arXiv:2506.18114cs.CRcs.LG2025-06中稿 · the 10th Internati…被引 1

用动态时间编码提升物联网早期入侵检测准确率

Dynamic Temporal Positional Encodings for Early Intrusion Detection in IoT

  • 基于Transformer,用动态时间位置编码捕捉流量时序特征
  • 在CICIoT2023数据集上精度与检测提前量均优于现有模型
  • 适合资源受限的物联网设备实时部署

物联网(IoT)的快速发展带来了严峻的安全挑战,亟需高效且自适应的入侵检测系统(IDS)。传统IDS模型常忽略网络流量的时间特性,限制了其在早期威胁检测中的效果。我们提出一种基于Transformer的早期入侵检测系统(EIDS),引入动态时间位置编码以提升检测精度并保持计算效率。通过利用网络流的时间戳,该方法能够捕捉序列结构及异常时间模式,这些特征可指示恶意行为。此外,我们设计了一条数据增强流水线以提升模型鲁棒性。在CICIoT2023数据集上的评估显示,本方法在准确率和检测提前量方面均优于现有模型。我们还验证了其在资源受限的IoT设备上的实时可行性,实现低延迟推理与极小内存占用。

原文摘要 · Abstract (English)

The rapid expansion of the Internet of Things (IoT) has introduced significant security challenges, necessitating efficient and adaptive Intrusion Detection Systems (IDS). Traditional IDS models often overlook the temporal characteristics of network traffic, limiting their effectiveness in early threat detection. We propose a Transformer-based Early Intrusion Detection System (EIDS) that incorporates dynamic temporal positional encodings to enhance detection accuracy while maintaining computational efficiency. By leveraging network flow timestamps, our approach captures both sequence structure and timing irregularities indicative of malicious behaviour. Additionally, we introduce a data augmentation pipeline to improve model robustness. Evaluated on the CICIoT2023 dataset, our method outperforms existing models in both accuracy and earliness. We further demonstrate its real-time feasibility on resource-constrained IoT devices, achieving low-latency inference and minimal memory footprint.

入侵检测物联网安全Transformer时间编码

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。