信息网络安全 ›› 2026, Vol. 26 ›› Issue (8): 1290-1307.doi: 10.3969/j.issn.1671-1122.2026.08.010
收稿日期:2026-05-31
出版日期:2026-08-10
发布日期:2026-09-23
通讯作者:
刘光华
E-mail:guanghualiu@hust.edu.cn
作者简介:朱慧敏(2005—),女,河南,硕士研究生,主要研究方向为弱网安全|王晨龙(2000—),男,河南,博士研究生,主要研究方向为弱网安全、无线传感器网络、图异常检测|刘光华(1991—),男,江西,副教授,博士,主要研究方向为磁感应通信和探测、地下及水下通信、弱网安全
基金资助:
Zhu Huimin, Wang Chenlong, Liu Guanghua(
)
Received:2026-05-31
Online:2026-08-10
Published:2026-09-23
Contact:
Liu Guanghua
E-mail:guanghualiu@hust.edu.cn
摘要:
无线弱链路传感器网络(弱网)长期部署于地下空间、管道系统及复杂工业环境,其通信链路易受降雨、高湿、障碍物遮挡及介质衰减影响,导致链路质量波动与数据丢包。弱网中传感器节点的异常传输行为,既可能由外部环境变化引起,也可能源于恶意节点的选择性转发、丢包或篡改等攻击。由于两类因素在观测层面表现相似,传统方法难以有效区分,限制了复杂场景下的异常识别能力。为此,文章提出双图变分时序模型(DGVT)。其中,环境协同变化图刻画降雨、高湿等引发的节点协同波动,通信链路质量图表征节点间正常通信或攻击下的链路质量与转发关系。模型采用变分图自编码器学习节点结构表示,时序模型捕捉异常行为演化过程,多标签预测层输出环境协同异常与攻击异常两类非互斥标签。实验结果表明,DGVT在精准率、召回率、F1分数上显著优于基准方法,攻击异常的F1分数和完全匹配率较普通多标签模型分别提升10%和27%以上。消融实验验证了双图结构在区分异常类型中的关键作用。该方法将异常检测从“是否异常”扩展为“何种异常”,为弱网下区分环境扰动与恶意行为提供了可行路径,并为后续环境确认、攻击告警及节点处置提供安全支撑。
中图分类号:
朱慧敏, 王晨龙, 刘光华. 基于双关系图时序建模的弱网异常行为区分方法[J]. 信息网络安全, 2026, 26(8): 1290-1307.
Zhu Huimin, Wang Chenlong, Liu Guanghua. An anomaly behavior differentiation method for weak networks based on dual-relation graph temporal modeling[J]. Netinfo Security, 2026, 26(8): 1290-1307.
表1
主要符号说明
| 符号 | 含义 |
|---|---|
| 第t个时间窗的节点特征矩阵 | |
| 序列样本的时间增强节点特征矩阵 | |
| 节点在时间窗内的特征向量 | |
| 节点丢包、环境丢包、攻击丢包、雨区标记、同步丢包、湿度、信噪比和连续异常特征 | |
| 通信链路质量邻接矩阵、环境协同变化邻接 矩阵 | |
| 第t个时间窗对应的带属性双关系图 | |
| 由连续L个时间窗构成的序列样本 | |
| VGAE输出的节点潜在表示矩阵 | |
| 节点潜在分布的均值和标准差 | |
| 两个非互斥标签的预测概率、环境扰动与攻击异常真值 | |
| 环境协同变化异常标签与攻击异常标签 | |
| 环境协同变化异常与攻击异常的判定阈值 |
表2
NS-3仿真与数据生成关键配置
| 配置项 | 设置 | 说明 |
|---|---|---|
| NS-3与场景 | ns-3.33;20 m×20 m; 100节点 | 1个汇聚节点,节点为随机静态位置 |
| 仿真时长 | 1800 s/轮;30轮 | RngRun范围为1001~1030 |
| 攻击比例 | BH=0.15/0.20/0.25;SF=0.15/0.20/0.25 | 每轮独立抽取 |
| 攻击起始 | 20~50s,步长5 s | 每轮随机;之前攻击标签恒为0 |
| 雨区 | 宽、高各6~10 m; 概率0.45~0.75 | 位置与范围逐轮随机 |
| 湿/干期 | 湿期:15~55 s; 干期:10~40 s | 雨脉冲0.2~1.0 min,间隔5~25 s |
| 温度 | 基准:13℃~17℃; 振幅:3℃~6℃ | 逐轮随机 |
表4
模型效果对比
| 模型 | Env F1 | Attack F1 | Exact Match | Hamming Loss |
|---|---|---|---|---|
| DGVT | 0.9693 | 0.9572 | 0.8896 | 0.0581 |
| TimeMixer++-style[ | 0.9298 | 0.9235 | 0.8000 | 0.1111 |
| TimesNet-style[ | 0.9146 | 0.8858 | 0.7370 | 0.1537 |
| iTransformer-style[ | 0.9161 | 0.9173 | 0.7852 | 0.1241 |
| Zhang[ | 0.8025 | 0.9420 | 0.6407 | 0.1889 |
| Cook[ | 0.8154 | 0.9467 | 0.6444 | 0.1778 |
表5
扰动鲁棒实验结果
| 场景组 | 场景 | Env F1 | Attack F1 | Exact Match | Hamming Loss |
|---|---|---|---|---|---|
| 基准 | 基准场景 | 0.9693 | 0.9572 | 0.8896 | 0.0581 |
| 环境扰动 | 降雨强度随机 | 0.9219 | 0.8841 | 0.7333 | 0.1444 |
| 环境扰动 | 雨区范围随机 | 0.6517 | 0.7667 | 0.4889 | 0.3278 |
| 环境扰动 | 湿度起始偏移 | 0.8027 | 0.9459 | 0.6111 | 0.2056 |
| 环境扰动 | 湿度变化缩放 | 0.8679 | 0.8741 | 0.6889 | 0.1722 |
| 攻击扰动 | 攻击强度变化 | 0.9508 | 0.8841 | 0.7778 | 0.1222 |
| 攻击扰动 | 攻击行为集中 | 0.9593 | 0.8841 | 0.7889 | 0.1167 |
表6
模型核心参数说明
| 参数/符号 | 设置 | 说明 |
|---|---|---|
| GCN隐藏维度/潜在维度 | 128/32 | 双关系分支结构一致 |
| 32/4/2 | 前馈层维度128 | |
| Dropout/权重衰减 | 0.2/1×10-2 | 抑制小样本过拟合 |
| 批大小/学习率/优化器 | 4/0.001/Adam | 梯度范数裁剪为5 |
| 最大轮数/早停耐心值 | 100/15 | 依据验证Macro-F1早停 |
| 1/0.1/0.001 | 由验证集敏感性实验确定 | |
| 0.50/0.40 | 验证集0.20~0.80步长0.05扫描 |
| [1] | Liu Guanghua, Wang Chenlong, Tang Shuqi, et al. Security in wireless weak-link sensor networks: directions, recent advances, and challenges[J]. IEEE Network, 2026, 40(1): 322-329. |
| [2] | Liu Guanghua. Data collection in MI-assisted wireless powered underground sensor networks: directions, recent advances, and challenges[J]. IEEE Communications Magazine, 2021, 59(4): 132-138. |
| [3] | Akyildiz I F, Stuntebeck E P. Wireless underground sensor networks: research challenges[J]. Ad Hoc Networks, 2006, 4(6): 669-686. |
| [4] | Yu Xiaoqing, Han Wenting, Zhang Zenglin. Path loss estimation for wireless underground sensor network in agricultural application[J]. Agricultural Research, 2017, 6(1): 97-102. |
| [5] | Liu Guanghua, Wang Zehua, Jiang Tao. QoS-aware throughput maximization in wireless powered underground sensor networks[J]. IEEE Transactions on Communications, 2016, 64(11): 4776-4789. |
| [6] | Rajasegarar S, Leckie C, Palaniswami M. Anomaly detection in wireless sensor networks[J]. IEEE Wireless Communications, 2008, 15(4): 34-40. |
| [7] | Xie Min, Han Song, Tian Bo, et al. Anomaly detection in wireless sensor networks: a survey[J]. Journal of Network and Computer Applications, 2011, 34(4): 1302-1325. |
| [8] | Karlof C, Wagner D. Secure routing in wireless sensor networks: attacks and countermeasures[J]. Ad Hoc Networks, 2003, 1(2): 293-315. |
| [9] | Wood A D, Stankovic J A. Denial of Service in Sensor networks[J]. Computer, 2002, 35(10): 54-62. |
| [10] | Newsome J, Shi E, Song D, et al. The sybil attack in sensor networks: analysis and defenses[C]// The 3rd International Symposium on Information Processing in Sensor Networks. New York: ACM, 2004: 259-268. |
| [11] | Beutel J, Romer K, Ringwald M, et al. Deployment techniques for sensor networks[M]. Heidelberg: Springer, 2010: 219-248. |
| [12] | Branch J W, Giannella C, Szymanski B, et al. In-network outlier detection in wireless sensor networks[C]// The 26th IEEE International Conference on Distributed Computing Systems. New York: IEEE, 2006: 51. |
| [13] | Fawzy A, Mokhtar H, Hegazy O. Outliers detection and classification in wireless sensor networks[J]. Egyptian Informatics Journal, 2013, 14(2): 157-164. |
| [14] | Hong C O, Choi Y H. Proximity-based robust event detection in wireless sensor networks[J]. International Journal of Distributed Sensor Networks, 2014, 2014: 97-106. |
| [15] | Ma Xiaoxiao, Wu Jia, Xue Shan, et al. A comprehensive survey on graph anomaly detection with deep learning[J]. IEEE Transactions on Knowledge and Data Engineering, 2023, 35(12): 12012-12038. |
| [16] | Akoglu L, Tong Hanghang, Koutra D. Graph based anomaly detection and description: a survey[J]. Data Mining and Knowledge Discovery, 2015, 29(3): 626-688. |
| [17] | Kipf T N, Welling M. Semi-supervised classification with graph convolutional networks[C]// International Conference on Learning Representations. Toulon: ICLR, 2017: 1-14. |
| [18] | Kipf T N, Welling M. Variational graph auto-encoders[EB/OL]. (2016-11-21)[2026-03-25]. https://arxiv.org/abs/1611.07308. |
| [19] | Velickovic P, Cucurull G, Casanova A, et al. Graph attention networks[C]// International Conference on Learning Representations. San Diego: ICLR, 2018: 1-12. |
| [20] | Deng Ailin, Hooi B. Graph neural network-based anomaly detection in multivariate time series[C]// The AAAI Conference on Artificial Intelligence. Menlo Park: AAAI, 2021: 4027-4035. |
| [21] | Zhao Hang, Wang Yujing, Duan Juanyong, et al. Multivariate time-series anomaly detection via graph attention network[C]// 2020 IEEE International Conference on Data Mining. New York: IEEE, 2020: 841-850. |
| [22] | Audibert J, Michiardi P, Guyard F, et al. USAD: Unsupervised anomaly detection on multivariate time series[C]// The 26th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining. New York: ACM, 2020: 3395-3404. |
| [23] | Su Ya, Zhao Youjian, Niu Chenhao, et al. Robust anomaly detection for multivariate time series through stochastic recurrent neural network[C]// The 25th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining. New York: ACM, 2019: 2828-2837. |
| [24] | Vaswani A, Shazeer N, Parmar N, et al. Attention is all you need[C]// Advances in Neural Information Processing Systems. New York: Curran Associates, 2017: 5998-6008. |
| [25] | Wang Shiyu, Li Jiawei, Shi Xiaoming, et al. TimeMixer++: a general time series pattern machine for universal predictive analysis[C]// International Conference on Learning Representations. San Diego: ICLR, 2025: 1-22. |
| [26] | Wu Haixu, Hu Tengge, Liu Yong, et al. TimesNet: temporal 2D-variation modeling for general time series analysis[C]// International Conference on Learning Representations. San Diego: ICLR, 2023: 1-17. |
| [27] | Liu Yong, Hu Tengge, Zhang Haoran, et al. iTransformer: inverted transformers are effective for time series forecasting[C]// International Conference on Learning Representations. San Diego: ICLR, 2024: 1-25. |
| [28] | Chung J, Gulcehre C, Cho K, et al. Empirical evaluation of gated recurrent neural networks on sequence modeling[EB/OL]. (2014-12-11)[2026-03-25]. https://arxiv.org/abs/1412.3555. |
| [29] | Zhang Minling, Zhou Zhihua. A review on multi-label learning algorithms[J]. IEEE Transactions on Knowledge and Data Engineering, 2014, 26(8): 1819-1837. |
| [30] | Read J, Pfahringer B, Holmes G, et al. Classifier chains for multi-label classification[J]. Machine Learning, 2011, 85(3): 333-359. |
| [31] | Tsoumakas G, Katakis I. Multi-label classification: an overview[J]. International Journal of Data Warehousing and Mining, 2007, 3(3): 1-13. |
| [32] | Boutell M R, Luo Jiebo, Shen Xipeng, et al. Learning multi-label scene classification[J]. Pattern Recognition, 2004, 37(9): 1757-1771. |
| [33] | Junejo K N, Goh J. Behaviour-based attack detection and classification in cyber physical systems using machine learning[C]// The 2nd ACM International Workshop on Cyber-Physical System Security. New York: ACM, 2016: 34-43. |
| [34] | Cook M, Paterson C, Marnerides A K, et al. Anomaly diagnosis in cyber-physical systems[C]// ICC 2022-IEEE International Conference on Communications. New York: IEEE, 2022: 5445-5450. |
| [35] | Kingma D P, Welling M. Auto-encoding variational bayes[EB/OL]. (2022-12-10)[2026-03-25]. https://arxiv.org/abs/1312.6114. |
| [36] | Kingma D P, Ba J. Adam: a method for stochastic optimization[C]// The 3rd International Conference on Learning Representations. San Diego: ICLR, 2015: 1-13. |
| [37] | Pedregosa F, Varoquaux G, Gramfort A, et al. Scikit-learn: machine learning in Python[J]. Journal of Machine Learning Research, 2011, 12: 2825-2830. |
| [38] | Paszke A, Gross S, Massa F, et al. PyTorch:an imperative style, high-performance deep learning library[C]// Advances in Neural Information Processing Systems. New York: Curran Associates, 2019: 8024-8035. |
| [1] | 刘光华, 王晨龙, 王连坤. 弱网的安全框架研究与实现[J]. 信息网络安全, 2026, 26(5): 667-683. |
| 阅读次数 | ||||||
|
全文 |
|
|||||
|
摘要 |
|
|||||