arXiv:2607.00553cs.CRcs.AI2026-07被引 1

轻量级工控网络入侵检测模型在跨域场景下表现差,因依赖可被利用的端口特征。

Cross-Domain Generalization Failure in Lightweight Intrusion Detection Models for IIoT Networks

论文配图:Cross-Domain Generalization Failure in Lightweight Intrusion Detection Models for IIoT Networks
图 1 · 摘自论文原文
  • 用跨域特征评估轻量模型,避免仅在训练域测试的偏差。
  • 96至435倍的端口类别差异导致模型依赖虚假捷径,跨域泛化失败。
  • 适合关注边缘部署安全性的研究人员和工业系统开发者。

由于资源受限的边缘部署需求,轻量级机器学习模型在工业互联网(IIoT)网络入侵检测中日益流行。现有研究多仅在训练网络内评估模型性能,未验证其在未知网络中的表现。本研究在一份IIoT数据集上训练四种轻量架构,使用跨源可用的特征表示,在两个结构不同的IIoT数据集上进行无重训练评估。对两个表现最佳模型的可解释性分析显示,两者均严重依赖粗粒度端口类别特征;该类别在源域攻击流量中的频率是目标域的96至435倍,表明粗化端口分辨率只是转移而非消除已知捷径。在自然不平衡类别分布下评估发现,评价协议本身可颠倒哪个目标域更具泛化挑战性。还评估了对抗鲁棒性及有限目标域暴露下的恢复能力:对抗扰动鲁棒性与跨网络泛化无关,而适应恢复能力则因架构而异。结果表明,应基于真实类别分布下的跨网络评估来判断部署可行性,而非仅依赖域内准确率。

原文摘要 · Abstract (English)

Lightweight machine learning models are increasingly proposed for intrusion detection in Industrial Internet of Things (IIoT) networks due to their suitability for resource-constrained edge deployment. Most reported results evaluate these models only within their training network, leaving behavior on unseen networks unverified. This study trains four lightweight architectures on one IIoT dataset and evaluates them, without retraining, on two structurally distinct IIoT datasets using a feature representation restricted to attributes available across all three sources. Explainability analysis across two top-performing models shows both rely overwhelmingly on coarse port-category features; the most influential category occurs in source-domain attack traffic at 96 to 435 times the rate in the two target domains, indicating that coarsening port resolution relocates rather than removes a documented shortcut. Evaluation under naturally imbalanced class distributions reveals a further effect: the evaluation protocol used can reverse which target network appears to pose the greater generalization challenge. Adversarial robustness and recovery through limited target-domain exposure are also assessed; robustness to adversarial perturbation is unrelated to cross-network generalization, and recovery through adaptation varies considerably by architecture. These findings suggest deployment readiness should be assessed using cross-network evaluation under realistic class distributions, rather than within-domain accuracy alone.

入侵检测轻量模型跨域泛化

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。