SNN检测网络入侵时,脉冲时间比频率更重要,需谨慎设计评估方式。
The Value of Spike Timing: A Leakage-Resistant Benchmark of SNN Design Choices for Network Intrusion Detection

- 对比27种神经元与编码组合,发现漏电型脉冲时间编码表现最优
- 脉冲时间携带信息可提升宏观F1,且影响网络动态响应效果
- 适合关注SNN设计细节的网络安全研究者与模型开发者
脉冲神经网络(SNN)在网络安全入侵检测中日益受到关注,但关于神经元模型与脉冲编码对性能影响的对比证据仍有限。当预处理、捕获结构或场景信息跨越训练-测试边界时,评估选择可能影响结果。本研究评估了snnTorch中的九类神经元与三种脉冲编码,共27种SNN配置,在四个入侵检测基准上进行测试。先进行设计空间筛选,再使用仅训练集变换、种子无关划分及捕获/场景感知分离重复评估。结果显示,漏电并行/延迟编码在27种配置中表现最佳。筛选出的领先配置在严格协议下依然保持一致,表明筛选能有效保留设计选择排序。进一步分析发现,在固定激活脉冲集合下,仅改变其时间分布:在主运行点T=25处,将特征幅度映射到脉冲时间可提升所有五个验证协议的宏平均F1;而单纯延展脉冲时间却可能导致性能提升或下降。这说明延迟编码的作用来自脉冲时间所携带的信息及其与网络时间动态的交互。此外,稀疏输入编码并不直接导致内部活动稀疏,尽管在所测模型中,延迟编码所需加权操作数少于速率编码。总体表明,将SNN应用于静态网络流数据时,需分别审视设计选择、评估协议、脉冲时间表示与计算活跃度。
原文摘要 · Abstract (English)
Spiking neural networks (SNNs) are increasingly studied for network intrusion detection, but comparative evidence on how neuron models and spike encodings affect performance remains limited. Evaluation choices can influence results when preprocessing, capture structure, or scenario information crosses the train--test boundary. We evaluate nine snnTorch neuron families with three spike encodings, yielding 27 SNN configurations across four intrusion-detection benchmarks. We screen the design space and then repeat the evaluation using train-only transforms, seed-independent partitions, and capture- or scenario-aware separation. In our study, LeakyParallel/latency ranked first in both 27-configuration evaluations. The leading configurations identified during screening also remained largely consistent under confirmation, indicating that screening preserved the ordering useful for design selection even when the measured performance changed under the stricter protocol. We then examine what latency coding contributes by holding the active spike set fixed and changing only its temporal organization. At the main T=25 operating point, mapping feature magnitude to spike time improved macro-F1 on all five confirmation protocols, while spreading the same spikes through time without that mapping could either improve or reduce performance. This shows that the effect of latency coding comes from both the information carried by spike time and how those spikes interact with the temporal dynamics of the network. Finally, sparse input encoding does not directly translate into sparse internal activity, although latency coding requires fewer fanout-weighted operations than rate coding in the evaluated models. Overall, the results show that SNN design choice, evaluation protocol, spike-timing representation, and computational activity should be examined separately when applying SNNs to static network-flow data.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。