Lune

DAC2025顶会

CND-IDS: Continual Novelty Detection for Intrusion Detection Systems

Sean Fuhrman, Onat Güngör, Tajana Rosing

2025年份
9被引次数

摘要

Intrusion detection systems (IDS) play a crucial role in IoT and network security by monitoring system data and alerting to suspicious activities. Machine learning (ML) has emerged as a promising solution for IDS, offering highly accurate intrusion detection. However, ML-IDS solutions often overlook two critical aspects needed to build reliable systems: continually changing data streams and a lack of attack labels. Streaming network traffic and associated cyber attacks are continually changing, which can degrade the performance of deployed ML models. Labeling attack data, such as zero-day attacks, in real-world intrusion scenarios may not be feasible, making the use of ML solutions that do not rely on attack labels necessary. To address both these challenges, we propose CND-IDS, a continual novelty detection IDS framework which consists of (i) a learning-based feature extractor that continuously updates new feature representations of the system data, and (ii) a novelty detector that identifies new cyber attacks by leveraging principal component analysis (PCA) reconstruction. Our results on realistic intrusion datasets show that CND-IDS achieves up to 6.1×6.1 \times F-score improvement, and up to 6.5×6.5 \times improved forward transfer over the SOTA unsupervised continual learning algorithm. Our code is available at https://github.com/Sean-Fuhrman/CND-IDS.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

lune papers fulltext 211fe20c-8da7-4850-b0d8-e8f3530ec541

它引用的顶会 Paper1

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖