feature matrix is composed of the fusion features obtained for each node; According to the forward infection status and the fusion feature matrix, perform reverse iteration from the maximum time step to time step zero, and sequentially determine the reverse estimated infection status at each reverse iteration time step until the initial infection status is obtained; From the vector equal to the total number of nodes included in the initial infection status, select the node with the largest probability value as the predicted propagation source.

2. The method according to claim 1, wherein Before obtaining the infection status of all nodes at the observation time step from the propagation cascade snapshot, it further includes: Receiving the propagation cascade snapshot selected from the dataset and the noise predicted by the pre-trained denoising model.

3. The method according to claim 1, wherein The observation time step is determined by the following formula: The cumulative intensity used to control noise in the diffusion process within the forward diffusion time step is determined by the following formula: The forward infection status is determined by the following formula: Among them, represents the observation time step, represents the maximum time step, represents the total number of nodes, represents the number of infected nodes in the current state, represents the single-step attenuation coefficient of the forward diffusion time step ; represents the forward diffusion time step to the cumulative intensity of the observation time step ; represents the forward infection state of all nodes at the forward diffusion time step ; represents the observation time step of the observation time step infection state of all nodes, represents the standard Gaussian noise, represents the all-one vector.

4. The method according to claim 1, wherein Performing reverse iteration from the maximum time step to time step zero, and sequentially determining the reverse estimated infection status at each reverse iteration time step specifically includes: Within each reverse iteration period, determine the variance of reverse diffusion, the optimal estimated mean of the previous state, and the reverse estimated infection status at each reverse iteration time step through the following formula: Among them, represents the single-step decay coefficient of the reverse iteration time step, which represents a preset parameter, , represents the variance of the reverse diffusion, represents the optimal estimated mean of the previous state, represents the noise predicted by the denoising model, represents the learnable parameters of the denoising model, represents the reverse iteration time step of the reverse estimated infection state, represents the reverse iteration time step, represents the set of nodes, represents the set of edges, represents the fusion feature matrix, represents the all-one vector, represents the reverse iteration time step of the reverse estimated infection state, represents being sampled from the standard normal distribution.

5. The method according to claim 1, wherein The fusion feature matrix is as follows: Among them, represents the set of attribute features of each node, represents the observation time step the infection status of all nodes at the observation time step, represents the fusion feature matrix, represents concatenation.

6. The method according to claim 1, wherein The predicted propagation source is determined by the following formula: Among them, represents the node at the initial time step with the initial infection status, represents the predicted source of transmission, represents each node, , represents taking the maximum value.

7. A propagation source location device, characterized in that Including: The first determination unit is used to obtain the infection status of all nodes at the observation time step from the propagation cascade snapshot. According to the number of infected nodes and the total number of nodes in the infection status at the observation time step, combined with the maximum time step, determine the stage of the current infection progress in the entire diffusion process and the corresponding observation time step; According to the single-step attenuation coefficient, obtain the cumulative intensity used to control noise in the diffusion process within the forward diffusion time step; Determine the forward infection status of all nodes at the forward diffusion time step according to the cumulative intensity and the infection status of all nodes at the observation time step; The fusion unit is used to concatenate the node attributes of each node included in the propagation cascade snapshot and the infection status at the observation time step to obtain the fusion feature matrix corresponding to the propagation cascade snapshot, where the fusion feature matrix is composed of the fusion features obtained for each node; A second determination unit, configured to, according to the forward infection state and the fusion feature matrix, perform reverse iteration from the maximum time step to time step zero, and sequentially determine the reverse estimated infection states at each reverse iteration time step until the initial infection state is obtained; A selection unit, configured to select, from the vectors equal in number to the total number of nodes included in the initial infection state, the node with the largest probability value as the predicted source of propagation.

8. A computer device, characterized in that, The computer device includes a memory and a processor. When a computer program stored in the memory is executed by the processor, the processor is caused to execute the propagation source location method according to any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, A computer program is stored. When the computer program is executed by a processor, the processor is caused to execute the propagation source location method according to any one of claims 1-6.

Citation Information

Patent Citations

  • Network risk source tracing method based on back propagation

    CN105915399A

  • Online social network information source detection method based on reinforcement learning

    CN110362754A

  • Network information tracing method and device and medium

    CN116488847A

  • Propagation source positioning method based on encoder and decoder framework

    CN117034134A

  • Marine organism-oriented sound extraction enhancement method, system, equipment and medium

    CN120089150A