基于联邦持续学习的可泛化无监督网络入侵检测系统
作者:
作者单位:

作者简介:

通讯作者:

中图分类号:

基金项目:

国家自然科学基金(62372343)


Generalized Unsupervised Network Intrusion Detection System Based on Federated Continual Learning
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    网络入侵检测系统(network intrusion detection system, NIDS)是识别潜在威胁的关键设施. 针对现有无监督入侵检测模型在异构网络中泛化能力不足, 以及主流联邦聚合方法难以有效缓解由非独立同分布(non-independent and identically distributed, Non-IID)数据引发的本地模型权重差异问题, 提出了一种基于联邦持续学习的可泛化无监督网络入侵检测系统GenFCLNIDS. 首先, 每个客户端与一个数据孤岛相关联, 并独立部署基于能量流分类器(energy flow classifier, EFC)与堆叠降噪稀疏自编码器(stacked denoising sparse autoencoder, SDSAE)的无监督模型EFC-SDSAE. EFC通过增强流量间差异来提高SDSAE的泛化能力. 随后, 通过联邦持续学习方法FedSI减小Non-IID数据导致的本地模型权重差异, 获得最优全局模型. 最后, 使用基于F1-score最大化的双阈值异常流量检测算法自适应确定检测阈值以支持精确检测. 实验结果表明, GenFCLNIDS实现了异构网络中异常流量的精准识别, 有效保护了各客户端网络流量的数据隐私, 并且在异构网络中的泛化能力方面显著优于其他方案.

    Abstract:

    Network intrusion detection system (NIDS) plays a critical role in identifying potential threats. However, existing unsupervised intrusion detection models lack sufficient generalization ability in heterogeneous networks. Furthermore, mainstream federated aggregation methods fail to effectively mitigate the local model weight divergence caused by non-independent and identically distributed (Non-IID) data. To address these issues, this study proposes a generalizable unsupervised NIDS based on federated continual learning, named GenFCLNIDS. First, each client is associated with a data silo and independently deploys an unsupervised detection model, EFC-SDSAE, which combines an energy flow classifier (EFC) with a stacked denoising sparse autoencoder (SDSAE). The EFC enhances inter-traffic distinctions to improve the generalization capability of the SDSAE. The FedSI method is then employed to mitigate the divergence of local model weights caused by Non-IID data, yielding an optimal global model. Finally, a dual-threshold anomaly traffic detection algorithm based on F1-score maximization adaptively determines the detection thresholds for precise detection. Experimental results demonstrate that GenFCLNIDS can accurately detect anomalous traffic in heterogeneous networks. Data privacy of network traffic at each client is effectively protected. Furthermore, the generalization capability in heterogeneous networks is significantly superior to other schemes.

    参考文献
    相似文献
    引证文献
引用本文

彭曾,何亨,徐钦,石鑫科.基于联邦持续学习的可泛化无监督网络入侵检测系统.计算机系统应用,2026,35(8):102-116

复制
分享
相关视频

文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2025-12-18
  • 最后修改日期:2026-01-26
  • 录用日期:
  • 在线发布日期: 2026-06-26
  • 出版日期:
文章二维码
您是第位访问者
版权所有:中国科学院软件研究所 京ICP备05046678号-3
地址:北京市海淀区中关村南四街4号,邮政编码:100190
电话:010-62661041 传真: Email:csa@iscas.ac.cn
技术支持:北京勤云科技发展有限公司

京公网安备 11040202500063号