无需标签数据,用对抗学习检测多变量物联网异常流量
An Adversarial Zero-Shot Learning Approach for Anomaly Detection in Multivariate IoT Traffic Data

- 基于变分自编码器构建对抗训练框架,学习跨域不变特征
- 在44个跨域场景中实现强零样本泛化,准确率优于对比基线
- 适合缺乏标注数据的工业、智能家居等真实物联网环境
物联网网络中的异常检测因设备多样性、标签数据缺失及环境差异而面临挑战。本文提出一种基于序列的变分自编码器框架,融合对抗学习与对比损失,实现无需标签数据或原始特征迁移的零样本域适应。通过引入编码器和解码器适配层,对齐不同域的特征分布并保留上下文语义;同时设计基于目标地址的流量分段策略,更好建模真实通信结构。在涵盖工业、企业、通用、智能家居及军事自动化等六类数据集的44个跨域场景中进行评估,实验表明该方法在多个跨域设置下展现出优异的零样本泛化能力,在异构且隐私受限的真实物联网条件下性能优于对比基线。
原文摘要 · Abstract (English)
Anomaly detection in Internet of Things (IoT) networks presents unique challenges due to the diversity of devices, lack of labeled data, and domain variability across environments. In this paper, we propose a novel framework for multivariate time-series anomaly detection that leverages adversarial learning and contrastive loss within a sequence-based Variational Autoencoder (VAE) architecture. Our method enables zero-shot domain adaptation by jointly optimizing domain-invariant latent representations and semantically structured embedding spaces, without requiring labeled data or raw feature transfer. To address the heterogeneity of IoT deployments, we introduce encoder and decoder adaptor layers that align feature distributions across domains while preserving contextual semantics. Additionally, we propose a destination-based segmentation strategy to better model real-world communication structures in IoT traffic. Our framework is comprehensively evaluated on six distinct datasets spanning industrial, enterprise, general-purpose, smart home, and military automation domains across 44 transfer scenarios. Experimental results demonstrate strong zero-shot generalization in several cross-domain settings and competitive performance against a contrastive domain-adaptation baseline under realistic, heterogeneous, and privacy-constrained IoT conditions.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。