<p>In practical deployment, the performance of network intrusion detection systems is often degraded by class imbalance in training data and distribution shifts across different network environments. To address these challenges, a domain adaptation intrusion detection algorithm based on class-balanced knowledge transfer and multi-structure domain alignment is proposed in this paper. First, a class separation loss is proposed to mitigate the effect of class overlap caused by data imbalance processing on cross-domain knowledge transfer, and high-confidence pseudo-labels of the target domain are selected through a dynamic threshold for subsequent domain alignment. In addition, a multi-structure domain alignment method is proposed to reduce the discrepancy between the data distributions of the source domain and the target domain. The domain discrepancy is reduced from three aspects, including the overall feature distribution, inter-feature relationships, and class representations, thereby extracting domain-invariant features from the source domain and the target domain. Class prototypes are constructed using supervision information, and the relative relationships among different classes in the source domain and the target domain are aligned to reduce cross-domain discrepancies in class representations. Experiments are conducted on four public NIDS datasets under two cross-domain scenarios. In the cross-domain experiments from UNSW-NB15 to ToN-IoT and from NSL-KDD to BoT-IoT, the F1-score of the proposed algorithm reaches 89.73% and 84.10%, respectively, thereby verifying the effectiveness and superiority of the proposed algorithm.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A domain adaptation network intrusion detection algorithm based on class-balanced knowledge transfer and multi-structure domain alignment

  • Qian Wang,
  • Xiang Liu,
  • Yifan Cheng,
  • Yongqiang Cheng,
  • Bing Zhang

摘要

In practical deployment, the performance of network intrusion detection systems is often degraded by class imbalance in training data and distribution shifts across different network environments. To address these challenges, a domain adaptation intrusion detection algorithm based on class-balanced knowledge transfer and multi-structure domain alignment is proposed in this paper. First, a class separation loss is proposed to mitigate the effect of class overlap caused by data imbalance processing on cross-domain knowledge transfer, and high-confidence pseudo-labels of the target domain are selected through a dynamic threshold for subsequent domain alignment. In addition, a multi-structure domain alignment method is proposed to reduce the discrepancy between the data distributions of the source domain and the target domain. The domain discrepancy is reduced from three aspects, including the overall feature distribution, inter-feature relationships, and class representations, thereby extracting domain-invariant features from the source domain and the target domain. Class prototypes are constructed using supervision information, and the relative relationships among different classes in the source domain and the target domain are aligned to reduce cross-domain discrepancies in class representations. Experiments are conducted on four public NIDS datasets under two cross-domain scenarios. In the cross-domain experiments from UNSW-NB15 to ToN-IoT and from NSL-KDD to BoT-IoT, the F1-score of the proposed algorithm reaches 89.73% and 84.10%, respectively, thereby verifying the effectiveness and superiority of the proposed algorithm.