多度量空间融合提升少样本网络攻击检测能力
Learning in Multiple Spaces: Few-Shot Network Attack Detection with Metric-Fused Prototypical Networks
- 融合欧氏、余弦等四种距离度量,通过约束加权增强特征鲁棒性
- 在少量样本下对低频和新型攻击检测准确率显著优于传统方法
- 适合安全研究者用于零日攻击快速识别与模型泛化能力评估
网络入侵检测系统在识别新兴攻击模式时面临挑战,尤其在数据样本有限的情况下。为此,我们提出一种面向少样本攻击检测的多空间原型学习(MSPL)框架。该框架在欧氏、余弦、切比雪夫和沃瑟斯坦距离等多种度量空间中协同工作,通过约束权重机制提升嵌入鲁棒性并增强模式识别能力。结合Polyak平均原型生成,稳定学习过程,有效适应罕见及零日攻击。此外,采用周期性训练范式,确保各类攻击样本表示均衡,实现良好泛化。在基准数据集上的实验表明,MSPL在检测低活跃度和新型攻击类型方面优于传统方法,为零日攻击检测提供了稳健解决方案。
原文摘要 · Abstract (English)
Network intrusion detection systems face significant challenges in identifying emerging attack patterns, especially when limited data samples are available. To address this, we propose a novel Multi-Space Prototypical Learning (MSPL) framework tailored for few-shot attack detection. The framework operates across multiple metric spaces-Euclidean, Cosine, Chebyshev, and Wasserstein distances-integrated through a constrained weighting scheme to enhance embedding robustness and improve pattern recognition. By leveraging Polyak-averaged prototype generation, the framework stabilizes the learning process and effectively adapts to rare and zero-day attacks. Additionally, an episodic training paradigm ensures balanced representation across diverse attack classes, enabling robust generalization. Experimental results on benchmark datasets demonstrate that MSPL outperforms traditional approaches in detecting low-profile and novel attack types, establishing it as a robust solution for zero-day attack detection.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。