arXiv:2511.04114cs.CRcs.AI2025-11被引 1

用自动化机器学习和可解释性技术提升DDoS攻击检测的准确率与透明度。

Automated and Explainable Denial of Service Analysis for AI-Driven Intrusion Detection Systems

  • 用TPOT自动优化模型与特征选择,减少人工调参。
  • 关键特征如平均后向包长度对检测贡献显著。
  • 适合需要可解释性的安全系统开发者与运维人员。

随着分布式拒绝服务(DDoS)攻击频率与复杂度的上升,开发更高效且可解释的检测方法变得至关重要。传统检测系统常因扩展性差和透明度不足,影响实时响应与攻击路径理解。本文提出一种基于机器学习的自动化框架,用于检测并解释DDoS攻击。该方法利用树基管道优化工具(TPOT)实现模型与特征的自动化选择与优化,降低人工实验成本。同时引入SHapley Additive exPlanations(SHAP)提升模型可解释性,揭示各特征对检测结果的贡献。实验表明,均值后向包长度、最小前向包头长度等关键特征在检测中起决定性作用。该方法在保证高精度的同时提供可解释性,为网络安全领域提供了可扩展、可解释的解决方案。

原文摘要 · Abstract (English)

With the increasing frequency and sophistication of Distributed Denial of Service (DDoS) attacks, it has become critical to develop more efficient and interpretable detection methods. Traditional detection systems often struggle with scalability and transparency, hindering real-time response and understanding of attack vectors. This paper presents an automated framework for detecting and interpreting DDoS attacks using machine learning (ML). The proposed method leverages the Tree-based Pipeline Optimization Tool (TPOT) to automate the selection and optimization of ML models and features, reducing the need for manual experimentation. SHapley Additive exPlanations (SHAP) is incorporated to enhance model interpretability, providing detailed insights into the contribution of individual features to the detection process. By combining TPOT's automated pipeline selection with SHAP interpretability, this approach improves the accuracy and transparency of DDoS detection. Experimental results demonstrate that key features such as mean backward packet length and minimum forward packet header length are critical in detecting DDoS attacks, offering a scalable and explainable cybersecurity solution.

DDoS检测可解释性自动化机器学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。