###
计算机系统应用英文版:2026,35(8):102-116
本文二维码信息
码上扫一扫!
基于联邦持续学习的可泛化无监督网络入侵检测系统
彭曾1,2, 何亨1,2, 徐钦1,2, 石鑫科1,2
(1.武汉科技大学 计算机科学与技术学院, 武汉 430065;2.武汉科技大学 湖北省智能信息处理与实时工业系统重点实验室, 武汉 430065)
Generalized Unsupervised Network Intrusion Detection System Based on Federated Continual Learning
(1.School of Computer Science and Technology, Wuhan University of Science and Technology, Wuhan 430065, China;2.Hubei Province Key Laboratory of Intelligent Information Processing and Real-time Industrial System, Wuhan University of Science and Technology, Wuhan 430065, China)
摘要
图/表
参考文献
相似文献
本文已被:浏览 42次   下载 46
Received:December 18, 2025    Revised:January 26, 2026
中文摘要: 网络入侵检测系统(network intrusion detection system, NIDS)是识别潜在威胁的关键设施. 针对现有无监督入侵检测模型在异构网络中泛化能力不足, 以及主流联邦聚合方法难以有效缓解由非独立同分布(non-independent and identically distributed, Non-IID)数据引发的本地模型权重差异问题, 提出了一种基于联邦持续学习的可泛化无监督网络入侵检测系统GenFCLNIDS. 首先, 每个客户端与一个数据孤岛相关联, 并独立部署基于能量流分类器(energy flow classifier, EFC)与堆叠降噪稀疏自编码器(stacked denoising sparse autoencoder, SDSAE)的无监督模型EFC-SDSAE. EFC通过增强流量间差异来提高SDSAE的泛化能力. 随后, 通过联邦持续学习方法FedSI减小Non-IID数据导致的本地模型权重差异, 获得最优全局模型. 最后, 使用基于F1-score最大化的双阈值异常流量检测算法自适应确定检测阈值以支持精确检测. 实验结果表明, GenFCLNIDS实现了异构网络中异常流量的精准识别, 有效保护了各客户端网络流量的数据隐私, 并且在异构网络中的泛化能力方面显著优于其他方案.
Abstract:Network intrusion detection system (NIDS) plays a critical role in identifying potential threats. However, existing unsupervised intrusion detection models lack sufficient generalization ability in heterogeneous networks. Furthermore, mainstream federated aggregation methods fail to effectively mitigate the local model weight divergence caused by non-independent and identically distributed (Non-IID) data. To address these issues, this study proposes a generalizable unsupervised NIDS based on federated continual learning, named GenFCLNIDS. First, each client is associated with a data silo and independently deploys an unsupervised detection model, EFC-SDSAE, which combines an energy flow classifier (EFC) with a stacked denoising sparse autoencoder (SDSAE). The EFC enhances inter-traffic distinctions to improve the generalization capability of the SDSAE. The FedSI method is then employed to mitigate the divergence of local model weights caused by Non-IID data, yielding an optimal global model. Finally, a dual-threshold anomaly traffic detection algorithm based on F1-score maximization adaptively determines the detection thresholds for precise detection. Experimental results demonstrate that GenFCLNIDS can accurately detect anomalous traffic in heterogeneous networks. Data privacy of network traffic at each client is effectively protected. Furthermore, the generalization capability in heterogeneous networks is significantly superior to other schemes.
文章编号:     中图分类号:    文献标志码:
基金项目:国家自然科学基金(62372343)
引用文本:
彭曾,何亨,徐钦,石鑫科.基于联邦持续学习的可泛化无监督网络入侵检测系统.计算机系统应用,2026,35(8):102-116
PENG Zeng,HE Heng,XU Qin,SHI Xin-Ke.Generalized Unsupervised Network Intrusion Detection System Based on Federated Continual Learning.COMPUTER SYSTEMS APPLICATIONS,2026,35(8):102-116