arXiv:2602.23846cs.CRcs.AI2026-02中稿 · publication in the…

提出多层框架,让工业物联网系统自动识别新旧攻击并持续学习。

MI$^2$DAS: A Multi-Layer Intrusion Detection Framework with Incremental Learning for Securing Industrial IoT Networks

  • 分层检测:先区分正常与异常,再识别已知/未知攻击,最后细分类别。
  • 已知攻击识别率94.1%(宏F1),未知攻击检出率达88.2%。
  • 支持增量学习,新增攻击类型只需少量标注数据即可适应。

工业物联网(IIoT)系统的快速扩展带来了安全挑战,异构设备和动态流量模式增加了遭受复杂新型攻击的风险。传统入侵检测系统因依赖大量标注数据且难以发现新威胁而表现不佳。为此,本文提出MI$^2$DAS多层入侵检测框架,集成基于异常的分层流量聚合、开放集识别以区分已知与未知攻击,以及增量学习机制以在极少标注下适应新型攻击。在Edge-IIoTset数据集上的实验表明:第一层中,GMM模型正常-攻击判别准确率达0.953,召回率1.000;开放集识别中,GMM对已知攻击召回率为0.813,LOF对未知攻击召回率为0.882;已知攻击细粒度分类中,随机森林宏F1达0.941;增量学习模块在引入新攻击类别后仍保持稳定,宏F1为0.8995。结果证明,MI$^2$DAS是一种高效、可扩展且具备自适应能力的工业物联网安全防护框架。

原文摘要 · Abstract (English)

The rapid expansion of Industrial IoT (IIoT) systems has amplified security challenges, as heterogeneous devices and dynamic traffic patterns increase exposure to sophisticated and previously unseen cyberattacks. Traditional intrusion detection systems often struggle in such environments due to their reliance on extensive labeled data and limited ability to detect new threats. To address these challenges, we propose MI$^2$DAS, a multi-layer intrusion detection framework that integrates anomaly-based hierarchical traffic pooling, open-set recognition to distinguish between known and unknown attacks and incremental learning for adapting to novel attack types with minimal labeling. Experiments conducted on the Edge-IIoTset dataset demonstrate strong performance across all layers. In the first layer, GMM achieves superior normal-attack discrimination (accuracy = 0.953, TPR = 1.000). In open-set recognition, GMM attains a recall of 0.813 for known attacks, while LOF achieves 0.882 recall for unknown attacks. For fine-grained classification of known attacks, Random Forest achieves a macro-F1 of 0.941. Finally, the incremental learning module maintains robust performance when incorporation novel attack classes, achieving a macro-F1 of 0.8995. These results showcase MI$^2$DAS as an effective, scalable and adaptive framework for enhancing IIoT security against evolving threats.

入侵检测工业物联网增量学习开放集识别

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。