用注意力机制提升LSTM-CNN模型,精准识别工业物联网攻击
Adaptive Cyber-Attack Detection in IIoT Using Attention-Based LSTM-CNN Models
- 融合LSTM、CNN与注意力机制,动态捕捉时序和特征模式
- 在多类攻击分类中达99.04%准确率,损失仅0.0220%
- 针对数据不平衡问题使用SMOTE增强小样本类别,提升泛化能力
工业物联网(IIoT)的快速发展带来了复杂网络威胁的安全挑战。本文提出一种基于混合LSTM-CNN-Attention架构的入侵检测系统(IDS),专门用于检测和分类IIoT环境中的网络攻击。研究聚焦二分类与多分类任务,采用Edge-IIoTset数据集进行严格评估。为缓解数据集中的类别不平衡问题,应用合成少数类过采样技术(SMOTE)生成合成样本,使模型能有效学习所有类别,从而提升整体性能。通过系统实验对比多种深度学习模型,结果表明,LSTM-CNN-Attention模型在关键指标上持续领先:在二分类任务中接近完美准确率;在多分类任务中保持99.04%的高准确率,同时损失值仅为0.0220%。
原文摘要 · Abstract (English)
The rapid expansion of the industrial Internet of things (IIoT) has introduced new challenges in securing critical infrastructures against sophisticated cyberthreats. This study presents the development and evaluation of an advanced Intrusion detection (IDS) based on a hybrid LSTM-convolution neural network (CNN)-Attention architecture, specifically designed to detect and classify cyberattacks in IIoT environments. The research focuses on two key classification tasks: binary and multi-class classification. The proposed models was rigorously tested using the Edge-IIoTset dataset. To mitigate the class imbalance in the dataset, the synthetic minority over-sampling technique (SMOTE) was employed to generate synthetic samples for the underrepresented classes. This ensured that the model could learn effectively from all classes, thereby improving the overall classification performance. Through systematic experimentation, various deep learning (DL) models were compared, ultimately demonstrating that the LSTM-CNN-Attention model consistently outperformed others across key performance metrics. In binary classification, the model achieved near-perfect accuracy, while in multi-class classification, it maintained a high accuracy level (99.04%), effectively categorizing different attack types with a loss value of 0.0220%.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。