The Attack and Defense Researches on the Dual‐Layer Network of Multivariable Anomaly Causes
Jiaxin Han, Rui Zhang, Zhonglin Ye, Xuanrong Huo, Yuzhi Xiao, Yuhui Zheng · International Journal of Intelligent Systems · 2025
Multivariate anomaly causes interpretation provides insight into the root cause of information system anomalies, identifying the direct factors that trigger anomalies and revealing potential systemic flaws. However, current research generally focuses on two directions: on the one hand, anomaly diagnosis research for nodes with high anomaly degree; on the other hand, single‐layer anomaly causes interpretation graph construction based on explicit features capturing anomaly locations and their neighborhood structures. These approaches pay insufficient attention to the attack defense of anomaly causes interpretation graph, thereby weakening the credibility and reliability of anomaly causation interpretation. Therefore, we systematically explore the attack strategy and defense mechanism of the multivariate anomaly causes interpretation graph. Firstly, we propose an adaptive learning method for constructing a dual‐layer anomaly causes interpretation graph. The method reduces the dependence on artificial a priori assumptions by introducing an adaptive mechanism and realizes the dynamic decoupling of the spatiotemporal coupling relationships of multivariate data, thus providing a diversified perspective for the multivariate anomaly causes interpretation. Second, considering the vulnerability of the multivariate spatiotemporal correlation after decoupling and the structural characteristics of the dual‐layer anomaly causes interpretation graph, we further propose a structural protection mechanism based on dual‐layer complex networks to improve the structural robustness and resistance to the interference of anomaly causes interpretation graph. Finally, we verify the effectiveness of the proposed model by testing various attack defense scenarios such as noise attack, gradient attack, and structure attack. The experimental results show that the model in this paper can effectively defend against multiple attack methods and ensure the integrity and reliability of the anomaly causes interpretation graph.