arXiv:2411.11293cs.LG2024-11被引 1

让少样本网络异常检测既准又可解释

AnomalyAID: Reliable Interpretation for Semi-supervised Network Anomaly Detection

  • 用全局+局部解释器结合,提升解释可靠性
  • 通过双阶段框架给无标签数据高置信伪标签
  • 适合需要可信解释的工业级安全系统

半监督学习在网络安全领域至关重要,但仅用少量标注样本学习异常模式仍具挑战。现有解释方法多用于有监督/无监督或非安全场景,难以提供可靠解释。本文提出AnomalyAID框架,旨在实现两个目标:(1) 提升异常检测过程的可解释性并增强解释结果可靠性;(2) 为无标签样本生成高置信度伪标签,以提升有限标注数据下的检测性能。针对(1),设计新型解释方法,融合全局与局部解释器;针对(2),构建两阶段半监督学习框架,通过特殊约束对齐各阶段模型预测。在两个典型网络异常检测任务上验证,实验表明AnomalyAID能实现高精度检测与可靠解释。

原文摘要 · Abstract (English)

Semi-supervised Learning plays a crucial role in network anomaly detection applications, however, learning anomaly patterns with limited labeled samples is not easy. Additionally, the lack of interpretability creates key barriers to the adoption of semi-supervised frameworks in practice. Most existing interpretation methods are developed for supervised/unsupervised frameworks or non-security domains and fail to provide reliable interpretations. In this paper, we propose AnomalyAID, a general framework aiming to (1) make the anomaly detection process interpretable and improve the reliability of interpretation results, and (2) assign high-confidence pseudo labels to unlabeled samples for improving the performance of anomaly detection systems with limited supervised data. For (1), we propose a novel interpretation approach that leverages global and local interpreters to provide reliable explanations, while for (2), we design a new two-stage semi-supervised learning framework for network anomaly detection by aligning both stages' model predictions with special constraints. We apply AnomalyAID over two representative network anomaly detection tasks and extensively evaluate AnomalyAID with representative prior works. Experimental results demonstrate that AnomalyAID can provide accurate detection results with reliable interpretations for semi-supervised network anomaly detection systems.

异常检测半监督可解释性网络安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。