解耦图神经网络提升攻击检测准确率
Global Context Enhanced Anomaly Detection of Cyber Attacks via Decoupled Graph Neural Networks
- 分离节点表征与分类器训练,提升模型灵活性
- 引入全局上下文增强表示,AUC显著优于现有方法
- 适合网络安全领域研究者与工业界异常检测场景
近期,基于图神经网络(GNN)的异常检测受到广泛关注。现有方法多采用浅层模型同时学习节点表征与分类器,难以捕捉非线性网络信息,导致性能不佳。本文提出解耦式GNN架构,将节点表征学习与分类器训练分离。针对节点表征学习,设计包含两个模块的GNN结构,分别聚合节点特征信息以生成最终嵌入。通过实证实验验证所提方法的有效性。结果表明,解耦训练结合全局上下文增强的节点表示,在AUC指标上优于现有最先进模型,为节点信息建模提供了新思路。
原文摘要 · Abstract (English)
Recently, there has been a substantial amount of interest in GNN-based anomaly detection. Existing efforts have focused on simultaneously mastering the node representations and the classifier necessary for identifying abnormalities with relatively shallow models to create an embedding. Therefore, the existing state-of-the-art models are incapable of capturing nonlinear network information and producing suboptimal outcomes. In this thesis, we deploy decoupled GNNs to overcome this issue. Specifically, we decouple the essential node representations and classifier for detecting anomalies. In addition, for node representation learning, we develop a GNN architecture with two modules for aggregating node feature information to produce the final node embedding. Finally, we conduct empirical experiments to verify the effectiveness of our proposed approach. The findings demonstrate that decoupled training along with the global context enhanced representation of the nodes is superior to the state-of-the-art models in terms of AUC and introduces a novel way of capturing the node information.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。