arXiv:2504.03742cs.CRcs.AI2025-04被引 1

提出分层特征学习框架,提升少样本恶意流量检测准确率

Hierarchical Local-Global Feature Learning for Few-shot Malicious Traffic Detection

  • 分阶段提取流量会话的局部与全局特征
  • 在三个数据集上召回率更高,误报率显著降低
  • 适合网络安全领域应对新型攻击的快速检测

随着互联网流量激增,网络攻击日益频繁且复杂,对全球网络安全构成重大威胁。传统基于规则和机器学习的检测方法难以准确识别新兴威胁,尤其在样本稀缺场景下表现不佳。尽管少样本学习取得进展,现有方法仍存在高误报率,且难以有效捕捉关键局部流量模式。本文提出HLoG框架,通过滑动窗口将流量会话分段,利用分层双向GRU编码捕获细粒度局部交互模式,同时建模全局上下文依赖。设计会话相似性评估模块,融合局部相似性与全局自注意力增强表示,实现精准鲁棒的少样本流量分类。在三个精心重构的数据集上进行的全面实验表明,HLoG显著优于现有最先进方法,尤其在保持高召回率的同时大幅降低误报,凸显其在真实网络安全应用中的有效性与实用价值。

原文摘要 · Abstract (English)

With the rapid growth of internet traffic, malicious network attacks have become increasingly frequent and sophisticated, posing significant threats to global cybersecurity. Traditional detection methods, including rule-based and machine learning-based approaches, struggle to accurately identify emerging threats, particularly in scenarios with limited samples. While recent advances in few-shot learning have partially addressed the data scarcity issue, existing methods still exhibit high false positive rates and lack the capability to effectively capture crucial local traffic patterns. In this paper, we propose HLoG, a novel hierarchical few-shot malicious traffic detection framework that leverages both local and global features extracted from network sessions. HLoG employs a sliding-window approach to segment sessions into phases, capturing fine-grained local interaction patterns through hierarchical bidirectional GRU encoding, while simultaneously modeling global contextual dependencies. We further design a session similarity assessment module that integrates local similarity with global self-attention-enhanced representations, achieving accurate and robust few-shot traffic classification. Comprehensive experiments on three meticulously reconstructed datasets demonstrate that HLoG significantly outperforms existing state-of-the-art methods. Particularly, HLoG achieves superior recall rates while substantially reducing false positives, highlighting its effectiveness and practical value in real-world cybersecurity applications.

少样本学习恶意流量检测分层特征网络安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。