用因果关系提升网络攻击检测的可解释性与适应性
Rethinking Spatio-Temporal Anomaly Detection: A Vision for Causality-Driven Cybersecurity
- 基于因果图建模时空系统中的因果关系
- 实现早期预警与攻击根源定位,优于黑箱模型
- 适合关注可解释安全系统的研究人员
随着网络物理系统日益互联和空间分布化,保障其免受持续演化的网络攻击已成为关键挑战。时空异常检测在维护系统安全与运行完整性方面发挥重要作用。然而,当前以黑箱深度学习为主的数据驱动方法,在可解释性、分布偏移适应性和动态系统鲁棒性方面面临挑战。本文倡导采用因果学习视角,推动空间分布式基础设施中异常检测的发展,将检测建立在结构化的因果关系基础上。我们识别并形式化了三个关键方向:因果图画像、多视角融合与持续因果图学习,各自在揭示时空动态因果结构方面具有独特优势。结合水处理基础设施等真实案例,说明因果模型能提供早期预警与根因归因,克服黑箱检测器的局限。展望未来,我们提出以多模态、生成式AI驱动和可扩展自适应因果框架为核心的科研议程。目标是构建可扩展、自适应、可解释且空间扎根的异常检测系统,推动网络安全研究范式转型,以应对互联基础设施中的演化威胁。
原文摘要 · Abstract (English)
As cyber-physical systems grow increasingly interconnected and spatially distributed, ensuring their resilience against evolving cyberattacks has become a critical priority. Spatio-Temporal Anomaly detection plays an important role in ensuring system security and operational integrity. However, current data-driven approaches, largely driven by black-box deep learning, face challenges in interpretability, adaptability to distribution shifts, and robustness under evolving system dynamics. In this paper, we advocate for a causal learning perspective to advance anomaly detection in spatially distributed infrastructures that grounds detection in structural cause-effect relationships. We identify and formalize three key directions: causal graph profiling, multi-view fusion, and continual causal graph learning, each offering distinct advantages in uncovering dynamic cause-effect structures across time and space. Drawing on real-world insights from systems such as water treatment infrastructures, we illustrate how causal models provide early warning signals and root cause attribution, addressing the limitations of black-box detectors. Looking ahead, we outline the future research agenda centered on multi-modality, generative AI-driven, and scalable adaptive causal frameworks. Our objective is to lay a new research trajectory toward scalable, adaptive, explainable, and spatially grounded anomaly detection systems. We hope to inspire a paradigm shift in cybersecurity research, promoting causality-driven approaches to address evolving threats in interconnected infrastructures.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。