arXiv:2510.25802cs.CRcs.LG2025-10被引 4

融合GNN、RNN与注意力机制,提升复杂网络入侵检测能力

Attention Augmented GNN RNN-Attention Models for Advanced Cybersecurity Intrusion Detection

  • 用图结构+序列分析捕捉网络流量的空间与时间特征
  • 在UNSW-NB15数据集上多指标表现优于传统模型
  • 擅长识别高级持续性威胁等复杂攻击,适合实时安全系统

本文提出一种新型混合深度学习架构,将图神经网络(GNN)、循环神经网络(RNN)与多头注意力机制协同结合,显著提升网络安全入侵检测能力。基于包含多样化网络流量模式的UNSW-NB15数据集,该方法通过图结构关系捕获空间依赖性,通过事件序列分析捕捉时间动态性。集成的注意力机制兼具提升模型可解释性与增强特征选择能力,使安全分析师能聚焦高影响安全事件,满足现代实时入侵检测系统的核心需求。大量实验表明,所提混合模型在准确率、精确率、召回率和F1分数等多项指标上均优于传统机器学习方法与独立深度学习模型。尤其在检测高级持续性威胁(APTs)、分布式拒绝服务(DDoS)攻击及零日漏洞利用等复杂攻击模式方面表现优异,为复杂网络环境下的下一代网络安全应用提供了有力解决方案。

原文摘要 · Abstract (English)

In this paper, we propose a novel hybrid deep learning architecture that synergistically combines Graph Neural Networks (GNNs), Recurrent Neural Networks (RNNs), and multi-head attention mechanisms to significantly enhance cybersecurity intrusion detection capabilities. By leveraging the comprehensive UNSW-NB15 dataset containing diverse network traffic patterns, our approach effectively captures both spatial dependencies through graph structural relationships and temporal dynamics through sequential analysis of network events. The integrated attention mechanism provides dual benefits of improved model interpretability and enhanced feature selection, enabling cybersecurity analysts to focus computational resources on high-impact security events -- a critical requirement in modern real-time intrusion detection systems. Our extensive experimental evaluation demonstrates that the proposed hybrid model achieves superior performance compared to traditional machine learning approaches and standalone deep learning models across multiple evaluation metrics, including accuracy, precision, recall, and F1-score. The model achieves particularly strong performance in detecting sophisticated attack patterns such as Advanced Persistent Threats (APTs), Distributed Denial of Service (DDoS) attacks, and zero-day exploits, making it a promising solution for next-generation cybersecurity applications in complex network environments.

入侵检测图神经网络注意力机制网络安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。