arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.02469cs.CR

基于机器学习的入侵检测系统评估:模型效能的幻象

Evaluating ML-based Intrusion Detection Systems: The Illusion of Model Efficacy

Achilleas Spanos, Ioanna Kantzavelou

首次发表
浏览论文内容

中文总结 AI 辅助

本文针对基于机器学习的入侵检测系统评估中存在的模型效能幻象问题,设计实验探究分类器对未见过攻击的泛化能力,指出相关研究的结构性缺陷并提出七条评估标准。

中文摘要 AI 辅助

机器学习的集成推动了入侵检测的革新,提升的检测率、降低的误报率以及优化的算法,使人们认为系统具备最优准确率与近乎完美的性能,这便是模型效能的幻象。然而,面对未见过的攻击时,这种效能的价值会大打折扣。本文不局限于仅优化基于机器学习的网络入侵检测系统(ML-based Network Intrusion Detection Systems)的算法与调整指标,而是设计实验测试特定分类器对未见过攻击的泛化能力,通过两种实验方法在两种不同场景中探究维度参数的影响。实验结果揭示了模型能识别出的未见过攻击的占比,并强调了基于机器学习的入侵检测系统(ML-based IDS)研究与评估技术存在的结构性缺陷,最后提出了七条评估标准以应对这些挑战。

英文摘要

Intrusion Detection has been revolutionized due to the integration of Machine Learning. Improved detection rates, reduced false alarms, and optimized algorithms contribute to the perception of improved systems with optimal accuracy and near-perfect performance, the illusion of model efficacy. However, the value of this effectiveness diminishes when confronted with unseen attacks. In this paper, we go beyond solely algorithmic enhancements and metric adjustments in ML-based Network Intrusion Detection Systems. We design an experiment to test the generalization capabilities of certain classifiers on unseen attacks. Our approach examines the dimensionality parameter's impact through two experimental methodologies, which are applied in two distinct settings. The experimental findings reveal how effectively the models could identify even a fraction of unseen attacks and underscore structural weaknesses in ML-based IDS research and evaluation techniques. Finally, seven evaluation criteria are outlined to address these challenges.

发表机构

  • University of West Attica(西阿提卡大学)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑