用生成模型合成逼真网络攻击数据,提升入侵检测系统性能
PHANTOM: Progressive High-fidelity Adversarial Network for Threat Object Modeling
- 分阶段训练+双路径VAE-GAN架构生成高保真攻击数据
- 在真实攻击上达到98%加权准确率,数据分布与真实一致
- 适合安全研究者构建隐私保护的检测模型
网络安全攻击数据稀缺制约了入侵检测系统的鲁棒性发展。本文提出PHANTOM,一种新型对抗变分框架,用于生成高保真合成攻击数据。其创新包括分阶段训练、双路径VAE-GAN架构以及领域特定特征匹配,以保留攻击语义。在10万条网络流量样本上评估,使用PHANTOM生成数据训练的模型在真实攻击上达到98%加权准确率。统计分析表明,合成数据保持了真实的分布特性和多样性。但对罕见攻击类型的生成仍存局限,凸显严重类别不平衡带来的挑战。本工作推动了用于训练鲁棒、隐私保护检测系统的合成数据生成。
原文摘要 · Abstract (English)
The scarcity of cyberattack data hinders the development of robust intrusion detection systems. This paper introduces PHANTOM, a novel adversarial variational framework for generating high-fidelity synthetic attack data. Its innovations include progressive training, a dual-path VAE-GAN architecture, and domain-specific feature matching to preserve the semantics of attacks. Evaluated on 100,000 network traffic samples, models trained on PHANTOM data achieve 98% weighted accuracy on real attacks. Statistical analyses confirm that the synthetic data preserves authentic distributions and diversity. Limitations in generating rare attack types are noted, highlighting challenges with severe class imbalance. This work advances the generation of synthetic data for training robust, privacy-preserving detection systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。