量子自编码器在少量数据下仍能高效识别网络异常,优于传统方法。
Quantum Autoencoders for Anomaly Detection in Cybersecurity
- 用量子自编码器结合密集角度编码,处理网络安全异常检测。
- 仅用少量样本训练,量子模型F1达0.87,超过经典模型的0.77。
- 适合数据稀缺场景,为量子机器学习在安全领域应用提供实证。
网络安全中的异常检测面临正常事件远多于异常事件且新异常频繁出现的挑战。传统自编码器在数据有限时表现不佳,而量子自编码器(QAEs)或可克服此问题。本文将QAE应用于BPF-扩展追踪蜜罐(BETH)数据集的异常检测,评估了多种编码方式、线路结构、重复次数和特征选择策略。结果表明,使用8个特征、密集角度编码与RealAmplitude线路的QAE,在训练样本显著更少的情况下,仍能超越经典自编码器(CAE)。在数据受限环境下,最优QAE模型的F1得分为0.87,优于CAE的0.77。研究验证了量子编码与特征选择对模型性能的影响,表明QAE在小样本场景中具有实际优势。
原文摘要 · Abstract (English)
Anomaly detection in cybersecurity is a challenging task, where normal events far outnumber anomalous ones with new anomalies occurring frequently. Classical autoencoders have been used for anomaly detection, but struggles in data-limited settings which quantum counterparts can potentially overcome. In this work, we apply Quantum Autoencoders (QAEs) for anomaly detection in cybersecurity, specifically on the BPF-extended tracking honeypot (BETH) dataset. QAEs are evaluated across multiple encoding techniques, ansatz types, repetitions, and feature selection strategies. Our results demonstrate that an 8-feature QAE using Dense-Angle encoding with a RealAmplitude ansatz can outperform Classical Autoencoders (CAEs), even when trained on substantially fewer samples. The effects of quantum encoding and feature selection for developing quantum models are demonstrated and discussed. In a data-limited setting, the best performing QAE model has a F1 score of 0.87, better than that of CAE (0.77). These findings suggest that QAEs may offer practical advantages for anomaly detection in data-limited scenarios.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。