arXiv:2603.00453cs.CRcs.LG2026-03中稿 · IEEE ICC 2026被引 1

用神经符号方法解决物联网中隐蔽攻击检测难题

Neurosymbolic Learning for Advanced Persistent Threat Detection under Extreme Class Imbalance

  • 结合BERT与逻辑张量网络,实现可解释的威胁检测
  • 在极端不平衡数据下达成95.27%的二分类F1分数
  • 适合需要高可信度和可解释性的工业安全场景

智能城市与工业环境中物联网设备的广泛应用,加剧了隐蔽、多阶段高级持续性威胁(APTs)通过无线通信发起的风险。由于网络流量存在严重类别不平衡,传统深度学习方法效果受限且缺乏决策可解释性。本文提出一种神经符号架构,将优化的BERT模型与逻辑张量网络(LTN)结合,用于无线物联网网络中的可解释APT检测。该方法通过高效特征编码,将网络流数据转化为BERT兼容序列,同时保留关键的时间依赖性以识别攻击阶段。针对严重类别不平衡问题,采用焦点损失、分层分类(区分正常流量与攻击分类)及自适应采样策略。在SCVIC-APT2021数据集上的评估显示,二分类任务的F1得分为95.27%,误报率为0.14%;多分类攻击识别的宏平均F1为76.75%。此外,新颖的可解释性分析统计验证了不同网络特征的重要性。结果表明,神经符号学习可实现高性能、可解释且具备实际部署可行性的物联网网络威胁检测。

原文摘要 · Abstract (English)

The growing deployment of Internet of Things (IoT) devices in smart cities and industrial environments increases vulnerability to stealthy, multi-stage advanced persistent threats (APTs) that exploit wireless communication. Detection is challenging due to severe class imbalance in network traffic, which limits the effectiveness of traditional deep learning approaches and their lack of explainability in classification decisions. To address these challenges, this paper proposes a neurosymbolic architecture that integrates an optimized BERT model with logic tensor networks (LTN) for explainable APT detection in wireless IoT networks. The proposed method addresses the challenges of mobile IoT environments through efficient feature encoding that transforms network flow data into BERT-compatible sequences while preserving temporal dependencies critical for APT stage identification. Severe class imbalance is mitigated using focal loss, hierarchical classification that separates normal traffic detection from attack categorization, and adaptive sampling strategies. Evaluation on the SCVIC-APT2021 dataset demonstrates an operationally viable binary classification F1 score of 95.27% with a false positive rate of 0.14%, and a 76.75% macro F1 score for multi-class attack categorization. Furthermore, a novel explainability analysis statistically validates the importance of distinct network features. These results demonstrate that neurosymbolic learning enables high-performance, interpretable, and operationally viable APT detection for IoT network monitoring architectures.

威胁检测神经符号物联网安全可解释性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。