arrow
Return

Boosting incremental intrusion detection system with adversarial samples

delete2025-05-01
delete0
PRE
AI
金志刚 cover
金志刚 (Zhigang Jin) *
X
Xuyang Chen
K
Kai Liu
DOI:10.1016/j.eswa.2025.126632delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Most data-driven intrusion detection system (IDS) fasten their model on offline training in resisting attacks, which hardly answers ever-increasing new attacks in fickle network environment. Incremental IDS (IIDS) based on incremental learning detect new attacks effectively, but the problems of excessive learning on new classes, poor generalizability on old classes, and catastrophic forgetting should be fixed. To this end, we propose an adversarial assistance based IIDS, which harness adversarial samples uniquely via batch normalization to improve the detection performance of IIDS rather than robustness against adversarial attacks. First, the generation networks of adversarial samples are decoupled with classification networks to guarantee varying data features of different clean samples are inherited by corresponding adversarial samples. On one hand, in addition to clean samples in training, the generated adversarial samples are used as training data in a way of disentangled distribution to exert regularization constraints on clean samples of new classes for preventing excessive learning on new classes. On the other hand, a dual distribution simulation memory is proposed to boost the generalizability of IIDS on old classes by storing both clean and adversarial samples of old classes dynamically. Furthermore, a weighted cross-entropy loss is introduced to mitigate catastrophic forgetting that arose from the size imbalance between new classes and memory. The experimental results verified with CNN, DNN, and RNN on the UNSW-NB15 dataset as well as on the CSE-CIC-IDS2018 dataset and corresponding discussions for abundant ablations fully illustrate the effectiveness of the proposed method, proving application value of the proposed method in dynamic and complex real network environments.
Keywords:
Intrusion detection system
Incremental learning
Adversarial learning
Data replay

Journal

Expert Systems with Applications cover
Expert Systems with Applications
IF:
7.5
Papers:
2.9W
Citations:
10.2W

Organization

I
Inner Mongolia Univ Technol
Scholars:
565
Papers: 221
Citations: 77