arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

面向异构网络流的原生事件符号-时间脉冲编码框架

Event-Native Symbolic-Temporal Spike Encoding Framework for Heterogeneous Cyber Streams

Dalton Diez, Peyton Andras, Max Shroyer, James Ghawaly

arXiv 2609.15772首次发表:更新:

发表机构

Louisiana State University(路易斯安那州立大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

提出一种原生事件符号-时间脉冲编码框架,将异构网络事件直接映射为稀疏脉冲输入,保留分类语义与时间动态,在边缘硬件约束下使紧凑循环SNN在Network IDS和CAN IDS上分别达到0.987和0.980的混合指标。

AI 中文摘要

脉冲神经网络(SNNs)通过状态化处理在稀疏、事件驱动的计算中展现出潜力,且天然兼容低功耗边缘硬件。这些特性与网络监控场景相契合,其中数据以异步方式到达,恶意行为往往通过事件序列中的时间模式显现。然而,网络流并非仅由连续数值信号组成:其信息结构还由分类标识符、不规则时序和局部行为上下文承载。传统的基于速率和群体的脉冲编码方式并不天然适应这些异构语义,而传统入侵检测系统(IDS)流程通常通过将原始事件转换为流、固定聚合窗口或稠密张量来解决这种不匹配。尽管这些转换对传统分类器有用,但会引入缓冲延迟、掩盖原生时间结构,并削弱事件驱动神经形态计算的计算优势。我们提出了一种原生事件符号-时间脉冲编码框架,将异构网络事件直接映射为稀疏、脉冲兼容的输入。通过为语义身份、局部频率上下文和事件间时序分配编码角色,该框架保留了分类语义和时间动态。我们在数据包级网络入侵检测系统(Network IDS)上验证了该方法,并将其扩展到消息级控制器局域网入侵检测系统(CAN IDS),利用这两个领域评估编码是否为直接在原生事件流上运行的循环SNN提供了可用结构。在面向边缘、与$\mu$Caspian对齐的硬件约束下,紧凑的循环SNN实现了强大的异常检测性能,在Network IDS上操作混合指标($J_{hybrid}$)为0.987,在CAN IDS上为0.980。

英文摘要

Spiking neural networks (SNNs) have shown promise for sparse, event-driven computation through stateful processing that is naturally compatible with low-power edge hardware. These properties align with cyber monitoring, where data arrives asynchronously, and malicious behavior often emerges through temporal patterns across event sequences. However, cyber streams are not composed solely of continuous numeric signals: their informative structure is also carried by categorical identifiers, irregular timing, and local behavioral context. Traditional rate- and population-based spike encodings are not naturally suited to these heterogeneous semantics, while conventional intrusion detection system (IDS) pipelines typically resolve the mismatch by converting raw events into flows, fixed aggregation windows, or dense tensors. Although useful for conventional classifiers, these transformations introduce buffering latency, obscure native temporal structure, and weaken the computational advantages of event-driven neuromorphic processing. We introduce an event-native symbolic-temporal spike encoding framework that maps heterogeneous cyber events directly into sparse, spike-compatible inputs. By assigning encoding roles to semantic identity, local frequency context, and inter-event timing, the framework preserves categorical semantics and temporal dynamics. We validate the approach on packet-level Network IDS and extend it to message-level CAN IDS, using both domains to evaluate whether the encoding exposes usable structure for recurrent SNNs operating directly on native event streams. Under edge-oriented, $μ$Caspian-aligned hardware constraints, compact recurrent SNNs achieve strong anomaly detection performance, with an operational hybrid metric ($J_{hybrid}$) of 0.987 on Network IDS and 0.980 on CAN IDS.

CommentsAccepted in The 38th IEEE International Conference on Tools with Artificial Intelligence (ICTAI)

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑