基于数据驱动蒸馏与性能激励的入侵检测迭代模型
作者:
作者单位:

作者简介:

通讯作者:

中图分类号:

TP309

基金项目:

国家重点研发计划(2023YFB3107203)


Iterative Model for Intrusion Detection via Data-driven Distillation and Performance Motivation
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    入侵检测系统对先验知识的依赖及其输入数据中丰富的文本语义使其较为适合在大语言模型中应用, 但大语言模型的算力开销与数据隐私约束使其难以直接落地, 与此同时小模型虽便于部署但性能受限. 鉴于此, 提出一种基于数据驱动蒸馏与性能激励的入侵检测迭代模型RADOM, 通过大小模型之间的数据交互实现知识蒸馏, 并以小模型的错误预测作为迭代反馈改进大语言模型的数据生成质量. 同时, 引入特征维度优化机制, 借助大语言模型完成特征筛选与迭代更新, 以进一步提升小模型的分类能力. 在公开数据集与自采数据集上的实验结果表明, RADOM能够有效提升小模型对攻击行为的检测与分类性能, 小模型的准确率由67.30%提高到96.19%, 验证了该方法的有效性.

    Abstract:

    Intrusion detection systems rely on prior knowledge, and their input data contain rich semantic information, making them well suited for large language models (LLMs). However, the computational overhead of LLMs and data privacy constraints make their direct deployment difficult. Meanwhile, although small models are convenient for deployment, their performance is limited. To address this issue, this study proposes an iterative model for intrusion detection based on data-driven distillation and performance motivation, termed as RADOM. RADOM performs knowledge distillation through data exchange between LLMs and small models, and improves the quality of LLM-generated data by using incorrect predictions from the small models as iterative feedback. At the same time, this study introduces a feature dimension optimization mechanism, in which LLMs are used to perform feature selection and iterative updating, thereby further improving the classification capability of small models. Experimental results on public datasets and self-collected datasets show that RADOM effectively improves the detection and classification performance of small models for attack behaviors, and the accuracy of small models increases from 67.30% to 96.19%, verifying the effectiveness of the proposed method.

    参考文献
    相似文献
    引证文献
引用本文

田润,张海霞,连一峰,张立武.基于数据驱动蒸馏与性能激励的入侵检测迭代模型.软件学报,,():1-17

复制
相关视频

分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2025-08-12
  • 最后修改日期:2026-01-03
  • 录用日期:
  • 在线发布日期: 2026-08-12
  • 出版日期:
文章二维码
您是第位访问者
版权所有:中国科学院软件研究所 京ICP备05046678号-3
地址:北京市海淀区中关村南四街4号,邮政编码:100190
电话:010-62562563 传真:010-62562533 Email:jos@iscas.ac.cn
技术支持:北京勤云科技发展有限公司

京公网安备 11040202500063号