Netinfo Security ›› 2026, Vol. 26 ›› Issue (8): 1290-1307.doi: 10.3969/j.issn.1671-1122.2026.08.010

Previous Articles     Next Articles

An anomaly behavior differentiation method for weak networks based on dual-relation graph temporal modeling

Zhu Huimin, Wang Chenlong, Liu Guanghua()   

  1. School of Cyber Science and Engineering, Huazhong University of Science and Technology, Wuhan 430074, China
  • Received:2026-05-31 Online:2026-08-10 Published:2026-09-23
  • Contact: Liu Guanghua E-mail:guanghualiu@hust.edu.cn

Abstract:

Wireless weak-link sensor networks are long-term deployed in underground spaces, pipeline systems, and complex industrial environments. Their wireless communication links are susceptible to rainfall, high humidity, obstructions, and medium attenuation, leading to link quality fluctuations and packet loss. Abnormal data transmission behaviors in weak-link networks may arise either from external environmental changes or from malicious attacks such as selective forwarding, packet dropping, or tampering. Since environment-induced disturbances and malicious behaviors exhibit similar observation patterns, existing methods struggle to distinguish between them, limiting their capability for anomaly identification in complex scenarios.To address this, this paper proposed a dual-graph variational temporal model (DGVT). The environmental covariation graph captured node co-variations caused by rainfall, high humidity, and synchronous packet loss, while the communication link quality graph characterizes link quality and forwarding relationships under normal communication or malicious attacks. The model employed a variational graph autoencoder to learn node structural representations, a temporal module to capture the evolution of anomalies over consecutive time windows, and a multi-label prediction layer to output two non-mutually-exclusive labels: environmental covariation anomalies and attack anomalies.Experimental results show that DGVT significantly outperforms baseline methods in precision, recall, and F1-score. For attack anomalies, the F1-score and exact-match ratio improve by over 10% and 27%, respectively, compared to conventional multi-label classification models. Ablation studies further validate the critical roles of both graphs in distinguishing different anomaly types. The proposed approach extends anomaly detection from a binary "anomalous or not" judgment to a fine-grained classification of anomaly categories, offering a feasible technical pathway for differentiating environmental disturbances from malicious node behaviors in weak-link networks, and providing security support for subsequent environmental status confirmation, attack alerting, and node mitigation.

Key words: wireless weak-link sensor networks, abnormal behavior discrimination, multi-label learning, variational graph autoencoder, environment-induced anomaly

CLC Number: