EDBT 2026 Demo / reviewers in the wild / expert
Mingshu He
dblp:213/7028
· DBLP profile ↗
21ranked-venue papers
5as first author
21since 2021 · last 2026
0000-0002-2896-4595ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 8 · 2 first-author · 8 since 2021Security and privacy · 5 · 2 first-author · 5 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Systems, architecture and hardware · 3 · 1 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | GIANT: Structure-Agnostic Practical Adversarial Attacks for Graph-based Network Intrusion Detection Systems
Jianjin Zhao, Qi Li 0057, Hua Zhang 0001, Mingshu He, Jiong Dong, Yuyin Ma, Meng Shen 0001 |
WWW | 8 |
| 2026 | A Real-Time Channel-Level Intrusion Detection System Based on Multimodal LearningabstractWith the proliferation of Internet of Things (IoT) devices, cybersecurity threats are escalating. To protect user privacy and data integrity, a significant portion of IoT traffic is secured using encryption technologies. Additionally, certain IoT scenarios demand that Intrusion Detection Systems (IDS) process traffic in real-time. Thus, encrypted flow detection and real-time detection have emerged as two core challenges for IDS in IoT. To address these challenges, this paper proposes RCML-IDS, a Real-time Channel-level Intrusion Detection System based on Multimodal Learning. The core novelty of RCML-IDS lies in its real-time, online processing capability, enabled by a time-window-based traffic preprocessing mechanism. Additionally, it performs channel-level traffic aggregation and integrates multi-modal features, namely raw bytes and packet lengths, to capture rich behavioral patterns from encrypted traffic. Architecturally, two Transformers learn multi-level byte representations from local to global contexts, while an LSTM captures temporal patterns in packet length sequences. To our knowledge, this is the first multimodal IDS capable of real-time online traffic processing. Experimental results demonstrate that RCML-IDS outperforms existing approaches on public and self-collected datasets. Its lightweight version achieves a per-sample processing time of approximately 20 milliseconds and permits deployment on resource-constrained devices, offering an effective solution for IoT security. Mingshu He |
IEEE Internet Things J. | 2 |
| 2026 | MTRF: Multidomain Transformation Representation for Network Flows in Network Intrusion DetectionabstractIn IoT device applications, due to privacy protection requirements, it is often impossible to obtain large-scale labeled datasets for model training. A representation model that effectively extracts flow features with limited labeled samples is therefore critical. To meet this need, we propose a model combining temporal features (for trend changes/short-term fluctuations) and frequency-domain features (for periodicity/stability patterns) in network flows. In order to fully tap the potential of these two types of features, contrastive learning (CL) technology is used to model them respectively. For temporal-domain features, we employ a momentum encoder-based training strategy to learn robust representations adaptable to network-induced noise. For frequency domain features, we propose a new supervised CL loss function. It enhances inter-class separability while improving the representation ability (i.e., the model's capacity to extract discriminative features) of minority classes. The experimental results demonstrate the universality of this approach, which is not limited to specific data sets or attack types. The most representative results were obtained on the UNSW-NB15 dataset, with an accuracy of 0.9699 for the balanced training sets, surpassing the other best models' performance(0.6300). We have released our source code to facilitate future studies onhttps://github.com/Ann96125/MTRF. Mingshu He, Shize Guo |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | HKD-Net: Hierarchical Knowledge Distillation Based on Multi-Domain Feature Fusion for Efficient Network Intrusion DetectionabstractWe propose HKD-Net1, a hierarchical knowledge distillation network based on multi-domain feature fusion, for efficient network intrusion detection on resource-constrained edge devices. The framework incorporates dedicated feature extraction modules across temporal, frequency, and spatial domains, and introduces a dynamic gating mechanism for adaptive feature fusion, resulting in a more discriminative and comprehensive feature representation. Moreover, a hierarchical distillation mechanism is designed that not only preserves soft labels from the output layer but also aligns intermediate features from spatial, temporal, frequency, and fused domains, enabling efficient knowledge transfer from a large teacher model to a compact student model. Through knowledge distillation, the final lightweight model requires only 278,580 parameters, reducing the number of parameters by approximately 74.68% compared to the teacher, while maintaining high detection accuracy. Extensive experiments on three public datasets (Kitsune, CIRA-CIC-DoHBrw2020, and CICIoT2023) demonstrate that HKD-Net outperforms five state-of-the-art methods, achieving accuracies of 96.72%, 97.19%, and 87.19%, respectively, while reducing parameters by 74.68% and maintaining low computational cost. Mingshu He |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2025 | NFD-TRG: Network Flow Detection via Traffic Relationship Graphs with Statistical Feature EmbeddingabstractIntrusion Detection Systems (IDS) are powerful tools in today’s arsenal for identifying and preventing cybersecurity attacks. A significant challenge to classification performance arises from previously unknown attack traffic within traffic classification systems. In this paper, we propose a novel Network Flow Detection via Traffic Relationship Graphs with statistical feature embedding (NFD-TRG), which can address this challenge by combining the accurate characterization of data features and the utilization of graph neural networks. The proposed detection model can identify intrusive data traffic and accurately distinguish the categories of attack traffic flows. This method introduces a traffic relationship graph to represent the relationships between all traffic flows and designs an attack traffic detection method based on this graph representation using graph neural networks. Experimental validation of real-world traffic data confirms the effectiveness of the proposed approach. When real-time traffic detection with minimal data volume is needed, this approach exhibits shorter running time and superior classification performance compared to other state-of-the-art methods. NFD-TRG can achieve millisecond-level detection in real network flow data validation, and the detection accuracy for single-category attacks can reach 98.56%, 99.92%, and 98.89% in the CICDDOS-2019, MQTT, and CICIoT2023 datasets. Mingshu He, Liu Yang 0016 |
TrustCom | 1 |
| 2025 | ACE: A Static Android Malware Detection Method Based on Supervised Contrastive LearningabstractSmart and mobile devices are essential components of the Internet of Things (IoT) ecosystems, facilitating connectivity and automation across various domains. Due to its flexibility, the Android operating system is widely adopted in these devices. However, their increasing integration into IoT networks has introduced significant security risks, particularly from Android malware. To address these challenges, effective detection methods are needed to enhance IoT security. Given the success of contrastive learning in computer vision, researchers have increasingly explored its potential for Android malware detection. This article presents a static Android malware detection method that integrates deep learning with supervised contrastive learning. Based on the characteristic that contrastive learning enhances the model’s ability to effectively represent input samples, we design a novel contrastive loss based on structural similarity metrics and integrate it with contractive loss and binary cross-entropy loss to construct a hierarchical loss function for guiding model optimization. Furthermore, the method directly analyzes the classes.dex file from Android application package, eliminating the need for feature engineering or domain expertise, thus enhancing its applicability. Experimental results demonstrate that the proposed method achieves an 87.13% F1-score on the AndroZoo dataset, outperforming baseline models while maintaining computational efficiency and practical usability. Ablation studies validate the effectiveness of the hierarchical loss function in improving model performance and ensuring consistent malware representation within the same family. Yuanming Huang, Mingshu He, Jie Zhang 0006, Shize Guo |
IEEE Internet Things J. | 2 |
| 2025 | Semi-Supervised Learning With Interpolation and Pseudo-Labeling for Few-Label Intrusion DetectionabstractGiven the scarcity of labels in network traffic data, traditional supervised learning methods are limited by their dependence on large amounts of labeled data. While semi-supervised learning (SeSL) offers potential solutions, existing SeSL-based intrusion detection systems (IDS) still require substantial labeled samples for effective training, severely constraining their adaptability to emerging cyber threats under extreme label scarcity scenarios (e.g., 3-5 labels per class). This paper proposes IPL-SeSL, a novel SeSL framework that synergistically integrates Interpolation and Pseudo-Labeling mechanisms to enhance IDS’s performance under severe label constraints. IPL-SeSL consists of a supervised branch, a pseudo-labeling branch, and an interpolation branch. In the pseudo-labeling branch, we propose a data augmentation method specifically designed for network traffic data, which enhances the model’s robustness and generalization ability. The interpolation mechanism introduces a novel sample generation strategy that reinforces decision boundaries through geometrically meaningful feature space transformations. Comprehensive evaluations on the CICIoMT2024 benchmark demonstrate the framework’s exceptional performance, achieving 91% detection accuracy with merely 5 labeled instances per class. Mingshu He |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2025 | An Efficient DDoS Detection Method Based on Packet Grouping via Online Data Flow ProcessingabstractDistributed Denial of Service attacks are considered to be one of the most common and effective threats in the security field, aiming to deny or weaken the service providing of its victims. Most traditional solutions are only for DDoS detection in offline scenarios, which are challenging to detect real-time DDoS attacks. Therefore, the application scenarios are limited. In this paper, we propose a packet grouping-based DDoS detection method, which uses an online data flow processing mechanism to focus on data collection and processing efforts, which is suitable for online and offline detection. The proposed method simulates the process of real-time packet capture by grouping packets through a time window and realizes the binary classification of traffic through the lightweight CNN model. Most crucially, selecting the optimal number of packets per time window minimizes the time overhead without affecting detection accuracy. To further improve the accuracy in offline scenarios, we perform ensemble learning on the prediction results of packet groups. The proposed method attains 99.99$\%$accuracy on the CICIDS2017 offline dataset and demonstrates a latency of only 1.05 seconds with a 99.86$\%$accuracy in online testing, surpassing other methods in terms of response speed. Mingshu He |
IEEE Trans. Sustain. Comput. | 1 |
| 2024 | Global-To-Pixel Regression for Human Mesh Recovery
Yabo Xiao, Mingshu He, Dongdong Yu |
ECCV (16) | 2 |
| 2024 | Intrusion Detection for Encrypted Flows Using Single Feature Based on Graph Integration TheoryabstractTo ensure the privacy and security of Internet of Things data, encrypted transmission of data has become a common approach. However, this has also introduced limitations for the detection of malicious network flows, often requiring reliance on only a few selected features for categorizing malicious flows. In this paper, we proposed a novel Graph Integration Theory and applied it to construct graphs based solely on packet length sequences, aiming to enhance the detection capability of single-feature-based methods, such as packet length sequences. Our proposed approach not only demonstrated its applicability in binary and multi-class classification problems but also provided a detailed analysis of the underlying reasons for its effectiveness in detecting different types of attacks and in various classification networks. Additionally, we proposed the use of the Tree-Like structure to construct Traffic Interaction Graphs and verified that the Graph Integration Theory achieved excellent classification results in both the Tree-Like and Cross-Linked list structures. Specifically, the average detection accuracy achieved in the Tree-Like structure was 0.9842, while that in the Cross-Linked list structure was 0.9836. These results significantly outperformed those obtained using either original graph structure or packet length sequences alone for detection. In the ten-class classification problem, the proposed approach achieved a detection accuracy of 0.8557, which was much higher than the accuracy of 0.6252 obtained using only packet length sequences, as well as the accuracy of 0.6634 obtained using only the original graph structure. Mingshu He, Shize Guo |
IEEE Internet Things J. | 3 |
| 2024 | A Lightweight and Efficient IoT Intrusion Detection Method Based on Feature GroupingabstractInternet of Things (IoT) devices have been widely used in many fields, bringing many conveniences to people’s life. With the massive deployment and application of IoT devices, how to maintain the IoT from cyber-attacks has become one of the major concerns of researchers. Due to IoT devices’ limited computational capabilities and storage resources, IoT usually does not have sufficient security defense mechanisms, making it vulnerable to malware or device attacks. However, existing IoT-oriented intrusion detection systems usually only support the detection of specific malicious attacks or require complex models and massive computational resources to obtain high detection accuracy. We propose a lightweight and efficient intrusion detection method based on feature grouping to address the above challenges. We first design a fast protocol parsing method on the raw packet capture files to generate semantic-level parsing features. Then, we propose session merging and feature grouping methods. Finally, we verify the proposed features’ effectiveness and analyze the malicious attacks’ working process. The proposed method achieves more than 99.5% classification accuracy on three public IoT data sets. The proposed method requires significantly fewer computational resources than baseline methods in the protocol parsing and model training process. Experimental results show that the proposed method is lightweight, efficient, and extensible. Therefore, the proposed method is suitable for IoT intrusion detection. Mingshu He, Yuanming Huang |
IEEE Internet Things J. | 1 |
| 2024 | HeVulD: A Static Vulnerability Detection Method Using Heterogeneous Graph Code RepresentationabstractVulnerability detection in source code has been a focal point of research in recent years. Traditional rule-based methods fail to identify complex and unknown vulnerabilities, leading to poor performance. While deep learning (DL)-based methods have improved these shortcomings, there is still room for enhancement. For C/C++ source code, effective vulnerability detection requires considering both the information in code statements and the structural information of the code. Graph-based code representation methods can address this need, but existing approaches often use homogeneous graphs that do not differentiate between various types of code statements or dependencies. Few methods use heterogeneous graphs for C/C++ code representation. This study explores this potential and proposes a new C/C++ vulnerability detection method named HeVulD. HeVulD introduces two node definition approaches and a key-node-based program slicing method, generating heterogeneous graph representations for source code. These representations consist of both heterogeneous nodes and edges, providing a more precise representation of source code. HeVulD achieves an F1-score of 96.4% on the SARD dataset, outperforming nine baseline C/C++ vulnerability detection methods. HeVulD has been tested under adversarial attack scenarios to assess its robustness. Additionally, HeVulD has been tested on ten open-source software projects and the latest CVEs, demonstrating its detection and generalization capabilities in real-world scenarios and its ability to identify unknown vulnerabilities. Yuanming Huang, Mingshu He, Jie Zhang 0006 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Spatial-Temporal Graph Model Based on Attention Mechanism for Anomalous IoT Intrusion DetectionabstractWe propose an attention-weighted model for parallel extraction of spatial-temporal features to enhance the detection capabilities in the message queuing telemetry transport protocol, widely used in the Internet of Things. Our approach involves constructing perception node collection graphs based on packet header information, which capture transmission-dependent and context-sequence-dependent relationships in the data streams. We leverage a message-passing mechanism to aggregate adjacent nodes and update the weight matrix accordingly. Additionally, we employ a bidirectional long short-term memory model to capture long-distance dependencies in the sequence. The updated graph and the output of the time-series model are fused and processed by a self-attention mechanism, generating weights for classification. The classification results are obtained using a fully connected network. We evaluate our approach on four datasets (ToN-IoT, BoT-IoT, UNSW-NB15, and DoHBrw2020) and compare it against nine different algorithms. Experimental results demonstrate the effectiveness of our method, achieving high accuracy levels, such as 0.8874 on ToN-IoT, 0.9386 on BoT-IoT, 0.9390 on DoHBrw2020, and the best accuracy of 0.8659 on the unbalanced UNSW-NB15 dataset. Mingshu He, Min Zhang 0022, Zikui Lu |
IEEE Trans. Ind. Informatics | 3 |
| 2024 | Reinforcement Learning Meets Network Intrusion Detection: A Transferable and Adaptable Framework for Anomaly Behavior IdentificationabstractAnomaly detection plays an essential role in network security and traffic classification. Many studies have focused on anomaly detection to improve network security, including machine learning and deep learning methods. These methods often require numerous samples and must obtain the results by classifying the entire data set, thereby limiting their inflexibility. Although transfer and multitask learning have achieved some results in the model’s transferability, these methods must manually label or reprocess the test set. These problems limit the application of previous methods in network security management. To solve these problems, we propose a transferable and adaptable network intrusion detection system (TA-NIDS) based on deep reinforcement learning. The interaction process between the agent and the environment varies every time. A small-scale data set can be used to produce many interactive processes. Therefore, robustness is guaranteed when there are few samples. Then, a reasonable reward function allows the agent to learn how to first choose outliers without classifying the entire data set. This makes the TA-NIDS more adaptable to the scene when we prioritize apparent outliers. More importantly, the original features are transformed into the state of the environment, so no requirement exists for the feature dimension. Furthermore, the general rather than the specific state of one data set makes the model transferable to other data sets. The experimental results for IDS2017, IDS2018, NSL-KDD, UNSW-NB15 and CIC-IoT2023 show that the proposed framework maintains good accuracy when prioritizing outliers and transferability are prioritized simultaneously. Mingshu He, Liu Yang 0016, Yinglei Teng, Renjian Lyu |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2024 | A Semantic Detection Method for Network Flows With Global and Generalized NatureabstractNetwork threat detection and identification are essential tasks in the defense of cyberspace. However, current network threat detection methods have limitations such as narrow feature extraction, targeted feature effects, and limited generalization performance. Therefore, there is a need for a more comprehensive understanding and description of network behavior. As a result, we propose a global and generalized method for semantic detection of network flow to enhance the definition of flow data and representation of network behavior. To improve the problem of narrow feature range in existing methods, this paper designs three feature embedding methods that represent global, temporal, and local semantic correlations from both temporal and spatial dimensions: global embedding, position embedding, and learning embedding. In order to overcome the problem of existing methods only targeting specific behaviours, this article focuses on constructing global correlation features to replace the detection mode of building an inherent feature set. By utilizing text analysis features, we extract global embedding features containing network flow relationship information by constructing a topology heterogeneous graph between flows and bytes. This is combined with position embedding and learning embedding to complete data detection and behavior classification through input into the transformer encoder. We validated the effectiveness of our method in three scenarios: the Internet, the Internet of Things, and encryption. The final experimental results demonstrated that our proposed method outperformed existing advanced models. Furthermore, after incorporating global embedding representing international correlation relationships, the model’s classification accuracy was further improved. Yiqing Luo, Mingshu He |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2024 | Supervised Representation Learning for Network Traffic With Cluster CompressionabstractIn the face of increasing network traffic, network security issues have gained significant attention. Existing network intrusion detection models often improve the ability to distinguish network behaviors by optimizing the model structure, while ignoring the expressiveness of network traffic at the data level. Visual analysis of network behavior through representation learning can provide a new perspective for network intrusion detection. Unfortunately, representation learning based on machine learning and deep learning often suffer from scalability and interpretability limitations. In this article, we establish an interpretable multi-layer mapping model to enhance the expressiveness of network traffic data. Moreover, the unsupervised method is used to extract the internal distribution characteristics of the data before the model to enhance the data. What’s more, we analyze the feasibility of the proposed flow spectrum theory on the UNSW-NB15 dataset. Experimental results demonstrate that the flow spectrum exhibits significant advantages in characterizing network behavior compared to the original network traffic features, underscoring its practical application value. Finally, we conduct an application analysis using multiple datasets (CICIDS2017 and CICIDS2018), revealing the model’s strong universality and adaptability across different datasets. Yu Zhang 0165, Mingshu He, Shize Guo, Liu Yang 0016 |
IEEE Trans. Sustain. Comput. | 3 |
| 2023 | A Manifold Consistency Interpolation Method of Poisoning Attacks Against Semi-Supervised ModelabstractSemi-Supervised Learning (SSL) is an influential derivative that allows humans to uncover invisible knowledge, potentially substituting it for extensive labeling data. Despite the optimism generated by the availability of unlabeled data, its potential unreliability can result in numerous unknown security risks. Assailants may covertly contaminate data, leading to potentially catastrophic and unpredictable outcomes. We investigate poisoning attacks in triangular manifolds to understand how SSL models defend against attacks resulting from small perturbations. By inserting tiny amounts of artificially modified samples totaling 2% of the entire training set, we can deceive classification models into altering the prediction results of arbitrary categories. In addition, considering that the poisoned data in practical scenarios belong to a minority sample attack, which is typically only about 0.1%-2% of the total data, we employed outlier detection to examine all inserted instances and discovered that it could bypass discovery. Our poisoning strategy can work across multiple datasets, models, and application domains of images and network traffic. Experimental results prove that our proposed method is effective on at least seven semi-supervised models. The declining ratio of model detection accuracy of autoencoder with confidence (ConAE) is 52.55% at the lowest cost. Another persuasive result is that our model poisoning exceeds the state-of-the-art methods in the image domain. The extended conclusion corroborates that the more accurate classification models do not have a corresponding improvement in their ability to resist interference, which also provides a new standard for testing model robustness. Mingshu He, Min Zhang 0022, Zhao Zhang 0023 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2022 | AdaptivePose: Human Parts as Adaptive PointsabstractMulti-person pose estimation methods generally follow top-down and bottom-up paradigms, both of which can be considered as two-stage approaches thus leading to the high computation cost and low efficiency. Towards a compact and efficient pipeline for multi-person pose estimation task, in this paper, we propose to represent the human parts as points and present a novel body representation, which leverages an adaptive point set including the human center and seven human-part related points to represent the human instance in a more fine-grained manner. The novel representation is more capable of capturing the various pose deformation and adaptively factorizes the long-range center-to-joint displacement thus delivers a single-stage differentiable network to more precisely regress multi-person pose, termed as AdaptivePose. For inference, our proposed network eliminates the grouping as well as refinements and only needs a single-step disentangling process to form multi-person pose. Without any bells and whistles, we achieve the best speed-accuracy trade-offs of 67.4% AP / 29.4 fps with DLA-34 and 71.3% AP / 9.1 fps with HRNet-W48 on COCO test-dev dataset. Yabo Xiao, Dongdong Yu, Guoli Wang 0004, Qian Zhang 0009, Mingshu He |
AAAI | 6 |
| 2022 | QueryPose: Sparse Multi-Person Pose Regression via Spatial-Aware Part-Level QueryabstractWe propose a sparse end-to-end multi-person pose regression framework, termed QueryPose, which can directly predict multi-person keypoint sequences from the input image. The existing end-to-end methods rely on dense representations to preserve the spatial detail and structure for precise keypoint localization. However, the dense paradigm introduces complex and redundant post-processes during inference. In our framework, each human instance is encoded by several learnable spatial-aware part-level queries associated with an instance-level query. First, we propose the Spatial Part Embedding Generation Module (SPEGM) that considers the local spatial attention mechanism to generate several spatial-sensitive part embeddings, which contain spatial details and structural information for enhancing the part-level queries. Second, we introduce the Selective Iteration Module (SIM) to adaptively update the sparse part-level queries via the generated spatial-sensitive part embeddings stage-by-stage. Based on the two proposed modules, the part-level queries are able to fully encode the spatial details and structural information for precise keypoint regression. With the bipartite matching, QueryPose avoids the hand-designed post-processes. Without bells and whistles, QueryPose surpasses the existing dense end-to-end methods with 73.6 AP on MS COCO mini-val set and 72.7 AP on CrowdPose test set. Code is available at https://github.com/buptxyb666/QueryPose. Yabo Xiao, Dongdong Yu, Lei Jin 0003, Mingshu He, Zehuan Yuan |
NeurIPS | 6 |
| 2022 | Topology analysis and routing algorithms design for PTNet networkabstractSummary Data center network (DCN) is used for transmission, storage, and processing of big data, which plays an important role in cloud computing and CDN distribution. Network topology and routing algorithm are its core research content and key technical issues. The traditional network topology is difficult to guarantee the quality of service in scalability and fault tolerance. The server‐centric DCN topology can ensure the scale of the DCN by recursively increasing the number of network nodes and links. Relative to the Dcell, BCube, and BCCC typical network topology, PTNet network as a typical representative of a new type of the server‐centric DCN topology, which has more advantages in scalability, fault tolerance, and so on. The PTNet network topology is theoretically analyzed in terms of network diameter, bottleneck throughput, and total number of links in the network. Based on the deep research of PTNet network, this article analyzes and studies the network topology, multicast, and broadcast routing algorithm. Zhijie Han 0001, Qingfang Zhang, Xiaoyu Du 0001, Kun Guo 0001, Mingshu He |
Concurr. Comput. Pract. Exp. | 5 |
| 2021 | Deep-Feature-Based Autoencoder Network for Few-Shot Malicious Traffic DetectionabstractWith the increase of Internet visits and connections, it is becoming essential and arduous to protect the networks and different devices of the Internet of Things (IoT) from malicious attacks. The intrusion detection systems (IDSs) based on supervised machine learning (ML) methods require a large number of labeled samples. However, the number of abnormal behaviors is far less than that of normal behaviors, let alone that the shots of malicious behavior samples which can be intercepted as training dataset are actually limited. Consequently, it is a key research topic to conduct the anomaly detection for the small number of abnormal behavior samples. This paper proposes an anomaly detection model with a few abnormal samples to solve the problem in few-shot detection based on convolutional neural networks (CNN) and autoencoder (AE). This model mainly consists of the CNN-based supervised pretraining module and the AE-based data reconstruction module. Only a few abnormal samples are utilized to the pretrain module to build the structure of extracting deep features. The data reconstruction module simply chooses the deep features of normal samples as training data. There also exist some effective attention mechanisms in the pretraining module. Through the pretraining of small samples, the accuracy of abnormal detection is improved compared with merely training normal samples with AE. The simulation results prove that this solution can solve the above problems occurring in network behavior anomaly detection. In comparison to the original AE model and other clustering methods, the proposed model advances the detection results in a visible way. Mingshu He, Junhua Zhou, Yuanyuan Xi, Lei Jin 0003 |
Secur. Commun. Networks | 1 |