arXiv:2506.14937cs.LGcs.AI2025-06中稿 · SBrT 2022

用机器学习自动确定网络攻击检测的异常阈值,提升检测效果。

Determinação Automática de Limiar de Detecção de Ataques em Redes de Computadores Utilizando Autoencoders

  • 通过KNN、K-Means和SVM自动设定自编码器的异常判定阈值
  • 解决传统方法依赖人工设定阈值导致性能不稳定的问题
  • 适合网络安全领域研究人员及系统部署者参考

目前,使用自编码器(AE)的异常检测系统在克服数据固有的不平衡问题方面展现出巨大潜力。由于自编码器采用非平凡且非标准化的重建误差分离阈值来分类异常,该阈值的定义直接影响检测性能。因此,本文提出利用机器学习算法自动确定该阈值。为此,评估了三种算法:K-近邻(KNN)、K-均值(K-Means)和支持向量机(SVM)。

原文摘要 · Abstract (English)

Currently, digital security mechanisms like Anomaly Detection Systems using Autoencoders (AE) show great potential for bypassing problems intrinsic to the data, such as data imbalance. Because AE use a non-trivial and nonstandardized separation threshold to classify the extracted reconstruction error, the definition of this threshold directly impacts the performance of the detection process. Thus, this work proposes the automatic definition of this threshold using some machine learning algorithms. For this, three algorithms were evaluated: the K-Nearst Neighbors, the K-Means and the Support Vector Machine.

异常检测自编码器网络安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。