arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

结合Transformer神经网络与对抗性研究的持续学习自适应入侵检测系统

Adaptive Intrusion Detection System using Transformer-Based Neural Networks and Continual Learning Approach with Adversarial Investigation

Azizi Ariffin, Afif Haris, Faiz Zaki, Hazim Hanif, Nor Badrul Anuar

arXiv 2608.04602首次发表:更新:

AI 中文总结

本文提出结合表格型Transformer编码器与类别平衡经验重放缓冲区的自适应IDS框架,在CICIDS2017基准测试中表现优异,同时揭示了重放缓冲区存在的标签翻转与后门攻击漏洞。

AI 中文摘要

基于固定流量快照训练的网络入侵检测系统(IDS)在部署后会随威胁分布变化而性能悄然衰减。对新攻击微调模型会触发灾难性遗忘,而从头重新训练在计算上不可行。基于重放的持续学习可应对此问题,但现有方法不切实际地将良性流量限制在单个早期任务中,且忽视了重放缓冲区可能成为攻击面。为解决这些问题,本文提出一种自适应IDS框架,其结合表格型Transformer编码器与类别平衡经验重放缓冲区,在每次更新时重放良性流量以稳定决策边界。本文引入类别实例增量(CII)场景,其中良性流量与新攻击一同出现,作为更符合实际的压力测试,并通过显性标签翻转和隐蔽后门投毒攻击探测该缓冲区。在CICIDS2017基准测试中,该框架在传统类别增量设置下准确率达0.9994,在CII设置下达0.9989,遗忘可忽略不计,显著优于顺序微调(0.0052)、EWC(0.0324)、LwF(0.0699)和iCaRL(0.8770)等基线方法。尽管将良性流量注入每段经验对防止遗忘至关重要,但重放缓冲区引入了关键漏洞:在1%预算下,标签翻转会使模型完全崩溃(准确率为0.0053);而后门攻击在保持0.97总体准确率的同时,使触发流的攻击成功率达到95%,从而规避标准监测。最终,适度的重放预算可恢复接近联合训练的性能,而确保缓冲区完整性成为严格的操作要求。

英文摘要

Network intrusion detection systems (IDS) trained on fixed traffic snapshots decay silently after deployment as threat distributions shift. Fine-tuning models on new attacks triggers catastrophic forgetting, while retraining from scratch is computationally infeasible. Replay-based continual learning counters this, but existing methods unrealistically confine benign traffic to a single early task and ignore the replay buffer as a potential attack surface. To address this, we present an adaptive IDS framework coupling a tabular transformer encoder with a class balanced experience replay buffer that replays benign traffic at every update to stabilize decision boundaries. We introduce the class-instance incremental (CII) scenario where benign flows reappear alongside new attacks as a more faithful stress test, and probe the buffer with overt label flipping and stealthy backdoor poisoning attacks. On the CICIDS2017 benchmark, our framework achieved 0.9994 accuracy under the traditional class incremental setup and 0.9989 under CII, with negligible forgetting, drastically outperforming sequential fine-tuning (0.0052), EWC (0.0324), LwF (0.0699), and iCaRL (0.8770) baselines. While injecting benign traffic into every experience proves essential for preventing forgetting, the replay buffer introduces critical vulnerabilities. Label-flipping collapses the model entirely (0.0053 accuracy at a 1% budget), and the backdoor maintains 0.97 overall accuracy while driving the attack success rate on trigger flows to 95%, evading standard monitoring. Ultimately, while a modest replay budget recovers near-joint-training performance, ensuring buffer integrity emerges as a strict operational requirement.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑