arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.16769cs.CR

面向部署且资源高效的神经-符号框架,用于运营技术网络中可解释的DDoS检测

A Deployment-Oriented and Resource-Efficient Neuro-Symbolic Framework for Explainable DDoS Detection in Operational Technology Networks

Mikiyas Alemayehu, Mohamed Chahine Ghanem, Hamza Kheddar, Aohan Li, J. J. Garcia-Luna-Aceves

首次发表
浏览论文内容

中文总结 AI 辅助

该研究针对运营技术网络,提出融合GRU与浅层决策树的神经-符号框架,在三类DDoS数据集上实现高检测精度与低误报率,推理延迟满足OT控制循环要求。

中文摘要 AI 辅助

运营技术(OT)环境,包括可编程逻辑控制器(PLC)、工业控制系统(ICS)以及监控与数据采集(SCADA)系统,正日益成为分布式拒绝服务(DDoS)攻击的目标。本文提出一种专为这些资源受限环境设计的鲁棒DDoS检测神经-符号框架,该框架将门控循环单元(GRU)神经网络与作为符号组件的浅层决策树相融合;符号组件单独提供紧凑、可解释的规则集,而融合则结合了两种范式的优势。该混合模型在三个真实世界基准DDoS数据集(CIC-DDoS2019、Edge-IIoTset、CICIoT23)上进行评估,应用了包含标签映射、数值特征选择、鲁棒缩放和类别平衡的统一综合预处理流程;在验证数据上联合优化融合权重α和决策阈值,以最大化F1分数。该混合模型在CIC-DDoS2019上达到99.04%的准确率(MCC为0.97),在CICIoT23上达到98.61%的准确率(MCC为0.76),两种情况下的误报率(FNR)均低于纯神经和纯符号基线;在可线性分离的Edge-IIoTset上,仅浅层决策树就已达到100%,因此该基准验证的是预处理流程而非融合。融合的主要优势在于,在可控的误报成本下实现更低的误报率,这在运营技术中至关重要,因为漏报攻击比误报的破坏性更大。仅模型的推理延迟在标准中央处理器上为亚毫秒级(每个样本0.58-0.79毫秒);若包含设备上的流特征提取,端到端路径仍保持在个位数毫秒的预算内,与OT控制循环时序兼容。

英文摘要

Operational technology (OT) environments, including programmable logic controllers (PLCs), industrial control systems (ICS), and supervisory control and data acquisition (SCADA) systems, are increasingly targeted by distributed denial-of-service (DDoS) attacks. This paper presents a neuro-symbolic framework specifically designed for robust DDoS detection in these resource-constrained environments. The framework fuses a gated recurrent unit (GRU) neural network with a shallow decision tree as a symbolic component. The symbolic component alone provides a compact, interpretable rule set, while the fusion combines the strengths of both paradigms. The hybrid model is evaluated on three real-world benchmark DDoS datasets: CIC-DDoS2019, Edge-IIoTset, and CICIoT23. A unified comprehensive preprocessing pipeline including label mapping, numerical feature selection, robust scaling, and class balancing is applied. The fusion weight alpha and decision threshold are jointly optimised on validation data to maximise F1-score. The hybrid model attains 99.04% accuracy (MCC 0.97) on CIC-DDoS2019 and 98.61% accuracy (MCC 0.76) on CICIoT23, in both cases reducing the FNR below that of the pure-neural and pure-symbolic baselines; on the linearly separable Edge-IIoTset the shallow decision tree alone already reaches 100%, so this benchmark validates the preprocessing pipeline rather than the fusion. The principal gain of the fusion is a lower FNR at a controlled false-positive cost, which matters in operational technology, where a missed attack is more damaging than a false alarm. Model-only inference latency is sub-millisecond (0.58-0.79 milliseconds per sample) on a standard central processing unit; including on-device flow-feature extraction, the end-to-end path remains within a single-digit-millisecond budget, which is compatible with OT control-loop timing.

补充信息

↑