arXiv:2604.12655cs.LGcs.CR2026-04中稿 · publication in IEE…

提出鲁棒半监督方法,应对云网络中对抗性流量与数据漂移问题。

Robust Semi-Supervised Temporal Intrusion Detection for Adversarial Cloud Networks

  • 结合一致性正则化与置信度感知伪标签,筛选可靠无标签数据
  • 在有限标注下实现比现有方法更高的检测准确率与抗干扰能力
  • 适合实际云环境中的动态攻击检测,尤其适用于标注稀缺场景

云网络日益依赖基于机器学习的入侵检测系统应对不断演化的网络威胁。然而,真实部署面临标注数据有限、流量非平稳及自适应攻击者等挑战。现有半监督方法通常假设无标签流量为良性且稳定,导致在对抗性云环境中性能下降。本文提出一种鲁棒的半监督时序学习框架,显式处理无标签流量中的对抗污染与时序漂移。该框架基于流级数据,融合监督学习与一致性正则化、置信度感知伪标签及选择性时序不变性,在保守利用无标签数据的同时抑制不可靠样本。通过挖掘网络流的时序结构,提升了跨异构云环境的鲁棒性与泛化能力。在公开数据集CIC-IDS2017、CSE-CIC-IDS2018和UNSW-NB15上,于有限标注条件下进行大量评估,结果表明该框架在检测性能、标签效率及对对抗性与非平稳流量的鲁棒性方面均持续优于当前最优的监督与半监督入侵检测系统。

原文摘要 · Abstract (English)

Cloud networks increasingly rely on machine learning based Network Intrusion Detection Systems to defend against evolving cyber threats. However, real-world deployments are challenged by limited labeled data, non-stationary traffic, and adaptive adversaries. While semi-supervised learning can alleviate label scarcity, most existing approaches implicitly assume benign and stationary unlabeled traffic, leading to degraded performance in adversarial cloud environments. This paper proposes a robust semi-supervised temporal learning framework for cloud intrusion detection that explicitly addresses adversarial contamination and temporal drift in unlabeled network traffic. Operating on flow-level data, this framework combines supervised learning with consistency regularization, confidence-aware pseudo-labeling, and selective temporal invariance to conservatively exploit unlabeled traffic while suppressing unreliable samples. By leveraging the temporal structure of network flows, the proposed method improves robustness and generalization across heterogeneous cloud environments. Extensive evaluations on publicly available datasets (CIC-IDS2017, CSE-CIC-IDS2018, and UNSW-NB15) under limited-label conditions demonstrate that the proposed framework consistently outperforms state-of-the-art supervised and semi-supervised network intrusion detection systems in detection performance, label efficiency, and resilience to adversarial and non-stationary traffic.

入侵检测半监督学习云安全时序建模

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。