ARTICLE · 1147565
AI开发之基础快速入门神经网络






AI开发之基础快速入门神经网络
1)神经网络(Neural Network)介绍
框架介绍完以后,咱们不能像传统的机器学习那样,只当一个只会调用别人写好的黑盒模型的调包侠。为了能针对复杂的web恶意流量定制最强防御网,咱们必须把神经网络的底层运转逻辑彻底吃透。
咱们在第一节课简单提过神经网络的四大核心基石,今天咱们结合代码,再来深度复习和死磕一下这四个概念哦:
神经元与多层拓扑/layers神经网络的结构可以看作是一场数据的接力赛
输入层: 负责接收原始的特征数据如咱们web流量里的请求频率,404次数等。
隐藏层: 这是ai的大脑深层思考区。数据在这里通过前向传播公式:Y=X * W + b被不断扭曲重组,ai会在这个过程中自动提取出人类肉眼无法察觉的高阶抽象特征,如高频 + 特定 404 组合往往代表某种自动化扫描器的特征。
输出层: 给出最终的预测答案如通过sigmoid给出0.0 - 1.0之间的恶意攻击概率。
激活函数(Activation Function)如果没有它ai只是个笨蛋为什么绝对需要它: 矩阵乘法X * W + b在数学上是纯线性的。如果不加激活函数,无论咱们叠加100层还是 1000层隐藏层,它们最终都会塌陷合并成一个最简单的线性方程就像一条直线永远没办法分类复杂的弯弯曲曲的现实数据。激活函数就像是在电路里加入了非线性开关,让网络拥有了拟合任何复杂曲线的能力。
最常用搭档:
ReLU:公式是max(0, x),负数直接变0,正数照旧。计算速度快到飞起,是隐藏层的标配。
Sigmoid:把任何数字压缩到0-1之间,完美对应概率值,通常死死守在输出层的最后一关哦。
损失函数(Loss Function)说白了就是衡量ai犯错有多严重的尺子,ai在刚开始训练时参数都是随机瞎猜的。损失函数就是用来告诉ai:你猜得离谱到了什么程度。
二分类交叉熵(Binary Cross-Entropy):咱们waf网关做的是恶意或正常的二分类任务。如果真实标签是1/攻击,ai却猜了0.01/安全,损失函数就会计算出一个巨大的惩罚值,狠狠地刺激ai去改错误哦。
正反向传播与优化器这是神经网络能够自动进化的核心闭环:
正向传播(Forward Pass):数据从输入层出发,经过隐藏层,最后在输出层吐出一个预测概率。
反向传播(Backpropagation):拿预测概率去对答案计算损失,然后利用微积分的导数链式法则,把误差从输出层一路倒推回去,计算出每个层里每个权重参数应该往哪个方向修改。
优化器(Optimizers,如 SGD, Adam):通过字面意思咱们可以知道就是修改方向优化器负责决定具体迈多大的步子然后取去更新参数,确保模型稳扎稳打地找到误差最小的最优解。
2)深度学习需要用到的库安装
python下载地址
https://www.python.org/downloads/
miniconda下载地址
https://repo.anaconda.com/miniconda/
pip install numpy -i https://mirrors.aliyun.com/pypi/simple/
3)代码案例
为了让各位彻底看清这四个步骤是如何在计算机里运转的,咱们接下来脱离keras和pyTorch的高级封装,直接用最底层的numpy,纯手写一个包含输入层隐藏层和输出层的神经网络。通过这段代码咱们能清晰地看到每一个矩阵是如何相乘,激活函数是如何扭转空间,以及反向传播是如何推导梯度的哈哈哈。
import numpy as npimport torchimport torch.nn as nnimport torch.optim as optimRED = "\033[31m"GREEN = "\033[32m"YELLOW = "\033[33m"BOLD = "\033[1m"END = "\033[0m"# =====================================================================# 1) Prepare Sample Data (Web Traffic Features)# Feature shape details: [Request Frequency, 404 Count, Contains Sensitive Keywords (0/1), Average Response Size]# =====================================================================X_data = np.array([[2.1, 0.0, 0, 0.1], # 1) Normal traffic[95.4, 42.0, 1, 8.5], # 2) Vulnerability scanning (Attack)[4.5, 1.0, 0, 0.5], # 3) Normal traffic[1.2, 0.0, 0, 0.0], # 4) Normal traffic[88.0, 35.0, 1, 12.1], # 5) Credential stuffing (Attack)], dtype=np.float32)# Ground truth labels: 0.0 for normal traffic, 1.0 for malicious attacky_data = np.array([[0.0], [1.0], [0.0], [0.0], [1.0]], dtype=np.float32)visitor_names = ["User A", "User B", "User C", "User D", "User E"]# Convert NumPy arrays to PyTorch TensorsX_tensor = torch.tensor(X_data)y_tensor = torch.tensor(y_data)# =====================================================================# 2) Define Network Structure & Activation Functions# =====================================================================class WafModel(nn.Module):def __init__(self):super(WafModel, self).__init__()# Hidden Layer: 4 input features mapped to 8 hidden abstract dimensionsself.hidden = nn.Linear(in_features=4, out_features=8)# Output Layer: 8 hidden features mapped to 1 final probability outputself.output = nn.Linear(in_features=8, out_features=1)def forward(self, x):# Forward propagation data workflowx = self.hidden(x)x = torch.relu(x) # Standard activation for hidden layers: ReLUx = self.output(x)x = torch.sigmoid(x) # Final activation: Sigmoid to compress output into a 0~1 probability rangereturn x# Instantiate the WAF neural network modelmodel = WafModel()# =====================================================================# 3) Define Loss Function & Optimizer# =====================================================================# Binary Cross-Entropy Loss: The industry standard for binary classification (Malicious vs Normal)criterion = nn.BCELoss()# Adam Optimizer: Handles gradient updates dynamically with a learning rate of 0.01optimizer = optim.Adam(model.parameters(), lr=0.01)# =====================================================================# 4) Model Training Loop (Forward & Backward Optimization)# =====================================================================epochs = 100 # Number of times the AI loops through the entire training datasetprint("-" * 75)print(f"{BOLD}{YELLOW}===== AI Threat Perception System: Training PyTorch nn.Module Model ====={END}")print("-" * 75)print("Starting Mini-WAF Malicious Traffic Model Training...")for epoch in range(epochs):# --- The Core Optimization Loop ---# Forward Pass — Let the AI make predictionspredictions = model(X_tensor)# Compute Loss — Measure how far off the predictions are from realityloss = criterion(predictions, y_tensor)# Backward Pass — Clear old gradients and backpropagate the error using chain ruleoptimizer.zero_grad() # Reset residual gradients from the previous iterationloss.backward() # Calculate how much weights (W) and biases (b) need to change# Optimization Step — Update parameters based on calculated gradientsoptimizer.step()# Print training logs every 10 epochsif (epoch + 1) % 10 == 0:print(f"Epoch [{epoch + 1:03d}/{epochs}] | Current Loss: {loss.item():.4f}")print(f"\n{BOLD}{GREEN}Model training completed! Model parameters have successfully converged.{END}\n")# =====================================================================# 5) Verify AI Defense Performance# =====================================================================# Disable gradient computation since we are running evaluation, not trainingwith torch.no_grad():final_preds = model(X_tensor).numpy().flatten()threshold = 0.5 # Risk control interception thresholdprint("-" * 75)print(f"{BOLD}{YELLOW}===== AI WAF Gateway: Real-Time Live Traffic Inspection Active ====={END}")print("-" * 75)for i, (name, score) in enumerate(zip(visitor_names, final_preds)):if score > threshold:action = f"{BOLD}{RED}[BLOCK & DROP] - Intercepted by AI Neural Network! (Risk Prob: {score*100:.2f}%){END}"else:action = f"{BOLD}{GREEN}[PASS] - Clear Traffic. (Risk Prob: {score*100:.2f}%){END}"print(f"Live Flow: {name:<12} -> Predicted: {action}")print("-" * 75)
过去帮客户写的AI案例请看这里:
https://space.bilibili.com/1456034618/lists/3151496?type=season