Frequency-Domain Mixing Data Augmentation for Malicious Traffic Detection

📅 2026-09-07
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
针对恶意流量检测中数据多样性不足问题,提出一种改进的频域混合数据增强方法,提高了模型在不同网络环境下的泛化能力。
📝 Abstract
The strong dynamics of network traffic often force malicious traffic detection models to handle out-of-distribution data. Typically, deep learning-based malicious traffic detection models require a large amount of high-quality training data. However, owing to challenges such as high labeling difficulty and resource consumption, existing datasets often suffer from insufficient diversity and fail to capture evolving traffic patterns, leading to poor out-of-distribution generalization ability of the trained models. Data augmentation has been widely adopted to improve data diversity and model generalization. Recently, frequency-domain mixing augmentation has shown promising performance because it effectively perturbs data while preserving key structural information. This approach shows potential for enhancing malicious traffic detection models. However, existing studies lack theoretical interpretation of the mixing mechanism, and do not adapt to the characteristics of network traffic. In this paper, we first conduct a theoretical analysis of the current frequency-domain mixing method, revealing its underlying principles and limitations. We further propose an improved frequency-domain mixing-based data augmentation method for network traffic data, which enhances the diversity of sequence features in network traffic and improves the out-of-distribution generalization of malicious traffic detection models. Extensive experiments on multiple artificial and real-world datasets demonstrate that our method substantially improves detection performance across diverse network environments and outperforms other data augmentation approaches.
Problem

Research questions and friction points this paper is trying to address.

malicious traffic detection
out-of-distribution data
data diversity
network traffic
Innovation

Methods, ideas, or system contributions that make the work stand out.

Frequency-Domain Mixing
Data Augmentation
Malicious Traffic Detection
Out-of-Distribution Generalization
🔎 Similar Papers
Y
Yuhao Yan
State Key Laboratory of Complex & Critical Software Environment, Beihang University, Beijing, China
Bo Lang
Bo Lang
BUAA
computer science
X
Xiangyu Li
State Key Laboratory of Complex & Critical Software Environment, Beihang University, Beijing, China