Adaptive Clustering-based Malicious Traffic Classification at the Network Edge
Alec F. Diallo, Paul Patras
摘要
The rapid uptake of digital services and Internet of Things (IoT) technology gives rise to unprecedented numbers and diversification of cyber attacks, with which commonly-used rule-based Network Intrusion Detection Systems (NIDSs) are struggling to cope. Therefore, Artificial Intelligence (AI) is being exploited as second line of defense, since this methodology helps in extracting non-obvious patterns from network traffic and subsequently in detecting more confidently new types of threats. Cybersecurity is however an arms race and intelligent solutions face renewed challenges as attacks evolve while network traffic volumes surge. In this paper, we propose Adaptive Clustering-based Intrusion Detection (Acid), a novel approach to malicious traffic classification and a valid candidate for deployment at the network edge. Acid addresses the critical challenge of sensitivity to subtle changes in traffic features, which routinely leads to misclassification. We circumvent this problem by relying on low-dimensional embeddings learned with a lightweight neural model comprising multiple kernel networks that we introduce, which optimally separates samples of different classes. We empirically evaluate our approach with both synthetic and three intrusion detection datasets spanning 20 years, and demonstrate Acid consistently attains 100% accuracy and F1-score, and 0% false alarm rate, thereby significantly outperforming state-of-the-art clustering methods and NIDSs.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper7
- Sabre: Cutting through Adversarial Noise with Adaptive Spectral Filtering and Input ReconstructionAlec F. Diallo, Paul PatrasS&P 2024 · 被引用 9 次
- MalDetectFormer: Leveraging Sparse SpatioTemporal Information for Effective Malicious Traffic DetectionShuai Zhang, Yu Fan, Haoyi Zhou, Bo LiAAAI 2025 · 被引用 1 次
- CoLD: Collaborative Label Denoising Framework for Network Intrusion DetectionShuo Yang, Xinran Zheng, Jinze Li, Jinfeng Xu 等NDSS 2026 · 被引用 1 次
- BARS: Local Robustness Certification for Deep Learning based Traffic Analysis SystemsKai Wang, Zhiliang Wang, Dongqi Han, Wenqi Chen 等NDSS 2023
- Frequency-Domain Mixing Data Augmentation for Malicious Traffic DetectionYuhao Yan, Bo Lang, Xiangyu LiCCS 2026
相关 Paper
- Hawkware: Network Intrusion Detection based on Behavior Analysis with ANNs on an IoT DeviceSunwoo Ahn, Hayoon Yi, Younghan Lee, Whoi Ree Ha 等DAC 2020 · 被引用 13 次
- MANDA: On Adversarial Example Detection for Network Intrusion Detection SystemNing Wang, Yimin Chen, Yang Hu, Wenjing Lou 等INFOCOM 2021 · 被引用 44 次
- CND-IDS: Continual Novelty Detection for Intrusion Detection SystemsSean Fuhrman, Onat Güngör, Tajana RosingDAC 2025 · 被引用 9 次
- Realtime Robust Malicious Traffic Detection via Frequency Domain AnalysisChuanpu Fu, Qi Li, Meng Shen, Ke XuCCS 2021 · 被引用 194 次
- Trident: A Universal Framework for Fine-Grained and Class-Incremental Unknown Traffic DetectionZiming Zhao, Zhaoxuan Li, Zhuoxue Song, Wenhao Li 等WWW 2024 · 被引用 38 次
