UNAD+提升未知攻击检测精度,降低误报并提供可解释性。
UNAD+: An Explainable Hybrid Framework for Unknown Network Attack Detection

- 用无监督集成加加权投票检测未知攻击,再通过伪标签微调优化
- 在CICIDS2017和NSL-KDD上F1超98%,误报率显著下降
- 新增事后解释层,适合需透明决策的安全系统部署
未知网络攻击的检测仍是入侵检测系统的主要挑战。尽管监督学习在已知攻击类别上表现良好,但当训练数据中不包含新攻击类型时便受限。无监督方法更适合检测零日攻击,因其无需标注攻击样本,但常面临高误报率,限制了实际应用。本文提出改进框架UNAD+,基于先前的未知网络攻击检测器(UNAD)。UNAD+结合仅良性流量的无监督集成与加权多数投票(WMV),利用伪标签检测结果进行有监督精炼,并引入事后可解释层,提供局部与全局解释。在CICIDS2017和NSL-KDD基准数据集上评估显示,相比原始UNAD,UNAD+在所有数据集上实现超过98%的F1分数,显著降低误报率,并通过集成可解释性增强透明度与部署可行性。
原文摘要 · Abstract (English)
The detection of previously unseen network attacks remains a major challenge for intrusion detection systems. Although supervised learning methods often perform well on known attack classes, they are limited when new attack types are not represented in the training data. Unsupervised methods are more suitable for detecting zero-day attacks, as they do not require labelled attack samples, but they often suffer from high false positive rates, which limits their real-world usefulness. This paper presents UNAD+, an enhanced framework for unknown network attack detection derived from the previously proposed Unknown Network Attack Detector (UNAD). UNAD+ combines a benign-only unsupervised ensemble with Weighted Majority Voting (WMV), a supervised refinement stage trained on pseudo-labelled detections, and a post hoc explainability layer that provides both local and global explanations. The framework was evaluated on the CICIDS2017 and NSL-KDD benchmark datasets. The results show that UNAD+ improves on the original UNAD framework, achieving F1-scores above 98% across the benchmark datasets while significantly reducing false positives and enhancing transparency and deployment suitability through integrated explainability.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。