Heterogeneous deployment method for network intrusion detection based on deep neural network quantization
Through the automatic quantization and heterogeneous deployment solution of the deep learning compiler TVM, the rapid development and deployment of lightweight network intrusion detection methods in heterogeneous environments is solved, and the efficient adaptation and rapid response of the model on different devices is achieved, which improves the flexibility and reliability of network security.
Patent Information
- Application Number
- CN202510499708.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-21
- Publication Date
- 2025-07-25
AI Technical Summary
The existing lightweight network intrusion detection method based on deep learning network quantization is difficult to achieve rapid development and deployment under different devices and different environment characteristics, resulting in delays and vulnerabilities in network security protection, and it is impossible to deal with network threats in a timely manner.
The automatic quantization and heterogeneous deployment scheme based on the deep learning compiler is adopted, and the deep learning compiler TVM is automatically identified by the deep learning compiler, TVM, and the lightweight deep neural network model is optimized to achieve efficient adaptation and deployment of the model in a heterogeneous environment.
It realizes efficient operation of the model on heterogeneous devices, shortens the development and deployment cycle, responds to network security incidents quickly, reduces the dependence of professionals, and improves detection efficiency and accuracy.
Smart Images

Figure CN120378155A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network security, and particularly relates to a heterogeneous deployment method for network intrusion detection based on deep neural network quantization. Background Art
[0002] Through optimized design, lightweight network intrusion detection systems can reduce the consumption of system resources while ensuring detection performance. This is particularly important for edge computing nodes with limited resources, such as Internet of Things (IoT) devices and in-vehicle network devices. These nodes have relatively limited memory, computing power, and storage resources. Traditional complex network intrusion detection systems may not be able to operate effectively on resource-limited devices due to excessive resource consumption. By simplifying the design, optimizing algorithms, and reducing unnecessary components, lightweight network intrusion detection systems can reduce the occupation of system resources while ensuring a certain detection performance, making them more suitable for deployment in resource-limited environments. At the same time, the network intrusion detection algorithm for each node needs to meet the requirements of a specific node traffic environment and has highly dynamic characteristics, requiring the network intrusion detection algorithm to have the ability of agility and high efficiency (Ye Tianpeng, Lin Xiang, Li Jianhua, etc. Personalized lightweight distributed network intrusion detection system for fog computing [J]. Journal of Network and Information Security, 2023, 9(3): 28-37.).
[0003] With the rapid progress in the field of artificial intelligence, researchers have proposed network intrusion detection models using deep learning techniques, which have been widely applied to various network intrusion detection systems. Hossain et al. described a network intrusion detection system based on Long Short-Term Memory (LSTM), which uses the better temporal perception of LSTM for sequence data to more accurately classify in-vehicle network traffic (Hossain M D, Inoue H, Ochiai H, et al. LSTM-based intrusion detection system for in-vehicle can bus communications[J]. Ieee Access, 2020, 8:185489-185502.). Abebe et al. proposed a deep learning-based intrusion detection system. The hybrid model combines different types of deep learning models, including convolutional neural networks, long short-term memory, deep autoencoders, etc., and uses their different attributes to achieve high performance (Abebe D, Chilamkurti N. Leveraging LSTM networks for attack detection in fog-to-things communications[J]. IEEE Communications Magazine, 2018, 56(9):124-130.). As the core algorithm of deep learning technology, deep neural networks can automatically construct complex mappings of network flow data from low-level features to high-level semantics, and achieve accurate prediction or recognition through layer-by-layer feature transformation. This feature effectively solves the limitation of traditional network intrusion detection systems that require manual feature screening, and their defect of being unable to generalize and identify future similar behaviors based on historical behaviors. Therefore, network intrusion detection models using deep learning technology exhibit more powerful detection capabilities, can identify more types of unknown attacks, and significantly improve the effectiveness and adaptability of network intrusion detection systems. Due to the rapid development of deep learning algorithms, researchers are constantly studying deep learning model compression algorithms to reduce their application limitations (Liu H Y, Lang B. Machine learning and deep learning methods for intrusion detection systems: A survey[J]. Applied Sciences, 2019, 9(20):4396.).
[0004] In the study of lightweight deep neural network models, in addition to finding lightweight models, researchers have also proposed a variety of lightweight methods based on distillation, quantization, sparsity, etc. Quantization is another type of technology widely used in the field of deep learning. By reducing the storage requirements of the model, while reducing the computational complexity and improving the inference speed, the accuracy can be avoided as much as possible. However, whether it is pre-training quantization or post-training quantization, additional manual optimization is required for different operating environments, which is time-consuming and labor-intensive. Ye Tianpeng et al. proposed a personalized lightweight distributed network intrusion detection system for fog computing architecture, personalized model distillation algorithm and weighted first-order Taylor approximation pruning algorithm for fast personalized compression of complex models (Ye Tianpeng, Lin Xiang, Li Jianhua, et al. Personalized lightweight distributed network intrusion detection system for fog computing [J]. Journal of Network and Information Security, 2023, 9(3): 28-37.). In the field of quantization, Gong et al. used the K-means clustering algorithm to cluster the weight parameters of a lightweight deep neural network model, so that only K centroids need to be stored during the storage of the model, thereby effectively reducing the memory overhead of the model (Gong Y, Liu L, Yang M, et al. Compressing deep convolutional networks using vector quantization [EB / OL]. https: / / arxiv.org / abs / 1412.06115.).
[0005] Optimizing and compressing various models based on deep learning compilers such as TVM has become an important research direction. This type of optimization scheme based on deep learning compilers such as TVM and XLA uses heuristic algorithms to search the computational graph for automatic optimization based on specific rules, and also realizes code generation for heterogeneous devices (Chen T, Moreau T, Jiang Z, et al. TVM: An automated end-to-end optimizing compiler for deep learning [C]. 13th USENIX Symposium on Operating Systems Design and Implementation (OSDI 18), 2018: 578-594.). TVM also provides a general quantization framework to support quantization of different model frameworks, including two modes: one is a quantization mechanism based on ONNX model quantization, and the other is a quantization mechanism based on QNN pre-quantization model.
[0006] Traditional network intrusion detection models based on deep neural networks usually use a certain lightweight deep neural network model to train and perform inference tests on network intrusion datasets (Jiang Yuchang, Xu Yang, Li Kezi, et al. A lightweight vehicle network intrusion detection method based on deep learning [J]. Computer Engineering and Applications, 2023, 59(22): 284-292.). However, this manually introduced quantization method not only requires researchers to have rich quantization knowledge and experience, but also the whole process is very cumbersome and prone to errors. Researchers need to carry out manual adaptation work for different operating environments. Different hardware devices have different hardware characteristics such as computing power, memory bandwidth, and storage capacity; different software environments, such as the type of operating system and the version of the runtime library, also vary. Researchers need to manually adjust the parameter configuration, calculation process, etc. of the model according to these complex and variable environmental factors to ensure that the model can run normally in the target environment. Moreover, once a new deployment environment appears, whether it is a brand-new hardware architecture or a unique software setting, researchers have to invest a large amount of time and effort again to perform manual adaptation and optimization work. The entire above process, from model training, quantization to final deployment adaptation, has a long development cycle and cannot deploy effective network intrusion detection models in a timely manner, resulting in delays and vulnerabilities in network security protection, making the network system face huge security risks.
[0007] Existing lightweight network intrusion detection methods based on deep learning network quantization usually rely on specific environments and specific devices (Choudhary T, Mishra V, Goswami A, et al. A comprehensive survey on model compression and acceleration [J]. Artificial Intelligence Review, 2020, 53(7): 5113-5155.). Their heterogeneous deployment capabilities are limited and it is difficult to achieve optimized deployment for different devices and different environmental characteristics. It requires researchers and experts to conduct professional development based on specific environments and is difficult to achieve rapid development and deployment. In practical applications, when facing urgent network security requirements, existing lightweight network intrusion detection methods based on deep learning network quantization are difficult to achieve rapid development and deployment and cannot respond to changing network threats in a timely and effective manner. This situation urgently requires researchers to explore new solutions to improve the generality and flexibility of lightweight network intrusion detection methods and achieve their rapid deployment and efficient operation in multi-platform heterogeneous environments. Summary of the Invention
[0008] To solve the problem of network intrusion detection, the present invention provides a heterogeneous deployment method for network intrusion detection based on deep neural network quantization. The present invention can significantly reduce the resource consumption and inference latency of the model, realize the lightweight of the system, facilitate the deployment on edge devices, and at the same time, the present invention can also realize heterogeneous deployment in different environments. The present invention has important practical significance for solving the deployment problem of network intrusion detection models on edge devices in resource-constrained environments.
[0009] The technical solutions adopted by the present invention to solve the technical problems are as follows:
[0010] A heterogeneous deployment method for network intrusion detection based on deep neural network quantization of the present invention includes the following steps:
[0011] Step S1: A 2D data generation scheme based on network traffic;
[0012] First, clean the network traffic data, then use a sliding window to obtain continuous traffic frames, and finally construct 2D data frames based on the linear interpolation method;
[0013] Step S2: Select a specific lightweight deep neural network model for training and testing;
[0014] Step S3: An automatic quantization scheme based on a deep learning compiler;
[0015] Using a deep learning compiler, first perform a structural analysis on the lightweight deep neural network model, then perform a data feature analysis in combination with the network intrusion detection data set, then automatically select a suitable quantization scheme based on the analysis results, and finally monitor the model performance in real time during the automatic quantization process and adjust the parameters according to the monitoring feedback results; at the same time, optimize and match the automatic quantization mode for a specific lightweight deep neural network model;
[0016] Step S4: An automatic heterogeneous deployment scheme based on a deep learning compiler;
[0017] First, use a deep learning compiler to automatically identify the hardware characteristics and computing capabilities of different devices; then use the deep learning compiler to optimize and adjust the model according to the identified hardware characteristics.
[0018] Further, in step S1, when cleaning the network traffic data, complete the empty fields in the network traffic data and delete the network traffic data with obvious errors.
[0019] Further, in step S1, a sliding window with a fixed window length is used to generate a new 2D data frame from multiple consecutive network traffic data and slide down sequentially; from the newly generated 2D data frame, ID data and DATA data are extracted for a single CAN data to obtain a 2D data frame, and the 2D data frame is converted into vector data.
[0020] Further, in step S1, the corresponding label data is extracted from the 2D data frame, and the label data is re-encoded. The label of the abnormal traffic containing attack traffic is set to 1, and the label of normal traffic is set to 0.
[0021] Further, in step S2, a specific lightweight deep neural network model is selected on a local large server, and the generated 2D data frame is used for model training, testing and evaluating the model to comprehensively evaluate the model's detection ability for attack traffic; when the model meets the expected standard and can accurately identify malicious components in network traffic, the selected specific lightweight deep neural network model is saved.
[0022] Further, the deep learning compiler selects TVM.
[0023] Further, in step S3, the trained lightweight deep neural network model is converted into a Relay FP32 / FP64 computational graph through the ONNX model in the deep learning compiler TVM, representing the model written by Relay IR. The model is converted into the corresponding schedule for the FP16 model or INT model through the specific Pass written.
[0024] Further, in step S3, a quantization Pass is developed for specific network layers and operators to optimize the execution efficiency of the lightweight deep neural network model.
[0025] Further, in step S3, the computational graph will trigger the Auto-Tuning mechanism, automatically search for and select the best compilation options and running parameters, and select the best parameters for the current model inference through the optimized lightweight deep neural network model, and generate the corresponding TIR by accessing other Relay optimizations.
[0026] Further, in step S4, the hardware characteristics include: processor architecture, memory bandwidth, storage capacity and computing power.
[0027] The beneficial effects of the present invention are:
[0028] A heterogeneous deployment method for network intrusion detection based on deep neural network quantization provided by the present invention converts continuous network traffic data into specific vector data according to different network intrusion attack characteristics. After cleaning, a 2D data frame is constructed by using a sliding window and linear interpolation method to fuse spatio-temporal information and enrich data features, thereby improving the intrusion detection rate.
[0029] In addition, the present invention also uses a deep learning compiler to automatically analyze and select the optimal quantization strategy by comprehensively considering the network intrusion detection data set, model structure, and deployment environment characteristics, without manual adaptation, greatly improving the quantization efficiency.
[0030] At the same time, the present invention can identify the hardware characteristics and computing power of different devices, realize the efficient adaptation of the model on various devices, shorten the model development and deployment cycle, quickly respond to security events, reduce the dependence on professionals, reduce costs, automatically optimize and improve the detection efficiency, and provide reliable and flexible protection for network security. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] Figure 1 It is a flowchart of a heterogeneous deployment method for network intrusion detection based on deep neural network quantization provided by the present invention.
[0032] Figure 2 It is a 2D data generation scheme based on network traffic. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0033] The present invention will be further described in detail below with reference to the accompanying drawings.
[0034] As Figure 1 shown, a heterogeneous deployment method for network intrusion detection based on deep neural network quantization provided by the present invention includes the following steps:
[0035] (1) A 2D data generation scheme based on network traffic;
[0036] First, the network traffic data is additionally cleaned; then, continuous traffic frames are obtained by using a sliding window; finally, a 2D data frame is constructed based on the linear interpolation method.
[0037] (2) Select a specific lightweight deep neural network model for training and testing;
[0038] In the present invention, the selected lightweight deep neural network model only needs to meet the input of module (1), with high adaptability and flexibility.
[0039] (3) An automatic quantization scheme based on a deep learning compiler;
[0040] Using a deep learning compiler, first, model analysis is carried out. By analyzing the structure of lightweight deep neural network models, a solid foundation is laid for subsequent automatic quantization work. Then, data feature analysis is performed, closely exploring in combination with the characteristics of the network intrusion detection dataset, so as to provide a strong basis for reasonably selecting an automatic quantization scheme. Subsequently, based on the above model analysis and data feature analysis results, an appropriate automatic quantization scheme is automatically selected. Finally, during the automatic quantization process, the model performance is monitored in real time, and the parameters are flexibly adjusted according to the results feedback by the automatic quantization process monitoring to ensure the efficiency and accuracy of the automatic quantization work. At the same time, the present invention matches the automatic quantization mode based on common lightweight deep neural network models, facilitating the deployment and adaptation of automatic quantization.
[0041] (4) Automatic heterogeneous deployment scheme based on a deep learning compiler;
[0042] After automatic quantization is completed, it enters the automatic heterogeneous deployment stage, which includes two important sub-steps: one is hardware feature recognition, that is, automatically identifying the hardware features and computing capabilities of different devices; the other is model optimization and adjustment, that is, optimizing and adjusting the model in a targeted manner according to the identified hardware features.
[0043] A heterogeneous deployment method for network intrusion detection based on deep neural network quantization according to the present invention has the following specific implementation process:
[0044] Step S1: 2D data generation scheme based on network traffic;
[0045] By studying common network intrusion detection datasets, it can be seen that tampering attacks such as flood attacks are mainly identified through frame space features. However, when facing non-tampering injection attacks such as Replay attacks that use retransmitted normal traffic as an attack means, it is necessary to distinguish whether the injected data is normal traffic or abnormal traffic through the time features of the sequence. Therefore, continuous traffic frames need to be collected. Currently, when common lightweight deep neural network models classify pictures, their input is usually picture data with a shape of n×n×3. Therefore, in order to facilitate the use of such lightweight deep neural network models, the present invention adopts a similar method to convert continuous network traffic data into vector data with a shape of n×n×3.
[0046] First, clean the network traffic data, complete the fields with empty values in the network traffic data, and delete some network traffic data with obvious errors. Then, perform data construction on the network traffic data after data cleaning. Specifically, first use a sliding window to obtain continuous traffic frames, and then construct a data processing scheme for 2D data frames based on the linear interpolation method. The present invention constructs a 2D data frame based on a sliding window and the linear interpolation method, can fuse spatio-temporal information, enrich data features, contribute to network traffic analysis, improve the network intrusion detection rate, and adapt to existing lightweight deep neural network models, reducing the application difficulty and application cost of existing lightweight deep neural network models.
[0047] As Figure 2 shown, the specific implementation process is as follows:
[0048] S1.1: Use a sliding window with a fixed window length of 27 to generate a new 2D data frame from 27 consecutive network traffic data, and slide down sequentially;
[0049] S1.2: From the newly generated 2D data frame, extract ID data and DATA data for a single CAN data, a total of 9 bytes, so as to obtain a 2D data frame with a shape of 27×9. At the same time, extract the corresponding label data and re-encode the label data. Among them, the label of abnormal traffic containing attack traffic is set to 1, and the label of normal traffic is set to 0; for continuous data frames, if they contain attack traffic, they can be classified according to the following method: the label of the data frame containing a Flooding attack (Flooding attack is a common form of denial-of-service (DoS) attack) is set to 1, the label of the data frame containing a Spoofing attack is set to 2, the label of the data frame containing a Replay attack (i.e., Replay Attack, a network attack method in which an attacker intercepts and repeatedly sends captured legitimate communication data packets in an attempt to impersonate a legitimate user without the victim's knowledge) is set to 3, and the label of the data frame containing a Fuzzy attack is set to 4;
[0050] S1.3: Convert the 2D data frame with a shape of 27×9 into vector data with a shape of 9×9×3;
[0051] S1.4: In order to facilitate matching the model input and avoid overfitting, use the linear interpolation method to expand the vector data with a shape of 9×9×3 into a data frame with a shape of 96×96×3. After the conversion is completed, the data frame can be directly input into the corresponding lightweight deep neural network model.
[0052] The present invention adopts a scheme of constructing a 2D data frame based on a sliding window and linear interpolation method, which enables the 2D data frame to carry spatial information and time series information simultaneously, making the 2D data contain richer features, contributing to a more comprehensive analysis of network traffic, effectively improving the network intrusion detection rate, having good model adaptability, facilitating the use of existing lightweight deep neural network models, and reducing the difficulty and cost of applying existing lightweight deep neural network models.
[0053] Step S2: Training and testing of the lightweight deep neural network model;
[0054] First, on a local large server, select a specific lightweight deep neural network model from among numerous lightweight deep neural network models adapted to network intrusion detection, and at the same time use the generated 2D data frame for model training; then test and evaluate the model to comprehensively evaluate the model's detection ability for attack traffic. When the model meets the expected standards in key indicators such as accuracy and ensures that it can accurately identify malicious components in network traffic, save the selected specific lightweight deep neural network model.
[0055] Step S3: Automatic quantization scheme based on a deep learning compiler;
[0056] Currently, there are already various quantization schemes in the field of deep learning, such as traditional quantization methods based on fixed parameters and some quantization ideas that focus on simplifying the model structure. However, these methods often have certain limitations in the network intrusion detection environment, rarely fully considering the diversity of data characteristics in the network intrusion detection dataset, such as the unique patterns of data of different attack types, and the adaptability of the model in different hardware environments for network intrusion detection, which to a certain extent limits the performance improvement of the quantized model for network intrusion detection. In addition, these methods also require researchers to manually adapt to the network intrusion detection environment. Facing the hardware and data characteristics in different network intrusion detection environments, different characteristics need to be manually adapted, resulting in a cumbersome and inefficient quantization process and being difficult to meet the requirements of the rapidly changing actual application scenarios in network intrusion detection.
[0057] Therefore, the present invention proposes an automatic quantization scheme based on a deep learning compiler, which is particularly suitable for the network intrusion detection environment. This automatic quantization scheme comprehensively considers the data characteristics of the network intrusion detection dataset, the model structure for network intrusion detection, and the characteristics of the deployment environment of the network intrusion detection system, can automatically analyze and select the optimal quantization strategy without manual adaptation, not only improves the quantization efficiency, but also enables the quantized model to maintain good performance in different network intrusion detection environments, greatly enhancing the generalization ability and practicality of the model in network intrusion detection tasks and more effectively identifying and preventing various network intrusion behaviors.
[0058] Specifically, the present invention introduces the deep learning compiler TVM (Tensor Virtual Machine, an end-to-end deep learning compiler), and optimizes and performs automatic quantization pattern matching on the specific lightweight deep neural network model selected in step S2.
[0059] The specific implementation process is as follows:
[0060] The trained lightweight deep neural network model is converted into a Relay FP32 / FP64 computational graph through the ONNX (Open Neural Network Exchange, an open deep learning model exchange format) model in the deep learning compiler TVM, representing the model written by Relay IR (Intermediate Representation). The model will be converted into the corresponding schedule for the FP16 model or INT model through the specific Passes written (i.e., the process of the deep learning compiler TVM analyzing and optimizing the compilation unit).
[0061] To fully utilize the hardware performance and optimize the execution efficiency of the lightweight deep neural network model, it is necessary to develop quantization Passes for specific network layers and operators. In the present invention, first, the obtained Relay FP32 / FP64 computational graph optimization Passes are utilized. After optimization, hardware-dependent optimization can also be performed according to the current hardware device, such as the tensor core in NVIDIA GPUs, which provides matrix operation optimization based on INT8. These Passes are designed to ensure that after the model is converted to a low-precision format, it can not only maintain the accuracy of the high-precision version but also maximize the computing efficiency and throughput.
[0062] Finally, these computational graphs will trigger the Auto-Tuning mechanism, automatically search for and select the best compilation options and running parameters, and select the best parameters for the current model inference through the optimized lightweight deep neural network model. Then, other Relay optimizations are connected (Relay optimization refers to the process of optimizing the computational graph represented by the functional programming language Relay that describes the deep learning network in TVM). Finally, the corresponding TIR (i.e., TensorIR, a specific language for an intermediate representation of the deep learning compiler TTVM, used to represent the abstraction of program optimization) is generated.
[0063] Through the above process, the deep learning compiler TVM can be automatically quantized; at the same time, the present invention also specializes the deep learning compiler TVM, adding pattern matching and template codes for common operators and quantization operators in common lightweight deep neural network models.
[0064] Step S4: Automatic heterogeneous deployment solution based on deep learning compiler;
[0065] At present, heterogeneous deployment based on network intrusion detection models is basically carried out in the form of manual deployment and manual adjustment. The present invention is based on the automatic heterogeneous deployment solution of the deep learning compiler, which can identify the hardware characteristics and computing power of devices such as the Internet of Things, vehicle networks, and cloud servers. Regardless of the device resource status, the model can be efficiently adapted. This solution greatly shortens the model development and deployment cycle, and can respond quickly to emergency security incidents. At the same time, the solution also reduces dependence on professionals, reduces costs, and facilitates rapid deployment of models. In addition, the deep learning compiler automatically optimizes and explores better configurations, improves the accuracy and efficiency of network intrusion detection, and provides reliable and flexible protection for network security to resist complex intrusions.
[0066] Specifically, after optimization by the TVM backend of the deep learning compiler, the generated content, i.e., the optimized results based on TIR, can be deployed to different heterogeneous devices to form a model that can run efficiently on these heterogeneous devices. When the automatic quantization step of step S3 is successfully completed, it naturally enters the automatic heterogeneous deployment stage.
[0067] In the automatic heterogeneous deployment phase, the deep learning compiler TVM demonstrates its excellent adaptability and flexibility. This phase mainly includes two crucial sub-steps:
[0068] One is hardware feature identification;
[0069] TVM, the deep learning compiler, will make full use of its built-in detection mechanism to automatically and accurately identify the hardware characteristics of different devices, including but not limited to key parameters such as processor architecture, memory bandwidth, storage capacity, and computing power. These detailed hardware characteristic information will provide a solid foundation for subsequent operations.
[0070] The second is model optimization and adjustment;
[0071] Based on the hardware feature information identified in the first step, the deep learning compiler TVM will optimize and adjust the model in a targeted manner. For devices with strong computing power, a more complex but more accurate calculation method may be used; for devices with relatively limited resources, the model will be appropriately simplified and lightweight to ensure that the model can guarantee a certain detection performance on the device without excessively consuming resources.
[0072] Through these two closely connected sub-steps, the deep learning compiler TVM achieves efficient and stable model deployment on different heterogeneous devices, fully unleashing the potential of various devices.
[0073] A heterogeneous deployment method for network intrusion detection based on deep neural network quantization according to the present invention can achieve automatic quantization and heterogeneous deployment of a network intrusion detection model based on a deep neural network by introducing a deep learning compiler. During automatic quantization, the deep learning compiler analyzes the model structure, understands the functions, parameters, and data flow of each layer, and combines characteristics such as the scale of the data set and the feature distribution to automatically select a quantization scheme using advanced algorithms. During heterogeneous deployment, the deep learning compiler can identify the hardware characteristics and computing capabilities of different devices, optimize the model specifically, enable the model to run efficiently on devices such as the Internet of Things, vehicle-mounted networks, and cloud servers, quickly adapt to edge devices and central nodes, and exert the best performance.
[0074] The present invention not only greatly shortens the development and deployment cycle of the model, can quickly respond when an emergency network security event occurs, and timely deploy an effective detection model, but also reduces the dependence on professional researchers, reduces the development costs of professionals, and can also quickly implement the deployment and application of the model with the help of the deep learning compiler tool. At the same time, the automated optimization process of the deep learning compiler can continuously explore better model configurations, further improve the accuracy and efficiency of network intrusion detection, and provide a more reliable and flexible guarantee for network security.
[0075] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art in the technical field, without departing from the principle of the present invention, several improvements and retouches can still be made, and these improvements and retouches should also be regarded as the protection scope of the present invention.
Claims
1. A heterogeneous deployment method for network intrusion detection based on deep neural network quantization, characterized in that, It includes the following steps: Step S1: A 2D data generation scheme based on network traffic; First, clean the network traffic data, then use a sliding window to obtain continuous traffic frames, and finally construct 2D data frames based on linear interpolation; Step S2: Select a specific lightweight deep neural network model for training and testing; Step S3: An automatic quantization scheme based on a deep learning compiler; Using a deep learning compiler, first perform a structural analysis on the lightweight deep neural network model, then perform data feature analysis in combination with a network intrusion detection data set, then automatically select a suitable quantization scheme based on the analysis results, and finally monitor the model performance in real time during the automatic quantization process and adjust the parameters according to the monitoring feedback results; at the same time, optimize and match the automatic quantization mode for a specific lightweight deep neural network model; Step S4: An automatic heterogeneous deployment scheme based on a deep learning compiler; First, use a deep learning compiler to automatically identify the hardware characteristics and computing capabilities of different devices; then use the deep learning compiler to optimize and adjust the model according to the identified hardware characteristics.
2. The heterogeneous deployment method for network intrusion detection based on deep neural network quantization according to claim 1, characterized in that In step S1, when cleaning the network traffic data, fill in the empty fields in the network traffic data and delete the network traffic data with obvious errors.
3. The heterogeneous deployment method for network intrusion detection based on deep neural network quantization according to claim 1, characterized in that, In step S1, use a sliding window with a fixed window length to generate a new 2D data frame from multiple consecutive network traffic data and slide down sequentially; from the newly generated 2D data frame, extract the ID data and DATA data for a single CAN data to obtain a 2D data frame, and convert the 2D data frame into vector data.
4. The heterogeneous deployment method for network intrusion detection based on deep neural network quantization according to claim 3, wherein, In step S1, extract the corresponding label data from the 2D data frame and re-encode the label data. Set the label of abnormal traffic containing attack traffic to 1 and the label of normal traffic to 0.
5. The heterogeneous deployment method for network intrusion detection based on deep neural network quantization according to claim 1, characterized in that In step S2, first select a specific lightweight deep neural network model on a local large server, and use the generated 2D data frame to train, test and evaluate the model, and comprehensively evaluate the model's detection ability for attack traffic; when the model meets the expected standard and can accurately identify malicious components in network traffic, save the selected specific lightweight deep neural network model.
6. The heterogeneous deployment method of network intrusion detection based on deep neural network quantization according to claim 1, characterized in that The deep learning compiler selects TVM.
7. The heterogeneous deployment method for network intrusion detection based on deep neural network quantization according to claim 1, characterized in that In step S3, convert the already trained lightweight deep neural network model into a Relay FP32 / FP64 computational graph through the ONNX model in the deep learning compiler TVM, representing the model written by Relay IR. The model is converted into the corresponding schedule for the FP16 model or INT model through a specific Pass written.
8. The heterogeneous deployment method for network intrusion detection based on deep neural network quantization according to claim 7, characterized in that, In step S3, develop a quantization Pass for specific network layers and operators to optimize the execution efficiency of the lightweight deep neural network model.
9. The heterogeneous deployment method for network intrusion detection based on deep neural network quantization according to claim 7, wherein In step S3, the computational graph will trigger the Auto-Tuning mechanism, automatically search for and select the best compilation options and running parameters, and select the best parameters for the current model inference through the optimized lightweight deep neural network model, and generate the corresponding TIR by accessing other Relay optimizations.
10. The heterogeneous deployment method for network intrusion detection based on deep neural network quantization according to claim 1, characterized in that In step S4, the hardware characteristics include: processor architecture, memory bandwidth, storage capacity, and computing power.