• 融合类别选择性编码器与CTGAN的流量异常检测模型

    A traffic anomaly detection model integrating class-selective encoder and CTGAN

    • 针对入侵检测中少数类样本分布不均及特征维度冗余的双重挑战,提出一种融合类别选择性编码器与条件式表格生成对抗网络的流量异常检测模型CSE-CTGAN(Class-Selective Encoder with Conditional Tabular Generative Adversarial Network)。该模型构建类间-类内双通道特征提取结构,引入专家通道判别机制,依据类原型相似度实现自适应类别选择,并在训练与推理阶段分别采用协同优化与专家投票策略,以增强特征判别性与模型泛化能力。同时,基于自适应提升算法AdaBoost构建条件式表格生成对抗网络,定向合成难以建模的少数类样本,以缓解数据不平衡对分类性能的制约。实验结果表明:在NSL-KDD数据集上,模型准确率提升11.47%,F1分数提升10.23%,召回率提升7.46%;在UNSW-NB15数据集上,多种分类器下的平均召回率提升5.73%,F1分数提升6.49%;在TON_IoT数据集上的流式检测模拟中亦展现出良好的适应性与稳定性。

       

      Abstract: To address the dual challenges of imbalanced distribution of minority-class samples and feature dimension redundancy in intrusion detection, this paper proposes a traffic anomaly detection model named CSE-CTGAN, which integrates a class-selective encoder with a conditional tabular generative adversarial network. The model constructs an inter-class and intra-class dual-channel feature extraction architecture and incorporates an expert-channel discrimination mechanism. Adaptive class selection is achieved based on class prototype similarity, while collaborative optimization and expert voting strategies are employed during the training and inference phases, respectively, to enhance feature discriminability and model generalization. Furthermore, a conditional tabular generative adversarial network built upon the AdaBoost algorithm is developed to synthetically generate minority-class samples that are difficult to model, thereby alleviating the constraints imposed by data imbalance on classification performance. Experimental results demonstrate that on the NSL-KDD dataset, the proposed model achieves improvements of 11.47% in accuracy, 10.23% in F1-score, and 7.46% in recall. On the UNSW-NB15 dataset, the average recall and F1-score improvements across multiple classifiers are 5.73% and 6.49%, respectively. The model also exhibits favorable adaptability and stability in streaming detection simulations on the TON_IoT dataset.

       

    /

    返回文章
    返回