arXiv:2512.22488cs.LGcs.CV2025-12

提出无需重训练的物联网僵尸网络检测框架,应对流量漂移挑战。

Toward Real-World IoT Security: Concept Drift-Resilient IoT Botnet Detection via Latent Space Representation Learning and Alignment

  • 通过隐空间表征与对齐,实现历史攻击知识保留
  • 在概念漂移下仍保持高检测准确率,避免灾难性遗忘
  • 适合动态大规模物联网环境中的安全防护

尽管基于AI的模型在物联网威胁检测中已取得高准确率,但其在企业环境中的部署受限于对静态数据集的依赖,而真实世界物联网网流数据常受概念漂移影响。现有方法多依赖周期性重训练分类器,导致计算开销大且存在灾难性遗忘风险。本文提出一种可扩展的自适应物联网威胁检测框架,无需持续重训练分类器:先在历史流量的隐空间表征上训练一次分类器,再通过对齐模型将新流量映射至已学隐空间进行分类,从而保留对过往攻击的知识。为捕捉攻击样本间的实例关系,低维隐空间进一步转换为图结构,并采用图神经网络进行分类。在真实异构物联网流量数据集上的实验表明,该框架在概念漂移下仍保持稳健检测性能,展现出在动态、大规模物联网环境中实用部署的潜力。

原文摘要 · Abstract (English)

Although AI-based models have achieved high accuracy in IoT threat detection, their deployment in enterprise environments is constrained by reliance on stationary datasets that fail to reflect the dynamic nature of real-world IoT NetFlow traffic, which is frequently affected by concept drift. Existing solutions typically rely on periodic classifier retraining, resulting in high computational overhead and the risk of catastrophic forgetting. To address these challenges, this paper proposes a scalable framework for adaptive IoT threat detection that eliminates the need for continuous classifier retraining. The proposed approach trains a classifier once on latent-space representations of historical traffic, while an alignment model maps incoming traffic to the learned historical latent space prior to classification, thereby preserving knowledge of previously observed attacks. To capture inter-instance relationships among attack samples, the low-dimensional latent representations are further transformed into a graph-structured format and classified using a graph neural network. Experimental evaluations on real-world heterogeneous IoT traffic datasets demonstrate that the proposed framework maintains robust detection performance under concept drift. These results highlight the framework's potential for practical deployment in dynamic and large-scale IoT environments.

物联网安全概念漂移图神经网络隐空间对齐

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。