用神经符号方法提升网络入侵检测的可靠性与泛化能力。
Neurosymbolic Artificial Intelligence for Robust Network Intrusion Detection: From Scratch to Transfer Learning
- 融合深度聚类与符号推理,实现可解释的入侵检测
- 在CIC-IDS-2017上优于传统模型,误报率更低
- 迁移学习仅需1.6万样本即达高性能,适合数据少场景
网络入侵检测系统(NIDS)对防御日益复杂的网络威胁至关重要。本文扩展了神经符号人工智能框架ODXU,该框架结合深度嵌入聚类用于特征提取、基于XGBoost的符号推理,以及全面的不确定性量化(UQ),以增强检测系统的鲁棒性、可解释性和泛化能力。扩展的ODXU引入基于得分的方法(如置信度评分、香农熵)和基于元模型的技术(如SHAP值、信息增益),评估预测可靠性。在CIC-IDS-2017数据集上的实验表明,ODXU在六项评估指标(包括分类准确率和假阴性率)上优于传统神经模型。尽管迁移学习在计算机视觉与自然语言处理中广泛应用,但在网络安全领域尚未充分探索。为此,本文提出一种迁移学习策略,复用预训练的ODXU模型于新数据集。在ACI-IoT-2023上的消融研究显示,最优配置为复用预训练自编码器、重训聚类模块并微调XGBoost分类器,在仅使用16,000个样本(约50%训练数据)时仍优于传统神经模型。此外,元模型类不确定性量化方法在两个数据集上均持续优于基于得分的方法。
原文摘要 · Abstract (English)
Network Intrusion Detection Systems (NIDS) play a vital role in protecting digital infrastructures against increasingly sophisticated cyber threats. In this paper, we extend ODXU, a Neurosymbolic AI (NSAI) framework that integrates deep embedded clustering for feature extraction, symbolic reasoning using XGBoost, and comprehensive uncertainty quantification (UQ) to enhance robustness, interpretability, and generalization in NIDS. The extended ODXU incorporates score-based methods (e.g., Confidence Scoring, Shannon Entropy) and metamodel-based techniques, including SHAP values and Information Gain, to assess the reliability of predictions. Experimental results on the CIC-IDS-2017 dataset show that ODXU outperforms traditional neural models across six evaluation metrics, including classification accuracy and false omission rate. While transfer learning has seen widespread adoption in fields such as computer vision and natural language processing, its potential in cybersecurity has not been thoroughly explored. To bridge this gap, we develop a transfer learning strategy that enables the reuse of a pre-trained ODXU model on a different dataset. Our ablation study on ACI-IoT-2023 demonstrates that the optimal transfer configuration involves reusing the pre-trained autoencoder, retraining the clustering module, and fine-tuning the XGBoost classifier, and outperforms traditional neural models when trained with as few as 16,000 samples (approximately 50% of the training data). Additionally, results show that metamodel-based UQ methods consistently outperform score-based approaches on both datasets.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。