In Search of netUnicorn: A Data-Collection Platform to Develop Generalizable ML Models for Network Security Problems
Roman Beltiukov, Wenbo Guo, Arpit Gupta, Walter Willinger
摘要
The remarkable success of the use of machine learning-based solutions for network security problems has been impeded by the developed ML models' inability to maintain efficacy when used in different network environments exhibiting different network behaviors. This issue is commonly referred to as the generalizability problem of ML models. The community has recognized the critical role that training datasets play in this context and has developed various techniques to improve dataset curation to overcome this problem. Unfortunately, these methods are generally ill-suited or even counterproductive in the network security domain, where they often result in unrealistic or poor-quality datasets. To address this issue, we propose a new closed-loop ML pipeline that leverages explainable ML tools to guide the network data collection in an iterative fashion. To ensure the data's realism and quality, we require that the new datasets should be endogenously collected in this iterative process, thus advocating for a gradual removal of data-related problems to improve model generalizability. To realize this capability, we develop a data-collection platform, net-Unicorn, that takes inspiration from the classic "hourglass" model and is implemented as its "thin waist" to simplify data collection for different learning problems from diverse network environments. The proposed system decouples data-collection intents from the deployment mechanisms and disaggregates these high-level intents into smaller reusable, self-contained tasks. We demonstrate how netUnicorn simplifies collecting data for different learning problems from multiple network environments and how the proposed iterative data collection improves a model's generalizability.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Evaluating Machine Learning-Based IoT Device Identification Models for Security ApplicationsEman Maali, Omar Alrawi, Julie A. McCannNDSS 2025
- MineShark: Cryptomining Traffic Detection at ScaleShaoke Xi, Tianyi Fu, Kai Bu, Chunling Yang 等NDSS 2025
它引用的顶会 Paper22
- TabNet: Attentive Interpretable Tabular LearningSercan Ö. Arik, Tomas PfisterAAAI 2021 · 被引用 2,148 次
- DeepLog: Anomaly Detection and Diagnosis from System Logs through Deep LearningMin Du, Feifei Li, Guineng Zheng, Vivek SrikumarCCS 2017 · 被引用 1,823 次
- Kitsune: An Ensemble of Autoencoders for Online Network Intrusion DetectionYisroel Mirsky, Tomer Doitshman, Yuval Elovici, Asaf ShabtaiNDSS 2018 · 被引用 945 次
- Data Augmentation Can Improve RobustnessSylvestre-Alvise Rebuffi, Sven Gowal, Dan Andrei Calian, Florian Stimberg 等NeurIPS 2021 · 被引用 427 次
- Learning in situ: a randomized experiment in video streamingFrancis Y. Yan, Hudson Ayers, Chenzhi Zhu, Sadjad Fouladi 等NSDI 2020 · 被引用 360 次
相关 Paper
- AI/ML for Network Security: The Emperor has no ClothesArthur Selle Jacobs, Roman Beltiukov, Walter Willinger, Ronaldo A. Ferreira 等CCS 2022 · 被引用 76 次
- Robustifying ML-powered Network Classifiers with PANTSMinhao Jin, Maria ApostolakiUSENIX Security 2025
- Unicorn: reasoning about configurable system performance through the lens of causalityMd Shahriar Iqbal, Rahul Krishna, Mohammad Ali Javidian, Baishakhi Ray 等EuroSys 2022 · 被引用 60 次
- New Directions in Automated Traffic AnalysisJordan Holland, Paul Schmitt, Nick Feamster, Prateek MittalCCS 2021 · 被引用 122 次
- FILA: Online Auditing of Machine Learning Model Accuracy under Finite Labelling BudgetNaiqing Guan, Nick KoudasSIGMOD 2022 · 被引用 1 次
