arXiv:2511.08491cs.CRcs.LG2025-11中稿 · and To Appear in I…被引 9

用自动化机器学习实现高效智能的网络入侵检测

Toward Autonomous and Efficient Cybersecurity: A Multi-Objective AutoML-based Intrusion Detection System

  • 结合自动特征选择与多目标优化,自动平衡检测效果与计算开销
  • 在两个基准数据集上优于现有系统,检测准确率更高且资源消耗更低
  • 适合物联网和边缘设备等资源受限场景的自主安全防护

随着网络安全威胁日益复杂及网络自动化需求上升,自主化安全机制对现代网络至关重要。物联网(IoT)系统的快速扩展加剧了这一挑战,资源受限的物联网设备需要可扩展且高效的解决方案。本文提出一种基于自动化机器学习(AutoML)与多目标优化(MOO)的新型入侵检测系统(IDS),用于现代网络环境中的自主化、优化型攻击检测。该框架集成两项创新技术:基于重要性与占比的优化自动特征选择(OIP-AutoFS)和基于性能、置信度与效率的联合算法选择与超参数优化(OPCE-CASH),分别优化特征筛选与模型学习过程,以在检测有效性与计算效率间取得平衡。本工作首次完整整合AutoML四个阶段,并通过多目标优化同时优化检测效果、效率与置信度,适用于资源受限系统。在两个基准网络安全数据集上的实验表明,所提MOO-AutoML IDS优于当前先进系统,确立了自主、高效、优化安全的新基准。该框架专为支持物联网与边缘环境而设计,适用于多种异构网络环境下的自主安全应用。

原文摘要 · Abstract (English)

With increasingly sophisticated cybersecurity threats and rising demand for network automation, autonomous cybersecurity mechanisms are becoming critical for securing modern networks. The rapid expansion of Internet of Things (IoT) systems amplifies these challenges, as resource-constrained IoT devices demand scalable and efficient security solutions. In this work, an innovative Intrusion Detection System (IDS) utilizing Automated Machine Learning (AutoML) and Multi-Objective Optimization (MOO) is proposed for autonomous and optimized cyber-attack detection in modern networking environments. The proposed IDS framework integrates two primary innovative techniques: Optimized Importance and Percentage-based Automated Feature Selection (OIP-AutoFS) and Optimized Performance, Confidence, and Efficiency-based Combined Algorithm Selection and Hyperparameter Optimization (OPCE-CASH). These components optimize feature selection and model learning processes to strike a balance between intrusion detection effectiveness and computational efficiency. This work presents the first IDS framework that integrates all four AutoML stages and employs multi-objective optimization to jointly optimize detection effectiveness, efficiency, and confidence for deployment in resource-constrained systems. Experimental evaluations over two benchmark cybersecurity datasets demonstrate that the proposed MOO-AutoML IDS outperforms state-of-the-art IDSs, establishing a new benchmark for autonomous, efficient, and optimized security for networks. Designed to support IoT and edge environments with resource constraints, the proposed framework is applicable to a variety of autonomous cybersecurity applications across diverse networked environments.

入侵检测AutoML多目标优化物联网安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。