Intrusion Detection Systems (IDS) are significant technologies in network security that identify potential network attacks or abnormal activities by analyzing network traffic or system behavior. With the fast advancement of network technology, cyberattacks have become increasingly complex and diverse. Traditional intrusion detection methods have gradually exposed deficiencies, as these methods frequently rely on substantial amounts of labeled data for training. In real-world scenarios, complete and accurate intrusion data is quite limited, and the labeling process is expensive and time-consuming. Additionally, these methods have poor adaptability to unknown attacks, making it difficult to meet rapidly changing network security requirements. In actual network environments, the quantity of attack samples is typically quite limited, and traditional methods perform poorly when faced with few-shot problems, making them difficult to handle effectively. This paper proposes a new approach combining few-shot learning with Model-Agnostic Meta-Learning (MAML) networks, providing a new perspective. Through experiments on a self-constructed dataset, the results show that the proposed method can achieve optimal performance using only a small number of samples. Moreover, our method, under the training conditions of a small number of samples, can still be compared with experimental results using a large number of training samples, and even surpass them in certain aspects, demonstrating the superiority of the method proposed in this paper.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Few-Shot Intrusion Detection Method Combining Model-Agnostic Meta-Learning and Siamese Neural Network

  • Kaiyang Fang,
  • Bo Yang,
  • Runyuan Sun,
  • Zhifeng Liang,
  • Ge Zhai

摘要

Intrusion Detection Systems (IDS) are significant technologies in network security that identify potential network attacks or abnormal activities by analyzing network traffic or system behavior. With the fast advancement of network technology, cyberattacks have become increasingly complex and diverse. Traditional intrusion detection methods have gradually exposed deficiencies, as these methods frequently rely on substantial amounts of labeled data for training. In real-world scenarios, complete and accurate intrusion data is quite limited, and the labeling process is expensive and time-consuming. Additionally, these methods have poor adaptability to unknown attacks, making it difficult to meet rapidly changing network security requirements. In actual network environments, the quantity of attack samples is typically quite limited, and traditional methods perform poorly when faced with few-shot problems, making them difficult to handle effectively. This paper proposes a new approach combining few-shot learning with Model-Agnostic Meta-Learning (MAML) networks, providing a new perspective. Through experiments on a self-constructed dataset, the results show that the proposed method can achieve optimal performance using only a small number of samples. Moreover, our method, under the training conditions of a small number of samples, can still be compared with experimental results using a large number of training samples, and even surpass them in certain aspects, demonstrating the superiority of the method proposed in this paper.