计算机科学
入侵检测系统
物联网
互联网
人工智能
机器学习
弹丸
计算机安全
网络安全
模型攻击
数据挖掘
万维网
有机化学
化学
作者
Chaomeng Lu,Xufeng Wang,Aimin Yang,Yikai Liu,Ziao Dong
标识
DOI:10.1109/jiot.2023.3283408
摘要
Currently, the effective technologies used to protect the security of the Internet of Things (IoT) include blockchain and intrusion detection systems (IDSs). The traditional IoT IDSs based on supervised learning usually requires a large amount of data for training, with high costs, and most of them can only work in several specific types of attacks. Faced with the variability of current IoT attack methods and the complexity of the network environment, they are usually unable to play a role in a short time. Especially in dealing with new security problems such as Zero-day attacks, which have a small number of learnable samples. Therefore, this article proposed an IoT intrusion detection model to deal with the situation where learnable samples are insufficient. The model adopts the idea of meta-learning and divides the training process into two layers based on model-agnostic meta-learning. Its purpose is to train a relatively general model using the malicious network flow data of various known attack modes. To this end, a few-shot IoT intrusion detection data set, FSIDS-IoT, is constructed based on five data sets, namely, CIC-DDoS2019, CIC-IDS2017, CSE-CIC-IDS2018, NSL-KDD, and UNSW-NB15. Experiments show that our proposed approach, using only a few gradient steps and a small amount of training data from the new attack type, can perform well to protect cyber security. In the test of identifying unknown attacks, the optimal accuracy under the 5-way 1-shot setting reached 78.26%, 90.09% under the 5-way 5-shot setting, and 92.19% under the 5-way 10-shot setting.
科研通智能强力驱动
Strongly Powered by AbleSci AI