TY - GEN
T1 - A Few-Shot Network Flow Attack Classification via Graph Contrastive Learning
AU - Gel, Binbin
AU - Li, Bo
AU - Mou, Xudong
AU - Zhao, Jun
AU - Liu, Xudong
N1 - Publisher Copyright:
© 2024 IEEE.
PY - 2024
Y1 - 2024
N2 - Accurately identifying network attacks is crucial for maintaining network security. However, these attacks are often hide within massive volumes of network traffic, posing significant challenges for traditional detection methods. Supervised learning approaches require substantial labeled data and struggle to adapt to unknown attack types, while unsupervised methods face difficulties in accurately pinpointing specific attack categories. To address these limitations, we propose a novel fewshot learning model for network flow attack classification based on graph contrastive learning. Our model leverages contrastive learning to enhance feature representation and generalization capabilities, enabling high-accuracy attack detection even with limited training data. Specifically, we first construct a multi- graph representation of network traffic and segment the data into snapshots. Then, we perform graph data augmentation within each snapshot to generate augmented sample pairs, which are used to pre-train the model via contrastive learning. Finally, we fine-tune the model parameters to achieve multi-class attack classification, leveraging the learned feature representations to identify various attack types, even those unseen during training. Experimental results demonstrate that our model exhibits excellent generalization ability and achieves high attack detection performance, even with limited training data.
AB - Accurately identifying network attacks is crucial for maintaining network security. However, these attacks are often hide within massive volumes of network traffic, posing significant challenges for traditional detection methods. Supervised learning approaches require substantial labeled data and struggle to adapt to unknown attack types, while unsupervised methods face difficulties in accurately pinpointing specific attack categories. To address these limitations, we propose a novel fewshot learning model for network flow attack classification based on graph contrastive learning. Our model leverages contrastive learning to enhance feature representation and generalization capabilities, enabling high-accuracy attack detection even with limited training data. Specifically, we first construct a multi- graph representation of network traffic and segment the data into snapshots. Then, we perform graph data augmentation within each snapshot to generate augmented sample pairs, which are used to pre-train the model via contrastive learning. Finally, we fine-tune the model parameters to achieve multi-class attack classification, leveraging the learned feature representations to identify various attack types, even those unseen during training. Experimental results demonstrate that our model exhibits excellent generalization ability and achieves high attack detection performance, even with limited training data.
KW - Attack Classification
KW - Data Augmentation
KW - Few-Shot Learning
KW - Graph Contrastive Learning
UR - https://www.scopus.com/pages/publications/85201291836
U2 - 10.1109/CSCloud62866.2024.00013
DO - 10.1109/CSCloud62866.2024.00013
M3 - 会议稿件
AN - SCOPUS:85201291836
T3 - Proceedings - 11th IEEE International Conference on Cyber Security and Cloud Computing, CSCloud 2024
SP - 30
EP - 35
BT - Proceedings - 11th IEEE International Conference on Cyber Security and Cloud Computing, CSCloud 2024
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 11th IEEE International Conference on Cyber Security and Cloud Computing, CSCloud 2024
Y2 - 28 June 2024 through 30 June 2024
ER -