亲爱的研友该休息了!由于当前在线用户较少,发布求助请尽量完整地填写文献信息,科研通机器人24小时在线,伴您度过漫漫科研夜!身体可是革命的本钱,早点休息,好梦!

Disentangled Dynamic Intrusion Detection

计算机科学 入侵检测系统 人工智能 模式识别(心理学) 计算机视觉 数据挖掘
作者
Chenyang Qiu,Guoshun Nan,Hongrui Xia,Zheng-Yu Weng,Xueting Wang,Meng Shen,Xiaofeng Tao,Jun Liu
出处
期刊:IEEE Transactions on Pattern Analysis and Machine Intelligence [IEEE Computer Society]
卷期号:: 1-18
标识
DOI:10.1109/tpami.2025.3595671
摘要

Network-based intrusion detection system (NIDS) monitors network traffic for malicious activities, forming the frontline defense against increasing attacks over information infrastructures. Although promising, our quantitative analysis shows that existing methods perform inconsistently in attacks (e.g., 18% F1 for the MITM and 93% F1 for DDoS by a GCN-based state-of-the-art method), and perform poorly in few-shot intrusion detections (e.g., dramatically drops from 91% to 36% in 3D-IDS, and drops from 89% to 20% in E-GraphSAGE). We reveal that the underlying cause is entangled distributions of flow features. This motivates us to propose DIDS-MFL, a disentangled intrusion detection approach for various scenarios. DIDS-MFL involves two key components: a double Disentanglement-based Intrusion Detection System (DIDS) and a plug-and-play Multi-scale Few-shot Learning-based (MFL) intrusion detection module. Specifically, the proposed DIDS first disentangles traffic features by a non-parameterized optimization, automatically differentiating tens and hundreds of complex features. Such differentiated features will be further disentangled to highlight the attack-specific features. Our DIDS additionally uses a novel graph diffusion method that dynamically fuses the network topology for spatial-temporal aggregation in evolving data streams. Furthermore, the proposed MFL involves an alternating optimization framework to address the entangled representations in few-shot traffic threats with rigorous derivation. MFL first captures multi-scale information in latent space to distinguish attack-specific information and then optimizes the disentanglement term to highlight the attack-specific information. Finally, MFL fuses and alternately solves them in an end-to-end way. To the best of our knowledge, DIDS-MFL takes the first step toward disentangled dynamic intrusion detection under various attack scenarios. Equipped with DIDS-MFL, administrators can effectively identify various attacks in encrypted traffic, including known, unknown, and few-shot threats that are not easily detected. Comprehensive experiments show the superiority of our proposed DIDS-MFL. For few-shot NIDS, our DIDS-MFL achieves a 71.91% - 125.19% improvement in average F1-score over 14 baselines and shows versatility in multiple baselines and multiple tasks. Our code is available at https://github.com/qcydm/DIDS-MFL.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
Lucas应助小宋爱睡觉采纳,获得30
5秒前
6秒前
lijunliang完成签到,获得积分10
7秒前
星辰大海应助juaner采纳,获得10
7秒前
独特的鹅发布了新的文献求助10
12秒前
飘逸书雁发布了新的文献求助10
13秒前
13秒前
Cheng完成签到,获得积分10
15秒前
sunny发布了新的文献求助10
20秒前
20秒前
轩辕寄翠完成签到 ,获得积分10
23秒前
还好完成签到,获得积分10
25秒前
ltt发布了新的文献求助30
29秒前
一条咸瑜完成签到 ,获得积分10
33秒前
37秒前
北北完成签到 ,获得积分10
38秒前
丸子完成签到 ,获得积分0
45秒前
鲤鱼寻菡完成签到 ,获得积分10
50秒前
yangzai完成签到 ,获得积分0
51秒前
58秒前
wp完成签到,获得积分10
58秒前
58秒前
上官若男应助科研通管家采纳,获得10
58秒前
58秒前
yuhan完成签到 ,获得积分10
1分钟前
juaner发布了新的文献求助10
1分钟前
play6761发布了新的文献求助10
1分钟前
和谐凉面完成签到,获得积分10
1分钟前
大胆的碧菡完成签到,获得积分10
1分钟前
天天天晴完成签到 ,获得积分10
1分钟前
疯狂的毛豆完成签到 ,获得积分10
1分钟前
1分钟前
1分钟前
禾禾发布了新的文献求助10
1分钟前
传奇3应助juaner采纳,获得10
1分钟前
1分钟前
悦耳冰香完成签到,获得积分10
1分钟前
1分钟前
初景发布了新的文献求助10
1分钟前
1分钟前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
晶种分解过程与铝酸钠溶液混合强度关系的探讨 8888
Chemistry and Physics of Carbon Volume 18 800
The Organometallic Chemistry of the Transition Metals 800
Leading Academic-Practice Partnerships in Nursing and Healthcare: A Paradigm for Change 800
The formation of Australian attitudes towards China, 1918-1941 640
Signals, Systems, and Signal Processing 610
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6425903
求助须知:如何正确求助?哪些是违规求助? 8243519
关于积分的说明 17526677
捐赠科研通 5480751
什么是DOI,文献DOI怎么找? 2894402
邀请新用户注册赠送积分活动 1870500
关于科研通互助平台的介绍 1708674