Enhanced Few-Shot Malware Traffic Classification via Integrating Knowledge Transfer With Neural Architecture Search

被引:7
作者
Zhang, Xixi [1 ]
Wang, Qin [1 ]
Qin, Maoyang [1 ]
Wang, Yu [1 ]
Ohtsuki, Tomoaki [2 ]
Adebisi, Bamidele [3 ]
Sari, Hikmet [1 ]
Gui, Guan [1 ]
机构
[1] Nanjing Univ Posts & Telecommun, Coll Telecommun & Informat Engn, Nanjing 210003, Peoples R China
[2] Keio Univ, Dept Informat & Comp Sci, Yokohama, Kanagawa 2238522, Japan
[3] Manchester Metropolitan Univ, Fac Sci & Engn, Dept Engn, Manchester M1 5GD, England
关键词
Feature extraction; Malware; Task analysis; Knowledge transfer; Convolutional neural networks; Image edge detection; Data models; Malware traffic classification; cyber security; deep learning; neural architecture search; few-shot learning; NETWORK INTRUSION DETECTION; INTERNET; THINGS; MODEL;
D O I
10.1109/TIFS.2024.3396624
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Malware traffic classification (MTC) is one of the important research topics in the field of cyber security. Existing MTC methods based on deep learning have been developed based on the assumption of enough high-quality samples and powerful computing resources. However, both are hard to obtain in real applications especially in availability of IoT. In this paper, we propose a few-shot MTC (FS-MTC) method combining knowledge transfer and neural architecture search (i.e. NAS-based FS-MTC) with limited training samples as well as acceptable computational resources, in order to mitigate the identified challenges. Specifically, our proposed method first converts the raw network traffic into traffic images through data pre-processing to serve as input data for the neural network. Second, we use neural architecture search to adaptively search for the effective feature extraction model on the source domain (including Edge-IIoTset, Bot-IoT, and benign USTC-TFC2016). Third, the searched model is pre-trained on source task to achieve the generic feature representation of malware traffic. Finally, we only use few-shot malware traffic samples to fine-tune the pre-trained model to quickly adapt to new types of MTC tasks in realistic network environments. The experimental results show that the proposed NAS-based FS-MTC method has great scalability and classification performance in different FS-MTC tasks, including 5-way K-shot USTC-TFC2016 dataset and 10-way K-shot CIC-IoT dataset. Compared with state-of-the-art methods in the field of malware classification, the proposed NAS-based FS-MTC has higher classification accuracy. Especially in the 1-shot case of the USTC-TFC2016 dataset, its average accuracy is as high as 86.91%.
引用
收藏
页码:5245 / 5256
页数:12
相关论文
共 50 条
  • [31] Few-Shot Text and Image Classification via Analogical Transfer Learning
    Liu, Wenhe
    Chang, Xiaojun
    Yan, Yan
    Yang, Yi
    Hauptmann, Alexander G.
    ACM TRANSACTIONS ON INTELLIGENT SYSTEMS AND TECHNOLOGY, 2018, 9 (06)
  • [32] Few-shot Heterogeneous Graph Learning via Cross-domain Knowledge Transfer
    Zhang, Qiannan
    Wu, Xiaodong
    Yang, Qiang
    Zhang, Chuxu
    Zhang, Xiangliang
    PROCEEDINGS OF THE 28TH ACM SIGKDD CONFERENCE ON KNOWLEDGE DISCOVERY AND DATA MINING, KDD 2022, 2022, : 2450 - 2460
  • [33] Generalized Few-Shot Node Classification With Graph Knowledge Distillation
    Wang, Jialong
    Zhou, Mengting
    Zhang, Shilong
    Gong, Zhiguo
    IEEE TRANSACTIONS ON COMPUTATIONAL SOCIAL SYSTEMS, 2024, : 1 - 11
  • [34] Multi-Dimensional Edge Features Graph Neural Network on Few-Shot Image Classification
    Xiong, Chao
    Li, Wen
    Liu, Yun
    Wang, Minghui
    IEEE SIGNAL PROCESSING LETTERS, 2021, 28 : 573 - 577
  • [35] Knowledge transfer based hierarchical few-shot learning via tree-structured knowledge graph
    Zhang, Zhong
    Wu, Zhiping
    Zhao, Hong
    Hu, Minjie
    INTERNATIONAL JOURNAL OF MACHINE LEARNING AND CYBERNETICS, 2023, 14 (01) : 281 - 294
  • [36] Knowledge transfer based hierarchical few-shot learning via tree-structured knowledge graph
    Zhong Zhang
    Zhiping Wu
    Hong Zhao
    Minjie Hu
    International Journal of Machine Learning and Cybernetics, 2023, 14 : 281 - 294
  • [37] Multi-directional Knowledge Transfer for Few-Shot Learning
    Wang, Shuo
    Zhang, Xinyu
    Hao, Yanbin
    Wang, Chengbing
    He, Xiangnan
    PROCEEDINGS OF THE 30TH ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2022, 2022, : 3993 - 4002
  • [38] Few-shot encrypted traffic classification via multi-task representation enhanced meta-learning
    Yang, Chen
    Xiong, Gang
    Zhang, Qing
    Shi, Junzheng
    Gou, Gaopeng
    Li, Zhen
    Liu, Chang
    COMPUTER NETWORKS, 2023, 228
  • [39] Adapting Few-Shot Classification via In-Process Defense
    Yang, Xi
    Kong, Dechen
    Lin, Ren
    Wang, Nannan
    Gao, Xinbo
    IEEE TRANSACTIONS ON IMAGE PROCESSING, 2024, 33 : 5232 - 5245
  • [40] Few-Shot Classification Model Compression via School Learning
    Yang, Sai
    Liu, Fan
    Chen, Delong
    Huang, Huaxi
    Zhou, Jun
    IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS FOR VIDEO TECHNOLOGY, 2024, 34 (12) : 12244 - 12257