inklap

A network intrusion detection method based on contrastive learning and Bayesian Gaussian Mixture Model

Liyou Liu, Ming Xu · Cybersecurity · 2025

Abstract Network Intrusion Detection Systems (NIDS) are essential for safeguarding networks against malicious activities. However, existing machine learning-based NIDS often require complex feature engineering, which demands significant domain expertise and experimentation, leading to suboptimal model performance in complex network environments. In contrast, deep learning approaches, while powerful, struggle with imbalanced data, resulting in a bias towards normal traffic and reduced effectiveness in detecting rare attacks. To address these issues, we propose a method that combines contrastive learning and Bayesian Gaussian Mixture Model (BGMM). Specifically, we propose a novel contrastive learning loss that enables the model to automatically learn the similarity within normal traffic and the distinction between normal and malicious traffic, thereby generating robust and distinguishable feature representations. This approach not only eliminates the need for manual feature engineering but also helps alleviate the issue of weak feature representations for rare attacks. BGMM further enhances detection performance by adapting to both normal and malicious patterns through the

📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً