arXiv:2604.20934cs.CRcs.LG2026-04

基于SDN流量的高精度入侵检测框架,兼具高准确率与可解释性。

SDNGuardStack: An Explainable Ensemble Learning Framework for High-Accuracy Intrusion Detection in Software-Defined Networks

  • 构建融合特征选择与集成学习的SDNGuardStack模型
  • 在InSDN数据集上达到99.98%准确率与0.9998的Cohen Kappa值
  • 通过SHAP方法实现预测可解释,适合安全运维人员使用

软件定义网络(SDN)因其集中化设计提升了网络可编程性与管理效率,但也带来了显著安全风险,亟需高效入侵检测系统。本文提出一种基于机器学习的SDN专用检测框架,首次在模拟真实攻击场景与流量模式的InSDN数据集上训练与测试。该框架包含完整的预处理流程、基于互信息的特征选择,以及创新的集成学习模型SDNGuardStack,通过融合多个基础学习器提升检测精度与效率。同时引入可解释AI方法(如SHAP),增强模型决策透明度,帮助安全分析师快速响应。实验表明,该模型在准确率上达99.98%,Cohen Kappa系数为0.9998,优于现有方法。关键影响因素包括Flow ID、Bwd Header Len和Src Port等。该工作推动了高性能检测与实际部署之间的融合,助力构建更安全、韧性的网络基础设施。

原文摘要 · Abstract (English)

Software-Defined Networking (SDN) is another technology that has been developing in the last few years as a relevant technique to improve network programmability and administration. Nonetheless, its centralized design presents a major security issue, which requires effective intrusion detection systems. The SDN-specific machine learning-based intrusion detection system described in this paper is innovative because it is trained and tested on the InSDN dataset which models attack scenarios and realistic traffic patterns in SDN. Our approach incorporates a comprehensive preprocessing pipeline, feature selection via Mutual Information, and a novel ensemble learning model, SDNGuardStack, which combines multiple base learners to enhance detection accuracy and efficiency. In addition, we include explainable AI methods, including SHAP to add transparency to model predictions, which helps security analysts respond to incidents. The experiments prove that SDNGuard-Stack has an accuracy rate of 99.98% and a Cohen Kappa of 0.9998, surpassing other models, and at the same time being interpretable and practically executable. It is interesting to see such features like Flow ID, Bwd Header Len, and Src Port as the most important factors in the model predictions. The work is a step towards closing the gap between performance intrusion detection and realistic deployment in SDN, which will lead to the creation of secure and resilient network infrastructures.

入侵检测SDN可解释AI集成学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。