State Key Laboratory of Networking and Switching Technology
被引用0|浏览1
摘要
Intelligent network operations increasingly rely on structured anomaly knowledge to support anomaly analysis, alert correlation, and root-cause investigation. However, under emerging and few-shot anomaly scenarios, anomaly-related knowledge graphs are often incomplete, which limits their operational value. To address this issue, this paper studies the problem of few-shot anomaly knowledge completion and proposes a Neighbor-Enhanced Knowledge Graph Completion model (NEKC). NEKC employs a similarity-aware neighbor selection mechanism to retain semantically relevant neighbors while introducing diversity constraints to avoid representation bias caused by overly homogeneous neighborhoods. An attention mechanism is further used to dynamically weight neighbor entities, and a Transformer-based encoder is adopted to capture contextual dependencies for task-specific relation representation. To evaluate the proposed method, experiments are conducted on the generic few-shot knowledge graph completion benchmark NELL and on a constructed Network Anomaly Knowledge Graph (NAKG) derived from public anomaly-related knowledge sources. The results show that NEKC achieves moderate overall improvements on NELL, whereas its advantages are more evident on NAKG compared with representative baseline methods in few-shot link prediction and knowledge completion tasks. These results indicate that NEKC can effectively improve the completeness of anomaly knowledge graphs and provide semantic support for downstream anomaly analysis in intelligent network operations.