针对战场物联网的未知攻击,提出可自适应区域协同检测的新方法。
Collaborative Zone-Adaptive Zero-Day Intrusion Detection for IoBT
- 用通用卷积模型+自编码器重构信号+轻量适配模块实现跨域协作
- 在未见攻击上最高达83.16%准确率,跨数据集迁移达71.64%
- 适合资源受限、连接不稳的战场网络环境使用
战场物联网(IoBT)依赖异构、带宽受限且间歇连通的战术网络,面临快速演化的网络威胁。在此场景下,无法依赖持续的中心化原始流量采集,因链路中断、延迟、作战安全限制以及各区域间非独立同分布的流量特性。本文提出区域自适应入侵检测(ZAID),一种针对未见攻击类型(零日攻击)的协同检测与模型优化框架。ZAID结合通用卷积模型以生成可泛化的流量表示,采用自编码器的重构信号作为辅助异常评分,并引入轻量适配模块实现参数高效的区域个性化。为支持在弱连接条件下的跨区域泛化,使用联邦聚合与伪标签机制,利用本地观察到的弱标注行为。在ToN_IoT数据集上评估,排除中间人、分布式拒绝服务和拒绝服务攻击用于监督训练,仅在区域部署与适应阶段引入。ZAID在未见攻击流量上达到最高83.16%准确率,并在相同流程下迁移至UNSW-NB15,最佳准确率达71.64%。结果表明,参数高效、区域个性化的协作机制可显著提升受控环境下对未知攻击的检测能力。
原文摘要 · Abstract (English)
The Internet of Battlefield Things (IoBT) relies on heterogeneous, bandwidth-constrained, and intermittently connected tactical networks that face rapidly evolving cyber threats. In this setting, intrusion detection cannot depend on continuous central collection of raw traffic due to disrupted links, latency, operational security limits, and non-IID traffic across zones. We present Zone-Adaptive Intrusion Detection (ZAID), a collaborative detection and model-improvement framework for unseen attack types, where "zero-day" refers to previously unobserved attack families and behaviours (not vulnerability disclosure timing). ZAID combines a universal convolutional model for generalisable traffic representations, an autoencoder-based reconstruction signal as an auxiliary anomaly score, and lightweight adapter modules for parameter-efficient zone adaptation. To support cross-zone generalisation under constrained connectivity, ZAID uses federated aggregation and pseudo-labelling to leverage locally observed, weakly labelled behaviours. We evaluate ZAID on ToN_IoT using a zero-day protocol that excludes MITM, DDoS, and DoS from supervised training and introduces them during zone-level deployment and adaptation. ZAID achieves up to 83.16% accuracy on unseen attack traffic and transfers to UNSW-NB15 under the same procedure, with a best accuracy of 71.64%. These results indicate that parameter-efficient, zone-personalised collaboration can improve the detection of previously unseen attacks in contested IoBT environments.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。