Adaptive Clustering-based Malicious Traffic Classification at the Network Edge
Alec F. Diallo, Paul Patras
Abstract
The rapid uptake of digital services and Internet of Things (IoT) technology gives rise to unprecedented numbers and diversification of cyber attacks, with which commonly-used rule-based Network Intrusion Detection Systems (NIDSs) are struggling to cope. Therefore, Artificial Intelligence (AI) is being exploited as second line of defense, since this methodology helps in extracting non-obvious patterns from network traffic and subsequently in detecting more confidently new types of threats. Cybersecurity is however an arms race and intelligent solutions face renewed challenges as attacks evolve while network traffic volumes surge. In this paper, we propose Adaptive Clustering-based Intrusion Detection (Acid), a novel approach to malicious traffic classification and a valid candidate for deployment at the network edge. Acid addresses the critical challenge of sensitivity to subtle changes in traffic features, which routinely leads to misclassification. We circumvent this problem by relying on low-dimensional embeddings learned with a lightweight neural model comprising multiple kernel networks that we introduce, which optimally separates samples of different classes. We empirically evaluate our approach with both synthetic and three intrusion detection datasets spanning 20 years, and demonstrate Acid consistently attains 100% accuracy and F1-score, and 0% false alarm rate, thereby significantly outperforming state-of-the-art clustering methods and NIDSs.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 909aeac4-335a-4bb6-83c2-a657e2f71ea4Cited by top-tier papers7
- Sabre: Cutting through Adversarial Noise with Adaptive Spectral Filtering and Input ReconstructionAlec F. Diallo, Paul PatrasS&P 2024 · 9 citations
- MalDetectFormer: Leveraging Sparse SpatioTemporal Information for Effective Malicious Traffic DetectionShuai Zhang, Yu Fan, Haoyi Zhou, Bo LiAAAI 2025 · 1 citation
- CoLD: Collaborative Label Denoising Framework for Network Intrusion DetectionShuo Yang, Xinran Zheng, Jinze Li, Jinfeng Xu et al.NDSS 2026 · 1 citation
- BARS: Local Robustness Certification for Deep Learning based Traffic Analysis SystemsKai Wang, Zhiliang Wang, Dongqi Han, Wenqi Chen et al.NDSS 2023
- Frequency-Domain Mixing Data Augmentation for Malicious Traffic DetectionYuhao Yan, Bo Lang, Xiangyu LiCCS 2026
Related papers
- Hawkware: Network Intrusion Detection based on Behavior Analysis with ANNs on an IoT DeviceSunwoo Ahn, Hayoon Yi, Younghan Lee, Whoi Ree Ha et al.DAC 2020 · 13 citations
- MANDA: On Adversarial Example Detection for Network Intrusion Detection SystemNing Wang, Yimin Chen, Yang Hu, Wenjing Lou et al.INFOCOM 2021 · 44 citations
- CND-IDS: Continual Novelty Detection for Intrusion Detection SystemsSean Fuhrman, Onat Güngör, Tajana RosingDAC 2025 · 9 citations
- Realtime Robust Malicious Traffic Detection via Frequency Domain AnalysisChuanpu Fu, Qi Li, Meng Shen, Ke XuCCS 2021 · 194 citations
- Trident: A Universal Framework for Fine-Grained and Class-Incremental Unknown Traffic DetectionZiming Zhao, Zhaoxuan Li, Zhuoxue Song, Wenhao Li et al.WWW 2024 · 38 citations
