Hierarchical Local-Global Feature Learning for Few-shot Malicious Traffic Detection

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Peng, Songtao, Wang, Lei, Shuai, Wu, Song, Hao, Zhou, Jiajun, Yu, Shanqing, Xuan, Qi
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916674808053760
author Peng, Songtao
Wang, Lei
Shuai, Wu
Song, Hao
Zhou, Jiajun
Yu, Shanqing
Xuan, Qi
author_facet Peng, Songtao
Wang, Lei
Shuai, Wu
Song, Hao
Zhou, Jiajun
Yu, Shanqing
Xuan, Qi
contents With the rapid growth of internet traffic, malicious network attacks have become increasingly frequent and sophisticated, posing significant threats to global cybersecurity. Traditional detection methods, including rule-based and machine learning-based approaches, struggle to accurately identify emerging threats, particularly in scenarios with limited samples. While recent advances in few-shot learning have partially addressed the data scarcity issue, existing methods still exhibit high false positive rates and lack the capability to effectively capture crucial local traffic patterns. In this paper, we propose HLoG, a novel hierarchical few-shot malicious traffic detection framework that leverages both local and global features extracted from network sessions. HLoG employs a sliding-window approach to segment sessions into phases, capturing fine-grained local interaction patterns through hierarchical bidirectional GRU encoding, while simultaneously modeling global contextual dependencies. We further design a session similarity assessment module that integrates local similarity with global self-attention-enhanced representations, achieving accurate and robust few-shot traffic classification. Comprehensive experiments on three meticulously reconstructed datasets demonstrate that HLoG significantly outperforms existing state-of-the-art methods. Particularly, HLoG achieves superior recall rates while substantially reducing false positives, highlighting its effectiveness and practical value in real-world cybersecurity applications.
format Preprint
id arxiv_https___arxiv_org_abs_2504_03742
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Hierarchical Local-Global Feature Learning for Few-shot Malicious Traffic Detection
Peng, Songtao
Wang, Lei
Shuai, Wu
Song, Hao
Zhou, Jiajun
Yu, Shanqing
Xuan, Qi
Cryptography and Security
Artificial Intelligence
Machine Learning
With the rapid growth of internet traffic, malicious network attacks have become increasingly frequent and sophisticated, posing significant threats to global cybersecurity. Traditional detection methods, including rule-based and machine learning-based approaches, struggle to accurately identify emerging threats, particularly in scenarios with limited samples. While recent advances in few-shot learning have partially addressed the data scarcity issue, existing methods still exhibit high false positive rates and lack the capability to effectively capture crucial local traffic patterns. In this paper, we propose HLoG, a novel hierarchical few-shot malicious traffic detection framework that leverages both local and global features extracted from network sessions. HLoG employs a sliding-window approach to segment sessions into phases, capturing fine-grained local interaction patterns through hierarchical bidirectional GRU encoding, while simultaneously modeling global contextual dependencies. We further design a session similarity assessment module that integrates local similarity with global self-attention-enhanced representations, achieving accurate and robust few-shot traffic classification. Comprehensive experiments on three meticulously reconstructed datasets demonstrate that HLoG significantly outperforms existing state-of-the-art methods. Particularly, HLoG achieves superior recall rates while substantially reducing false positives, highlighting its effectiveness and practical value in real-world cybersecurity applications.
title Hierarchical Local-Global Feature Learning for Few-shot Malicious Traffic Detection
topic Cryptography and Security
Artificial Intelligence
Machine Learning
url https://arxiv.org/abs/2504.03742