将物联网流量的复杂关系映射到可解释的低维空间,实现安全监控可视化。
Interpreting Manifolds and Graph Neural Embeddings from Internet of Things Traffic Flows
- 通过流形投影将高维图神经网络嵌入转为可直观观察的低维表示。
- 入侵检测分类F1分数达0.830,同时捕捉概念漂移等动态现象。
- 适合网络安全分析人员与网络管理员理解设备间演化关系。
物联网生态系统的快速扩展带来了日益复杂和异构的网络拓扑结构。传统网络监控与可视化工具依赖聚合指标或静态表示,难以捕捉设备间的动态关系与结构依赖。尽管图神经网络(GNN)能从关系数据中学习,但其内部表示通常不透明,不利于安全关键操作。为此,本文提出一个可解释的流程,将高维嵌入映射到潜在流形上,生成直接可视化的低维表示。该投影实现了对动态网络状态的可解释监控与互操作性,结合特征归因技术解码了塑造流形结构的具体特征。框架在入侵检测任务中达到0.830的分类F1分数,并揭示了概念漂移等现象。该方法弥合了高维GNN嵌入与人类可理解的网络行为之间的差距,为网络管理员和安全分析师提供了新洞见。
原文摘要 · Abstract (English)
The rapid expansion of Internet of Things (IoT) ecosystems has led to increasingly complex and heterogeneous network topologies. Traditional network monitoring and visualization tools rely on aggregated metrics or static representations, which fail to capture the evolving relationships and structural dependencies between devices. Although Graph Neural Networks (GNNs) offer a powerful way to learn from relational data, their internal representations often remain opaque and difficult to interpret for security-critical operations. Consequently, this work introduces an interpretable pipeline that generates directly visualizable low-dimensional representations by mapping high-dimensional embeddings onto a latent manifold. This projection enables the interpretable monitoring and interoperability of evolving network states, while integrated feature attribution techniques decode the specific characteristics shaping the manifold structure. The framework achieves a classification F1-score of 0.830 for intrusion detection while also highlighting phenomena such as concept drift. Ultimately, the presented approach bridges the gap between high-dimensional GNN embeddings and human-understandable network behavior, offering new insights for network administrators and security analysts.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。