FeCoGraph: Label-Aware Federated Graph Contrastive Learning for Few-Shot Network Intrusion Detection

被引:0
|
作者
Mao, Qinghua [1 ]
Lin, Xi [1 ]
Xu, Wenchao [2 ,3 ]
Qi, Yuxin [1 ]
Su, Xiu [4 ,5 ]
Li, Gaolei [1 ]
Li, Jianhua [1 ]
机构
[1] Shanghai Jiao Tong Univ, Inst Cyber Sci & Technol, Sch Elect Informat & Elect Engn, Shanghai Key Lab Integrated Adm Technol Informat S, Shanghai 200240, Peoples R China
[2] Hong Kong Polytech Univ, Dept Comp, Hong Kong, Peoples R China
[3] Hong Kong Polytech Univ, Shenzhen Res Inst, Shenzhen 518057, Peoples R China
[4] Cent South Univ, Big Data Inst, Changsha 410075, Peoples R China
[5] Univ Sydney, Fac Engn, Sch Comp Sci, Sydney, NSW 2006, Australia
基金
中国国家自然科学基金;
关键词
Feature extraction; Contrastive learning; Data mining; Image edge detection; Botnet; Training; Topology; Telecommunication traffic; Network topology; Network intrusion detection; few-shot learning; graph contrastive learning; graph neural networks;
D O I
10.1109/TIFS.2025.3541890
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
With increasing cyber attacks over the Internet, network intrusion detection systems (NIDS) have been an indispensable barrier to protecting network security. Taking advantage of automatically capturing topology connections, recent deep graph learning approaches have achieved remarkable performance in distinguishing different types of malicious flows. However, there remain some critical challenges. 1) previous supervised learning methods rely heavily on abundant and high-quality annotated samples, while label annotation requires abundant time and expert knowledge. 2) Centralized methods require all data to be uploaded to a server for learning behavior patterns, which results in high detection latency and critical privacy leakage. 3) Diverse attack scenarios exhibit highly imbalanced distribution, making it hard to characterize abnormal behaviors. To address these issues, we proposed FeCoGraph, a label-aware federated graph contrastive learning framework for intrusion detection in few-shot scenarios. The line graph is introduced to directly process flow embeddings, which are compatible with diverse GNNs. Furthermore, We formulate a graph contrastive learning task to effectively leverage label information, allowing intra-class embeddings more compact than inter-class embeddings. To improve the scalability of NIDS, we utilize federated learning to cover more attack scenarios while protecting data privacy. Experiment results show that FeCoGraph surpass E-graphSAGE with an average 8.36% accuracy on binary classification and 6.77% accuracy on multiclass classification, demonstrating the efficiency of our approach.
引用
收藏
页码:2266 / 2280
页数:15
相关论文
共 50 条
  • [21] Graph Embedding Relation Network for Few-Shot Learning
    Liu, Zhen
    Xia, Yitong
    Zhang, Baochang
    PROCEEDINGS OF THE 39TH CHINESE CONTROL CONFERENCE, 2020, : 7328 - 7334
  • [22] Class Label-aware Graph Anomaly Detection
    Kim, Junghoon
    In, Yeonjun
    Yoon, Kanghoon
    Lee, Junmo
    Park, Chanyoung
    PROCEEDINGS OF THE 32ND ACM INTERNATIONAL CONFERENCE ON INFORMATION AND KNOWLEDGE MANAGEMENT, CIKM 2023, 2023, : 4008 - 4012
  • [23] A Survey of Few-Shot Learning: An Effective Method for Intrusion Detection
    Duan, Ruixue
    Li, Dan
    Tong, Qiang
    Yang, Tao
    Liu, Xiaotong
    Liu, Xiulei
    SECURITY AND COMMUNICATION NETWORKS, 2021, 2021
  • [24] Label-Aware Chinese Event Detection with Heterogeneous Graph Attention Network
    Cui, Shi-Yao
    Yu, Bo-Wen
    Cong, Xin
    Liu, Ting-Wen
    Tan, Qing-Feng
    Shi, Jin-Qiao
    JOURNAL OF COMPUTER SCIENCE AND TECHNOLOGY, 2024, 39 (01) : 227 - 242
  • [25] Label-Aware Automatic Verbalizer for Few-Shot Text Classification in Mid-To-Low Resource Languages
    Thaminkaew, Thanakorn
    Lertvittayakumjorn, Piyawat
    Vateekul, Peerapon
    PROCEEDINGS OF THE 62ND ANNUAL MEETING OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS, VOL 4: STUDENT RESEARCH WORKSHOP, 2024, : 119 - 127
  • [26] A Few-shot Deep Learning Approach for Improved Intrusion Detection
    Chowdhury, Md Moin Uddin
    Hammond, Frederick
    Konowicz, Glenn
    Xin, Chunsheng
    Wu, Hongyi
    Li, Jiang
    2017 IEEE 8TH ANNUAL UBIQUITOUS COMPUTING, ELECTRONICS AND MOBILE COMMUNICATION CONFERENCE (UEMCON), 2017, : 456 - +
  • [27] Towards multimodal sarcasm detection via label-aware graph contrastive learning with back-translation augmentation
    Wei, Yiwei
    Duan, Maomao
    Zhou, Hengyang
    Jia, Zhiyang
    Gao, Zengwei
    Wang, Longbiao
    KNOWLEDGE-BASED SYSTEMS, 2024, 300
  • [28] A Method of Few-Shot Network Intrusion Detection Based on Meta-Learning Framework
    Xu, Congyuan
    Shen, Jizhong
    Du, Xin
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2020, 15 : 3540 - 3552
  • [29] Few-Shot Network Intrusion Detection Using Discriminative Representation Learning with Supervised Autoencoder
    Iliyasu, Auwal Sani
    Abdurrahman, Usman Alhaji
    Zheng, Lirong
    APPLIED SCIENCES-BASEL, 2022, 12 (05):
  • [30] Joint contrastive learning with semantic enhanced label referents for few-shot NER
    Liu, Xiaoya
    Luo, Senlin
    Wu, Zhouting
    Pan, Limin
    Li, Xinshuai
    NEUROCOMPUTING, 2025, 618