Malicious traffic detection method based on neural architecture search
By constructing a lightweight malicious traffic detection model through neural architecture search, the problem of high computational complexity in IoT devices is solved, enabling fast and low-resource-consumption malicious traffic detection.
Patent Information
- Application Number
- CN202511442260.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-10
- Publication Date
- 2025-12-05
AI Technical Summary
Existing IoT intrusion detection models mainly rely on manual design, which is computationally complex, resulting in high computational costs and affecting the computing speed of devices.
A malicious traffic detection model is constructed using a neural architecture search-based approach. The neural network is optimized through training and validation sets. By utilizing the evaluation metric of computational multiplication-addition operations, a parameter-saving search space is constructed, enabling a lightweight monitoring model to be quickly searched.
It enables rapid detection of malicious traffic on IoT devices, reduces computing resource consumption, and improves detection efficiency.
Smart Images

Figure CN121077802A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and particularly relates to a malicious traffic detection method based on neural architecture search. BACKGROUND
[0002] The Internet of Things can connect the physical world with the network world. With the development of sensors, embedded networks and wireless networks, the Internet of Things has achieved rapid development. At present, Internet of Things devices have been widely used in smart home, smart medical care, intelligent transportation, industrial manufacturing and public facilities and other fields. With the wide popularity of the Internet of Things, security problems have become increasingly prominent.
[0003] At present, most of the establishment of Internet of Things intrusion detection models are designed by artificial design. Although the performance can be obviously better than other models, various situations are not fully considered. In addition, the model designed by artificial design has high complexity, which leads to high calculation cost and affects the calculation speed of the model on the Internet of Things device in certain cases. SUMMARY
[0004] To solve the above technical problems, the present application provides a malicious traffic detection method based on neural architecture search, which can obtain a malicious traffic detection model with fast running speed and small resource occupation by establishing an Internet of Things intrusion detection model.
[0005] To achieve the above purpose, the present application provides a malicious traffic detection method based on neural architecture search, comprising:
[0006] Constructing a malicious traffic neural network detection model;
[0007] Deploying the malicious traffic neural network detection model to an Internet of Things device, capturing real-time network flow for detection, and judging whether the network flow is malicious traffic according to the detection result;
[0008] The malicious traffic neural network detection model is trained by a training set and obtained by verifying a verification set, and the training set and the verification set are both network flow sets.
[0009] Preferably, the malicious traffic neural network detection model is constructed, comprising:
[0010] Constructing a first network flow set and a second network flow set, i.e. the training set and the verification set;
[0011] Determining the indicators and hyperparameters used for neural architecture search, obtaining a search space and optimizing it;
[0012] According to the search space, a hyperparameter network set, i.e. a population, is randomly generated, and the hyperparameter network set is trained, wherein the hyperparameter network set contains a super parameter network;
[0013] According to the super parameter network in the population, a neural network model corresponding to the super parameter network is built;
[0014] The neural network model is trained by the first network flow set, and the model prediction accuracy is calculated using the second network flow set, to obtain a super parameter network with the best performance, denoted as a parent model;
[0015] Based on the parent model, part of the parameters in the super parameter are randomly changed to obtain a new population, and the training, evaluation and mutation of the new population are repeated for several times until a super parameter network with the best performance is obtained;
[0016] According to the super parameter network with the best performance, a neural network model corresponding thereto is established, and the network parameters are trained using the training set and the verification set to obtain the malicious traffic neural network detection model.
[0017] Preferably, the indicator used in the neural architecture search is the overhead , and the super parameters include stride , kernel size , channel number and repetition number .
[0018] Preferably, the accuracy of the multiply-accumulate operation corresponding to the super parameter network and the neural network model corresponding to the super parameter on the verification set is taken as the evaluation index, and the method for calculating the overhead is:
[0019] ;
[0020] In the formula, is an efficiency factor for controlling the influence of the penalty term on the calculation overhead, represents the number of multiply-add operations for calculating the neural architecture, represents the accuracy of using the verification set under the specified neural architecture and parameters, is the neural architecture to be evaluated, is the parameter of the neural architecture to be evaluated, is the normalization of the multiply-accumulate operation corresponding to the super parameter network in the same search space.
[0021] Preferably, the search space is:
[0022] ;
[0023] In the formula, is the search space.
[0024] Preferably, the method for optimizing the search space is:
[0025] ;
[0026] ;
[0027] wherein, is the overhead of a certain hyperparameter network in the search space, is the hyperparameter obtained from the search space combination, is the neural architecture corresponding to the hyperparameter, is the network parameter of the neural architecture, is the abbreviation of "subject to", which means the maximum value needs to be the minimum value, is the accuracy of the neural network trained using the training set , the parameter is the corresponding parameter.
[0028] Preferably, according to the detection result, it is judged whether the network flow is malicious traffic, comprising:
[0029] inputting the real-time network flow into the malicious traffic neural network detection model to obtain , if the is True, it means that the real-time network flow is malicious traffic, and an alarm is output; if the is False, it means that the real-time network flow is normal traffic, and the monitoring continues.
[0030] Compared with the prior art, the present application has the following advantages and technical effects:
[0031] The present application proposes an evaluation index based on the calculation of multiplication-addition operation, balances the accuracy and inference cost, and at the same time, constructs a parameter-saving search space, which can quickly search out an extremely light monitoring model. BRIEF DESCRIPTION OF DRAWINGS
[0032] The accompanying drawings, which form a part of this application, are included to provide a further understanding of the application and are incorporated herein for explanation
[0033] Figure 1 is a neural architecture search-based malicious traffic detection method flowchart of an embodiment of the present application. DETAILED DESCRIPTION
[0034] It should be noted that the embodiments in the present application and the features in the embodiments can be combined with each other without conflict. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0035] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described herein can be executed in an order different from that shown herein.
[0036] The present application proposes a malicious traffic detection method based on neural architecture search, as shown in Figure 1 , comprising:
[0037] constructing a malicious traffic neural network detection model;
[0038] Specifically, comprising:
[0039] constructing a first network stream set, a second network stream set, i.e. a training set and the validation set;
[0040] determining the indicators and hyperparameters used for neural architecture search, obtaining the search space and optimizing it;
[0041] According to the search space, a set of hyperparameter networks, i.e. a population, is randomly generated and trained, wherein the set of hyperparameter networks contains hyperparameter networks;
[0042] According to the hyperparameter networks in the population, a neural network model corresponding to the hyperparameter networks is built;
[0043] The neural network model is trained by the first network stream set, and the model prediction accuracy is calculated using the second network stream set, to obtain the best hyperparameter network, which is recorded as the parent model;
[0044] Based on the parent model, some parameters in the hyperparameters are randomly changed to obtain a new population, and the new population is repeatedly trained, evaluated and mutated, and the process is repeated for several times until the best hyperparameter network is obtained;
[0045] According to the best hyperparameter network, a neural network model corresponding to it is established, and the network parameters are trained using the training set and the validation set to obtain a malicious traffic neural network detection model.
[0046] Further, the indicators used for neural architecture search are overhead , and the hyperparameters include stride , kernel size , channel number and repetition number .
[0047] The accuracy of the multiplication and accumulation operation corresponding to the hyperparameter network and the neural network model corresponding to the hyperparameter on the validation set is taken as an evaluation index, and the overhead is calculated:
[0048] ;
[0049] In the formula, is an efficiency factor for controlling the influence of the penalty term on the calculation overhead, represents the number of multiplication and addition operations for calculating the neural architecture, represents the accuracy of using the validation set under the specified neural architecture and parameters, is the neural architecture to be evaluated, is the parameter of the neural architecture to be evaluated, is the normalization of the MACCs corresponding to the hyperparameter network in the same search space.
[0050] The search space is:
[0051] ;
[0052] In the formula, is the search space.
[0053] The method for optimizing the search space is:
[0054] ;
[0055] ;
[0056] In the formula, is the overhead corresponding to a hyperparameter network in the search space, is a hyperparameter obtained by combining the search space, is the neural architecture corresponding to the hyperparameter, is the network parameter of the neural architecture, is the abbreviation of "subject to", which means the maximum value needs to be the minimum value, is the accuracy of the neural network trained using the training set under the specified neural architecture and parameters , is corresponding parameter.
[0057] The malicious traffic neural network detection model is deployed in an Internet of Things device to capture real-time network streams for detection, and according to the detection result, it is judged whether the network stream is malicious traffic or not.
[0058] Specifically, according to the detection result, it is judged whether the network flow is malicious traffic, comprising:
[0059] inputting the real-time network flow into the malicious traffic neural network detection model to obtain , if the is True, it indicates that the real-time network flow is malicious traffic, and an alarm is output; if the is False, it indicates that the real-time network flow is normal traffic, and the monitoring continues.
[0060] In order to more clearly express the technical scheme of the present application, the following provides specific embodiments for scheme introduction:
[0061] S1, a first network flow set (hereinafter referred to as "training set") is constructed, which is used for training architecture in the neural architecture search process, denoted as = ;
[0062] wherein, , is the number of network flows in the first network flow set, is the number of data packets in each network flow, .
[0063] S2, a second network flow set (hereinafter referred to as "validation set") is constructed, which is used for verifying the architecture trained in the neural architecture search process, denoted as = ;
[0064] wherein, , is the number of network flows in the second network flow set, is the number of data packets in each network flow, .
[0065] S3, define the index used for neural architecture search: computational overhead , the multiplication and accumulation operation corresponding to the hyperparameter network, the accuracy of the hyperparameter corresponding neural network model on the validation set are taken as evaluation indexes, and the specific form is:
[0066] ;
[0067] wherein, is an efficiency factor for controlling the influence of the penalty term on the computational overhead, represents the number of multiplication and addition operations for calculating the neural architecture, represents the accuracy of using the validation set under the specified neural architecture and parameters, is the neural architecture to be evaluated, Parameters of the neural architecture to be evaluated.
[0068] S4, stride , kernel size , number of channels , number of repetitions As hyperparameters, thus obtaining the search space , denoted as:
[0069] ;
[0070] S5, for the problem of neural architecture search, the target can be defined as a double-layer optimization problem, and the expression of the optimization problem is:
[0071] ;
[0072] wherein, is the overhead corresponding to a hyperparameter network in the search space, is a hyperparameter obtained from the search space combination, is the neural architecture corresponding to the hyperparameter, is the network parameter of the neural architecture;
[0073] ;
[0074] wherein, is the abbreviation of "subject to", which means the maximum value needs to be established at the minimum value, is the accuracy of the neural network trained using the training set , parameters under the specified neural architecture , is the corresponding parameter.
[0075] S6, since the search space is discrete and the parameter is continuous, an evolutionary algorithm is used to solve the optimization problem, and the specific steps are as follows:
[0076] S7, according to the search space , a set of hyperparameter networks is randomly generated, called population, denoted as .
[0077] wherein, the set of hyperparameter networks contains hyperparameter networks, is a parameter set by oneself.
[0078] S8, according to the hyperparameter network in the population, a neural network model corresponding thereto is built, denoted as .
[0079] S9, the neural network model is trained using the training set . .
[0080] S10, the neural network model is evaluated, the validation set is used to calculate the model prediction accuracy, and the computing overhead is calculated.
[0081] S11, the hyperparameter network with the best performance is denoted as , as the parent model.
[0082] S12, based on the parent model , part of the parameters in the hyperparameter network is randomly changed, i.e. mutation, to obtain a new population .
[0083] S13, jump to step S8, repeat the training, evaluation and mutation of the population, repeat C times, and the hyperparameter network with the best performance is denoted as .
[0084] wherein, is a parameter set by oneself.
[0085] S14, according to , a neural network model corresponding thereto is built , and the network parameters are trained using the training set , the validation set .
[0086] S15, after training, the neural network model with the minimum overhead corresponding to the training set and the validation set is obtained .
[0087] S16, the neural network model is deployed to the Internet of Things device, and real-time network flow is captured, denoted as .
[0088] wherein, is the number of network flow segments (referred to as "flow segments").
[0089] S17, the real-time network flow is input into , and is obtained.
[0090] S18, if is True, it indicates that the real-time network flow is malicious traffic, and an alarm is output.
[0091] S19、if If the result is False, it indicates that the real-time network flow is normal traffic, and the monitoring continues at S16.
[0092] Compared with the neural architecture search method taking accuracy as the only standard, the application proposes an evaluation index based on the calculation of the multiplication-add operation, balances the accuracy and the inference cost, and at the same time, constructs a parameter-saving search space, which can quickly search out an extremely light monitoring model.
[0093] The above is only a preferred specific embodiment of the present application, but the protection scope of the present application is not limited thereto, any person skilled in the art can easily think of changes or replacements within the technical range disclosed by the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A method for malicious traffic detection based on neural architecture search, characterized in that, The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic.
2. The method of claim 1, wherein, The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. According to the search space, a set of hyperparameter networks, i.e., a population, is randomly generated and trained, wherein the set of hyperparameter networks contains hyperparameter networks. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic.
3. The method of claim 2, wherein, The indicator used by the neural architecture search is overhead The hyperparameters include stride , kernel size , channel number and repetition number .
4. The method of claim 3, wherein, The application relates to an Internet of Things device and a method for detecting malicious traffic. ; wherein, is an efficiency factor to control the impact of the penalty term on the computation overhead, denotes the number of multiply-add operations for computing the neural architecture, denotes the accuracy using the validation set for the specified neural architecture, parameters, is a neural architecture to be evaluated, is a parameter of the neural architecture to be evaluated, is the corresponding is normalized.
5. The method of claim 3, wherein, The application relates to an Internet of Things device and a method for detecting malicious traffic. ; In the formula, is a search space.
6. The method of claim 5, wherein the method further comprises: The application relates to an Internet of Things device and a method for detecting malicious traffic. ; ; wherein, is the overhead of a certain hyperparameter network in the search space, is the hyperparameter resulting from the search space combination, is the neural architecture corresponding to the hyperparameter, is the network parameter of the neural architecture, is the abbreviation for "subject to" and refers to the maximum value of the minimum value holds, is the accuracy of the neural network trained on the parameters the training set resulting from the training, is the corresponding parameter.
7. The method of claim 1, wherein, The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic. The application relates to an Internet of Things device and a method for detecting malicious traffic inputting the real-time network flow into the malicious traffic neural network detection model to obtain , if the is True, it indicates that the real-time network flow is malicious traffic, and an alarm is output; if the is False, it indicates that the real-time network flow is normal traffic, and the monitoring is continued.
Citation Information
Patent Citations
Method, device and system for designing neural network through NAS
CN112101525A
Hyper-parameter optimization method and system based on genetic algorithm and Gaussian process
CN114118372A
Method and device for searching neural network and storage medium
CN114492767A
Searching method and system for multi-task neural network architecture
CN116258202A
Malicious traffic detection method, system and device and storage medium
CN116599683A