发表机构
The Hong Kong Polytechnic University(香港理工大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
PairAudit通过图标记捕获预测模式,在固定预算下发现并纠正入侵检测中被忽略的错误,实验证明其比基于不确定性的审查更有效。
AI 中文摘要
入侵检测器可能会自信地将训练期间未见过的攻击错误分类。人工审查可以纠正这些错误,但只能检查有限数量的案例。基于不确定性的审查可能会忽略自信的错误,而仅凭异常分数无法表明更改审查计划是否会纠正更多错误。我们引入了PairAudit,以在固定预算下发现被忽略的错误并改进审查。其图标记捕获跨连接节点的预测模式。PairAudit并非通过特征聚合构建另一个预测器,而是利用不寻常的关系模式来揭示现有预测中的潜在错误。随后,人工反馈有助于决定这些发现是否证明改变审查优先级是合理的。跨安全任务的实验表明,PairAudit平均比基于不确定性的审查纠正更多错误,包括在未见攻击上纠正更多错误。这些收益考虑了所有审查成本,且无需重新训练检测器。
英文摘要
Intrusion detectors can confidently misclassify attacks that were not seen during training. Human review can correct these errors, but only a limited number of cases can be checked. Uncertainty-based review may overlook confident errors, while anomaly scores alone do not show whether changing the review plan will correct more errors. We introduce PairAudit to find overlooked errors and improve review under a fixed budget. Its graph tokens capture prediction patterns across connected nodes. Rather than building another predictor through feature aggregation, PairAudit uses unusual relational patterns to uncover potential errors in existing predictions. Human feedback then helps decide whether these findings justify changing review priorities. Experiments across security tasks show that PairAudit corrects more errors on average than uncertainty-based review, including more errors on unseen attacks. These gains account for all review costs and do not require retraining the detector.
Comments22 pages, 3 figures