arXiv:2508.12885cs.LGcs.AI2025-08被引 5

用动态图模型提升未知攻击检测能力

One-Class Intrusion Detection with Dynamic Graphs

  • 结合动态图建模与深度异常检测,捕捉网络通信的时序结构
  • 在真实数据集上优于多个基线方法,对新型攻击识别率更高
  • 适合需要检测未知威胁的安全系统研发者

随着全球数字化进程加速,网络安全愈发重要。基于机器学习的入侵检测虽具前景,但仍面临挑战:需识别新型未见网络事件,且数据具有时间序列特性及网络通信的固有图结构。本文提出一种新方法TGN-SVDD,融合现代动态图建模与深度异常检测技术。实验表明,该方法在真实入侵检测数据集上优于多个基线,并提出了更具挑战性的测试变体。

原文摘要 · Abstract (English)

With the growing digitalization all over the globe, the relevance of network security becomes increasingly important. Machine learning-based intrusion detection constitutes a promising approach for improving security, but it bears several challenges. These include the requirement to detect novel and unseen network events, as well as specific data properties, such as events over time together with the inherent graph structure of network communication. In this work, we propose a novel intrusion detection method, TGN-SVDD, which builds upon modern dynamic graph modelling and deep anomaly detection. We demonstrate its superiority over several baselines for realistic intrusion detection data and suggest a more challenging variant of the latter.

入侵检测动态图异常检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。