A method and device for locating a transmission source

Through the learning dissemination framework and reverse diffusion process, the existing source positioning methods are solved in real scenario adaptability and data dependence, and high-accuracy dissemination source positioning is achieved, reducing costs and applied to cyberspace security.

CN120342782BActive Publication Date: 2025-08-26NORTHWESTERN POLYTECHNICAL UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510789421.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-13
Publication Date
2025-08-26
Estimated Expiration
2045-06-13

AI Technical Summary

Technical Problem

Existing source positioning methods are difficult to adapt to real scenarios, lack fine-grained feature capture of propagation patterns, and relying on a large amount of data leads to insufficient generalization capabilities and poor prediction performance.

Method used

Using a diffusion framework based on learnable propagation dynamics, non-zero mean Gaussian noise is introduced through the forward diffusion process, combining the fusion feature matrix and the reverse diffusion process to directly infer the propagation source from the observed data without the need for historical data of explicit source labels.

Benefits of technology

It improves the accuracy of source positioning, enhances the applicability and migration capabilities of the model, reduces deployment costs, and can quickly locate the source of rumors or online virus transmission, helps social media content governance and network security prevention and control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342782B_ABST
    Figure CN120342782B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and device for locating a transmission source, relating to the technical field of cyberspace security information tracing technology. The method is used to address the problems of existing source location methods, such as their difficulty adapting to real-world scenarios, their inability to effectively capture transmission patterns during source derivation, and their reliance on large amounts of data, which leads to insufficient generalization and an inability to achieve optimal prediction performance. The method comprises: based on a forward infection state and a fused feature matrix, reversely iterating from the maximum time step to time step zero, sequentially determining the reverse infection state for each reverse iterative time step until an initial infection state is obtained; and selecting the node with the largest probability value as the predicted transmission source from a vector equal to the total number of nodes included in the initial infection state.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of cyberspace security information tracing technology, and more specifically to a method and device for locating a transmission source. Background Art

[0002] In recent years, internet technology has developed rapidly, and devices such as mobile phones and computers have become widely available. According to the International Telecommunication Union's 2024 Facts and Figures annual report, the number of global internet users is expected to reach 5.5 billion by the end of 2024. In today's information age, human interaction is increasingly shifting to virtual networks. Social media has become a core vehicle for the public to access information and participate in public debates. However, various types of harmful information and security risks often spread rapidly through the rapid fission and spread of social media, posing risks to users' property and social stability. In this context, timely and effective locating the source of transmission is crucial for maintaining property safety and social stability.

[0003] Currently, snapshot-based source localization methods have attracted widespread attention due to their tractability. In Bayesian-based methods, the localization problem can be transformed into maximum a posteriori estimation or maximum likelihood estimation. Among them, the maximum a posteriori estimation branch focuses on inferring the most likely source based on the observed data, while the maximum likelihood estimation method reconstructs the observed propagation scenario by selecting specific sources. Since the maximum likelihood estimation method involves high-complexity methods such as computationally intensive Monte Carlo simulations, current research mainly focuses on MPE methods, including centrality methods and deep learning-based methods. However, many existing source localization methods heavily rely on the assumption of specific propagation models, which limits their effectiveness and transferability in other propagation scenarios. Although some work does not rely on the underlying propagation dynamics for source localization, many of these methods still fail to effectively capture the propagation pattern during source inference and lack sufficient consideration of the fine-grained characteristics of the propagation process, resulting in the model being unable to achieve optimal prediction performance.

[0004] The performance of existing source localization methods is highly dependent on the preset propagation model assumptions and is only effective under specific models. It is difficult to adapt to the diverse propagation dynamics in real scenarios, resulting in insufficient model generalization ability. Furthermore, the propagation pattern cannot be effectively captured during source inference, and the fine-grained characteristics of the propagation process are not fully considered, resulting in the model being unable to achieve optimal prediction performance. At the same time, existing source localization methods rely on a large amount of historical data containing explicit source labels for training, which leads to failure in data-scarce scenarios and a significant decline in model performance. Summary of the Invention

[0005] Embodiments of the present invention provide a propagation source localization method and device, which are used to solve the problems that existing source localization methods are difficult to adapt to real scenarios, cannot effectively capture propagation patterns in source inference, and rely on large amounts of data, resulting in insufficient generalization ability and poor prediction performance.

[0006] An embodiment of the present invention provides a method for locating a propagation source, including:

[0007] Obtaining the infection status of all nodes at the observation time step from the propagation cascade snapshot; judging the stage of the current infection progress in the entire diffusion process and the observation time step corresponding to the stage based on the number of infected nodes and the total number of nodes in the infection status of the observation time step, in combination with the maximum time step; obtaining the cumulative intensity of the forward diffusion time step used to control the noise in the diffusion process based on the single-step attenuation coefficient; and determining the forward infection status of all nodes at the forward diffusion time step based on the cumulative intensity and the infection status of all nodes at the observation time step;

[0008] splicing the node attributes of each node included in the propagation cascade snapshot and the infection state of the observation time step to obtain a fusion feature matrix corresponding to the propagation cascade snapshot, wherein the fusion feature matrix is ​​composed of fusion features obtained from each node;

[0009] According to the forward infection state and the fusion feature matrix, reverse iterate from the maximum time step to time step zero, and determine the reverse estimated infection state of each reverse iterative time step in sequence until an initial infection state is obtained;

[0010] From the vectors included in the initial infection state and equal to the total number of nodes, a node with the largest probability value is selected as the predicted transmission source.

[0011] An embodiment of the present invention provides a propagation source positioning device, comprising:

[0012] A first determination unit is configured to obtain the infection status of all nodes in the observation time step from the propagation cascade snapshot, determine the stage of the current infection progress in the entire diffusion process and the observation time step corresponding to the stage based on the number of infected nodes and the total number of nodes in the infection status of the observation time step, combined with the maximum time step; obtain the cumulative intensity of the forward diffusion time step used to control the noise in the diffusion process based on the single-step attenuation coefficient; and determine the forward infection state of all nodes in the forward diffusion time step based on the cumulative intensity and the infection status of all nodes in the observation time step;

[0013] a fusion unit, configured to concatenate the node attributes of each node included in the propagation cascade snapshot and the infection state of the observation time step to obtain a fusion feature matrix corresponding to the propagation cascade snapshot, wherein the fusion feature matrix is ​​composed of fusion features obtained from each node;

[0014] a second determining unit, configured to reversely iterate from the maximum time step to time step zero according to the forward infection state and the fusion feature matrix, and sequentially determine the reverse estimated infection state of each reverse iterative time step until an initial infection state is obtained;

[0015] A selection unit is configured to select a node with the largest probability value as a predicted transmission source from the vectors equal to the total number of nodes included in the initial infection state.

[0016] An embodiment of the present invention provides a computer device, which includes a memory and a processor, wherein the memory stores a computer program, and when the computer program is executed by the processor, the processor executes any one of the above-mentioned propagation source positioning methods.

[0017] An embodiment of the present invention provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the processor executes any one of the above-mentioned propagation source positioning methods.

[0018] An embodiment of the present invention provides a method and device for locating a transmission source. The method is based on a diffusion framework of learnable transmission dynamics, breaks through the limitations of traditional methods that rely on the assumption of a specific fixed transmission model, and significantly expands the applicability of the model and enhances the cross-scenario migration capability through flexible adaptation to various transmission dynamics characteristics. The forward diffusion process is redefined by introducing non-zero mean Gaussian noise to converge to a fully infected state consistent with the actual transmission dynamics. This redefinition enables the model to derive unbiased noise, which can encode the microscopic state of different transmission mechanisms, thereby accurately capturing the fine-grained features that are critical to source positioning and improving the accuracy of source positioning. Based on the unbiased noise learned in the forward diffusion process, the transmission source is accurately traced through an interpretable closed reverse diffusion process. It realizes the direct inference of the transmission source from the observation data without relying on historical data containing explicit source labels; the expected benefits and commercial value of this method after transformation are: using the present invention to perform the task of locating the transmission source under cyberspace security, it is possible to quickly locate the source of rumor or network virus transmission, assist in social media content governance and network public safety prevention and control, and reduce social and economic losses; at the same time, the general framework of the present invention reduces the deployment cost of multiple scenarios, and does not require a large amount of historical data containing source labels, which significantly saves time and economic investment, provides important guarantees for the rapid deployment and practical application of transmission source positioning technology, and has broad application prospects and commercial value. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0020] Figure 1 A schematic flow chart of a method for locating a transmission source provided by an embodiment of the present invention;

[0021] Figure 2 A schematic structural diagram of a propagation source locating device provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0022] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0023] Step 101: Obtain the infection status of all nodes in the observation time step from the propagation cascade snapshot. Based on the number of infected nodes and the total number of nodes in the infection status of the observation time step, combined with the maximum time step, determine the stage of the current infection progress in the entire diffusion process and the observation time step corresponding to the stage; obtain the cumulative intensity of the forward diffusion time step used to control the noise in the diffusion process based on the single-step attenuation coefficient; determine the forward infection status of all nodes in the forward diffusion time step based on the cumulative intensity and the infection status of all nodes in the observation time step;

[0024] Step 102: Concatenate the node attributes of each node included in the propagation cascade snapshot and the infection state of the observation time step to obtain a fusion feature matrix corresponding to the propagation cascade snapshot, wherein the fusion feature matrix is ​​composed of fusion features obtained from each node;

[0025] Step 103, based on the forward infection state and the fusion feature matrix, reversely iterate from the maximum time step to time step zero, and determine the reverse estimated infection state of each reverse iterative time step in sequence until the initial infection state is obtained;

[0026] Step 104 : Select a node with the largest probability value as the predicted transmission source from the vectors equal to the total number of nodes included in the initial infection state.

[0027] It should be noted that the embodiment of the present invention mentions that the execution subject is a propagation data processing system.

[0028] The data processing system here can be understood as a computing framework or software platform that implements functions such as recovering the infection state from transmission cascade snapshots. For example, it could be a system built on a deep learning framework such as PyTorch or TensorFlow, encompassing a series of functional modules such as model loading, data processing, forward propagation, and result output. Alternatively, it could be a more specific application system, such as one used for infectious disease transmission simulation and analysis, which uses the noise predicted by a previously trained denoising model and transmission cascade snapshots as input to analyze and predict the infectious disease's spread.

[0029] In the propagation source localization method provided by the embodiment of the present invention, the propagation cascade snapshots selected from the data set and the noise predicted by the pre-trained denoising model are key prerequisites for the implementation of the entire technology.

[0030] Before step 101, it is necessary to select a propagation cascade snapshot from the dataset and obtain preliminary training data (including real social network data collection and model propagation data generation). Specifically, data is collected from real social network platforms (such as Weibo and Twitter). Using web crawler technology, according to the platform's permitted rules, propagation data for a specific topic or event within a time step is obtained. This data includes node (user account) information, such as user ID (Identity) and basic information as node attributes; edge (user relationship) information, such as follow, forward, and comment relationships; and various user infection states at different time steps (observation time step infection state, forward infection state, backward estimated infection state, and initial infection state). Based on these infection states, the spread of a specific information is determined: if it spreads, it is marked as 1; if it does not spread, it is marked as 0.

[0031] Take the Twitter15 dataset as an example. The Twitter15 dataset contains 1490 communication cascades, 580593 relationship edges, 480987 user nodes and their node attributes. The node attributes include 7-dimensional features such as user description, blue label authentication status, and geographic location. In practical applications, we can take a snapshot of a communication cascade as input. Assuming that a certain observation time step is obtained, The propagation cascade .

[0032] The propagation cascade is , the details of which include: Represents a node set, for example, 5000 nodes can be represented as ; Represents an edge set. For example, 10,000 relationship edges can be represented as ; Indicates the infection state at the observation time step. When the number of infected nodes is 1250, it can be expressed as ; Represents node attributes, which can include seven-dimensional features such as user description, blue label authentication status, and geographic location.

[0033] The pre-training of the denoising model includes model construction and initialization, determination of the loss function and the training process. In practical applications, common pre-trained denoising models include denoising auto-encoders (DAE) and variational auto-encoders (VAE). Taking DAE as an example, it consists of an encoder and a decoder. The encoder maps the input data to the latent space, and the decoder reconstructs the original data from the latent space. The noise predicted by the pre-trained denoising model is the weight matrix, bias vector, etc. of the encoder and decoder learned during the training process. For example, in a DAE with a simple fully connected neural network structure, there will be a weight matrix from the input layer to the hidden layer. , the weight matrix from the hidden layer to the output layer , and the corresponding bias vector 、 etc. These are the noises predicted by the pre-trained denoising model.

[0034] Furthermore, the propagation cascade snapshots selected from the dataset and the noise predicted by the pre-trained denoising model are input into the propagation data processing system.

[0035] In an embodiment of the present invention, the noise predicted by the pre-trained denoising model includes the knowledge and features learned by the denoising model during the previous training process. These parameters enable the propagation data processing system to perform denoising processing and analysis on the propagation cascade snapshot. Without these parameters, the denoising model in the propagation data processing system will not be able to function and will not be able to effectively process the input propagation cascade snapshot. The noise predicted by the pre-trained denoising model is input into the propagation data processing system, which allows the propagation data processing system to operate in accordance with the trained model when processing new propagation cascade snapshots, avoiding unstable or inaccurate results due to differences in model parameters.

[0036] In step 101, first, the infection status of all nodes in the observation time step is obtained from the propagation cascade snapshot. According to the number of infected nodes, the total number of nodes and the maximum time step in the infection status of all nodes in the observation time step, the observation time step is determined by formula (1). , where the stage of the current infection progress in the entire diffusion process can be determined according to the observation time step.

[0037] (1)

[0038] in, represents the observation time step, represents the maximum time step, Indicates the total number of nodes, Indicates the number of infected nodes in the current state.

[0039] For example, in the above embodiment, when the number of infected nodes is 1250, , ,like , then observe the time step This value indicates that the infection progress at the observed time step corresponds to the first 25% of the spreading process.

[0040] Secondly, according to the forward diffusion time step Determined forward attenuation coefficient , the forward diffusion time step is obtained by formula (2) To the observation time step Used to control the diffuse cumulative intensity of noise, which is determined by the following formula:

[0041] (2)

[0042] in, represents the forward diffusion time step To the observation time step The cumulative intensity of the forward diffusion time step To the observation time step Multiple single-step attenuation coefficients included The continuous product of represents the cumulative intensity of the control noise in the diffusion process, represents the forward diffusion time step The single-step attenuation coefficient.

[0043] In practical applications, the single-step attenuation coefficient corresponding to each time step may be different. In practical applications, the initial single-step attenuation coefficient ( ) is preset through experiments, such as selecting according to the cosine scheduling strategy , and simulate the change of noise by multiplying operations to ensure that the diffusion process gradually approaches the full infection state. In this embodiment of the present invention, the full infection state means that the infection state of all nodes is 1.

[0044] For example, in the above embodiment , ,by For example, there is a single-step attenuation coefficient corresponding to the 1000th time step, ; Similarly, the single-step attenuation coefficient corresponding to the 999th time step is ; Single-step attenuation coefficient corresponding to the 250th time step, . .

[0045] Furthermore, according to the cumulative intensity and the infection status of all nodes in the observation time step, the forward infection status of all nodes in the forward diffusion time step can be determined by formula (3):

[0046] (3)

[0047] in, represents the forward diffusion time step The positive infection status of all nodes under represents standard Gaussian noise, , represents the identity matrix, with the same dimension as the number of nodes, Represents an all-one vector, which is used to guide the forward diffusion process to converge to the fully infected state. When the forward diffusion time step is equal to the maximum time step, that is, When , the current full infection status is obtained , that is, the forward diffusion time step The full infection state of all nodes, that is, the forward diffusion time step All nodes are infected. represents the observation time step The infection status of all nodes at the observed time step.

[0048] It should be noted that the forward diffusion time step is calculated here. When calculating the forward infection state of all nodes under the forward diffusion time step, each node is taken as the object, and the forward infection state of each node is calculated separately. Then, the forward infection states of all nodes are spliced ​​together to obtain the forward infection state of all nodes under the forward diffusion time step.

[0049] For example, let node A be observed at time step The infection state at the observation time step is , if the forward diffusion to When, assuming ,but: ; ; Therefore, the forward diffusion time step is The positive infection state of the next node A is: .

[0050] It should be noted that in the above formula (3), Indicates that the observed infection status information is retained and the cumulative intensity attenuation, It indicates that the guiding state converges towards full infection, ensuring that the diffusion process eventually covers all nodes. Indicates the introduction of Gaussian noise , , simulate the uncertainty in the propagation process and enhance the robustness of the model.

[0051] In the embodiment of the present invention, in order to enable the denoising model to obtain more comprehensive and effective information so as to more accurately process and analyze the propagation cascade, it is necessary to construct a fusion feature.

[0052] In step 102, the node attribute set is concatenated with the infection status row of the observation time step to form a fusion feature matrix as shown below:

[0053] (4)

[0054] in, represents the fusion feature matrix, Represents the attribute feature set of each node, represents the observation time step The observed time step infection state of all nodes is obtained by splicing the multidimensional attribute feature set of each node with the observed time step infection state of all nodes (splicing the attribute features of each node with the observed time step infection state by dimension). The fusion feature matrix of all nodes can be obtained. Indicates splicing.

[0055] For example, for node A, if the attribute feature set it includes is 3, that is, node A includes 3-dimensional attribute features, assuming it is [1,1,1], the infection state of node A at the observation time step is After splicing the multi-dimensional attribute feature set of node A with the infection state of the observed time step, the single node fusion feature can be obtained : .

[0056] Similarly, perform this operation on all remaining nodes to obtain the single node fusion feature of each node, and then combine the single node fusion features of all nodes to obtain the fusion feature matrix of all nodes. , , where the dimension of the fusion feature matrix is , fusion feature matrix Contains 3D attribute information of each node and 1D infection status information of the observation time step, 5000 represents the number of nodes. This fusion feature matrix It will be used as the input parameter of the denoising model for subsequent calculation and analysis.

[0057] In practical applications, the initial time step The initial infection state at the time is crucial for locating the source of transmission, because the initial infection state can reflect which nodes are initially infected at the beginning of the transmission process, that is, the source nodes. ) introduces noise, which requires reverse iteration (reverse iteration time step ) gradually removes the noise and restores the true state.

[0058] In step 103, according to the forward infection state of all nodes in the forward diffusion time step , fusion feature matrix , starting from the maximum time step and iterating backward to the minimum time step (time step is zero), determine the reverse estimated infection state of each reverse iterative time step in turn until the initial infection state when time step is zero is obtained.

[0059] Specifically, in each reverse iteration process, the variance of the reverse diffusion, the optimal estimated mean of the previous state, and the reverse estimated infection state corresponding to each reverse iteration time step are determined in turn by the following formulas, that is, the reverse estimated infection state of each reverse iteration time step:

[0060] (5)

[0061] (6)

[0062] (7)

[0063] in, Represents the reverse iteration time step The single-step attenuation coefficient (the reverse attenuation coefficient has the same physical meaning as the forward attenuation coefficient, which is only the representation of the same parameter at different stages), Indicates the preset parameters, , represents the variance of the reverse diffusion; represents the optimal estimated mean of the previous state, represents the noise predicted by the denoising model, represents the learnable parameters of the denoising model, Indicates the reverse iteration time step The inverse estimate of the infection state, represents the reverse iteration time step, Represents a collection of nodes, represents the edge set, represents the fusion feature matrix, Represents an all-one vector, which is used to guide the reverse iteration process to converge to the fully infected state. When the reverse iteration time step is equal to the minimum time step, that is, When the reverse iteration time step The infection status of all nodes It can also be called the initial infection state; Represents the reverse iteration time step The reverse estimation of infection status, when hour, represents sampling from a standard normal distribution, , Represents the identity matrix, with the same dimension as the number of nodes; when hour, .

[0064] Specifically, from the maximum time step Start the reverse iteration until the time step is equal to zero, and at each reverse iteration time step The variance of reverse diffusion, the optimal estimated mean of the previous state and the reverse estimated infection state are determined in turn by the following formulas.

[0065] For example, in the first iteration, Iterate to , specifically, ; To avoid division by zero, assume , , .

[0066] The variance of the reverse diffusion is determined according to formula (5): .

[0067] Taking node A as an example, determine the optimal estimated mean of the previous state: Assume , then ; Finally, according to formula (7), when hour, Sampled from a standard normal distribution ,get The reverse estimated infection state of node A at time .

[0068] The second iteration, Iterate to ,specifically, ; , .

[0069] The variance of the reverse diffusion is determined according to formula (5): .

[0070] Using the results from the previous step, , we can calculate According to formula (7), we can get The reverse estimated infection state of node A at time .

[0071] Repeat the above iterative process until the iteration reaches , get the initial infection state of all nodes , its dimension is 5000*1, and each element represents the initial infection state of the corresponding node.

[0072] In step 104, a node with the highest probability in the initial infection state is output according to the following formula, and the node is determined as the predicted transmission source.

[0073] (8)

[0074] in, Representation node At the initial time step In the embodiment of the present invention, the initial infection state, observation time step infection state, forward infection state, and reverse estimated infection state of each node can all be expressed in terms of probability, so here Also called a node At the initial time step The infection probability at this time, the larger the infection probability value, the greater the probability of infection, represents the predicted source node, that is, the node with the highest probability of infection, Represents each node, .

[0075] Example 1

[0076] Assume that in a small social network, there are 5 nodes, marked as A and The network simulates a rumor spreading scenario, and the following describes in detail an embodiment of locating the source of the rumor based on the above method.

[0077] Step 201: Environment and data preparation. The social network includes 5 nodes. W propagation cascade snapshots are selected from the 5-node small-scale social network. .

[0078] Propagating cascading snapshots middle, Represents a node set, there are 5 nodes here, namely , . Represents an edge set. There are 5 nodes in total, so there are 8 corresponding relationship edges. The edge represents the node information propagation path. The 8 relationship edges here can be . Represents a set of node attributes. For example, each node contains three attributes (i.e. ), such as node activity (high / medium / low, coded as [1,0.5,0]), whether it is authenticated (1 / 0), and regional label (local / foreign, coded as [1,0]). represents the observation time step The infection status of all nodes at the observation time step is Under this condition, if the infection status of two nodes in the observation time step is in the infected state (assuming AC), then , ; Since the rest of the nodes are not infected, there are , , .

[0079] Through preliminary training, the noise predicted by the optimized denoising model is obtained.

[0080] Step 202: Input the selected propagation cascade snapshot in the data set and the noise predicted by the pre-trained denoising model into the propagation data processing system;

[0081] Specifically, first calculate the observation time step according to formula (1): , assuming the maximum time step ,because, (Node C, node A is infected), so according to the formula .

[0082] According to formula (2), the forward diffusion time step is determined To the observation time step The cumulative intensity ,by For example, first determine the forward diffusion time step The single-step attenuation coefficient, , , , and then determine the cumulative intensity according to formula (3) .

[0083] Furthermore, according to formula (3), the forward diffusion time step is obtained The forward infection state of all nodes under the condition, taking node A as an example, assuming that the noise component ,but: ; ; Therefore, the forward diffusion time step is The positive infection status of node A: .

[0084] Similarly, the forward infection state of each node is calculated one by one according to the above method, and finally the .

[0085] Step 203: Concatenate the node attribute set with the infection status of all nodes in the observation time step to form a fusion feature.

[0086] Taking node A as an example, when the attribute feature set of node A When it is 3, if the infection state of node A in the observation time step is , then the obtained node A fusion feature is ,at this time The dimension is 5*4 (5 nodes, each node contains 3-dimensional attributes + 1-dimensional observation time step infection state). Furthermore, according to the above method, the fusion features of the other 4 nodes are obtained in turn, and the fusion features of all nodes are combined to obtain the fusion feature matrix of all nodes. , , whose dimensions are .

[0087] Step 204, reverse diffusion denoising. In each reverse iteration process, the variance of the reverse diffusion and the optimal estimated mean of the previous state are calculated according to formulas (5) and (6), and then the reverse estimated infection state of each node in each reverse iteration time step is determined according to formula (7).

[0088] The first iteration, from ,arrive , assuming ; , , . Then the variance of the reverse diffusion is: .

[0089] The optimal estimated mean of the previous state (taking node A as an example), assuming , According to formula (7), we can get: .

[0090] The second iteration, from arrive ; Assumption ; , , . Then the variance is: ;use calculate , and update the status .

[0091] Repeat the above iterative method until the iteration reaches , and finally get the initial infection state vector

[0092] Step 205: Output the predicted transmission source, and obtain the initial infection state of all nodes After that, you need to go from the initial infection state The predicted source of transmission is determined in is a length of (In this embodiment , that is, a vector containing nodes A, B, C, D, E), each element in the vector represents the probability of the corresponding node being infected at the initial moment.

[0093] The meaning of formula (8) is that among all nodes belonging to the set V In, find (i.e. node exist The node with the largest probability value for the corresponding position in the vector , this node It is the predicted source of transmission.

[0094] Assume that the iteration The initial infection state of all nodes is obtained as ; Compare these five probability values ​​according to formula (8): Specifically, the probability value corresponding to node A is 0.6; the probability value corresponding to node B is 0.2; the probability value corresponding to node C is 0.7; the probability value corresponding to node D is 0.1; and the probability value corresponding to node E is 0.1.

[0095] Obviously, 0.7 is the maximum value among these five probability values, and its corresponding node is C. Therefore, according to the above formula and comparison results, node C is determined as the predicted propagation source.

[0096] In summary, an embodiment of the present invention provides a method for locating a transmission source. This method is based on a diffusion framework of learnable transmission dynamics, breaks through the limitations of traditional methods that rely on the assumption of a specific fixed transmission model, and significantly expands the applicability of the model and enhances the cross-scenario migration capability through flexible adaptation to various transmission dynamics characteristics. The forward diffusion process is redefined by introducing non-zero mean Gaussian noise to converge to a fully infected state consistent with the real transmission dynamics. This redefinition enables the model to derive unbiased noise, which can encode the microscopic state of different transmission mechanisms, thereby accurately capturing the fine-grained features that are critical to source positioning and improving the accuracy of source positioning. Based on the unbiased noise learned in the forward diffusion process, the transmission source is accurately traced through an interpretable closed reverse diffusion process. It realizes the direct inference of the transmission source from the observation data without relying on historical data containing explicit source labels; the expected benefits and commercial value of this method after transformation are: using the present invention to perform the task of locating the transmission source under cyberspace security, it is possible to quickly locate the source of rumor or network virus transmission, assist in social media content governance and network public safety prevention and control, and reduce social and economic losses; at the same time, the general framework of the present invention reduces the deployment cost of multiple scenarios, and does not require a large amount of historical data containing source labels, which significantly saves time and economic investment, provides important guarantees for the rapid deployment and practical application of transmission source positioning technology, and has broad application prospects and commercial value.

[0097] Based on the same inventive concept, an embodiment of the present invention provides a propagation source positioning device. Since the principle of solving the technical problem of the device is similar to that of a propagation source positioning method, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be repeated.

[0098] like Figure 2 As shown, the device includes a first determining unit 201 , a fusion unit 202 , a second determining unit 203 and a selecting unit 204 .

[0099] The first determining unit 201 is configured to obtain the infection status of all nodes in the observation time step from the propagation cascade snapshot, determine the stage of the current infection progress in the entire diffusion process and the observation time step corresponding to the stage based on the number of infected nodes and the total number of nodes in the infection status of the observation time step, combined with the maximum time step; obtain the cumulative intensity of the forward diffusion time step used to control the noise in the diffusion process based on the single-step attenuation coefficient; and determine the forward infection status of all nodes in the forward diffusion time step based on the cumulative intensity and the infection status of all nodes in the observation time step;

[0100] A fusion unit 202 is configured to concatenate the node attributes of each node included in the propagation cascade snapshot and the infection state of the observation time step to obtain a fusion feature matrix corresponding to the propagation cascade snapshot, wherein the fusion feature matrix is ​​composed of fusion features obtained from each node;

[0101] A second determining unit 203 is configured to reversely iterate from the maximum time step to time step zero based on the forward infection state and the fusion feature matrix, and sequentially determine the reverse estimated infection state for each reverse iterative time step until an initial infection state is obtained;

[0102] The selection unit 204 is configured to select a node with the largest probability value as a predicted transmission source from the vectors equal to the total number of nodes included in the initial infection state.

[0103] It should be understood that the units included in the above-described apparatus for locating a transmission source are merely logical divisions based on the functions implemented by the apparatus. In actual applications, the above-described units can be combined or separated. Furthermore, the functions implemented by the apparatus for locating a transmission source provided in this embodiment correspond one-to-one with the method for locating a transmission source provided in the above-described embodiment. A more detailed description of the processing flow implemented by the apparatus is provided in the first embodiment of the method and will not be repeated here.

[0104] Another embodiment of the present invention also provides a computer device, which includes: a processor and a scene database; the scene database is used to store computer program code, and the computer program code includes computer instructions; when the processor executes the computer instructions, the electronic device executes each step of the propagation source positioning method shown in the above method embodiment.

[0105] Another embodiment of the present invention further provides a computer-readable storage medium, which stores computer instructions. When the computer instructions are executed on a computer device, the computer device executes each step of the propagation source positioning method shown in the above method embodiment.

[0106] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.

Claims

1. A method for locating a propagation source, characterized in that: include: Obtaining the infection status of all nodes at the observation time step from the propagation cascade snapshot; judging the stage of the current infection progress in the entire diffusion process and the observation time step corresponding to the stage based on the number of infected nodes and the total number of nodes in the infection status of the observation time step, in combination with the maximum time step; obtaining the cumulative intensity of the forward diffusion time step used to control the noise in the diffusion process based on the single-step attenuation coefficient; and determining the forward infection status of all nodes at the forward diffusion time step based on the cumulative intensity and the infection status of all nodes at the observation time step; splicing the node attributes of each node included in the propagation cascade snapshot and the infection state of the observation time step to obtain a fusion feature matrix corresponding to the propagation cascade snapshot, wherein the fusion feature matrix is ​​composed of fusion features obtained from each node; According to the forward infection state and the fusion feature matrix, reverse iterate from the maximum time step to time step zero, and determine the reverse estimated infection state of each reverse iterative time step in sequence until an initial infection state is obtained; Selecting a node with the largest probability value as a predicted transmission source from the vectors equal to the total number of nodes included in the initial infection state; The observation time step is determined by the following formula: The forward diffusion time step is used to control the cumulative intensity of noise during the diffusion process and is determined by the following formula: The positive infection state is determined by the following formula: The reverse iteration starting from the maximum time step until the time step is zero, and sequentially determining the reverse estimated infection state of each reverse iteration time step, specifically includes: In each reverse iteration cycle, the variance of the reverse diffusion, the optimal estimated mean of the previous state, and the reverse estimated infection state of each reverse iteration time step are determined by the following formula: Among them, t obs represents the observation time step, T max represents the maximum time step, |V| represents the total number of nodes, Indicates the number of infected nodes in the current state. represents the forward diffusion time step t forw The single-step attenuation coefficient, represents the forward diffusion time step t forw To observation time step t obs The cumulative intensity of represents the forward diffusion time step t forw The forward infection state of all nodes under obs represents the observation time step t obs The observed infection state of all nodes under time step, ∈ represents standard Gaussian noise, represents an all-one vector, Represents the single-step attenuation coefficient of the reverse iteration time step, represents the preset parameters, represents the variance of the reverse diffusion, represents the optimal estimated mean of the previous state, represents the noise predicted by the denoising model, θ represents the learnable parameters of the denoising model, shows the reverse iteration time step t back The reverse estimation of infection status, t back represents the reverse iteration time step, V represents the node set, E represents the edge set, F * represents the fusion feature matrix, Represents the reverse iteration time step t back -1 is the inverse estimate of the infection status, and z represents sampling from the standard normal distribution.

2. The method according to claim 1, wherein Before obtaining the infection status of all nodes at the observation time step from the propagation cascade snapshot, the method further includes: Receives a propagation cascade snapshot selected from the dataset and the noise predicted by a pre-trained denoising model.

3. The method according to claim 1, wherein The fusion feature matrix is ​​as follows: F * =(F‖H obs ) Among them, F represents the attribute feature set of each node, H obs represents the observation time step t obs The infection state of all nodes at the observed time step, F * represents the fused feature matrix of all nodes included in the propagation cascade snapshot, and || represents concatenation.

4. The method according to claim 1, wherein The predicted source of transmission is determined by the following formula: in, represents the initial infection state of node v at the initial time step t0=0, Represents the predicted propagation source, v represents each node, v∈V, and argmax represents the maximum value.

5. A transmission source positioning device, characterized in that: include: A first determination unit is configured to obtain the infection status of all nodes in the observation time step from the propagation cascade snapshot, determine the stage of the current infection progress in the entire diffusion process and the observation time step corresponding to the stage based on the number of infected nodes and the total number of nodes in the infection status of the observation time step, combined with the maximum time step; obtain the cumulative intensity of the forward diffusion time step used to control the noise in the diffusion process based on the single-step attenuation coefficient; and determine the forward infection state of all nodes in the forward diffusion time step based on the cumulative intensity and the infection status of all nodes in the observation time step; a fusion unit, configured to concatenate the node attributes of each node included in the propagation cascade snapshot and the infection state of the observation time step to obtain a fusion feature matrix corresponding to the propagation cascade snapshot, wherein the fusion feature matrix is ​​composed of fusion features obtained from each node; a second determining unit, configured to reversely iterate from the maximum time step to time step zero according to the forward infection state and the fusion feature matrix, and sequentially determine the reverse estimated infection state of each reverse iterative time step until an initial infection state is obtained; A selection unit, configured to select a node with a maximum probability value as a predicted transmission source from the vectors equal to the total number of nodes included in the initial infection state; The observation time step is determined by the following formula: The forward diffusion time step is used to control the cumulative intensity of noise during the diffusion process and is determined by the following formula: The positive infection state is determined by the following formula: The second determining unit is further configured to: In each reverse iteration cycle, the variance of the reverse diffusion, the optimal estimated mean of the previous state, and the reverse estimated infection state of each reverse iteration time step are determined by the following formula: Among them, t obs represents the observation time step, T max represents the maximum time step, |V| represents the total number of nodes, Indicates the number of infected nodes in the current state. represents the forward diffusion time step t forw The single-step attenuation coefficient, represents the forward diffusion time step t forw To observation time step t obs The cumulative intensity of represents the forward diffusion time step t forw The forward infection state of all nodes under obs represents the observation time step t obs The observed infection state of all nodes under time step, ∈ represents standard Gaussian noise, represents an all-one vector, Represents the single-step attenuation coefficient of the reverse iteration time step, represents the preset parameters, represents the variance of the reverse diffusion, represents the optimal estimated mean of the previous state, represents the noise predicted by the denoising model, θ represents the learnable parameters of the denoising model, shows the reverse iteration time step t back The reverse estimation of infection status, t back represents the reverse iteration time step, V represents the node set, E represents the edge set, F * represents the fusion feature matrix, Represents the reverse iteration time step t back -1 is the inverse estimate of the infection status, and z represents sampling from the standard normal distribution.

6. A computer device, characterized in that: The computer device includes a memory and a processor, the memory stores a computer program, and when the computer program is executed by the processor, the processor executes the propagation source positioning method according to any one of claims 1 to 4.

7. A computer-readable storage medium, characterized in that A computer program is stored, and when the computer program is executed by a processor, the processor executes the propagation source positioning method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Network risk source tracing method based on back propagation

    CN105915399A

  • Network information tracing method and device and medium

    CN116488847A