FeCoGraph: Label-Aware Federated Graph Contrastive Learning for Few-Shot Network Intrusion Detection

被引:0
作者
Mao, Qinghua [1 ]
Lin, Xi [1 ]
Xu, Wenchao [2 ,3 ]
Qi, Yuxin [1 ]
Su, Xiu [4 ,5 ]
Li, Gaolei [1 ]
Li, Jianhua [1 ]
机构
[1] Shanghai Jiao Tong Univ, Inst Cyber Sci & Technol, Sch Elect Informat & Elect Engn, Shanghai Key Lab Integrated Adm Technol Informat S, Shanghai 200240, Peoples R China
[2] Hong Kong Polytech Univ, Dept Comp, Hong Kong, Peoples R China
[3] Hong Kong Polytech Univ, Shenzhen Res Inst, Shenzhen 518057, Peoples R China
[4] Cent South Univ, Big Data Inst, Changsha 410075, Peoples R China
[5] Univ Sydney, Fac Engn, Sch Comp Sci, Sydney, NSW 2006, Australia
基金
中国国家自然科学基金;
关键词
Feature extraction; Contrastive learning; Data mining; Image edge detection; Botnet; Training; Topology; Telecommunication traffic; Network topology; Network intrusion detection; few-shot learning; graph contrastive learning; graph neural networks;
D O I
10.1109/TIFS.2025.3541890
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
With increasing cyber attacks over the Internet, network intrusion detection systems (NIDS) have been an indispensable barrier to protecting network security. Taking advantage of automatically capturing topology connections, recent deep graph learning approaches have achieved remarkable performance in distinguishing different types of malicious flows. However, there remain some critical challenges. 1) previous supervised learning methods rely heavily on abundant and high-quality annotated samples, while label annotation requires abundant time and expert knowledge. 2) Centralized methods require all data to be uploaded to a server for learning behavior patterns, which results in high detection latency and critical privacy leakage. 3) Diverse attack scenarios exhibit highly imbalanced distribution, making it hard to characterize abnormal behaviors. To address these issues, we proposed FeCoGraph, a label-aware federated graph contrastive learning framework for intrusion detection in few-shot scenarios. The line graph is introduced to directly process flow embeddings, which are compatible with diverse GNNs. Furthermore, We formulate a graph contrastive learning task to effectively leverage label information, allowing intra-class embeddings more compact than inter-class embeddings. To improve the scalability of NIDS, we utilize federated learning to cover more attack scenarios while protecting data privacy. Experiment results show that FeCoGraph surpass E-graphSAGE with an average 8.36% accuracy on binary classification and 6.77% accuracy on multiclass classification, demonstrating the efficiency of our approach.
引用
收藏
页码:2266 / 2280
页数:15
相关论文
共 54 条
  • [1] JGCL: Joint Self-Supervised and Supervised Graph Contrastive Learning
    Akkas, Selahattin
    Azad, Ariful
    [J]. COMPANION PROCEEDINGS OF THE WEB CONFERENCE 2022, WWW 2022 COMPANION, 2022, : 1099 - 1105
  • [2] Zero Trust-NIDS: Extended Multi-View Approach for Network Trace Anonymization and Auto-Encoder CNN for Network Intrusion Detection
    Alalmaie, Abeer Z.
    Nanda, Priyadarsi
    He, Xiangjian
    [J]. 2022 IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS, TRUSTCOM, 2022, : 449 - 456
  • [3] Anomal-E: A self-supervised network intrusion detection system based on graph neural networks
    Caville, Evan
    Lo, Wai Weng
    Layeghy, Siamak
    Portmann, Marius
    [J]. KNOWLEDGE-BASED SYSTEMS, 2022, 258
  • [4] Chang LY, 2021, Arxiv, DOI arXiv:2111.13597
  • [5] Chen T, 2020, PMLR, P1597
  • [6] Chen Yikuan, 2022, 2022 International Conference on Communications, Computing, Cybersecurity, and Informatics (CCCI), P111, DOI 10.1109/CCCI55352.2022.9926623
  • [7] APT attack detection based on flow network analysis techniques using deep learning
    Cho Do Xuan
    Mai Hoang Dao
    Hoa Dinh Nguyen
    [J]. JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2020, 39 (03) : 4785 - 4801
  • [8] Collaborative Intrusion Detection System for SDVN: A Fairness Federated Deep Learning Approach
    Cui, Jie
    Sun, Hu
    Zhong, Hong
    Zhang, Jing
    Wei, Lu
    Bolodurina, Irina
    He, Debiao
    [J]. IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2023, 34 (09) : 2512 - 2528
  • [9] Flow Topology-Based Graph Convolutional Network for Intrusion Detection in Label-Limited IoT Networks
    Deng, Xiaoheng
    Zhu, Jincai
    Pei, Xinjun
    Zhang, Lan
    Ling, Zhen
    Xue, Kaiping
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2023, 20 (01): : 684 - 696
  • [10] Hjelm RD, 2019, Arxiv, DOI [arXiv:1808.06670, 10.48550/arXiv.1808.06670, DOI 10.48550/ARXIV.1808.06670]