<p>With the persistent evolution of network attacks, intrusion detection systems need to enhance their identification capabilities for new types of network traffic attacks. However, the advent of new attacks often introduces the challenge of limited samples. We propose a few-shot intrusion detection method to address this challenge. The core of our approach is a cross-attention mechanism based on a meta-learning layer, which highlights the most distinctive regions between the support set and query set samples, thereby improving the model’s detection and recognition capabilities. Additionally, we perform classification using both nearest neighbor and global classifiers. Two loss functions are employed for optimization, ensuring the model is well-suited for specific few-shot learning tasks while maintaining strong generalization capabilities. To mitigate the problem of sparse sample data, we utilize a transductive inference algorithm that enhances the support set by iteratively incorporating more unlabeled query set samples. Experiments conducted on the CICIDS2017 and TUT datasets validate the effectiveness of the proposed method. By using only five samples to detect new attacks on the CICIDS2017 dataset, our method achieves an average recall of 96.28%, surpassing traditional machine learning methods and existing few-shot intrusion detection techniques. When detecting simulated new attacks on the TUT dataset, the average recall rate reached 88.68%. The method provides a practical technical approach for building intrusion detection systems capable of accurately responding to new attacks.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A few-shot detection method for new types of network traffic attacks based on meta-learning with cross-attention

  • Kai Shi,
  • Penghao Ding,
  • Jinsong Wang

摘要

With the persistent evolution of network attacks, intrusion detection systems need to enhance their identification capabilities for new types of network traffic attacks. However, the advent of new attacks often introduces the challenge of limited samples. We propose a few-shot intrusion detection method to address this challenge. The core of our approach is a cross-attention mechanism based on a meta-learning layer, which highlights the most distinctive regions between the support set and query set samples, thereby improving the model’s detection and recognition capabilities. Additionally, we perform classification using both nearest neighbor and global classifiers. Two loss functions are employed for optimization, ensuring the model is well-suited for specific few-shot learning tasks while maintaining strong generalization capabilities. To mitigate the problem of sparse sample data, we utilize a transductive inference algorithm that enhances the support set by iteratively incorporating more unlabeled query set samples. Experiments conducted on the CICIDS2017 and TUT datasets validate the effectiveness of the proposed method. By using only five samples to detect new attacks on the CICIDS2017 dataset, our method achieves an average recall of 96.28%, surpassing traditional machine learning methods and existing few-shot intrusion detection techniques. When detecting simulated new attacks on the TUT dataset, the average recall rate reached 88.68%. The method provides a practical technical approach for building intrusion detection systems capable of accurately responding to new attacks.