用流量采样与漂移检测结合,稳定识别物联网设备类型
Maintaining IoT Device Identification under Concept Drift via Budget-Aware Traffic Labeling

- 分离选择样本与决定数量:均匀采样+漂移检测控制标注量
- 两年数据验证:重新训练可恢复分类性能,漂移检测有效预警
- 提供特征级解释,适合网络运维与安全团队使用
从被动流量中识别物联网设备类型在企业与ISP网络中日益用于安全管理。然而,随着设备行为演变,基于机器学习的分类器性能会因概念漂移而下降。为维持性能,需定期用新标注的部署流量重训模型。核心挑战在于确定标注多少及哪些流量实例。本文表明这两者应分开处理:仅依赖漂移检测选样本会遗漏新兴行为空间,而均匀采样更能代表行为变化;漂移检测则更适合判断应标注的流量规模。本文贡献有三:(1) 对21类物联网设备进行为期两年的纵向研究,揭示行为演化的模式,并验证重新标注流量可恢复分类性能;(2) 提出基于一致性检验的漂移检测器,直接从原始流量特征构建类别条件行为模型,并提供行为演化特征级解释;(3) 证明根据观测到的行为演化调整标注率,配合均匀采样,比检测引导样本选择更有效,且显著降低标注负担。该策略性能接近置信度引导方法,但具备可解释性。评估基于超过两年内采集的380万条IPFIX流记录。
原文摘要 · Abstract (English)
Identification of IoT device types from passive traffic is increasingly used for security management in enterprise and ISP networks. However, the performance of machine learning-based classifiers gradually degrades under concept drift as device behavior evolves. Therefore, maintaining classification performance requires periodic retraining with newly labeled deployment traffic. The operational challenge is determining how much and which deployment traffic instances to label for maintaining classification performance. We show that these two decisions should be treated separately. While retraining solely on instances selected by a drift detector is prone to systematically overlooking parts of the emerging behavioral space, uniformly sampled deployment traffic captures more representative behavioral changes. Instead, drift detection is more effective at determining the amount of deployment traffic that should be labeled. We make three contributions. (1) We conduct a two-year longitudinal study of IoT traffic and characterize how behavioral evolution manifests across device classes and how retraining with newly labeled traffic restores classification performance. (2) We develop a conformity-based drift detector that captures class-conditional behavioral models directly from raw traffic features and provides feature-level explanations of behavioral evolution. (3) We demonstrate that adjusting the traffic labeling rate according to the observed behavioral evolution, combined with uniform traffic sampling, maintains classifier performance more effectively than detector-guided sample selection and is beneficial to managing the traffic labeling effort. We further show that this strategy performs comparably to confidence-guided adaptation while providing feature-level explanations. Our evaluation uses 3.8 million IPFIX flow records collected from 21 IoT types over more than 2 years.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。