Abnormal subgraph detection method based on fusion features
By constructing anomaly subgraph detection data set and using a dual attention network to fusion of traditional graph features and deep graph features, the problem of insufficient recognition performance and stability of the anomaly subgraph detection method in the prior art is solved, and higher detection accuracy and robustness are achieved.
Patent Information
- Application Number
- CN202510955618.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-11
- Publication Date
- 2025-08-12
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The prior art cannot effectively integrate the physical interpretability of traditional graph features with the nonlinear expression ability of deep learning, resulting in insufficient recognition performance and stability of anomaly subgraph detection methods under variable abnormal patterns or noise interference conditions.
The abnormal subgraph detection method based on fusion features is adopted. By constructing an abnormal subgraph detection data set, traditional graph features and deep graph features are extracted, and feature fusion is used for dual attention network to build an abnormal subgraph detector to improve the accuracy and stability of detection.
It enhances the interpretability and robustness of the model, can maintain high recognition performance and stability under variable abnormal patterns or noise interference conditions, and improves the accuracy and comprehensiveness of abnormal subgraph detection.
Smart Images

Figure CN120472281A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of graph anomaly detection, and in particular to a method for detecting abnormal subgraphs based on fusion features. Background Art
[0002] Graph data represents the connections between entities and consists of sets of nodes and edges. Nodes represent entities, and edges represent relationships between entities. In the era of big data, graph data, with its superior ability to represent relationships, has been widely used in the modeling and analysis of complex systems such as social networks, communication networks, computer networks, and biological networks. With the continuous expansion of network size and the increasing complexity of interactions, graph anomaly detection plays a vital role in areas such as system fault diagnosis and abnormal behavior identification. Graph anomalies can be viewed as nodes, edges, subgraphs, and other objects that differ from most other objects in the graph. Graph anomalies are detected to identify graphs whose structure or attributes differ significantly from normal patterns. These anomalies may indicate potential fraud, cyberattacks, or other unusual events.
[0003] Graph anomaly detection methods can be broadly categorized into four types: node-based, edge-based, subgraph-based, and full-graph-based. Traditional anomalous subgraph detection methods primarily rely on structural and spectral features of the graph. Structural features include node degree and clustering coefficient. Spectral feature methods utilize the eigenvalues and eigenvectors of the adjacency matrix or transformation matrix of a random graph to detect anomalous patterns in random networks. While these methods perform well in certain scenarios, their performance often degrades significantly when dealing with complex structures, dynamic changes, and networks with large numbers of nodes. The rise of deep learning technology has provided a new solution for anomalous subgraph detection. By automatically extracting deep features, deep learning can capture complex nonlinear patterns and implicit structural relationships, demonstrating greater flexibility and adaptability in anomalous subgraph detection. However, deep learning models often rely heavily on data, making performance particularly vulnerable to performance degradation when dealing with complex graph structures and a lack of sufficient labeled data. Existing technologies have not yet effectively solved the problem of how to effectively integrate the physical interpretability of traditional graph features with the nonlinear expression capabilities of deep learning, overcome their respective limitations, and construct a multi-source graph feature fusion detection model that is both robust and efficient. As a result, under the conditions of changing abnormal patterns or noise interference, the existing abnormal subgraph detection methods are unable to maintain high recognition performance and stability. Summary of the Invention
[0004] To solve the above problems, the present invention provides an abnormal subgraph detection method based on fusion features to improve the accuracy of abnormal subgraph detection.
[0005] The technical solution adopted by the present invention is as follows:
[0006] The abnormal subgraph detection method based on fusion features includes the following steps:
[0007] Step 1: Construct an abnormal subgraph detection dataset, which includes normal images and abnormal images, and divide the abnormal subgraph detection dataset into a training set and a test set;
[0008] Step 2: For each graph, extract traditional graph features and deep graph features, and use the dual attention network to fuse the traditional graph features and the deep graph features to obtain a fused feature matrix;
[0009] Step 3: Construct an abnormal subgraph detector with the fused feature matrix as input, train the abnormal subgraph detector using the training set, test the trained abnormal subgraph detector using the test set, use the tested abnormal subgraph detector to detect the data to be detected, and output the abnormal subgraph detection result.
[0010] The beneficial effects of the present invention are:
[0011] (1) This paper combines traditional graph features (such as degree distribution, clustering coefficient, spectral features, etc.) with deep graph features (deep features extracted by residual matrix), providing multi-level feature support for graph structure anomaly detection, which significantly improves the accuracy and comprehensiveness of the abnormal subgraph detection method. At the same time, it avoids the "black box" problem of deep learning models and enhances the interpretability of the model.
[0012] (2) The present invention introduces a dual attention network to fuse traditional graph features with deep graph features, dynamically adjusts the weights of different features in the detection process to adapt to diverse graph data structures, and effectively improves the robustness and stability of the model. This enables the abnormal subgraph detection method to maintain high recognition performance and stability under variable abnormal patterns or noise interference conditions. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] Figure 1 This is a flow chart of the abnormal subgraph detection method based on fusion features according to an embodiment of the present invention;
[0014] Figure 2 This is the network structure diagram of the deep graph feature extractor;
[0015] Figure 3 This is the network structure diagram of the abnormal subgraph detector;
[0016] Figure 4 Schematic diagram of graph feature extraction and fusion, and abnormal subgraph detection;
[0017] Figure 5 This is a curve showing the relationship between the accuracy of abnormal subgraph detection and the number of iterations. DETAILED DESCRIPTION
[0018] To accurately detect anomalous subgraphs in complex network environments, this paper addresses the problem of detecting anomalous subgraphs in graph structures. By combining multidimensional feature fusion with deep learning techniques, this paper constructs an anomalous subgraph detection network based on fused features, aiming to improve the accuracy and robustness of anomalous subgraph detection. The technical solutions of this invention are described in detail below with reference to the accompanying drawings and preferred embodiments.
[0019] This paper proposes a method for detecting abnormal subgraphs based on fused features. This method fuses traditional graph features such as degree distribution, clustering coefficient, path length, graph diameter, and spectral features with deep graph features extracted by a multi-scale convolutional neural network (MSCNN) model using a residual matrix to construct a more discriminative feature representation. A high-performance abnormal subgraph detector based on fused features and deep learning is designed, which can better capture the multi-dimensional structural information of the graph and improve the accuracy and stability of abnormal subgraph detection.
[0020] See Figure 1 , this embodiment provides an abnormal subgraph detection method based on fusion features, including the following steps 1 to 3.
[0021] Step 1: Create an abnormal subgraph detection dataset and divide it into a dataset and a test set.
[0022] The abnormal subgraph detection dataset consists of normal graphs and abnormal graphs. The normal graphs are generated by the Chung-Lu (CL) model, and the abnormal graphs are obtained by embedding the subgraphs generated by the Erdos-Renyi (ER) model into the normal graphs.
[0023] (1) Generate a normal map using the Chung-Lu model.
[0024] The Chung-Lu (CL) model is a model for generating random graphs. The model can generate a graph structure with the characteristics of real-world networks. The specific process is as follows: set the number of nodes in the network , power law distribution index , expected degree The node degree distribution and connection weights are calculated based on these parameters. The connection probability between each pair of nodes is then calculated based on the connection weights. Finally, an undirected graph is constructed to obtain a CL graph that conforms to the power-law distribution characteristics. The adjacency matrix of the generated CL graph is saved as a NumPy file and marked as a normal graph.
[0025] (2) Use the CL graph to construct an anomaly graph. The specific process is as follows:
[0026] Randomly select on the CL graph nodes, by setting the edge probability , randomly generate edges between these nodes to construct a subgraph with ER structure, namely ER subgraph; then embed the ER subgraph into the CL graph; since the edge connections of the ER subgraph are random, while the CL graph as a whole follows a power-law distribution, this local ER structure is significantly different from the global topological characteristics of the CL background graph, thus forming an abnormal subgraph. The adjacency matrix of the CL graph embedded in the ER subgraph is also saved as a NumPy format file and marked as an abnormal graph.
[0027] Optionally, normal images are marked as 0 as normal samples; abnormal images are marked as 1 as abnormal samples; there are 200 groups of normal images and 200 groups of abnormal images, for a total of 400 groups of image data. , , , , .
[0028] The established abnormal subgraph detection dataset is divided into a training set and a test set in a ratio of 8:2. The training set is used for training the abnormal subgraph detector, and the test set is used for performance evaluation of the abnormal subgraph detector.
[0029] Step 2: Graph feature extraction and fusion.
[0030] Step 2.1: Extract the structural features and spectral features of the graph, where the structural features include the degree distribution features, clustering coefficient mean features, average path length features, and graph diameter features.
[0031] (1) Extract degree distribution features.
[0032] Different types of graphs have different degree distribution characteristics. Abnormal subgraphs often cause the degree (number of connections) of some nodes to increase or decrease abnormally, thus changing the overall degree distribution characteristics. By counting the degrees of all nodes in the graph and calculating key characteristics such as their mean, variance, and maximum value, we can describe the density of node connections and the overall distribution characteristics, thereby providing effective structural information. Specifically, for a single graph, the degree of each node is calculated from the adjacency matrix, and the statistical information of the node degree is described using the mean, variance, and maximum value, which are expressed as:
[0033] ;
[0034] ;
[0035] ;
[0036] in, Indicated by A vector of node degrees, 、 and Respectively represent the mean operation, variance operation and maximum operation of the degree, 、 and They represent the mean, variance and maximum value of the extracted degrees respectively, and finally concatenate to obtain the 3D degree distribution feature vector .
[0037] (2) Extract clustering coefficient mean features.
[0038] The change in clustering coefficient can reflect potential abnormal areas in the graph, thus providing an important feature basis for anomaly detection. Calculating the clustering coefficient of each node in the graph's adjacency matrix can reflect the local connection density of the graph. By calculating the average clustering coefficient of all nodes, the overall clustering characteristics of the graph can be obtained, which can be expressed as:
[0039] ;
[0040] in, for the reason The vector of clustering coefficients of nodes, represents the mean operation of the clustering coefficient, represents the mean of the clustering coefficient.
[0041] (3) Extract average path length and graph diameter features.
[0042] The average path length refers to the average distance between any two nodes in the graph, which indicates the closeness of the graph. It can be expressed as:
[0043] ;
[0044] in, Represents the nodes in the adjacency matrix and nodes The path length between is the number of nodes, , .
[0045] The diameter of a graph refers to the maximum distance between any two nodes, which indicates the scalability of the graph. It can be expressed as:
[0046] ;
[0047] Finally, the two features of average path length and graph diameter are concatenated to obtain a 2D feature vector , which is used to measure the overall compactness and scalability of the graph.
[0048] (4) Extract spectral features.
[0049] By analyzing the eigenvalues of the adjacency matrix, we can effectively reflect the global properties of the graph structure. The mean of the eigenvalues describes the overall connectivity of the graph, while the variance reflects the structural complexity and heterogeneity of the graph. The embedding of anomalous subgraphs changes the overall eigenvalue distribution of the graph. By extracting these spectral features, we can quantitatively characterize the impact of anomalous subgraphs on the graph structure.
[0050] For each graph, calculate the eigenvalues of its adjacency matrix and obtain the eigenvalue set of the graph , ; Extract statistical features from the eigenvalue set, including mean, variance, maximum and minimum values, and use these statistical features to 、 、 and Indicates; integrate these statistics into a feature vector, recorded as a 4-dimensional spectral feature vector , used to capture the overall structural properties and modularity of the graph.
[0051] The extracted degree distribution, clustering coefficient mean, average path length, graph diameter and spectral features are integrated into a 10-dimensional traditional feature vector .
[0052] When processing multiple images, batch process these features and set the batch size. The size of The traditional feature matrix .
[0053] Optionally, .
[0054] Step 2.2: Use the MSCNN network to extract deep graph features.
[0055] Step 2.2.1: Compute the residual matrix of the graph.
[0056] In graph structure anomaly detection, the residual matrix is used to capture the difference between the actual structure of the graph and the expected background structure. Compared with directly using the adjacency matrix, the residual matrix can highlight the abnormal area more clearly. Therefore, in the deep graph feature extraction stage, the residual matrix of the graph is first calculated. , the specific calculation formula is:
[0057] ;
[0058] in, Represents the adjacency matrix of the graph; The mean matrix represents the average of the adjacency matrices of all normal graphs used, representing the "normal" structure of the network. By comparing the actual adjacency matrix of the graph with the mean matrix, the residual matrix can capture the "abnormal structure" in the graph, making it easier to identify abnormal graphs.
[0059] Step 2.2.2: Use the MSCNN network to construct a deep graph feature extractor.
[0060] like Figure 2 As shown in the figure, a deep graph feature extractor is constructed using the MSCNN network. The extractor consists of two-dimensional convolutional layers (Conv3×3, Conv5×5, and Conv7×7), a nonlinear activation layer (ReLu), a global average pooling layer (AvgPool2d), a linear layer (Linear), and a random dropout layer (Dropout). The residual matrix passes through the deep graph feature extractor to obtain the deep graph features, which can be expressed as follows:
[0061] ;
[0062] in, represents the network operation of the deep graph feature extractor, Represents the extracted deep graph features.
[0063] The network operation process of the deep graph feature extractor specifically includes the following steps:
[0064] Let the residual matrix The data dimension is , and To represent the size dimension of the residual matrix, it represents height and width respectively; to adapt to the network input format, the input residual matrix is processed in the data preprocessing stage. Add a channel dimension to make its dimension become .
[0065] In multi-scale feature extraction, a variety of convolution kernel sizes are used to capture different spatial details to more comprehensively describe the structural characteristics of the input data. Convolution features of different scales are extracted through three two-dimensional convolution layers of different sizes, which are expressed by the following formulas:
[0066] ;
[0067] ;
[0068] ;
[0069] in, express The two-dimensional convolution operation, Indicates passing Features extracted after convolution; express The two-dimensional convolution operation, Indicates passing Features extracted after convolution; express The two-dimensional convolution operation, Indicates passing Features extracted after convolution.
[0070] Then the three different convolution features are obtained 、 、 Through the nonlinear activation layer (ReLu), the extracted features are expressed as 、 and ; In order to enhance the spatial dimension expression of features, the features after the nonlinear activation layer 、 and After a global average pooling layer (AvgPool2d), the global features after pooling are obtained 、 and ; After pooling, the three sets of global features 、 and Concatenate along the channel dimension to form a fused multi-scale feature matrix .
[0071] Next, the multi-scale feature matrix First enter dimensional linear layer (Linear), and then enhance the nonlinear feature representation through the nonlinear activation layer (ReLu); then, randomly discard some neurons through the random inactivation layer (Dropout) to avoid overfitting of the model on the training data; finally, The linear layer (Linear) of dimension 1 processes the features after random inactivation and outputs a size of The deep graph feature matrix .
[0072] Optionally, , , ; .
[0073] Step 2.3: Use dual attention network to perform graph feature fusion.
[0074] As a feature fusion network, the Dual Attention Network (DANet) combines three modules: global attention, local dimension attention, and cross-channel attention. It effectively integrates deep graph features and traditional features through a multi-level weight adjustment mechanism. The dual attention network models the global importance, local weight, and inter-channel dependency of each dimension feature to enhance the expressive power of key features. In the abnormal subgraph detection method, the deep graph feature matrix and the traditional feature matrix The fusion process is:
[0075] See also Figure 4 First, the extracted deep graph feature matrix is transformed into and the traditional feature matrix Splicing is performed on the channel dimension to obtain the overall feature matrix ; Then the overall feature matrix The global weight ratio of deep graph features and traditional features is generated by combining the Multilayer Perceptron (MLP) and the Softmax activation function. ; Next, calculate the local dimension attention weights and perform the deep graph feature matrix and the traditional feature matrix The local dimension attention weight is generated by the corresponding attention network. After sigmoid activation, the two feature matrices each obtain a normalized weight matrix. Then, the two feature matrices are multiplied element-by-element with the corresponding normalized weight matrix to obtain the locally adjusted deep graph feature matrix. and the traditional feature matrix after local adjustment , to highlight key dimensions and suppress redundant dimensions;
[0076] After obtaining the local adjusted deep graph feature matrix and the traditional feature matrix after local adjustment Then, the global weight ratio The part corresponding to the deep graph feature matrix Expanded through the broadcast mechanism to the deep graph feature matrix after local adjustment The matching dimension is recorded as , and then the locally adjusted deep graph feature matrix and Multiply element by element to get the global weighted deep graph feature matrix ; Similarly, the global weight ratio The part corresponding to the traditional feature matrix Expanded through the broadcast mechanism to the traditional feature matrix after local adjustment The matching dimension is recorded as , then Element-wise and locally adjusted traditional feature matrix Multiply to get the traditional feature matrix after global weighting ;
[0077] Finally, the globally weighted deep graph feature matrix And the traditional feature matrix after global weighting Spliced into a whole, expressed as , the concatenated feature matrix Generate channel weights through one-dimensional convolution, apply the channel weights to the splicing features, further optimize the features in the channel dimension, and obtain the final fusion feature matrix .
[0078] Step 3: Construction, training and testing of abnormal subgraph detector.
[0079] Step 3.1: Build an abnormal subgraph detector.
[0080] like Figure 3 As shown in the figure, the constructed abnormal sub-graph detector includes two linear modules (Linear_block), two linear layers (Linear), a nonlinear activation layer (Relu) and a Softmax layer, where each linear module includes a linear layer (Linear), a normalization layer (BatchNorm1d), a nonlinear activation layer (ReLu) and a random inactivation layer (Dropout).
[0081] Fusion feature matrix After passing through the abnormal subgraph detector, the detection result is obtained, which is expressed as follows:
[0082] ;
[0083] in, Represents the operation process of the abnormal subgraph detector; Indicates the abnormal subgraph detection result of the abnormal subgraph detector; if Indicates that the graph has an abnormal subgraph. If Indicates that the graph does not have any abnormal subgraphs.
[0084] Step 3.2: Train an abnormal subgraph detector.
[0085] Still see Figure 4 First, the data in the training set are extracted and fused according to the same method as step 2 to obtain the fusion feature matrix ; Next, the fusion feature matrix Input into the abnormal subgraph detector constructed in step 3.1 to obtain the detection result ; Then, the detection results are analyzed through the loss function Quantify the difference between the actual label and the actual label and calculate the loss function value ; Finally, use the optimizer to calculate the loss function value Optimize the overall parameters, calculate the parameter gradients of each layer in the deep graph feature extractor, dual attention network and abnormal subgraph detector through backpropagation, and update the network parameters according to the adaptive gradient optimization.
[0086] Optionally, the training set includes 320 groups of normal images and abnormal images, the test set includes 80 groups of normal images and abnormal images, the learning rate is set to 0.0005, the epoch is set to 25, and the training uses the cross entropy loss function and the Adam optimizer.
[0087] Repeat the iterative training to complete the training of the abnormal subgraph detector.
[0088] Step 3.3: Test the anomalous subgraph detector.
[0089] First, perform feature extraction and fusion on the data in the test set in the same way as step 2 to obtain the fusion feature matrix , input into the abnormal subgraph detector trained in step 3.2 to generate the corresponding detection results ; By The performance of the abnormal subgraph detector is evaluated by comparing with the true labels of the test set.
[0090] The relationship curve between the abnormal subgraph detection accuracy and the number of iterations of the abnormal subgraph detection method proposed in this invention is shown in the figure: Figure 5 As shown. Figure 5 It can be seen that with the increase in the number of iterations, the detection accuracy of the abnormal subgraph detector gradually increases. When the epoch is 16, the accuracy of abnormal subgraph detection is the highest, with the highest accuracy of 99.25%, indicating that the abnormal subgraph detector after testing can accurately detect abnormal subgraphs.
[0091] In the actual abnormal subgraph detection process, after obtaining the data to be detected, the data to be detected is first subjected to feature extraction and fusion in the same way as step 2 to obtain the fusion feature matrix corresponding to the data to be detected. , and then the fusion feature matrix The data is input into a tested abnormal subgraph detector for detection, and the abnormal subgraph detection result corresponding to the data to be detected is output. Based on the abnormal subgraph detection result, it is determined whether there is an abnormal subgraph in the data to be detected.
[0092] The technical features of the above-mentioned embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above-mentioned embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0093] The above-described embodiments merely illustrate several implementations of the present invention, and while their descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the patent. It should be noted that a person skilled in the art would be able to make numerous variations and improvements without departing from the spirit of the present invention, all of which fall within the scope of protection of the present invention. Therefore, the scope of protection of the patent for this invention shall be determined by the appended claims.
Claims
1. The abnormal subgraph detection method based on fusion features is characterized by: The following steps are involved: Step 1: Construct an abnormal subgraph detection dataset, which includes normal images and abnormal images, and divide the abnormal subgraph detection dataset into a training set and a test set; Step 2: For each graph, extract traditional graph features and deep graph features, and use the dual attention network to fuse the traditional graph features and the deep graph features to obtain a fused feature matrix; Step 3: Construct an abnormal subgraph detector with the fused feature matrix as input, train the abnormal subgraph detector using the training set, test the trained abnormal subgraph detector using the test set, use the tested abnormal subgraph detector to detect the data to be detected, and output the abnormal subgraph detection result.
2. The abnormal subgraph detection method based on fusion features according to claim 1 is characterized in that: The process of extracting the deep graph features using the MSCNN network includes the following steps: Step 2.2.1: Calculate the residual matrix of the graph. The calculation formula is: ; in, Residual matrix representing the graph; Represents the adjacency matrix of the graph; represents the mean of the adjacency matrix of all normal graphs; Step 2.2.2: Use the MSCNN network to construct a deep graph feature extractor, which includes three different sizes of two-dimensional convolutional layers, nonlinear activation layers, global average pooling layers, linear layers and random inactivation layers. The residual matrix The deep graph features are obtained after passing through the deep graph feature extractor.
3. The abnormal subgraph detection method based on fusion features according to claim 2 is characterized in that: The deep graph feature extractor takes the residual matrix of the input The operation process includes the following steps: The residual matrix of the input Perform data preprocessing, add a channel dimension, and add the residual matrix The dimension is ,in, For batch, and Represent the height and width of the residual matrix respectively; Input residual matrix Convolution features of different scales are extracted through three two-dimensional convolution layers of different sizes, which are expressed as follows: ; ; ; in, express The two-dimensional convolution operation, Indicates passing Features extracted after convolution; express The two-dimensional convolution operation, Indicates passing Features extracted after convolution; express The two-dimensional convolution operation, Indicates passing Features extracted after convolution; The three different convolution features obtained 、 、 After passing through the nonlinear activation layer, the features after the nonlinear activation layer 、 and After a global average pooling layer, the global features after pooling are obtained 、 and ; After pooling, the three sets of global features 、 and Splicing along the channel dimension to form a fused multi-scale feature matrix ; The multi-scale feature matrix First enter dimensional linear layer, and then enhance the nonlinear feature representation through the nonlinear activation layer; Randomly drop some neurons through the random inactivation layer; pass The linear layer processes the features after random loss and outputs the deep graph feature matrix .
4. The abnormal subgraph detection method based on fusion features according to any one of claims 1 to 3, characterized in that: The process of fusing the traditional graph features and the deep graph features using the dual attention network to obtain a fused feature matrix includes the following steps: The deep graph feature matrix is transformed into and the traditional feature matrix Splicing is performed on the channel dimension to obtain the overall feature matrix ; The overall feature matrix Through the multi-layer perceptron, combined with the Softmax activation function, the global weight ratio of deep graph features and traditional features is generated ; The deep graph feature matrix and the traditional feature matrix The local dimension attention weight is generated by the corresponding attention network. After sigmoid activation, the two feature matrices each obtain a normalized weight matrix. Then, the two feature matrices are multiplied element by element with the corresponding normalized weight matrix to obtain the locally adjusted deep graph feature matrix. and the traditional feature matrix after local adjustment ; The global weight ratio The part corresponding to the deep graph feature matrix Expanded through the broadcast mechanism to the deep graph feature matrix after local adjustment The matching dimension is recorded as , and then the locally adjusted deep graph feature matrix and Multiply element by element to get the global weighted deep graph feature matrix ; Set the global weight ratio The part corresponding to the traditional feature matrix Expanded through the broadcast mechanism to the traditional feature matrix after local adjustment The matching dimension is recorded as , then the traditional feature matrix after local adjustment will with Multiply element by element to get the traditional feature matrix after global weighting ; The globally weighted deep graph feature matrix And the traditional feature matrix after global weighting Spliced into a whole, expressed as , the concatenated feature matrix Generate channel weights through one-dimensional convolution, apply the channel weights to the splicing features, and obtain the fusion feature matrix .
5. The abnormal subgraph detection method based on fusion features according to any one of claims 1 to 3, characterized in that: The abnormal subgraph detector includes two linear modules, two linear layers, a nonlinear activation layer and a Softmax layer, wherein each linear module includes a linear layer, a normalization layer, a nonlinear activation layer and a random dropout layer.
6. The abnormal subgraph detection method based on fusion features according to claim 5 is characterized in that: The abnormal subgraph detector is trained using the cross entropy loss function and the Adam optimizer.
7. The abnormal subgraph detection method based on fusion features according to any one of claims 1 to 3, characterized in that: The traditional graph features include degree distribution features, clustering coefficient mean features, average path length features, graph diameter features and spectrum features. The extracted degree distribution features, clustering coefficient mean features, average path length features, graph diameter features and spectrum features are integrated into the traditional feature vector , after batch processing the extracted features, the traditional feature matrix is obtained .
8. The abnormal subgraph detection method based on fusion features according to any one of claims 1 to 3, characterized in that: The normal graph is generated by the Chung-Lu model, and the abnormal graph is constructed by embedding the subgraph generated by the Erdos-Renyi model into the normal graph.
9. The abnormal subgraph detection method based on fusion features according to claim 8 is characterized in that: The process of generating the normal map includes the following steps: Set relevant parameters, including the number of nodes in the network , power law distribution index , expected degree , calculate the degree distribution of nodes and generate the connection weights of nodes; The connection probability between each pair of nodes is calculated according to the connection weight of the nodes, an undirected graph is constructed, and a CL graph that conforms to the power-law distribution characteristics is obtained; The adjacency matrix of the generated CL graph is saved as a NumPy format file and marked as a normal graph.
10. The abnormal subgraph detection method based on fusion features according to claim 9 is characterized in that: The process of constructing the anomaly map includes the following steps: Random selection on the CL graph nodes, by setting the edge probability , randomly generate edges between these nodes and construct a subgraph with ER structure, namely ER subgraph; Embed the ER subgraph into the CL graph; Save the adjacency matrix of the CL graph embedded in the ER subgraph as a NumPy format file and mark it as an abnormal graph.
Citation Information
Cited By
Botnet detection method and system based on fusion features
CN122027369A