arXiv:2604.06638cs.CRcs.AI2026-04

通过双向点机制提升未知攻击检测能力

RPM-Net Reciprocal Point MLP Network for Unknown Network Security Threat Detection

论文配图:RPM-Net Reciprocal Point MLP Network for Unknown Network Security Threat Detection
图 1 · 摘自论文原文
  • 为每类已知攻击学习'非类别'表示,增强未知威胁识别
  • 在多类不平衡数据上,F1-score和AUROC均优于现有方法
  • 几何可解释性设计,适合需要可信安全防护的场景

在多类别不平衡环境下,有效检测未知网络安全隐患对维护网络空间安全至关重要。现有方法虽侧重于学习类别表征,但在未知威胁检测、类别不平衡及可解释性方面仍面临挑战,限制了实际应用。为此,我们提出RPM-Net,一种新型框架,引入双向点机制,为每类已知攻击学习‘非类别’表示,并结合对抗性间隔约束,赋予未知威胁检测以几何可解释性。RPM-Net++通过Fisher判别正则化进一步提升性能。实验结果表明,RPM-Net在多个指标(包括F1-score、AUROC、AUPR-OUT)上均表现优异,显著超越现有方法,具备实际应用价值。代码已开源:https://github.com/chiachen-chang/RPM-Net。

原文摘要 · Abstract (English)

Effective detection of unknown network security threats in multi-class imbalanced environments is critical for maintaining cyberspace security. Current methods focus on learning class representations but face challenges with unknown threat detection, class imbalance, and lack of interpretability, limiting their practical use. To address this, we propose RPM-Net, a novel framework that introduces reciprocal point mechanism to learn "non-class" representations for each known attack category, coupled with adversarial margin constraints that provide geometric interpretability for unknown threat detection. RPM-Net++ further enhances performance through Fisher discriminant regularization. Experimental results show that RPM-Net achieves superior performance across multiple metrics including F1-score, AUROC, and AUPR-OUT, significantly outperforming existing methods and offering practical value for real-world network security applications. Our code is available at:https://github.com/chiachen-chang/RPM-Net

网络安全未知威胁不平衡学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。