发表机构
Department of CSE, BRAC University(BRAC大学计算机科学与工程系)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
提出一种结合孪生网络异常关联与PPO强化学习自适应防御的零日入侵检测系统,在物联网基准数据集上实现99.07%未知攻击检测准确率和93.94%零日检测率。
AI 中文摘要
零日威胁对物联网(IoT)网络安全而言是新兴的挑战,需要能够识别新兴恶意行为的认知检测机制。传统入侵检测机制难以在复杂的物联网环境中泛化动态的零日漏洞利用。本文提出了一种混合零日入侵检测系统,该系统基于孪生网络的异常关联和基于强化学习的自适应防御。此外,本文在基准物联网数据集上使用无监督机器学习分类器,旨在通过基于距离的相似性分析,将已知攻击类型与未知异常进行区分,以检测可能的零日攻击。为了增强适应性,基于近端策略优化(PPO)的强化学习智能体通过持续反馈和优化动态调整防御策略。实验评估表明,训练准确率达到99.28%,未知攻击检测准确率达到99.07%,零日检测率达到93.94%,证实了模型在该HTTP URL系统上的收敛性和稳定性。该系统通过在精度、延迟和误报之间找到合适的平衡,为物联网部署提供了一种自学习且可扩展的防御机制。这种深度异常关联与自适应强化学习的结合,为零日威胁不断变化的情况下,下一代自主网络安全解决方案奠定了坚实基础。
英文摘要
Zero-day threats are nascent for the Internet of Things (IoT) network security, which demands cognitive detec-tion mechanisms that can identify emerging malicious behavior. Conventional intrusion detection mechanisms fail to generalize dynamic zero-day exploits within sophisticated IoT environments. This paper proposes a hybrid zero-day intrusion detection system using Siamese network-based anomaly correlation and reinforcement learning-based adaptive defense. Furthermore, the paper uses unsupervised machine learning classifiers over benchmark IoT datasets with the intention of detection of known attack types compared to unknown anomalies using distance-based similarity analysis to detect possible zero-day attacks. To facilitate adaptability, a Proximal Policy Optimization (PPO) reinforcement learning-based agent dynamically adjusts the defense policy with continuous feedback and optimization. Experimental evaluations demonstrate 99.28% training accuracy, 99.07% accuracy in unknown attack detection, and 93.94% zero-day detection ratio, confirming the convergence and stability of the model on datasets.The system offers a self-learning and extensible defense mechanism of IoT deployments by finding the right balance between precision, latency and false positives. This deep anomaly correlation with adaptive reinforcement learning is a firm base on which the next generation and autonomic cyber security solutions can take the reins as the zero-day threats keep changing their course.
DOI:10.1016/j.icte.2026.05.001