FS-IDS: A framework for intrusion detection based on few-shot learning

被引:21
|
作者
Yang, Jingcheng [1 ]
Li, Hongwei [1 ]
Shao, Shuo [1 ]
Zou, Futai [1 ]
Wu, Yue [1 ]
机构
[1] Shanghai Jiao Tong Univ, Sch Elect Informat & Elect Engn, Shanghai, Peoples R China
基金
美国国家科学基金会; 国家重点研发计划;
关键词
Network security; Intrusion detection system; Few -shot learning; Feature fusion; CNN; Deep learning; NEURAL-NETWORKS;
D O I
10.1016/j.cose.2022.102899
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A B S T R A C T Due to the high dependency of traditional intrusion detection method on a fully-labeled large dataset, existing works can hardly be applied in real-world scenarios, especially facing zero-day attacks. In this paper we present a novel intrusion detection framework called "FS-IDS", including flow data encoding method, feature fusion mechanism and architecture of intrusion detection system based on few-shot learning. We utilize task generator to split the dataset into separate tasks and train model in an episodic way, hoping model to learn general knowledge rather than those specific to a single class. The extraction module and distance metric module are responsible for learning and determining whether the traffic data are benign or not. We conduct three sets of experiments on "FS-IDS", i.e., comparison study, abla-tion study and multiclass study. Comparison study firstly determines that the best measure metric for discrimination is Euclidean distance. Based on the optimal implementation, "FS-IDS" achieves compa-rable performance with existing works by using much fewer malicious samples. Ablation study sets two base models to explore how proposed encoding method and feature fusion mechanism improve detection capacity. Both the image representation and feature fusion achieve more than 2% improvement in accu-racy and recall. Finally, to test whether "FS-IDS" can perform well under real-world scenario or not, we design network traffic containing various attacks to simulate complex malicious network environment. Experimental results show that "FS-IDS" maintains more than 90% detection accuracy and recall under the worst circumstances, which composes of various seen or unseen attacks with only a few malicious samples available.(c) 2022 Elsevier Ltd. All rights reserved.
引用
收藏
页数:15
相关论文
共 50 条
  • [31] Few-shot learning for defect detection in manufacturing
    Zajec, Patrik
    Rozanec, Joze M.
    Theodoropoulos, Spyros
    Fontul, Mihail
    Koehorst, Erik
    Fortuna, Blaz
    Mladenic, Dunja
    INTERNATIONAL JOURNAL OF PRODUCTION RESEARCH, 2024, 62 (19) : 6979 - 6998
  • [32] Few-Shot Learning for Road Object Detection
    Majee, Anay
    Agrawal, Kshitij
    Subramanian, Anbumani
    AAAI WORKSHOP ON META-LEARNING AND METADL CHALLENGE, VOL 140, 2021, 140 : 115 - 126
  • [33] HoloDetect: Few-Shot Learning for Error Detection
    Heidari, Alireza
    McGrath, Joshua
    Ilyas, Ihab F.
    Rekatsinas, Theodoros
    SIGMOD '19: PROCEEDINGS OF THE 2019 INTERNATIONAL CONFERENCE ON MANAGEMENT OF DATA, 2019, : 829 - 846
  • [34] Few-Shot Few-Shot Learning and the role of Spatial Attention
    Lifchitz, Yann
    Avrithis, Yannis
    Picard, Sylvaine
    2020 25TH INTERNATIONAL CONFERENCE ON PATTERN RECOGNITION (ICPR), 2021, : 2693 - 2700
  • [35] Empowering few-shot learning: a multimodal optimization framework
    Liriam Enamoto
    Geraldo Pereira Rocha Filho
    Li Weigang
    Neural Computing and Applications, 2025, 37 (5) : 3539 - 3560
  • [36] Empowering few-shot learning: a multimodal optimization framework
    Enamoto, Liriam
    Rocha Filho, Geraldo Pereira
    Weigang, Li
    Neural Computing and Applications, 2024,
  • [37] The general framework for few-shot learning by kernel HyperNetworks
    Marcin Sendera
    Marcin Przewiȩźlikowski
    Jan Miksa
    Mateusz Rajski
    Konrad Karanowski
    Maciej Ziȩba
    Jacek Tabor
    Przemysław Spurek
    Machine Vision and Applications, 2023, 34
  • [38] Meta learning-based few-shot intrusion detection for 5G-enabled industrial internet
    Yan, Yu
    Yang, Yu
    Shen, Fang
    Gao, Minna
    Gu, Yuheng
    COMPLEX & INTELLIGENT SYSTEMS, 2024, 10 (03) : 4589 - 4608
  • [39] Meta learning-based few-shot intrusion detection for 5G-enabled industrial internet
    Yu Yan
    Yu Yang
    Fang Shen
    Minna Gao
    Yuheng Gu
    Complex & Intelligent Systems, 2024, 10 : 4589 - 4608
  • [40] The general framework for few-shot learning by kernel HyperNetworks
    Sendera, Marcin
    Przewiezlikowski, Marcin
    Miksa, Jan
    Rajski, Mateusz
    Karanowski, Konrad
    Zieba, Maciej
    Tabor, Jacek
    Spurek, Przemyslaw
    MACHINE VISION AND APPLICATIONS, 2023, 34 (04)