通过小波感知机制识别用户日志中的异常行为。
Wavelet-Aware Anomaly Detection in Multi-Channel User Logs via Deviation Modulation and Resolution-Adaptive Attention
- 用偏差调制抑制正常行为,突出异常波动。
- 多分辨率小波分解捕捉长期趋势与短期异常。
- 自适应注意力机制动态聚焦关键频率带,适合安全监控场景。
内部威胁检测是企业安全的关键挑战,依赖于记录丰富复杂行为模式的用户活动日志。这些日志通常为多通道、非平稳,且异常事件稀少,导致检测困难。为此,我们提出一种新框架,融合小波感知调制、多分辨率小波分解和分辨率自适应注意力,实现鲁棒的异常检测。首先,采用偏差感知调制方案抑制常规行为,同时增强异常偏离信号。其次,离散小波变换(DWT)将日志信号分解为多分辨率表示,捕捉长期趋势与短期异常。最后,可学习的注意力机制动态重加权最具判别性的频带以提升检测效果。在CERT r4.2基准上,本方法在不同时间粒度与场景下均持续优于现有基线,在精确率、召回率和F1分数上表现更优。
原文摘要 · Abstract (English)
Insider threat detection is a key challenge in enterprise security, relying on user activity logs that capture rich and complex behavioral patterns. These logs are often multi-channel, non-stationary, and anomalies are rare, making anomaly detection challenging. To address these issues, we propose a novel framework that integrates wavelet-aware modulation, multi-resolution wavelet decomposition, and resolution-adaptive attention for robust anomaly detection. Our approach first applies a deviation-aware modulation scheme to suppress routine behaviors while amplifying anomalous deviations. Next, discrete wavelet transform (DWT) decomposes the log signals into multi-resolution representations, capturing both long-term trends and short-term anomalies. Finally, a learnable attention mechanism dynamically reweights the most discriminative frequency bands for detection. On the CERT r4.2 benchmark, our approach consistently outperforms existing baselines in precision, recall, and F1 score across various time granularities and scenarios.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。