计算机科学 ›› 2026, Vol. 53 ›› Issue (8): 426-436.doi: 10.11896/jsjkx.250600041
冯皓宇1, 张雨轩2, 刘紫萱1, 孟华1
FENG Haoyu1, ZHANG Yuxuan2, LIU Zixuan1, MENG Hua1
摘要: 随着网络规模的指数级增长和流量形态的日益复杂化,传统基于流量样本的异常检测方法在实时性与计算效率方面面临严峻挑战。为此,提出一种融合门控注意力机制的深度多实例学习框架(GAD-MIL)。该框架对流量样本进行打包处理,用包级别的分析与异常样本定位代替传统的样本级别的分析,从而实现高效的异常流量检测。具体而言,针对打包后的流量数据,构建了双层学习架构。首先,利用基于预训练的特征提取器生成具有强判别性的流量嵌入表示;其次,引入门控注意力多实例池化层,动态聚合包内实例特征并识别异常样本。该架构打破了传统多实例学习模型对包级标签的强依赖,支持端到端的实例级异常定位,同时保持低的计算复杂度。在CICIDS2017和DoH2020等五大主流数据集上进行了实验,结果表明,GAD-MIL能显著缩短推理计算时间,在CICIDS2017数据集上,较传统深度学习方法,其不仅将F1分数提升了2.72个百分点,而且在计算效率层面上将速度提升了4.2倍。
中图分类号:
| [1] KWON D,KIM H,KIM J,et al.A survey of deep learning-based network anomaly detection[J].Cluster Computing,2019,22:949-961. [2] WANG W,ZHU M,ZENG X,et al.Malware traffic classification using convolutional neural network for representation learning[C]//2017 International Conference on Information Networking(ICOIN).New York,USA:IEEE Press,2017:712-717. [3] DING H,SUN Y,HUANG N,et al.TMG-GAN:Generative adversarial networks-based imbalanced learning for network intrusion detection[J].IEEE Transactions on Information Forensics and Security,2023,19:1156-1167. [4] DUAN X,FU Y,WANG K.Network traffic anomaly detection method based on multi-scale residual classifier[J].Computer Communications,2023,198:206-216. [5] ZHOU Z H.Multi-instance learning:A survey[R].Department of Computer Science & Technology,Nanjing University,2004:4. [6] JIANG X,ZHANG H R,ZHOU Y.Multi-granularity abnormal traffic detection based on multi-instance learning[J].IEEE Transactions on Network and Service Management,2023,21(2):1467-1477. [7] ZHANG J,HAN D,LV Z,et al.Bag2image:a multi-instancenetwork traffic representation for network security event prediction[J].Cybersecurity,2025,8(1):31. [8] KIM M S,KONG H J,HONG S C,et al.A flow-based method for abnormal network traffic detection[C]//2004 IEEE/IFIP Network Operations and Management Symposium(IEEE Cat.No.04CH37507).New York,USA:IEEE Press,2004:599-612. [9] FINSTERBUSCH M,RICHTER C,ROCHA E,et al.A survey of payload-based traffic classification approaches[J].IEEE Communications Surveys & Tutorials,2013,16(2):1135-1156. [10] FAN Z,LIU R.Investigation of machine learning based network traffic classification[C]//2017 International Symposium on Wireless Communication Systems(ISWCS).New York,USA:IEEE Press,2017:1-6. [11] YANG J,NARANTUYA J,LIM H.Bayesian neural networkbased encrypted traffic classification using initial handshake packets[C]//2019 49th Annual IEEE/IFIP International Conference on Dependable Systems and Networks-Supplemental Volume(DSN-S).Los Alamitos,USA:IEEE Press,2019:19-20. [12] MA Q,SUN C,CUI B,et al.A novel model for anomaly detection in network traffic based on kernel support vector machine[J].Computers & Security,2021,104:102215. [13] WU T,FAN H,ZHU H,et al.Intrusion detection system combined enhanced random forest with SMOTE algorithm[J].EURASIP Journal on Advances in Signal Processing,2022,2022(1):39. [14] LU C,CAO Y,WANG Z.Research on intrusion detection based on an enhanced random forest algorithm[J].Applied Sciences,2024,14(2):714. [15] CHEN Y.Convolutional neural network for sentence classification[D].Waterloo,Canada:University of Waterloo,2015. [16] LUO H,WAN L.A Network Traffic Intrusion Detection Method Based on Dynamic Spatio-Temporal Graph Neural Network[J].Computer Engineering,doi:10.19678/j.issn.1000-3428.0070520. [17] GRAVES A,SCHMIDHUBER J.Framewise phoneme classification with bidirectional LSTM and other neural network architectures[J].Neural Networks,2005,18(5/6):602-610. [18] ZHU Z,LIANG D,ZHANG S,et al.Traffic-sign detection and classification in the wild[C]//Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition.New York,USA:IEEE Press,2016:2110-2118. [19] GOODFELLOW I,POUGET-ABADIE J,MIRZA M,et al.Gene-rative adversarial networks[J].Communications of the ACM,2020,63(11):139-144. [20] GAO Z Y,WANG T J,WANG Y,et al.Traffic PredictionMethod for 5G Network Based on Generative Adversarial Network[J].Computer Science,2022,49(4):321-328. [21] VASWANI A,SHAZEER N,PARMAR N,et al.Attention is all you need[J].Advances in Neural Information Processing Systems,2017,30. [22] SHI L,ZHANG J T,GAO Y F,et al.Intrusion Detection of Network Traffic based on Transformer and BiLSTM[J].Computer Engineering,2023,49(3):29-36;57. [23] DIETTERICH T G,LATHROP R H,LOZANO-PÉREZ T.Solving the multiple instance problem with axis-parallel rectangles[J].Artificial Intelligence,1997,89(1/2):31-71. [24] ZHANG M L,ZHOU Z H.Multi-instance clustering with applications to multi-instance prediction[J].Applied Intelligence,2009,31:47-68. [25] WEI X S,WU J,ZHOU Z H.Scalable multi-instance learning[C]//2014 IEEE International Conference on Data Mining.New York,USA:IEEE Press,2014:1037-1042. [26] WEI X S,WU J,ZHOU Z H.Scalable algorithms for multi-instance learning[J].IEEE Transactions on Neural Networks and Learning Systems,2016,28(4):975-987. [27] WU J,PAN S,ZHU X,et al.Multi-instance learning with dis-criminative bag mapping[J].IEEE Transactions on Knowledge and Data Engineering,2018,30(6):1065-1080. [28] XU B C,TING K M,ZHOU Z H.Isolation set-kernel and its application to multi-instance learning[C]//Proceedings of the 25th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining.New York,USA:ACM,2019:941-949. [29] XIAO Y,LIU B,HAO Z.Multi-Instance Nonparallel TubeLearning[J].IEEE Transactions on Neural Networks and Learning Systems,2024,36:2563-2577. [30] ILSE M,TOMCZAK J,WELLING M.Attention-based deepmultiple instance learning[C]//International Conference on Machine Learning.San Diego,USA:PMLR,2018:2127-2136. [31] SHI X,XING F,XIE Y,et al.Loss-based attention for deepmultiple instance learning[C]//Proceedings of the AAAI Conference on Artificial Intelligence.Palo Alto,USA:AAAI Press,2020:5742-5749. [32] SHAO Z,BIAN H,CHEN Y,et al.Transmil:Transformerbased correlated multiple instance learning for whole slide image classification[J].Advances in Neural Information Processing Systems,2021,34:2136-2147. [33] ZHANG W,ZHANG X,ZHANG M L.Multi-instance causalrepresentation learning for instance label prediction and out-of-distribution generalization[J].Advances in Neural Information Processing Systems,2022,35:34940-34953. [34] SHARAFALDIN I,LASHKARI A H,GHORBANIA A.To-ward generating a new intrusion detection dataset and intrusion traffic characterization[J].ICISSP,2018,1(2018):108-116. [35] MONTAZERISHATOORI M,DAVIDSON L,KAUR G,et al.Detection of doh tunnels using time-series classification of encrypted traffic[C]//2020 IEEE Intl Conf on Dependable,Autonomic and Secure Computing,Intl Conf on Pervasive Intelligence and Computing,Intl Conf on Cloud and Big Data Computing,Intl Conf on Cyber Science and Technology Congress(DASC/PiCom/CBDCom/CyberSciTech).Los Alamitos,USA:IEEE Press,2020:63-70. [36] MOUSTAFA N,SLAY J.UNSW-NB15:a comprehensive dataset for network intrusion detection systems(UNSW-NB15 network data set)[C]//2015 Military Communications and Information Systems Conference(MilCIS).New York,USA:IEEE Press,2015:1-6. [37] SIDDIQUI M K,NAAHID S.Analysis of KDD CUP 99 dataset using clustering based data mining[J].International Journal of Database Theory and Application,2013,6(5):23-34. [38] KONSTANTINOV A V,UTKIN L V.Multi-attention multiple instance learning[J].Neural Computing and Applications,2022,34(16):14029-14051. |
|
||