发表机构
Center for Scalable Data Analytics and Artificial Intelligence (ScaDS.AI) Dresden/Leipzig, Leipzig University(莱比锡大学可扩展数据分析与人工智能中心(ScaDS.AI)德累斯顿/莱比锡)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文系统综述2022至2026年网络入侵检测的少样本学习方法,涵盖方法、数据集与性能,发现元学习和卷积神经网络为主流,但可复现性受限。
AI 中文摘要
基于异常的入侵检测系统(NIDS)是第一道重要的防线。然而,针对新型攻击类型训练NIDS具有挑战性,因为标记的攻击数据很少可用。少样本学习(FSL)通过从少量样本中学习来解决这一问题。然而,迄今为止研究的方法和评估设置差异很大。本工作系统性地回顾了2022年至2026年间发表的用于NIDS的FSL方法。我们采用类似PRISMA 2020的报告方式进行了系统性文献综述,检索了ACM数字图书馆、IEEE Xplore和Scopus。从1,358条初始记录中,经过筛选、去重和质量过滤后,我们保留了21项研究。我们对所应用的FSL方法、数据集和实验参数进行了分类,并比较了报告的性能。元学习和卷积神经网络是最常见的方法,分别有8项和10项研究。大多数研究评估每类五个或更少的样本,尽管设置各不相同。CIC-IDS2017和CSE-CIC-IDS2018是最常用的数据集。缺失的参数和源代码限制了方法的可复现性和直接比较。
英文摘要
Anomaly-based network intrusion detection systems (NIDS) are an important first line of defense. However, training NIDS for new attack types is challenging, because labeled attack data are rarely available. Few-shot learning (FSL) addresses this problem by learning from few samples. However, the approaches and evaluation settings, that have been investigated so far, vary widely. This work systematically reviews FSL approaches for NIDS published from 2022 to 2026. We conduct a systematic literature review with PRISMA 2020-like reporting to search ACM Digital Library, IEEE Xplore, and Scopus. From a set of 1,358 initial records, we retain 21 studies after screening, deduplication, and quality filtering. We classify the applied FSL approaches, datasets, and experimental parameters and compare reported performance. Meta-learning and convolutional neural networks are the most common approaches, with 8 and 10 studies, respectively. Most studies evaluate five or fewer samples per class, although settings vary. CIC-IDS2017 and CSE-CIC-IDS2018 are the most frequently used datasets. Missing parameters and source code limit reproducibility and direct comparison between approaches.