arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

基于聚类的物联网系统集体异常检测:一种图神经网络方法

Clustering-Based Collective Anomaly Detection in IoT Systems: A Graph Neural Network Approach

Dalila Khettaf, Djamel Djenouri, Zeinab Rezaeifar, Youcef Djenouri

arXiv 2609.22166首次发表:更新:

发表机构

University of South-Eastern Norway(东南挪威大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对物联网流量中集体异常检测不足的问题,提出无监督图集体异常检测框架UGCAD,利用变分图自编码器学习表示并增强聚类,在CICIoT2023和ToN-IoT数据集上验证了其优于现有方法。

AI 中文摘要

物联网(IoT)技术的快速发展促使智能互联设备在多个领域广泛部署。然而,这种扩张也导致了网络流量的显著增加,为恶意行为者发动网络攻击和破坏敏感信息创造了更多机会,从而增加了对有效异常检测的需求。当前最先进的异常检测方法主要集中于点异常。相比之下,集体异常的检测在文献中仍相对未被充分探索。在本文中,我们引入了无监督图集体异常检测(UGCAD),这是一种新颖的框架,旨在识别物联网网络流量中的集体异常。与许多现有方法不同,UGCAD在没有任何组标签或成员关系先验知识的情况下,对图结构数据进行操作。它利用变分图自编码器(VGAE)来学习图表示,随后将其用于增强聚类算法,以实现对节点的有效分组。为了检测集体异常,首先对识别为正常的簇进行聚合和细化,然后应用异常分数来检测集体异常。在CICIoT2023和ToN-IoT网络数据集上进行的大量实验证明了UGCAD在聚类和集体异常检测(CAD)方面的有效性。此外,与几种传统和最先进的基于聚类的CAD方法的比较评估证实了UGCAD在准确检测集体异常方面的优越性。

英文摘要

The rapid advancement of Internet of Things (IoT) technology has led to the widespread deployment of smart, interconnected devices across a range of domains. However, this expansion has also resulted in a substantial increase in network traffic, creating more opportunities for malicious actors to launch cyberattacks and compromise sensitive information, thereby increasing the need for effective anomaly detection. The state-of-the-art in anomaly detection has predominantly focused on point anomalies. In contrast, the detection of collective anomalies remains relatively under-explored in the literature. In this paper, we introduce Unsupervised Graph Collective Anomaly Detection (UGCAD), a novel frame- work designed to identify collective anomalies in IoT network traffic. Unlike many existing methods, UGCAD operates on graph-structured data without any prior knowledge of group labels or membership. It leverages a variational graph autoencoder (VGAE) to learn the graph representation, which is subsequently used to enhance a clustering algorithm for effective grouping of nodes. To detect collective anomalies, clusters identified as normal are first aggregated and refined, after which anomaly scores are applied to detect collective anomalies. Extensive experiments conducted on the CICIoT2023 and ToN-IoT network datasets demonstrate the effectiveness of UGCAD in both clustering and collective anomaly detection (CAD). Furthermore, comparative evaluations against several traditional and state-of-the-art clustering-based CAD approaches confirm the superiority of UGCAD in accurately detecting collective anomalies.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑