Network attack detection method, device, equipment, medium and computer program product

By training a network attack detection model in a remote cloud center and fine-tuning it on IoT edge devices, the problem of insufficient detection accuracy and flexibility in IoT devices is solved, enabling rapid detection and improved adaptability against unknown attacks.

CN120979704APending Publication Date: 2025-11-18INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511061067.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-30
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

Existing technologies for network attack detection in IoT devices have the problem of high detection accuracy but poor flexibility, and deep learning-based methods face the challenge of limited computing and storage resources when deployed on IoT edge devices.

Method used

By performing multi-dimensional feature extraction and fusion processing in a remote cloud center, a network attack detection model is trained offline and then distributed to IoT edge devices for fine-tuning. The lightweight model is adapted to the computing resources of the edge devices, and the adaptability of the detection model is improved by combining dynamic learning rate updates.

Benefits of technology

It enables rapid network attack detection in the IoT environment, improves the ability to detect unknown attacks, and adapts to the computing and storage limitations of IoT edge devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120979704A_ABST
    Figure CN120979704A_ABST
Patent Text Reader

Abstract

The invention relates to the field of network attack detection, and provides a network attack detection method, device and equipment, a medium and a computer program product, and the method comprises the steps: carrying out the multi-dimensional feature extraction and fusion processing of collected data flow, and obtaining data flow features; identifying the data stream features based on a network attack detection model to obtain a known network attack result; the network attack detection model is obtained by performing offline training on source domain data of a remote cloud center; issuing the network attack detection model to an Internet of Things edge device, and performing fine tuning on the network attack detection model based on a monitoring network data packet corresponding to the Internet of Things edge device; and determining an unknown network attack result based on the fine-tuned detection model. According to the invention, rapid detection of network attacks in the Internet of Things environment is realized, and the detection capability of unknown attacks is also improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network attack detection, and more particularly to a network attack detection method, apparatus, equipment, medium, and computer program product. Background Technology

[0002] In terms of security attack detection for IoT devices, current solutions mainly rely on statistical analysis or deep learning-based methods to detect known cybersecurity threats. For example, statistical analysis methods are used to collect and analyze the size, frequency, and quantity of data traffic in the IoT, identifying abnormal traffic to detect cyberattacks; deep learning-based methods are used to extract and analyze the high-dimensional features of data traffic in the IoT to detect attack threats.

[0003] However, while statistical analysis-based methods achieve high accuracy in detecting certain types of attacks, they lack flexibility. Deep learning-based methods employ improved model iteration strategies and memory-based optimization methods to obtain intrusion detection models for IoT sensing layer networks, enabling the detection of Advanced Persistent Threat (APT) attacks. However, the heterogeneity of IoT edge devices and limited computing and storage resources present challenges to the practical deployment of these highly complex models. Summary of the Invention

[0004] This invention provides a network attack detection method, apparatus, device, medium, and computer program product to solve the aforementioned problems existing in existing network security attack detection methods.

[0005] This invention provides a method for detecting network attacks, comprising the following steps: The collected data flow is subjected to multi-dimensional feature extraction and fusion processing to obtain data flow features; The data stream features are identified based on a network attack detection model to obtain known network attack results; the network attack detection model is obtained through offline training using source domain data from a remote cloud center. The network attack detection model is distributed to IoT edge devices, and the network attack detection model is fine-tuned based on the monitoring network data packets corresponding to the IoT edge devices. The results of unknown network attacks are determined based on the fine-tuned detection model.

[0006] According to a network attack detection method provided by the present invention, the multi-dimensional feature extraction and fusion processing of the collected data traffic to obtain data flow features includes: The collected traffic data packets are segmented and extracted according to the session to obtain the traffic data packets for each session; Feature extraction is performed on the traffic data packets of each session to obtain data flow features.

[0007] According to a network attack detection method provided by the present invention, the step of extracting features from the traffic data packets of each session to obtain data stream features includes: Obtain the header information of the traffic data packets for each session, and extract features from the header information to obtain the data packet header features; Obtain the data load information of the traffic data packets for each session, and extract features from the data load information to obtain data load features; The packet header features and the data payload features are fused to obtain the packet features for each session; Data flow characteristics are determined based on the packet characteristics of each session.

[0008] According to a network attack detection method provided by the present invention, the step of determining data flow characteristics based on packet characteristics of each session includes: Context features are extracted from the data packet features of all sessions to obtain data packet context features; The data packet context features are fused to obtain data stream features.

[0009] According to a network attack detection method provided by the present invention, the network attack detection method further includes: Collect network traffic within the source domain and label attack samples within the network traffic; Adapt lightweight models to the computing resources of IoT edge devices; A network attack detection model is obtained by training a lightweight model adapted to computing resources based on an optimized training strategy; the optimized training strategy is determined based on the attack samples.

[0010] According to a network attack detection method provided by the present invention, the step of fine-tuning the network attack detection model based on the monitoring network data packets corresponding to the IoT edge device includes: Attack-related features are extracted from the monitoring network data packets collected by the IoT edge devices; Based on the attack-related features, the parameters of each processing layer of the network attack detection model are fine-tuned in a differentiated manner. The network attack detection model is updated based on a dynamically adjusted learning rate.

[0011] The present invention also provides a network attack detection device, comprising the following modules: The data stream feature determination module is used to perform multi-dimensional feature extraction and fusion processing on the collected data stream to obtain data stream features; The known network attack identification module is used to identify the features of the data stream based on the network attack detection model to obtain known network attack results; the network attack detection model is obtained through offline training using source domain data from a remote cloud center; The model fine-tuning module is used to distribute the network attack detection model to the IoT edge device and fine-tune the network attack detection model based on the monitoring network data packets corresponding to the IoT edge device. The unknown network attack detection module is used to determine the results of unknown network attacks based on a fine-tuned detection model.

[0012] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and running on the processor, wherein the processor executes the computer program to implement any of the network attack detection methods described above.

[0013] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the network attack detection method as described above.

[0014] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements any of the network attack detection methods described above.

[0015] The network attack detection method, apparatus, device, medium, and computer program product provided by this invention trains a network attack detection model offline using source domain data from a remote cloud center. Then, it performs multi-dimensional feature extraction and fusion processing on the collected data traffic to obtain data flow features. These features are then identified using the trained network attack detection model to determine known network attack results. The trained model is then distributed to IoT edge devices, where the model is fine-tuned using network data packets collected by the edge devices. Finally, the fine-tuned model is used to detect unknown network attacks. This invention enables rapid network attack detection in an IoT environment and improves the ability to detect unknown attacks. Attached Figure Description

[0016] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0017] Figure 1 This is one of the flowcharts of the network attack detection method provided by the present invention.

[0018] Figure 2 This is the second flowchart of the network attack detection method provided by the present invention.

[0019] Figure 3 This is a schematic diagram of the network attack detection device provided by the present invention.

[0020] Figure 4 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation

[0021] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0022] The following is combined Figures 1-4 This invention describes the network attack detection method, apparatus, device, medium, and computer program product.

[0023] Figure 1 This is one of the flowcharts illustrating the network attack detection method provided by the present invention, such as... Figure 1 As shown, the method includes the following: Step 100: Perform multi-dimensional feature extraction and fusion processing on the collected data flow to obtain data flow features; Before collecting network traffic (data traffic), offline training of the attack threat detection model in the source domain is first performed at a resource-rich remote cloud center, based on multi-dimensional feature extraction and fusion analysis of source domain data (known attack data from the cloud center). The main processes of offline training include: preprocessing operations such as cleaning the data traffic collected from the remote cloud center; segmenting and extracting the cleaned traffic packets according to sessions to obtain the traffic packets for each session; and then obtaining data stream features through traffic packet spatial feature extraction and traffic packet context feature extraction.

[0024] Step 200: Identify the data stream features based on the network attack detection model to obtain known network attack results; the network attack detection model is obtained through offline training using source domain data from a remote cloud center; By inputting data stream features into an offline-trained network attack detection model for attack identification, known attack threats in the Internet of Things (IoT) environment can be identified, and known network attack results can be obtained.

[0025] Step 300: Distribute the network attack detection model to the IoT edge device, and fine-tune the network attack detection model based on the monitoring network data packets corresponding to the IoT edge device; Step 400: Determine the results of unknown network attacks based on the fine-tuned detection model.

[0026] Specifically, the threat detection model trained in the remote cloud center is distributed to IoT edge devices. An online update and maintenance method based on transfer learning is adopted. By using the target domain (e.g., real-time network traffic and device behavior logs) to monitor network packets in real time, the distributed network attack detection model is updated and fine-tuned, which will further improve the accuracy of attack detection and enhance the model's ability to detect unknown attacks.

[0027] This embodiment trains a network attack detection model offline using source domain data from a remote cloud center. Then, it performs multi-dimensional feature extraction and fusion processing on the collected data traffic to obtain data flow features. These features are then used by the trained network attack detection model to identify known network attacks. The trained model is then distributed to IoT edge devices, where the model is fine-tuned using network data packets collected by these devices. Finally, the fine-tuned model is used to detect unknown network attacks. This invention enables rapid network attack detection in an IoT environment and improves the ability to detect unknown attacks.

[0028] In one embodiment, the network attack detection method provided by this invention may further include: Step 110: Segment and extract the collected traffic data packets according to the session to obtain the traffic data packets for each session; Step 120: Extract features from the traffic data packets of each session to obtain data flow features.

[0029] Specifically, the data traffic collected from the remote cloud center is preprocessed by cleaning, and the cleaned traffic data packets are segmented and extracted according to sessions to obtain the traffic data packets for each session.

[0030] For each session's data packets, the packet header information is extracted, and then a feature extraction algorithm is used to extract features from the header information to obtain the data packet header features. For each data packet in each session, the data payload information is extracted, and a feature extraction algorithm is used to extract and compress features from the data payload information to obtain the data payload features. The obtained data packet header features and data payload features are then fused to obtain the complete data packet features. For the data packet features of all sessions, the feature extraction unit further performs feature extraction and fusion to obtain the data stream features of all sessions.

[0031] This embodiment completes the offline training of the attack threat detection model in the source domain by performing multi-dimensional feature extraction and fusion analysis on traffic data packets.

[0032] Figure 2 This is the second flowchart of the network attack detection method provided by the present invention, as shown below. Figure 2 As shown, the method may further include: Step 121: Obtain the header information of the traffic data packets for each session, and perform feature extraction on the header information to obtain the data packet header features; Step 122: Obtain the data load information of the traffic data packets for each session, and perform feature extraction on the data load information to obtain data load features; Step 123: Fuse the packet header features with the data payload features to obtain the packet features for each session; Step 124: Determine data flow characteristics based on packet characteristics of each session.

[0033] Specifically, for each session's data packets, the packet header information is extracted, and then a feature extraction algorithm is used to extract features from the packet header information to obtain the data packet header features. For each data packet in each session, data payload information is extracted. A feature extraction algorithm is then used to extract and compress features from the data payload information, thereby obtaining the data payload features. ; the obtained data packet header characteristics With data load characteristics By fusing the data packets, complete data packet characteristics can be obtained. .

[0034] Packet characteristics for all sessions The feature extraction unit further extracts and fuses features to obtain the data stream features of all sessions. .

[0035] This embodiment obtains data flow features by acquiring information and extracting features from the traffic data packets of each session, fusing the extracted packet header features with the data payload features and extracting the context.

[0036] In one embodiment, the network attack detection method provided by this invention may further include: Step 124-1: Extract context features from the data packet features of all sessions to obtain data packet context features; Step 124-2: Fuse the context features of the data packets to obtain data flow features.

[0037] Specifically, in network traffic analysis, the core objective of traffic packet context feature extraction is to capture the correlation information across packets and sessions, transforming isolated traffic packets into "data flow features" with global contextual significance, thereby more accurately identifying abnormal behaviors (such as attacks and data leaks) or optimizing network management.

[0038] Existing traffic analysis methods often focus on the static characteristics of individual data packets (e.g., source IP, destination port, and protocol type). However, network attacks or abnormal traffic often exhibit anomalous patterns across data packets (e.g., abnormal packet order and covert communication between sessions). Contextual features, by mining the temporal, logical, or semantic relationships between data packets, transform "isolated points" into "chains" or "graphs," improving the comprehensiveness of detection. For example, malware might evade single-packet detection by fragmenting multiple small data packets; contextual features can capture the complete payload characteristics after fragmentation and reassembly. APT attacks often proceed through multi-stage sessions; contextual features can identify the temporal relationships between sessions.

[0039] The main steps for extracting context features from traffic data packets are as follows: 1. (Data Preprocessing) From collected traffic data packets to structured features. Parse the traffic data packets into structured feature vectors.

[0040] 2. (Feature Extraction) includes three modules: basic feature extraction, temporal / logical context modeling, and multimodal fusion. These three modules upgrade single-packet features to data stream features.

[0041] Basic feature extraction: including traffic identification features, behavioral pattern features, and content attribute features; Temporal / logical context modeling: capturing the dynamic correlation between data packets; Multimodal fusion: network traffic usually contains multiple protocols or sessions, requiring the integration of multi-source information through fusion strategies.

[0042] 3. (Output Data Stream Features) Through the above modules, the collected traffic data packets are transformed into multi-dimensional context data stream features.

[0043] Multi-dimensional contextual data stream features include: low-dimensional session metadata, such as source IP, destination IP, session duration, number of packets, and total traffic; mid-dimensional time-series dynamic features, such as the mean / variance of time intervals between packets and the rate of change in packet size; mid-dimensional content association features, such as payload entropy, keyword matching score, and anomaly degree of protocol-specific fields; and high-dimensional cross-session association features, including the number of historical abnormal sessions with the same source IP and the proportion of cross-protocol traffic.

[0044] This embodiment extracts multi-dimensional contextual data stream features from the collected traffic data packets to obtain the data stream features to be identified.

[0045] In one embodiment, the network attack detection method provided by this invention may further include: Step 10: Collect network traffic within the source domain and label attack samples in the network traffic; Step 20: Adapt the lightweight model to the computing resources of IoT edge devices; Step 30: Train a lightweight model adapted to computing resources based on an optimized training strategy to obtain a network attack detection model; the optimized training strategy is determined based on the attack samples.

[0046] Specifically, the goal of offline training for network attack detection models is to train a base model using source domain data (large-scale known attack data) and extract general features of network attack behavior. This includes data collection and annotation, model architecture selection, and training strategy optimization.

[0047] Data collection and labeling: Collect network attack threat data (e.g., historical attack logs and vulnerability exploitation samples) from remote cloud centers, covering common network attack types; combine threat intelligence to label attack tags (including normal tags or malicious tags) to address the data needs of supervised learning.

[0048] Model architecture selection: A lightweight backbone network is adopted to adapt to the computing resources of edge devices; if processing time-series data (such as network traffic sequences), LSTM or lightweight Transformer can be selected to extract time-dependent features.

[0049] Training strategy optimization: For imbalanced data (e.g., the proportion of normal samples is too high), weighted learning weights of attack samples can be used; regularization is introduced to prevent overfitting and ensure that the trained model can generalize to unseen attack patterns.

[0050] This embodiment builds a detection model for detecting known network attacks by pre-training in a remote cloud center.

[0051] In one embodiment, the network attack detection method provided by this invention may further include: Step 310: Extract attack-related features from the monitoring network data packets collected by the IoT edge device; Step 320: Based on the attack-related features, fine-tune the parameters of each processing layer of the network attack detection model. Step 330: Update the network attack detection model based on the dynamically adjusted learning rate.

[0052] Specifically, the network attack detection model trained offline in the remote cloud center is distributed to IoT edge devices. The network attack detection model is then fine-tuned by monitoring network data packets collected in real time by the IoT edge devices. The goal is to improve the detection capability of unknown attacks by using network data packets monitored in real time by edge devices and fine-tuning the model through transfer learning.

[0053] The process includes data collection and preprocessing, migration layer selection, online fine-tuning strategy, and model evaluation. Data collection and preprocessing: Real-time acquisition of network traffic and device logs from edge devices, and extraction of attack-related features; Migration layer selection: Fixing the bottom feature extraction layer of the network attack detection model, and fine-tuning only the top classifier; Online fine-tuning strategy: Employing incremental learning, updating the model with only a small amount of new data each time; Model evaluation: Real-time evaluation of the detection accuracy and recall of the updated model; if performance degradation exceeds a threshold (e.g., accuracy less than 90%), rolling back to the previous model version.

[0054] Through the above model fine-tuning process, a dynamically updated network attack detection model (applied to edge devices) is obtained.

[0055] This embodiment utilizes network data packets monitored in real time by edge devices and fine-tunes the model through transfer learning to improve the detection capability of unknown network attacks.

[0056] The network attack detection device provided by the present invention is described below. The network attack detection device described below can be referred to in correspondence with the network attack detection method described above.

[0057] Please refer to Figure 3 The present invention also provides a network attack detection device, comprising: The data flow feature determination module 301 is used to perform multi-dimensional feature extraction and fusion processing on the collected data flow to obtain data flow features; The network attack identification module 302 is used to identify the features of the data stream based on the network attack detection model to obtain known network attack results; the network attack detection model is obtained through offline training using source domain data from a remote cloud center. The model fine-tuning module 303 is used to distribute the network attack detection model to the Internet of Things (IoT) edge device and fine-tune the network attack detection model based on the monitoring network data packets corresponding to the IoT edge device. The unknown network attack detection module 304 is used to determine the results of unknown network attacks based on the fine-tuned detection model.

[0058] Optionally, the data stream feature determination module includes: The traffic data packet determination unit is used to segment and extract the collected traffic data packets according to the session to obtain the traffic data packets for each session; The data flow feature determination unit is used to extract features from the traffic data packets of each session to obtain data flow features.

[0059] Optionally, the data stream feature determination unit includes: The packet header feature extraction unit is used to obtain the packet header information of the traffic packets of each session, and to extract features from the packet header information to obtain packet header features; The data load feature extraction unit is used to obtain the data load information of the traffic data packets of each session, and to extract the data load features from the data load information to obtain data load features. The feature fusion unit is used to fuse the packet header features and the data payload features to obtain the packet features for each session; The data stream feature extraction unit is used to determine data stream features based on the packet features of each session.

[0060] Optionally, determining the data stream characteristics based on the packet characteristics of each session includes: The context feature extraction unit is used to extract context features from the data packet features of all sessions to obtain data packet context features; The context feature fusion unit is used to fuse the context features of the data packet to obtain data flow features.

[0061] Optionally, the network attack detection method further includes: An attack sample labeling module is used to collect network traffic within the source domain and label attack samples in the network traffic. The model adaptation module is used to adapt lightweight models to the computing resources of IoT edge devices. The model training module is used to train a lightweight model adapted to computing resources based on an optimized training strategy to obtain a network attack detection model; the optimized training strategy is determined based on the attack samples.

[0062] Optionally, the model fine-tuning module includes: An attack-related feature extraction unit is used to extract attack-related features from monitoring network data packets collected by the IoT edge device; The differential fine-tuning unit is used to perform differential fine-tuning of the parameters of each processing layer of the network attack detection model based on the attack-related features. A network attack detection model update unit is used to update the network attack detection model based on a dynamically adjusted learning rate.

[0063] Figure 4 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 4 As shown, the electronic device may include a processor 410, a communications interface 420, a memory 430, and a communication bus 440, wherein the processor 410, communications interface 420, and memory 430 communicate with each other via the communication bus 440. The processor 410 can call logical instructions in the memory 430 to execute a network attack detection method. This method includes: performing multi-dimensional feature extraction and fusion processing on the collected data traffic to obtain data flow features; identifying the data flow features based on a network attack detection model to obtain known network attack results; the network attack detection model is obtained through offline training using source domain data from a remote cloud center; distributing the network attack detection model to IoT edge devices; fine-tuning the network attack detection model based on the monitoring network data packets corresponding to the IoT edge devices; and determining unknown network attack results based on the fine-tuned detection model.

[0064] Furthermore, the logical instructions in the aforementioned memory 430 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0065] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the network attack detection method provided by the above methods. The method includes: performing multi-dimensional feature extraction and fusion processing on the collected data traffic to obtain data flow features; identifying the data flow features based on a network attack detection model to obtain known network attack results; the network attack detection model is obtained through offline training using source domain data from a remote cloud center; distributing the network attack detection model to an IoT edge device; fine-tuning the network attack detection model based on the monitoring network data packets corresponding to the IoT edge device; and determining unknown network attack results based on the fine-tuned detection model.

[0066] In another aspect, the present invention also provides a non-transitory computer-readable storage medium storing a computer program thereon. When executed by a processor, the computer program implements the network attack detection method provided by the above methods. The method includes: performing multi-dimensional feature extraction and fusion processing on the collected data traffic to obtain data flow features; identifying the data flow features based on a network attack detection model to obtain known network attack results; the network attack detection model is obtained through offline training using source domain data from a remote cloud center; distributing the network attack detection model to an IoT edge device; fine-tuning the network attack detection model based on the monitoring network data packets corresponding to the IoT edge device; and determining unknown network attack results based on the fine-tuned detection model.

[0067] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0068] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0069] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for detecting network attacks, characterized in that, include: The collected data flow is subjected to multi-dimensional feature extraction and fusion processing to obtain data flow features; The data stream features are identified based on a network attack detection model to obtain known network attack results; the network attack detection model is obtained through offline training using source domain data from a remote cloud center. The network attack detection model is distributed to IoT edge devices, and the network attack detection model is fine-tuned based on the monitoring network data packets corresponding to the IoT edge devices. The results of unknown network attacks are determined based on the fine-tuned detection model.

2. The network attack detection method according to claim 1, characterized in that, The multi-dimensional feature extraction and fusion processing of the collected data flow yields the following data flow features: The collected traffic data packets are segmented and extracted according to the session to obtain the traffic data packets for each session; Feature extraction is performed on the traffic data packets of each session to obtain data flow features.

3. The network attack detection method according to claim 2, characterized in that, The feature extraction of traffic data packets for each session to obtain data stream features includes: Obtain the header information of the traffic data packets for each session, and extract features from the header information to obtain the data packet header features; Obtain the data load information of the traffic data packets for each session, and extract features from the data load information to obtain data load features; The packet header features and the data payload features are fused to obtain the packet features for each session; Data flow characteristics are determined based on the packet characteristics of each session.

4. The network attack detection method according to claim 3, characterized in that, The determination of data stream characteristics based on packet characteristics for each session includes: Context features are extracted from the data packet features of all sessions to obtain data packet context features; The data packet context features are fused to obtain data stream features.

5. The network attack detection method according to claim 1, characterized in that, The network attack detection method further includes: Collect network traffic within the source domain and label attack samples within the network traffic; Adapt lightweight models to the computing resources of IoT edge devices; A network attack detection model is obtained by training a lightweight model adapted to computing resources based on an optimized training strategy; the optimized training strategy is determined based on the attack samples.

6. The network attack detection method according to claim 1, characterized in that, The fine-tuning of the network attack detection model based on the monitoring network data packets corresponding to the IoT edge device includes: Attack-related features are extracted from the monitoring network data packets collected by the IoT edge devices; Based on the attack-related features, the parameters of each processing layer of the network attack detection model are fine-tuned in a differentiated manner. The network attack detection model is updated based on a dynamically adjusted learning rate.

7. A network attack detection device, characterized in that, include: The data stream feature determination module is used to perform multi-dimensional feature extraction and fusion processing on the collected data stream to obtain data stream features; The known network attack identification module is used to identify the features of the data stream based on the network attack detection model to obtain known network attack results; the network attack detection model is obtained through offline training using source domain data from a remote cloud center; The model fine-tuning module is used to distribute the network attack detection model to the IoT edge device and fine-tune the network attack detection model based on the monitoring network data packets corresponding to the IoT edge device. The unknown network attack detection module is used to determine the results of unknown network attacks based on a fine-tuned detection model.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the network attack detection method as described in any one of claims 1 to 6.

9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the network attack detection method as described in any one of claims 1 to 6.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the network attack detection method as described in any one of claims 1 to 6.