Collaborative P4-SDN DDoS Detection and Mitigation with Early-Exit Neural Networks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Karrakchou, Ouassim, Zniber, Alaa, Sebbar, Anass, Ghogho, Mounir
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913063523844096
author Karrakchou, Ouassim
Zniber, Alaa
Sebbar, Anass
Ghogho, Mounir
author_facet Karrakchou, Ouassim
Zniber, Alaa
Sebbar, Anass
Ghogho, Mounir
contents Distributed Denial of Service (DDoS) attacks pose a persistent threat to network security, requiring timely and scalable mitigation strategies. In this paper, we propose a novel collaborative architecture that integrates a P4-programmable data plane with an SDN control plane to enable real-time DDoS detection and response. At the core of our approach is a split early-exit neural network that performs partial inference in the data plane using a quantized Convolutional Neural Network (CNN), while deferring uncertain cases to a Gated Recurrent Unit (GRU) module in the control plane. This design enables high-speed classification at line rate with the ability to escalate more complex flows for deeper analysis. Experimental evaluation using real-world DDoS datasets demonstrates that our approach achieves high detection accuracy with significantly reduced inference latency and control plane overhead. These results highlight the potential of tightly coupled ML-P4-SDN systems for efficient, adaptive, and low-latency DDoS defense.
format Preprint
id arxiv_https___arxiv_org_abs_2509_12291
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Collaborative P4-SDN DDoS Detection and Mitigation with Early-Exit Neural Networks
Karrakchou, Ouassim
Zniber, Alaa
Sebbar, Anass
Ghogho, Mounir
Cryptography and Security
Distributed Denial of Service (DDoS) attacks pose a persistent threat to network security, requiring timely and scalable mitigation strategies. In this paper, we propose a novel collaborative architecture that integrates a P4-programmable data plane with an SDN control plane to enable real-time DDoS detection and response. At the core of our approach is a split early-exit neural network that performs partial inference in the data plane using a quantized Convolutional Neural Network (CNN), while deferring uncertain cases to a Gated Recurrent Unit (GRU) module in the control plane. This design enables high-speed classification at line rate with the ability to escalate more complex flows for deeper analysis. Experimental evaluation using real-world DDoS datasets demonstrates that our approach achieves high detection accuracy with significantly reduced inference latency and control plane overhead. These results highlight the potential of tightly coupled ML-P4-SDN systems for efficient, adaptive, and low-latency DDoS defense.
title Collaborative P4-SDN DDoS Detection and Mitigation with Early-Exit Neural Networks
topic Cryptography and Security
url https://arxiv.org/abs/2509.12291