计算机科学 ›› 2026, Vol. 53 ›› Issue (7): 397-405.doi: 10.11896/jsjkx.250600039

• 信息安全 • 上一篇    下一篇

基于集成学习与权重约束的网络流量对抗训练防御框架

黄奕鹭1, 何星星1, 任芮彬1, 曾文强2   

  1. 1 西南交通大学数学学院 成都 611756
    2 西南交通大学信息科学与技术学院 成都 611756
  • 收稿日期:2025-06-06 修回日期:2025-10-13 出版日期:2026-07-15 发布日期:2026-07-10
  • 通讯作者: 何星星(x.he@swjtu.edu.cn)
  • 作者简介:(huangyl202309@163.com)
  • 基金资助:
    教育部人文社会科学研究项目(20XJCZH016);成都市科技计划项目(2026-RK00-00028-ZF);四川省科技支撑项目(2024YFHZ0316);中央高校基本科研业务费专项资金(2682024ZTPY041)

Collaborative Adversarial Training Defense Framework for Network Traffic Classification Based on Ensemble Learning and Weight Constraint

HUANG Yilu1, HE Xingxing1, REN Ruibin1, ZENG Wenqiang2   

  1. 1 School of Mathematics,Southwest Jiaotong University,Chengdu 611756,China
    2 School of Information Science and Technology,Southwest Jiaotong University,Chengdu 611756,China
  • Received:2025-06-06 Revised:2025-10-13 Published:2026-07-15 Online:2026-07-10
  • About author:HUANG Yilu,born in 2000,postgra-duate.His main research interests include artificial intelligence and adversarial defense.
    HE Xingxing,born in 1982,Ph.D,associate professor,is a member of CCF(No.48067M).His main research interest is logic-based automated rea-soning.
  • Supported by:
    Ministry of Education of China Project of Humanities and Social Sciences(20XJCZH016),Chengdu Science and Technology Program(2026-RK00-00028-ZF),Science and Technology Support Project of Sichuan Province(2024YFHZ0316) and Fundamental Research Funds for the Central Universities(2682024ZTPY041).

摘要: 随着深度学习在网络流量分类中的广泛应用,其对微小扰动的敏感性问题日益凸显,对抗样本攻击已成为制约模型部署安全性的关键挑战。针对传统对抗训练方法在准确率与鲁棒性之间难以平衡的问题,提出一种融合集成学习与权重约束机制的协同对抗训练防御框架。该方法通过动态提升决策边界附近样本的训练权重,强化模型对易扰动样本的识别能力,同时借助多子模型集成策略,有效削弱单一模型对扰动梯度的敏感性,从而整体增强系统的鲁棒性。为验证所提方法的通用性与有效性,在3个典型的网络流量数据集(USTC-TFC2016,NSL-KDD 和 CIC-IDS2017)上进行了系统评估。实验结果表明,在多种类型攻击下,该方法较传统对抗训练在鲁棒性方面普遍提升10%以上,在高强度扰动场景中提升幅度甚至超过20%。所提框架具备良好的可扩展性,能够灵活适配不同网络结构与部署环境,展现出良好的实用价值与工程应用前景。

关键词: 对抗样本, 对抗训练, 权重约束, 集成学习, 网络流量分类

Abstract: With the growing adoption of deep learning in network traffic classification,model vulnerability to minor perturbations has become a critical security concern.Adversarial example attacks significantly compromise the reliability of real-world deployments.To address the longstanding trade-off between accuracy and robustness in conventional adversarial training,this paper proposes a collaborative adversarial defense framework that integrates ensemble learning with a dynamic weight constraint mechanism.The proposed approach assigns higher training weights to samples near decision boundaries to improve the model's sensitivity to vulnerable instances,while leveraging multi-model ensemble strategies to mitigate gradient overfitting and enhance robustness.Comprehensive experiments conducted on three widely used network traffic datasets-USTC-TFC2016,NSL-KDD,and CIC-IDS2017-demonstrate that the proposed method consistently improves robustness by over 10% across various attack types,and even exceeds 20% under high-intensity perturbations,compared with conventional baselines.The proposed framework de-monstrates exemplary scalability,affording seamless adaptation to heterogeneous network architectures and deployment contexts,thereby manifesting substantial practical utility and promising engineering applicability.

Key words: Adversarial examples, Adversarial training, Weight constraint, Ensemble learning, Network traffic classification

中图分类号: 

  • TP393
[1]LIU H,WANG H.Real-time anomaly detection of network traffic based on CNN[J].Symmetry,2023,15(6):1205.
[2]HU X,LIU W,HUO H.An intelligent network traffic predic-tion method based on Butterworth filter and CNN-LSTM[J].Computer Networks,2024,240:110172.
[3]DRAPER-GIL G,LASHKARI A H,MAMUN M S I,et al.Characterization of encrypted and vpn traffic using time-related[C]//Proceedings of the 2nd International Conference on Information Systems Security and Privacy(ICISSP).2016:407-414.
[4]LOTFOLLAHI M,JAFARI SIAVOSHANI M,SHIRALIHOSSEIN ZADE R,et al.Deep packet:A novel approach for encrypted traffic classification using deep learning[J].Soft Computing,2020,24(3):1999-2012.
[5]XU K,ZHANG X,WANG Y,et al.Self-supervised learningmalware traffic classification based on masked autoencoder[J].IEEE Internet of Things Journal,2024,11(10):17330-17340.
[6]DONG S,SU H,LIU Y.A-CAVE:Network abnormal traffic detection algorithm based on variational autoencoder[C]//ICT Express.2023:896-902.
[7]DONG S,XIA Y.Network traffic identification in packet sampling environment[J].Digital Communications and Networks,2023,9(4):957-970.
[8]DONG S,XIA Y,WANG T.Network abnormal traffic detection framework based on deep reinforcement learning[J].IEEE Wireless Communications,2024,31(3):185-193.
[9]SZEGEDY C,ZAREMBA W,SUTSKEVER I,et al.Intriguing properties of neural networks[C]//2nd International Confe-rence on Learning Representations.2014.
[10]PAPERNOT N,MCDANIEL P,WU X,et al.Distillation as adefense to adversarial perturbations against deep neural networks[C]//Proceedings of 2016 IEEE Symposium on Security and Privacy(SP).2016:582-597.
[11]ZHAO S,YU J,SUN Z,et al.Enhanced accuracy and robustness via multi-teacher adversarial distillation[C]//European Confe-rence on Computer Vision.2022:585-602.
[12]METZENJ H,GENEWEIN T,FISCHER V,et al.On Detecting Adversarial Perturbations[C]//International Conference on Learning Representations.2017.
[13]DONG M,XU C.Adversarial robustness via random projection filters[C]//Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition.2023:4077-4086.
[14]GOODFELLOWI J,SHLENS J,SZEGEDY C.Explaining and harnessing adversarial examples[J].arXiv:1412.6572,2014.
[15]MADRY A,MAKELOVA,SCHMIDT L,et al.Towards Deep Learning Models Resistant to Adversarial Attacks[C]//International Conference on Learning Representations.2018.
[16]ZHANG H,YU Y,JIAO J,et al.Theoretically principled trade-off between robustness and accuracy[C]//International Confe-rence on Machine Learning.PMLR,2019:7472-7482.
[17]WANG Y,ZOU D,YI J,et al.Improving adversarial robustness requires revisiting misclassified examples[C]//International Conference on Learning Representations.2019.
[18]SHAFAHI A,NAJIBI M,GHIASI M A,et al.Adversarialtraining for free![C]//Proceedings of the 33rd International Conference on Neural Information Processing Systems.2019:3358-3369.
[19]TRAMÈR F,KURAKIN A,PAPERNOT N,et al.Ensemble adversarial training:Attacks and defenses[C]//6th Interna-tional Conference on Learning Representations.2018.
[20]PANG T,XU K,DU C,et al.Improving adversarial robustness via promoting ensemble diversity[C]//International Conference on Machine Learning.2019:4970-4979.
[21]QINC L,MARTENS J,GOWAL S,et al.Adversarial robus-tness through local linearization[C]//Proceedings of the 33rd International Conference on Neural Information Processing Systems.2019:13842-13853.
[22]DONG S.Multi class SVM algorithm with active learning fornetwork traffic classification[J].Expert Systems with Applications,2021,176:114885.
[23]WANG W,ZHU M,ZENG X,et al.Malware traffic classification using convolutional neural network for representation learning[C]//2017 International Conference on Information Networking(ICOIN).IEEE,2017:712-717.
[24]KURAKIN A,GOODFELLOW I J,BENGIO S.AdversarialMachine Learning at Scale[C]//International Conference on Learning Representations.2017.
[25]KARIYAPPA S,QURESHI M K.Improving adversarial ro-bustness of ensembles with diversity training[J].arXiv:1901.09981,2019.
[26]TAVALLAEE M,BAGHERI E,LU W,et al.A detailed analysis of the KDD CUP 99 data set[C]//2009 IEEE Symposium on Computational Intelligence for Security and Defense Applications.2009:1-6.
[27]SHARAFALDIN I,LASHKARI A H,GHORBANI A A.Toward generating a new intrusion detection dataset and intrusion traffic characterization[J].ICISSp,2018,1(2018):108-116.
[28]MOOSAVI-DEZFOOLI S M,FAWZI A,FROSSARD P.Deepfool:a simple and accurate method to fool deep neural networks[C]//Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition.2016:2574-2582.
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!