Hierarchical Local-Global Feature Learning for Few-shot Malicious Traffic Detection

📅 2025-04-01
📈 Citations: 0
Influential: 0
📄 PDF

career value

208K/year
🤖 AI Summary
To address high false positive rates and insufficient modeling of local patterns in few-shot malicious traffic detection, this paper proposes HLoG, a Hierarchical Local-Global feature learning framework. HLoG segments network sessions via sliding windows and employs a hierarchical bidirectional GRU to capture fine-grained local temporal patterns, while integrating global self-attention to model long-range contextual dependencies. It further introduces a novel collaborative similarity assessment mechanism that synergistically combines local phase encoding with global self-attention enhancement, thereby improving discriminability for rare attacks. Extensive experiments on three restructured benchmark datasets demonstrate that HLoG significantly outperforms existing state-of-the-art methods: it achieves an average 12.7% improvement in recall and a 38.4% reduction in false positive rate. Moreover, HLoG exhibits strong generalization capability and practical deployability in real-world intrusion detection systems.

Technology Category

Application Category

📝 Abstract
With the rapid growth of internet traffic, malicious network attacks have become increasingly frequent and sophisticated, posing significant threats to global cybersecurity. Traditional detection methods, including rule-based and machine learning-based approaches, struggle to accurately identify emerging threats, particularly in scenarios with limited samples. While recent advances in few-shot learning have partially addressed the data scarcity issue, existing methods still exhibit high false positive rates and lack the capability to effectively capture crucial local traffic patterns. In this paper, we propose HLoG, a novel hierarchical few-shot malicious traffic detection framework that leverages both local and global features extracted from network sessions. HLoG employs a sliding-window approach to segment sessions into phases, capturing fine-grained local interaction patterns through hierarchical bidirectional GRU encoding, while simultaneously modeling global contextual dependencies. We further design a session similarity assessment module that integrates local similarity with global self-attention-enhanced representations, achieving accurate and robust few-shot traffic classification. Comprehensive experiments on three meticulously reconstructed datasets demonstrate that HLoG significantly outperforms existing state-of-the-art methods. Particularly, HLoG achieves superior recall rates while substantially reducing false positives, highlighting its effectiveness and practical value in real-world cybersecurity applications.
Problem

Research questions and friction points this paper is trying to address.

Detect malicious traffic with limited samples
Reduce false positives in few-shot learning
Capture local and global traffic patterns
Innovation

Methods, ideas, or system contributions that make the work stand out.

Hierarchical bidirectional GRU encoding
Sliding-window local feature extraction
Global self-attention-enhanced similarity assessment
Songtao Peng
Songtao Peng
Zhejiang University of Technology
Complex NetworkSocial NetworkNetwork AnalysisAnomaly Detection
L
Lei Wang
Institute of Cyberspace Security, Zhejiang University of Technology, Hangzhou 310023, China, with the Binjiang Institute of Artificial Intelligence, ZJUT, Hangzhou 310056, China
W
Wu Shuai
Institute of Cyberspace Security, Zhejiang University of Technology, Hangzhou 310023, China, with the Binjiang Institute of Artificial Intelligence, ZJUT, Hangzhou 310056, China
Hao Song
Hao Song
Group Leader, NHMRC Senior Research Fellow, University of Queensland; Research Scientist, MIT
Biomimetic NanomaterialsDrug DeliveryNucleic Acids NanomedicineNano-vaccine
J
Jiajun Zhou
Institute of Cyberspace Security, College of Computer Science and Technology, Zhejiang University of Technology, Hangzhou 310023, China, with the Binjiang Institute of Artificial Intelligence, ZJUT, Hangzhou 310056, China
S
Shanqing Yu
Institute of Cyberspace Security, Zhejiang University of Technology, Hangzhou 310023, China, with the Binjiang Institute of Artificial Intelligence, ZJUT, Hangzhou 310056, China
Qi Xuan
Qi Xuan
Professor, Zhejiang University of Technology
AI SecuritySocial NetworkDeep LearningData Mining