计算机科学 ›› 2026, Vol. 53 ›› Issue (8): 426-436.doi: 10.11896/jsjkx.250600041

• 信息安全 • 上一篇    下一篇

基于深度多实例学习的网络异常流量检测

冯皓宇1, 张雨轩2, 刘紫萱1, 孟华1   

  1. 1 西南交通大学数学学院 成都 611756
    2 西南交通大学信息科学与技术学院 成都 611756
  • 收稿日期:2025-06-06 修回日期:2025-09-29 发布日期:2026-08-17
  • 通讯作者: 孟华(menghua@swjtu.edu.cn)
  • 作者简介:(fhy20000804@gmail.com)
  • 基金资助:
    国家自然科学基金(62276218);保密通信全国重点实验室稳定计划支持项目(WD202403)

Network Anomaly Traffic Detection Based on Deep Multi-instance Learning

FENG Haoyu1, ZHANG Yuxuan2, LIU Zixuan1, MENG Hua1   

  1. 1 College of Mathematics, Southwest Jiaotong University, Chengdu 611756, China
    2 College of Information Science and Technology, Southwest Jiaotong University, Chengdu 611756, China
  • Received:2025-06-06 Revised:2025-09-29 Online:2026-08-17
  • About author:FENG Haoyu,born in 2000,postgra-duate.His main research interests include artificial intelligence and multi-instance learning.
    MENG Hua,born in 1982,Ph.D,asso-ciate professor.His main research in-terests include interpretability in deep learning,topological data analysis,knowledge representation and reaso-ning.
  • Supported by:
    National Natural Science Foundation of China(62276218) and Stability Program of National Key Laboratory of Security Communication(WD202403).

摘要: 随着网络规模的指数级增长和流量形态的日益复杂化,传统基于流量样本的异常检测方法在实时性与计算效率方面面临严峻挑战。为此,提出一种融合门控注意力机制的深度多实例学习框架(GAD-MIL)。该框架对流量样本进行打包处理,用包级别的分析与异常样本定位代替传统的样本级别的分析,从而实现高效的异常流量检测。具体而言,针对打包后的流量数据,构建了双层学习架构。首先,利用基于预训练的特征提取器生成具有强判别性的流量嵌入表示;其次,引入门控注意力多实例池化层,动态聚合包内实例特征并识别异常样本。该架构打破了传统多实例学习模型对包级标签的强依赖,支持端到端的实例级异常定位,同时保持低的计算复杂度。在CICIDS2017和DoH2020等五大主流数据集上进行了实验,结果表明,GAD-MIL能显著缩短推理计算时间,在CICIDS2017数据集上,较传统深度学习方法,其不仅将F1分数提升了2.72个百分点,而且在计算效率层面上将速度提升了4.2倍。

关键词: 网络异常流量检测, 多实例学习, 注意力机制, 推理效率, 特征提取

Abstract: With the exponential growth of network scale and the increasing complexity of traffic patterns,traditional anomaly traffic detection methods based on individual traffic samples face serious challenges in terms of real-time performance and computational efficiency.To address this issue,this study proposes a deep multi-instance learning framework with a gated attention mechanism,named GAD-MIL.This framework processes traffic samples in bags,replacing traditional instance-level analysis with bag-level analysis and anomaly localization to achieve efficient abnormal traffic detection.Specifically,for the bagged traffic data,the proposed method adopts a two-stage learning architecture.Firstly,a pre-trained feature extractor is used to generate discriminative traffic embeddings.Secondly,a gated attention-based multi-instance pooling layer is introduced to dynamically aggregate instance features within each bag and identify anomalous samples.This architecture overcomes traditional MIL models’ reliance on bag-level labels,enabling end-to-end instance-level anomaly localization while maintaining low computational complexity.Experimental results on five benchmark datasets such as CICIDS2017 and DoH2020 show that,GAD-MIL significantly reduces in-ference time and achieves a 2.72 percentage-point improvement in F1 score over traditional deep learning methods on the CICIDS2017 dataset and a 4.2× speedup in computational efficiency.

Key words: Network anomaly traffic detection, Multi-instance learning, Attention mechanism, Inference efficiency, Feature extraction

中图分类号: 

  • TP183
[1] KWON D,KIM H,KIM J,et al.A survey of deep learning-based network anomaly detection[J].Cluster Computing,2019,22:949-961.
[2] WANG W,ZHU M,ZENG X,et al.Malware traffic classification using convolutional neural network for representation learning[C]//2017 International Conference on Information Networking(ICOIN).New York,USA:IEEE Press,2017:712-717.
[3] DING H,SUN Y,HUANG N,et al.TMG-GAN:Generative adversarial networks-based imbalanced learning for network intrusion detection[J].IEEE Transactions on Information Forensics and Security,2023,19:1156-1167.
[4] DUAN X,FU Y,WANG K.Network traffic anomaly detection method based on multi-scale residual classifier[J].Computer Communications,2023,198:206-216.
[5] ZHOU Z H.Multi-instance learning:A survey[R].Department of Computer Science & Technology,Nanjing University,2004:4.
[6] JIANG X,ZHANG H R,ZHOU Y.Multi-granularity abnormal traffic detection based on multi-instance learning[J].IEEE Transactions on Network and Service Management,2023,21(2):1467-1477.
[7] ZHANG J,HAN D,LV Z,et al.Bag2image:a multi-instancenetwork traffic representation for network security event prediction[J].Cybersecurity,2025,8(1):31.
[8] KIM M S,KONG H J,HONG S C,et al.A flow-based method for abnormal network traffic detection[C]//2004 IEEE/IFIP Network Operations and Management Symposium(IEEE Cat.No.04CH37507).New York,USA:IEEE Press,2004:599-612.
[9] FINSTERBUSCH M,RICHTER C,ROCHA E,et al.A survey of payload-based traffic classification approaches[J].IEEE Communications Surveys & Tutorials,2013,16(2):1135-1156.
[10] FAN Z,LIU R.Investigation of machine learning based network traffic classification[C]//2017 International Symposium on Wireless Communication Systems(ISWCS).New York,USA:IEEE Press,2017:1-6.
[11] YANG J,NARANTUYA J,LIM H.Bayesian neural networkbased encrypted traffic classification using initial handshake packets[C]//2019 49th Annual IEEE/IFIP International Conference on Dependable Systems and Networks-Supplemental Volume(DSN-S).Los Alamitos,USA:IEEE Press,2019:19-20.
[12] MA Q,SUN C,CUI B,et al.A novel model for anomaly detection in network traffic based on kernel support vector machine[J].Computers & Security,2021,104:102215.
[13] WU T,FAN H,ZHU H,et al.Intrusion detection system combined enhanced random forest with SMOTE algorithm[J].EURASIP Journal on Advances in Signal Processing,2022,2022(1):39.
[14] LU C,CAO Y,WANG Z.Research on intrusion detection based on an enhanced random forest algorithm[J].Applied Sciences,2024,14(2):714.
[15] CHEN Y.Convolutional neural network for sentence classification[D].Waterloo,Canada:University of Waterloo,2015.
[16] LUO H,WAN L.A Network Traffic Intrusion Detection Method Based on Dynamic Spatio-Temporal Graph Neural Network[J].Computer Engineering,doi:10.19678/j.issn.1000-3428.0070520.
[17] GRAVES A,SCHMIDHUBER J.Framewise phoneme classification with bidirectional LSTM and other neural network architectures[J].Neural Networks,2005,18(5/6):602-610.
[18] ZHU Z,LIANG D,ZHANG S,et al.Traffic-sign detection and classification in the wild[C]//Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition.New York,USA:IEEE Press,2016:2110-2118.
[19] GOODFELLOW I,POUGET-ABADIE J,MIRZA M,et al.Gene-rative adversarial networks[J].Communications of the ACM,2020,63(11):139-144.
[20] GAO Z Y,WANG T J,WANG Y,et al.Traffic PredictionMethod for 5G Network Based on Generative Adversarial Network[J].Computer Science,2022,49(4):321-328.
[21] VASWANI A,SHAZEER N,PARMAR N,et al.Attention is all you need[J].Advances in Neural Information Processing Systems,2017,30.
[22] SHI L,ZHANG J T,GAO Y F,et al.Intrusion Detection of Network Traffic based on Transformer and BiLSTM[J].Computer Engineering,2023,49(3):29-36;57.
[23] DIETTERICH T G,LATHROP R H,LOZANO-PÉREZ T.Solving the multiple instance problem with axis-parallel rectangles[J].Artificial Intelligence,1997,89(1/2):31-71.
[24] ZHANG M L,ZHOU Z H.Multi-instance clustering with applications to multi-instance prediction[J].Applied Intelligence,2009,31:47-68.
[25] WEI X S,WU J,ZHOU Z H.Scalable multi-instance learning[C]//2014 IEEE International Conference on Data Mining.New York,USA:IEEE Press,2014:1037-1042.
[26] WEI X S,WU J,ZHOU Z H.Scalable algorithms for multi-instance learning[J].IEEE Transactions on Neural Networks and Learning Systems,2016,28(4):975-987.
[27] WU J,PAN S,ZHU X,et al.Multi-instance learning with dis-criminative bag mapping[J].IEEE Transactions on Knowledge and Data Engineering,2018,30(6):1065-1080.
[28] XU B C,TING K M,ZHOU Z H.Isolation set-kernel and its application to multi-instance learning[C]//Proceedings of the 25th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining.New York,USA:ACM,2019:941-949.
[29] XIAO Y,LIU B,HAO Z.Multi-Instance Nonparallel TubeLearning[J].IEEE Transactions on Neural Networks and Learning Systems,2024,36:2563-2577.
[30] ILSE M,TOMCZAK J,WELLING M.Attention-based deepmultiple instance learning[C]//International Conference on Machine Learning.San Diego,USA:PMLR,2018:2127-2136.
[31] SHI X,XING F,XIE Y,et al.Loss-based attention for deepmultiple instance learning[C]//Proceedings of the AAAI Conference on Artificial Intelligence.Palo Alto,USA:AAAI Press,2020:5742-5749.
[32] SHAO Z,BIAN H,CHEN Y,et al.Transmil:Transformerbased correlated multiple instance learning for whole slide image classification[J].Advances in Neural Information Processing Systems,2021,34:2136-2147.
[33] ZHANG W,ZHANG X,ZHANG M L.Multi-instance causalrepresentation learning for instance label prediction and out-of-distribution generalization[J].Advances in Neural Information Processing Systems,2022,35:34940-34953.
[34] SHARAFALDIN I,LASHKARI A H,GHORBANIA A.To-ward generating a new intrusion detection dataset and intrusion traffic characterization[J].ICISSP,2018,1(2018):108-116.
[35] MONTAZERISHATOORI M,DAVIDSON L,KAUR G,et al.Detection of doh tunnels using time-series classification of encrypted traffic[C]//2020 IEEE Intl Conf on Dependable,Autonomic and Secure Computing,Intl Conf on Pervasive Intelligence and Computing,Intl Conf on Cloud and Big Data Computing,Intl Conf on Cyber Science and Technology Congress(DASC/PiCom/CBDCom/CyberSciTech).Los Alamitos,USA:IEEE Press,2020:63-70.
[36] MOUSTAFA N,SLAY J.UNSW-NB15:a comprehensive dataset for network intrusion detection systems(UNSW-NB15 network data set)[C]//2015 Military Communications and Information Systems Conference(MilCIS).New York,USA:IEEE Press,2015:1-6.
[37] SIDDIQUI M K,NAAHID S.Analysis of KDD CUP 99 dataset using clustering based data mining[J].International Journal of Database Theory and Application,2013,6(5):23-34.
[38] KONSTANTINOV A V,UTKIN L V.Multi-attention multiple instance learning[J].Neural Computing and Applications,2022,34(16):14029-14051.
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!