arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

导航潜在流形:面向弹性NIDS的主动概念漂移适应

Navigating the Latent Manifold: Proactive Concept Drift Adaptation for Resilient NIDS

Chao Zha, Zifeng Kang, Tian Liu, Dakun Shen, Ruyun Zhang

arXiv 2609.08623首次发表:更新:

发表机构

Zhejiang University; Institute of Computing Technology, Chinese Academy of Sciences; Beijing University of Posts and Telecommunications; Institute of Agricultural Equipment, Zhejiang Academy of Agricultural Sciences; Shanghai AI Laboratory(浙江大学; 中国科学院计算技术研究所; 北京邮电大学; 浙江省农业科学院农业装备研究所; 上海人工智能实验室)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对AI-NIDS在动态网络中因概念漂移导致的性能下降问题,提出DriftXpert两阶段离线自适应框架,利用潜在流形偏差检测和表示一致性对齐,实现高灵敏漂移适应且避免灾难性遗忘,实验验证有效。

AI 中文摘要

网络入侵检测系统(NIDS)对于网络安全至关重要,保护服务和数据免受潜在攻击。然而,现有的基于人工智能的NIDS通常假设静态数据分布,无法处理概念漂移,导致在动态网络环境中性能下降和误报率增加。为解决此问题,我们提出了DriftXpert,一种新颖的用于漂移自适应检测的NIDS。具体而言,我们提出了一种解耦的两阶段离线自适应框架。在第一阶段,我们引入了一种基于潜在流形偏差的无监督异常度量。通过在潜在空间内进行离群点分析,该框架实现了对网络流量概念漂移的高灵敏度检测。在第二阶段,为缓解非平稳分布下的灾难性遗忘,我们设计了一种表示一致性对齐策略。该策略约束旧模型与漂移分布之间的特征映射,确保模型捕获新兴攻击特征,同时保留对已知模式的判别能力。此外,我们整合了跨周期神经元权重聚合和选择性冻结机制,以在参数空间中实现细粒度知识迁移,有效平衡模型的可塑性和稳定性。在公共数据集上的大量实验表明,DriftXpert能有效适应漂移数据且不发生灾难性遗忘。此外,在企业网络上的实际评估进一步证实了其鲁棒性和实际适用性,为数百万用户的安全保护做出了贡献。

英文摘要

Network intrusion detection systems (NIDS) are critical for cybersecurity, safeguarding services and data from potential attacks. However, existing AI-based NIDS often assume static data distributions and fail to handle concept drift, leading to degraded performance and increased false positives in dynamic network environments. To address this issue, we propose DriftXpert, a novel NIDS for drift-adaptive detection. Specifically, we propose a decoupled two-stage offline adaptive framework. In Phase 1, we introduce an unsupervised anomaly metric based on latent manifold deviation. By performing outlier analysis within the latent space, the framework achieves high-sensitivity detection of network traffic concept drift. In Phase 2, to mitigate catastrophic forgetting under non-stationary distributions, we design a representation consistency alignment strategy. This strategy constrains the feature mapping between the legacy model and the drifted distribution, ensuring the model captures emerging attack characteristics while retaining discriminative power over known patterns. Furthermore, we incorporate cross-epoch neuron weight aggregation and selective freezing mechanisms to enable fine-grained knowledge transfer in the parameter space, effectively balancing model plasticity and stability. Extensive experiments on public datasets demonstrate that DriftXpert effectively adapts to drifted data without catastrophic forgetting. Furthermore, real-world evaluations on enterprise network further confirm its robustness and practical applicability, contributing to improved security protection for millions of users.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑