Computer network data information identification system

By employing an edge cloud collaborative architecture and multimodal feature fusion, combined with federated learning and reinforcement learning, the problems of low real-time performance and accuracy in traditional network data identification methods are solved, achieving efficient and secure network data identification.

CN121037031APending Publication Date: 2025-11-28GUANGZHOU COLLEGE OF COMMERCE
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202511140024.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-14
Publication Date
2025-11-28

AI Technical Summary

Technical Problem

Traditional methods for identifying network data information suffer from poor real-time performance, low accuracy, and insufficient data security and privacy protection.

Method used

Data collection is performed using an edge-cloud collaborative architecture. The model is trained by combining multimodal feature fusion and federated learning. The decision-making strategy is optimized using self-attention mechanism and reinforcement learning to achieve collaborative processing and intelligent decision-making of multimodal data.

Benefits of technology

It improves the real-time performance and accuracy of network data identification, reduces data transmission volume and latency, protects data privacy and security, and enhances the system's adaptability and intelligent decision-making capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121037031A_ABST
    Figure CN121037031A_ABST
Patent Text Reader

Abstract

The invention provides a computer network data information identification system, which relates to the technical field of computer network security and data processing and comprises an edge cloud collaborative data acquisition module, a multi-modal feature fusion module, a federated learning dynamic model training module and an intelligent decision and response module. The method has the advantages that the edge cloud collaborative architecture is adopted, data preprocessing and feature extraction are conducted on the network edge, the transmission quantity and delay are reduced, and the real-time performance and the processing efficiency are improved; a self-attention mechanism is used for fusing multi-modal features, so that the recognition accuracy is improved; the data privacy security is protected based on a federated learning framework training model; a reinforcement learning algorithm is introduced to optimize federated learning and decision strategies, and the adaptability and intelligence of the system are enhanced; and response abnormal data can be intelligently dispatched according to an identification result to ensure safe and stable operation of the network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer network security and data processing technology, and in particular to a computer network data information identification system. Background Technology

[0002] With the rapid development of information technology, computer networks are expanding rapidly, and network data is experiencing explosive growth. Not only is the quantity of network data increasing dramatically, but its sources and types are also becoming increasingly diverse, including multiple modalities such as text, images, and video. At the same time, cybersecurity threats are becoming more complex and covert, posing significant challenges to traditional methods of identifying network data information.

[0003] Traditional methods often focus only on the characteristics of a single modality of data, making it difficult to fully capture the inherent relationships and features of network data, resulting in low recognition accuracy. Centralized processing requires uploading a large amount of sensitive data to the cloud, increasing the risk of data leakage. Summary of the Invention

[0004] The purpose of this invention is to provide a computer network data information recognition system that solves the problems of poor real-time performance of network data processing, low recognition accuracy, and insufficient data security and privacy protection in the prior art.

[0005] To achieve the above-mentioned objectives, the technical solution adopted by this invention is as follows:

[0006] A computer network data information identification system, comprising:

[0007] Edge cloud collaborative data acquisition module: It adopts a data acquisition architecture that coordinates edge nodes and cloud servers. The edge nodes are deployed at the network edge to collect multi-source heterogeneous data in real time and perform preliminary filtering and feature extraction. Only key feature data is uploaded to the cloud server.

[0008] Multimodal feature fusion module: used to fuse text features, image features, and temporal features of network data. It uses a self-attention mechanism to build a multimodal feature fusion model, automatically learns the correlation between different modal data and extracts fused features;

[0009] Federated Learning Dynamic Model Training Module: Based on the federated learning framework, this module enables collaborative model training between multiple edge nodes and the cloud server. Each edge node trains an initial recognition model using local data and uploads updated model parameter values ​​to the cloud server. The cloud server aggregates and updates the global model and distributes it to each edge node. At the same time, reinforcement learning algorithms are introduced to optimize the federated learning process.

[0010] Intelligent decision-making and response module: It inputs the fused feature data into the trained deep neural network model for identification, performs traffic scheduling and resource allocation for normal network data based on the identification results, triggers response mechanisms for abnormal data, and optimizes decision-making strategies through reinforcement learning.

[0011] As an improvement, the edge cloud collaborative data acquisition module includes: intelligent acquisition devices deployed at the network edge, including industrial gateways and intelligent routers, for acquiring network traffic data, device status data, and environmental perception data; an edge data preprocessing unit for standardizing the acquired data, detecting outliers, removing invalid data, and extracting key feature data; and an edge server for receiving key feature data uploaded by each edge node, integrating and verifying it before uploading it to the cloud server.

[0012] As an improvement, the multimodal feature fusion module includes: a text feature extraction unit for extracting protocol field text features from network data; an image feature extraction unit for generating and extracting network traffic waveform visualization image features; a time series feature extraction unit for extracting network data packet arrival time series features; and a self-attention fusion unit for calculating attention weights between different modal data based on a self-attention mechanism, and automatically filtering and fusing key features.

[0013] As an improvement, the federated learning dynamic model training module includes: an edge training unit deployed at each edge node, used to train an initial recognition model using local data and generate updated model parameter values; a parameter encryption upload unit, used to encrypt the updated model parameter values ​​and upload them to the cloud server; a secure aggregation unit deployed on the cloud server, which uses a secure aggregation algorithm to aggregate the updated parameter values ​​uploaded by each edge node; a reinforcement learning optimization unit, which dynamically adjusts the aggregation weights of model parameters based on the training data quality and model training effect of each edge node; and a global model distribution unit, which encrypts and distributes the updated global model to each edge node.

[0014] As an improvement, the intelligent decision-making and response module includes: an identification and classification unit that inputs fused feature data into a deep neural network model to identify data categories and determine whether the data is abnormal; a decision execution unit that executes traffic scheduling and resource allocation strategies for normal network data and triggers response measures such as blocking attack sources and isolating affected network areas for abnormal data; a report generation unit that generates security event reports containing attack type, occurrence time, and scope of impact; and a strategy optimization unit that optimizes decision-making strategies based on historical identification data and decision results using reinforcement learning algorithms.

[0015] As an improvement, in the federated learning dynamic model training module, the training cycle for each edge node is once a day.

[0016] As an improvement, when the intelligent decision-making and response module identifies malware propagation behavior, it prioritizes traffic cleaning and isolation to reduce interference with normal business operations while ensuring network security.

[0017] As an improvement, data transmission between the edge nodes and the cloud server uses a 5G network.

[0018] The beneficial effects of this invention are as follows: it adopts an edge-cloud collaborative architecture to preprocess data and extract features at the network edge, reducing transmission volume and latency, and improving real-time performance and processing efficiency; it uses a self-attention mechanism to fuse multimodal features, improving recognition accuracy; it trains models based on a federated learning framework to protect data privacy and security; it introduces reinforcement learning algorithms to optimize federated learning and decision-making strategies, enhancing system adaptability and intelligence; and it can intelligently schedule responses to abnormal data based on recognition results, ensuring the network security and stable operation. Attached Figure Description

[0019] Figure 1 This is a system flowchart of a computer network data information recognition system according to the present invention. Detailed Implementation

[0020] like Figure 1 As shown, a computer network data information identification system includes:

[0021] Edge cloud collaborative data acquisition module: It adopts a data acquisition architecture that combines edge nodes and cloud servers. Edge nodes are deployed at the network edge to collect multi-source heterogeneous data in real time and perform preliminary filtering and feature extraction. Only key feature data is uploaded to the cloud server.

[0022] Multimodal feature fusion module: used to fuse text features, image features, and temporal features of network data. It uses a self-attention mechanism to build a multimodal feature fusion model, automatically learns the correlation between different modal data and extracts fused features;

[0023] Federated Learning Dynamic Model Training Module: Based on the federated learning framework, this module enables collaborative model training between multiple edge nodes and the cloud server. Each edge node trains an initial recognition model using local data and uploads updated model parameter values ​​to the cloud server. The cloud server aggregates and updates the global model and distributes it to each edge node. At the same time, reinforcement learning algorithms are introduced to optimize the federated learning process.

[0024] Intelligent decision-making and response module: It inputs the fused feature data into the trained deep neural network model for identification, performs traffic scheduling and resource allocation for normal network data based on the identification results, triggers response mechanisms for abnormal data, and optimizes decision-making strategies through reinforcement learning.

[0025] The edge-cloud collaborative data acquisition module includes: intelligent acquisition devices deployed at the network edge, including industrial gateways and intelligent routers, used to collect network traffic data, device status data, and environmental perception data; an edge data preprocessing unit used to standardize the collected data, detect outliers, remove invalid data, and extract key feature data; and an edge server used to receive key feature data uploaded from each edge node, integrate and verify it, and then upload it to the cloud server. The multimodal feature fusion module includes: a text feature extraction unit used to extract protocol field text features from network data; an image feature extraction unit used to generate and extract network traffic waveform visualization image features; a time-series feature extraction unit used to extract network data packet arrival time-series features; and a self-attention fusion unit used to calculate attention weights between different modalities based on a self-attention mechanism, automatically filtering and fusing key features. The federated learning dynamic model training module includes: an edge training unit deployed at each edge node used to train the initial recognition model using local data. The system includes: a model identification and parameter update unit, a parameter encryption upload unit, a secure aggregation unit deployed on the cloud server, and a reinforcement learning optimization unit, which dynamically adjusts the aggregation weights of model parameters based on the training data quality and model training effect of each edge node; a global model distribution unit, which encrypts and distributes the updated global model to each edge node; and an intelligent decision-making and response module, which includes: a classification unit, which inputs fused feature data into a deep neural network model to identify data categories and determine whether they are abnormal data; a decision execution unit, which executes traffic scheduling and resource allocation strategies for normal network data and triggers response measures such as blocking attack sources and isolating affected network areas for abnormal data; a report generation unit, which generates security event reports containing attack type, occurrence time, and impact range; and a strategy optimization unit, which optimizes decision-making strategies based on historical identification data and decision results using reinforcement learning algorithms.

[0026] In the federated learning dynamic model training module, the training cycle for each edge node is once a day.

[0027] When the intelligent decision-making and response module identifies malware propagation behavior, it prioritizes traffic scrubbing and isolation to ensure network security while minimizing interference with normal business operations.

[0028] Data transmission between edge nodes and cloud servers uses a 5G network.

[0029] In use, network traffic data, device status data, and environmental perception data are first collected in real time by intelligent acquisition devices such as industrial gateways and smart routers deployed at the network edge. The edge data preprocessing unit standardizes the collected data, detects outliers, extracts key feature data, and uploads it to the edge server. After integration and verification, it is then transmitted to the cloud server. The multimodal feature fusion module starts working. The text feature extraction unit extracts protocol field text features from the network data. The image feature extraction unit generates and extracts network traffic waveform visualization image features. The time series feature extraction unit extracts network data packet arrival time series features. The self-attention fusion unit calculates the attention weights between different modal data based on the self-attention mechanism to achieve automatic selection and fusion of key features. In the federated learning dynamic model training module, the edge training unit of each edge node trains the initial recognition model daily based on local data. The generated model is then used to train the initial recognition model. The updated parameter values ​​are encrypted by the parameter encryption upload unit and then transmitted to the cloud server. The cloud-based security aggregation unit uses a secure aggregation algorithm to aggregate the data. The reinforcement learning optimization unit dynamically adjusts the aggregation weights based on the training data quality and model training effect of each edge node. Finally, the global model distribution unit encrypts and distributes the updated global model to each edge node. The intelligent decision-making and response module receives the fused feature data, and the identification and classification unit inputs it into the deep neural network model to determine the data category and whether it is abnormal. If it is normal network data, the decision execution unit executes traffic scheduling and resource allocation strategies. If it is abnormal data, it immediately triggers response measures such as blocking the attack source and isolating the affected network area. At the same time, the report generation unit generates a security event report. The strategy optimization unit optimizes subsequent decision strategies based on historical data and decision results through reinforcement learning algorithms, thereby ensuring the efficient, stable, and secure operation of the entire computer network data information identification system.

[0030] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A computer network data information recognition system, characterized by, Comprise: Edge cloud cooperative data acquisition module: an edge node and a cloud server cooperative data acquisition architecture is adopted, the edge node is deployed at the network edge, used for real-time acquisition of multi-source heterogeneous data and preliminary filtering and feature extraction, only the key feature data is uploaded to the cloud server; Multi-modal feature fusion module: for fusing text features, image features and time series features of network data, a multi-modal feature fusion model is constructed using a self-attention mechanism, which automatically learns the correlation between different modal data and extracts fusion features; Federal learning dynamic model training module: based on the federal learning framework, the model cooperative training between multiple edge nodes and the cloud server is realized, each edge node trains an initial identification model using local data and uploads model parameter update values to the cloud server, the cloud server aggregates and updates the global model and distributes it to each edge node, and a reinforcement learning algorithm is introduced to optimize the federal learning process; Intelligent decision and response module: the fused feature data is input into the trained deep neural network model for identification, the normal network data is scheduled and resource allocated according to the identification result, the response mechanism is triggered for abnormal data, and the decision strategy is optimized through reinforcement learning.

2. The computer network data information recognition system of claim 1, wherein, The edge cloud cooperative data acquisition module comprises: intelligent acquisition equipment, deployed at the network edge, including industrial gateway, intelligent router, used for acquiring network traffic data, device state data, environment perception data; edge data preprocessing unit, used for standardizing the collected data, detecting outliers, removing invalid data and extracting key feature data; edge server, used for receiving key feature data uploaded by each edge node, integrating and checking, and uploading to the cloud server.

3. The computer network data information recognition system of claim 1, wherein, The multi-modal feature fusion module comprises: a text feature extraction unit for extracting protocol field text features in network data; an image feature extraction unit for generating and extracting network traffic waveform visualization image features; a time series feature extraction unit for extracting network packet arrival time sequence features; a self-attention fusion unit for calculating attention weights between different modal data based on a self-attention mechanism, automatically filtering and fusing key features.

4. The computer network data information recognition system of claim 1, wherein, The federal learning dynamic model training module comprises: an edge training unit deployed at each edge node, used for training an initial identification model using local data and generating model parameter update values; a parameter encryption upload unit for encrypting and uploading model parameter update values to the cloud server; a secure aggregation unit deployed at the cloud server, using a secure aggregation algorithm to aggregate parameter update values uploaded by each edge node; a reinforcement learning optimization unit for dynamically adjusting model parameter aggregation weights according to the training data quality and model training effect of each edge node; a global model distribution unit for encrypting and distributing the updated global model to each edge node.

5. The computer network data information recognition system of claim 1, wherein, The intelligent decision and response module comprises: an identification and classification unit, which inputs the fused feature data into a deep neural network model, identifies the data category and determines whether the data is abnormal; a decision execution unit, which executes traffic scheduling and resource allocation strategies on normal network data, and triggers response measures such as blocking attack sources and isolating affected network areas on abnormal data; a report generation unit, which generates a security event report containing attack type, occurrence time and influence range; and a strategy optimization unit, which optimizes the decision strategy through reinforcement learning algorithm based on historical identification data and decision results.

6. The computer network data information recognition system of claim 1, wherein, In the federated learning dynamic model training module, the training cycle of each edge node is once a day.

7. The computer network data information recognition system of claim 1, wherein, When the intelligent decision and response module identifies the malicious software propagation behavior, it preferentially adopts the traffic cleaning and isolation method to ensure network security while reducing interference to normal business.

8. The computer network data information recognition system of claim 1, wherein, Data transmission between the edge node and the cloud server adopts 5G network.

Citation Information

Cited By

  • Power distribution network hidden danger monitoring method and system based on cloud edge and end detection cooperation

    CN121886717A

  • Power distribution network hidden danger monitoring method and system based on cloud edge-end inspection cooperation

    CN121886717B