Learning from Limited Heterogeneous Training Data: Meta-Learning for Unsupervised Zero-Day Web Attack Detection across Web Domains
Peiyang Li, Ye Wang, Qi Li, Zhuotao Liu, Ke Xu, Ju Ren, Zhiying Liu, Ruilin Lin
Abstract
Recently unsupervised machine learning based systems have been developed to detect zero-day Web attacks, which can effectively enhance existing Web Application Firewalls (WAFs). However, prior arts only consider detecting attacks on specific domains by training particular detection models for the domains. These systems require a large amount of training data, which causes a long period of time for model training and deployment. In this paper, we propose RETSINA, a novel meta-learning based framework that enables zero-day Web attack detection across different domains in an organization with limited training data. Specifically, it utilizes meta-learning to share knowledge across these domains, e.g., the relationship between HTTP requests in heterogeneous domains, to efficiently train detection models. Moreover, we develop an adaptive preprocessing module to facilitate semantic analysis of Web requests across different domains and design a multi-domain representation method to capture semantic correlations between different domains for cross-domain model training. We conduct experiments using four real-world datasets on different domains with a total of 293M Web requests. The experimental results demonstrate that RETSINA outperforms the existing unsupervised Web attack detection methods with limited training data, e.g., RETSINA needs only 5-minute training data to achieve comparable detection performance to the existing methods that train separate models for different domains using 1-day training data. We also conduct real-world deployment in an Internet company. RETSINA captures on average 126 and 218 zero-day attack requests per day in two domains, respectively, in one month.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bbf34b91-45bc-4a38-a157-62b278e3f6a8Cited by top-tier papers4
- Detecting Tunneled Flooding Traffic via Deep Semantic Analysis of Packet Length PatternsChuanpu Fu, Qi Li, Meng Shen, Ke XuCCS 2024 · 13 citations
- Helios: Learning and Adaptation of Matching Rules for Continual In-Network Malicious Traffic DetectionZhenning Shi, Dan Zhao, Yijia Zhu, Guorui Xie et al.WWW 2025 · 6 citations
- Achieving Interpretable DL-based Web Attack Detection through Malicious Payload LocalizationPeiyang Li, Fukun Mei, Ye Wang, Zhuotao Liu et al.NDSS 2026
- CertTA: Certified Robustness Made Practical for Learning-Based Traffic AnalysisJinzhu Yan, Zhuotao Liu, Yuyang Xie, Shiyu Liang et al.USENIX Security 2025
Builds on18
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Random Erasing Data AugmentationZhun Zhong, Liang Zheng, Guoliang Kang, Shaozi Li et al.AAAI 2020 · 4,134 citations
- DeepLog: Anomaly Detection and Diagnosis from System Logs through Deep LearningMin Du, Feifei Li, Guineng Zheng, Vivek SrikumarCCS 2017 · 1,823 citations
- TextBugger: Generating Adversarial Text Against Real-world ApplicationsJinfeng Li, Shouling Ji, Tianyu Du, Bo Li et al.NDSS 2019 · 876 citations
- Cross-Domain Few-Shot Classification via Learned Feature-Wise TransformationHung-Yu Tseng, Hsin-Ying Lee, Jia-Bin Huang, Ming-Hsuan YangICLR 2020 · 467 citations
Related papers
- REACT: Residual-Adaptive Contextual Tuning for Fast Model Adaptation in Threat DetectionJiayun Zhang, Junshen Xu, Bugra Can, Yi FanWWW 2025 · 3 citations
- Learning Meta Model for Zero- and Few-Shot Face Anti-SpoofingYunxiao Qin, Chenxu Zhao, Xiangyu Zhu, Zezheng Wang et al.AAAI 2020 · 127 citations
- Zero- and Few-Shot Event Detection via Prompt-Based Meta LearningZhenrui Yue, Huimin Zeng, Mengfei Lan, Heng Ji et al.ACL 2023 · 11 citations
- MetaLog: Generalizable Cross-System Anomaly Detection from Logs with Meta-LearningChenyangguang Zhang, Tong Jia, Guopeng Shen, Pinyan Zhu et al.ICSE 2024 · 28 citations
- Regularized Fine-Grained Meta Face Anti-SpoofingRui Shao, Xiangyuan Lan, Pong C. YuenAAAI 2020 · 185 citations
