计算机科学 ›› 2026, Vol. 53 ›› Issue (8): 469-477.doi: 10.11896/jsjkx.250700031

• 信息安全 • 上一篇    

基于多模态不确定性融合的动态对抗检测框架

符乐, 黄晓芳, 廖敏,宋鲁华   

  1. 西南科技大学计算机科学与技术学院 四川 绵阳 621000
  • 收稿日期:2025-07-07 修回日期:2025-12-13 发布日期:2026-08-17
  • 通讯作者: 黄晓芳(xf.swust@qq.com)
  • 作者简介:(fule0318@foxmail.com)
  • 基金资助:
    四川省自然科学基金(2022NSFSC0916);四川省科技厅重点研发项目(2022YFG0321)

Dynamic Adversarial Detection Framework Based on Multimodal Uncertainty Fusion

FU Le, HUANG Xiaofang, LIAO Min, SONG Luhua   

  1. School of Computer Science and Technology, Southwest University of Science and Technology, Mianyang, Sichuan 621000, China
  • Received:2025-07-07 Revised:2025-12-13 Online:2026-08-17
  • About author:FU Le,born in 2002,postgraduate,is a member of CCF(No.Z9118G).His main research interests include network security and intrusion detection.
    HUANG Xiaofang,born in 1977,Ph.D,professor,Ph.D supervisor,is a member of CCF(No.15666S).Her main research interests include network security,cryptography and blockchain.
  • Supported by:
    Natural Science Foundation of Sichuan Province(2022NSFSC0916) and Key Research and Development Project of Sichuan Provincial Department of Science and Technology(2022YFG0321).

摘要: 针对基于深度神经网络的入侵检测系统在多样化对抗攻击下表现出鲁棒性不足以及传统的融合方法难以兼顾不同攻击场景的特征差异性问题,提出了一种基于多模态不确定性融合的动态对抗样本检测框架。首先,设计了一种训练进度感知的动态损失调度机制,通过线性调度正常样本与对抗样本的权重,实现特征学习与防御鲁棒性的平衡优化。其次,提出不确定性与注意力协同的融合机制,通过蒙特卡罗dropout多次前向采样构建预测分布并量化模型不确定性,再结合上下文相关的注意力模块,自适应调整各子模型的贡献权重,实现多模态特征的动态加权集成,从而有效抑制对抗噪声并突出关键特征。实验结果表明,所提框架在正常样本与多种攻击样本(FGSM,PGD,BIM)下均获得了超过96%的检测准确率和接近100%的AUC,且显著优于AT-DNN与Roshan等代表性对抗防御方法,充分验证了所提框架在提升鲁棒性和泛化能力方面的有效性。

关键词: 对抗检测, 动态损失调度, 蒙特卡罗dropout, 多头注意力, 多模态不确定性融合

Abstract: Aiming at the problem that the intrusion detection system based on deep neural network shows insufficient robustness under diverse adversarial attacks and the traditional fusion method is difficult to take into account the characteristics of different attack scenarios,this paper proposes a dynamic adversarial sample detection framework based on multi-modal uncertainty fusion.Firstly,a training progress aware dynamic loss scheduling mechanism is designed to realize the balance optimization between feature learning and defense robustness by linearly scheduling the weights of normal samples and adversarial samples.Secondly,a collaborative fusion mechanism of uncertainty and attention is proposed.Monte Carlo dropout is used to construct the prediction distribution and quantify the uncertainty of the model.Then,the context-sensitive attention module is combined to adaptively adjust the contribution weights of each sub-model to realize the dynamic weighted integration of multimodal features,so as to effectively suppress the anti-noise and highlight the key features.Experimental results show that the proposed framework achieves more than 96% detection accuracy and nearly 100% AUC under normal samples and multiple attack samples(FGSM,PGD,BIM),which is significantly better than AT-DNN and Roshan and other representative adversarial defense methods,fully veri-fying the effectiveness of the proposed framework in improving robustness and generalization ability.

Key words: Adversarial detection, Dynamic loss scheduling, MC dropout, Multi-head attention, Multimodal uncertainty fusion

中图分类号: 

  • TP309
[1] CHAKRABORTY A,ALAM M,DEY V,et al.Adversarial attacks and defences:A survey[J].arXiv:1810.00069,2018.
[2] GOODFELLOW J I,SHLENS J,SZEGEDY C .Explaining and Harnessing Adversarial Examples[J].arXiv:1412.6572,2014.
[3] APRUZZESE G,ANDREOLINI M,COLAJANNI M,et al.Hardening Random Forest Cyber Detectors Against Adversarial Attacks[J].IEEE Transactions on Emerging Topics in Computational Intelligence,2020,4(4):427-439.
[4] MADRY A,MAKELOV A,SCHMIDT L,et al.Towards deep learning models resistant to adversarial attacks[J].arXiv:1706.06083,2017.
[5] CARLINI N,WAGNER D.Towards evaluating the robustness of neural networks[C]//2017 IEEE Symposium on Security and Privacy(SP).IEEE,2017:39-57.
[6] YANG Y Q ,LV H J,CHEN N.A Survey on ensemble learning under the era of deep learning[J].Artificial Intelligence Review,2022,56(6):5545-5589.
[7] LAZZARINI R,TIANFIELD H,CHARISSIS V.A stacking ensemble of deep learning models for IoT intrusion detection[J].Knowledge-Based Systems,2023,279:110941.
[8] DONG X,YU Z,CAO W,et al.A survey on ensemble learning[J].Frontiers of Computer Science,2020,14:241-258.
[9] JAIN A,KUMAR A,SUSAN S.Evaluating deep neural network ensembles by majority voting cum meta-learning scheme[C]//Soft Computing and Signal Processing:Proceedings of 3rd ICSCSP 2020,Volume 2.Springer.Singapore,2022:29-37.
[10] QIN R,WANG L,DU X,et al.Dynamic ensemble selectionbased on deep neural network uncertainty estimation for adversarial robustness[J].arXiv:2308.00346,2023.
[11] CHAI Y,LIU Y,EBRAHIMI M,et al.Enhancing Adversarial Robustness:A Novel Bayesian Uncertainty-Based Ensemble Learning Method[C]//2024 IEEE 9th International Conference on Data Science in Cyberspace(DSC).IEEE,2024:329-336.
[12] LECUN Y,BOTTOU L,BENGIO Y,et al.Gradient-basedlearning applied to document recognition[J].Proceedings of the IEEE,2002,86(11):2278-2324.
[13] HASANM M,ISLAM R,MAMUN Q.Adversarial Attacks on Deep Learning-based Network Intrusion Detection Systems:A Taxonomy and Review[EB/OL].(2025-01-14).https://ssrn.com/abstract=5096420.
[14] ROSHAN K,ZAFAR A,HAQUE S B U.A novel deep learning based model to defend network intrusion detection system against adversarial attacks[C]//2023 10th International Confe-rence on Computing for Sustainable Global Development(INDIACom).IEEE,2023:386-391.
[15] Untargeted white-box adversarial attack with heuristic defence methods in real-time deep learning based network intrusion detection system[C]//Computer Communications.2024:97-113.
[16] TALPINI J,SARTORI F,SAVI M.Enhancing trustworthiness in ML-based network intrusion detection with uncertainty quantification[J].Journal of Reliable Intelligent Environments,2024,10(4):501-520.
[17] YANG T,QIAO Y,LEE B.Towards trustworthy cybersecurity operations using Bayesian Deep Learning to improve uncertainty quantification of anomaly detection[J].Computers & Security,2024,144:103909.
[18] ASGHARNEZHAD H,SHAMSI A,ALIZADEHSANI R,et al.Enhancing monte carlo dropout performance for uncertainty quantification[J].arXiv:2505.15671,2025.
[19] MEDJADBA Y,DRID H,RAHOUTI M.Intrusion detection in Software-Defined Networking using hybrid Bayesian model averaging for reliable uncertainty quantification[J].Computer Networks,2025,269:111436-111436.
[20] AHMED U,JIANGBIN Z,ALMOGREN A,et al.Explainable AI-based innovative hybrid ensemble model for intrusion detection[J].Journal of Cloud Computing,2024,13(1):150-150.
[21] WANG Q,JIANG H,REN J,et al.An intrusion detection algorithm based on joint symmetric uncertainty and hyperparameter optimized fusion neural network[J].Expert Systems with Applications,2024,244:123014.
[22] DALY L M,SIAMAK L,WENG W L,et al.FlowTransformer:A transformer framework for flow-based network intrusion detection systems[J].Expert Systems With Applications,2024,241:112564.
[23] ZHOU Y,ZHU H,CHAI Y,et al.Towards Trustworthy Web Attack Detection:An Uncertainty-Aware Ensemble Deep Kernel Learning Model[J].arXiv:2410.07725,2024.
[24] ANTONIO P,SERGIO A,VICENTE G,et al.Apollon:A robust defense system against Adversarial Machine Learning attacks in Intrusion Detection Systems[J].Computers & Security,2024,136:103546.
[25] BAI M,HUANG W,LI T,et al.Diffusion models demand contrastive guidance for adversarial purification to advance[C]//Forty-first International Conference on Machine Learning.2024.
[26] HEYDARI V,NYARKO K.Enhancing Adversarial Robustness in Network Intrusion Detection:A Novel Adversarially Trained Neural Network Approach[J].Electronics,2025,14(16):3249-3249.
[27] SEN J,DASGUPTA S.Adversarial attacks on image classification models:FGSM and patch attacks and their impact[J].ar-Xiv:2307.02055,2023.
[28] WU Y,PENG P,CAI B,et al.Batch-in-Batch:a new adversarial training framework for initial perturbation and sample selection[J].Complex & Intelligent Systems,2025,11(2):132.
[29] YE N Y,LI Q X,ZHANG X Y,et al.An Annealing Mechanism for Adversarial Training Acceleration[J].IEEE transactions on neural networks and learning systems,2021,34(2):882-893.
[30] GAURAV M,RAVI R C.A review paper on IDS classificationusing KDD 99 and NSL KDD dataset in WEKA[C]//2017 International Conference on Computer,Communications and Electronics.2017:553-558.
[31] KURNIABUDI K,STIAWAN D,DARMAWIJOYO D,et al.CICIDS-2017 Dataset Feature Analysis With Information Gain for Anomaly Detection[J].IEEE Access,2020,8:132911-132921.
[32] ASHRAPOV I.Tabular GANs for uneven distribution[J].arXiv:2010.00638,2020.
[33] MILENKOSKI A,VIEIRA M,KOUNEV S,et al.EvaluatingComputer Intrusion Detection Systems:A Survey of Common Practices[J].ACM computing surveys,2016,48(1):1-41.
[34] ZEINAB A,MAGDY Z,RASHA H.An enhanced ensemble defense framework for boosting adversarial robustness of intrusion detection systems[J].Scientific Reports,2025,15:14177.
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!