信息网络安全 ›› 2026, Vol. 26 ›› Issue (8): 1183-1193.doi: 10.3969/j.issn.1671-1122.2026.08.002
收稿日期:2026-07-05
出版日期:2026-08-10
发布日期:2026-09-23
通讯作者:
金志刚
E-mail:zgjin@tju.edu.cn
作者简介:金志刚(1972—),男,上海,教授,博士,主要研究方向为无线网络、网络安全|李其睿(2003—),男,四川,硕士研究生,主要研究方向为入侵检测、深度学习|丁禹(2001—),男,四川,硕士研究生,主要研究方向为入侵检测、联邦学习
基金资助:
Jin Zhigang(
), Li Qirui, Ding Yu
Received:2026-07-05
Online:2026-08-10
Published:2026-09-23
Contact:
Jin Zhigang
E-mail:zgjin@tju.edu.cn
摘要:
针对资源受限场景下入侵检测系统难以兼顾检测精度与计算效率的问题,文章提出一种融合轻量级注意力机制的双分支入侵检测方法。该方法以轻量化过程中的特征损失与多类攻击间的特征混叠为核心设计出发点,构建双分支-可分离卷积-高效注意力机制协同架构。双分支结构负责从网络流量中捕获多尺度特征,保障模型对复杂攻击行为的完整感知;深度可分离卷积大幅压缩参数量与计算复杂度,并引入残差网络连接补偿轻量化带来的特征退化;在特征融合阶段,轻量级通道注意力机制ECA对关键通道特征进行自适应增强,提升复杂攻击流量的区分能力。实验结果表明,该方法在各项指标上均优于基线对比模型,其中在UNSW-NB15数据集上准确率为89.69%,精确率为89.83%,并且F1分数为89.70%,较次优基线模型提升7.13个百分点,表明模型在精确率与召回率间取得了良好的平衡。模型参数量与一维卷积神经网络处于同一量级,验证了其在资源受限网络环境中的应用潜力。
中图分类号:
金志刚, 李其睿, 丁禹. 融合轻量级注意力机制的双分支入侵检测方法[J]. 信息网络安全, 2026, 26(8): 1183-1193.
Jin Zhigang, Li Qirui, Ding Yu. A dual-branch intrusion detection method integrated with lightweight attention mechanism[J]. Netinfo Security, 2026, 26(8): 1183-1193.
表4
不同模型性能对比
| 模型 | 数据集 | 准确率 | 精确率 | 召回率 | F1分数 |
|---|---|---|---|---|---|
| LSTM | UNSW-NB15 | 81.36% | 85.53% | 81.95% | 80.93% |
| CIC-IDS-2017 | 95.12% | 94.38% | 91.87% | 92.74% | |
| RNN | UNSW-NB15 | 81.69% | 85.96% | 82.29% | 81.26% |
| CIC-IDS-2017 | 94.67% | 93.85% | 91.43% | 91.96% | |
| 1D CNN | UNSW-NB15 | 82.13% | 86.10% | 82.71% | 81.76% |
| CIC-IDS-2017 | 96.84% | 95.76% | 93.21% | 94.05% | |
| CBAM + CNN | UNSW-NB15 | 82.88% | 86.41% | 83.42% | 82.57% |
| CIC-IDS-2017 | 97.53% | 97.11% | 94.69% | 95.88% | |
| 本文模型 | UNSW-NB15 | 89.69% | 89.83% | 89.78% | 89.70% |
| CIC-IDS-2017 | 99.14% | 98.22% | 97.63% | 98.45% |
| [1] | 邓淼磊, 阚雨培, 孙川川, 等. 基于深度学习的网络入侵检测系统综述[J]. 计算机应用, 2025, 45(2):453-466. |
| [2] | Sharma S, Gupta R K. Intrusion detection system: a review[J]. International Journal of Software and Its Applications, 2015, 9(5): 69-76. |
| [3] | Catania C, Garino P C. Automatic network intrusion detection: current techniques and open issues[J]. Computers & Electrical Engineering, 2012, 38(5): 1062-1072. |
| [4] | Liao H J, Lin C H R, Lin Y C, et al. Intrusion detection system: a comprehensive review[J]. Journal of Network and Computer Applications, 2013, 36(1): 16-24. |
| [5] | Sabhnani M, Serpen G. Application of machine learning algorithms to KDD intrusion detection dataset within misuse detection context[C]// The 2003 International Conference on Machine Learning and Applications (ICMLA). Las Vegas: CSREA Press, 2003: 209-215. |
| [6] | Vinayakumar R, Alazab M, Soman K P, et al. Deep learning approach for intelligent intrusion detection system[J]. IEEE Access, 2019, 7: 41525-41550. |
| [7] | 蹇诗婕, 卢志刚, 杜丹, 等. 网络入侵检测技术综述[J]. 信息安全学报, 2020, 5(4):96-122. |
| [8] | Lecun Y, Boser B, Denker J S, et al. Backpropagation applied to handwritten zip code recognition[J]. Neural Computation, 1989, 1(4): 541-551. |
| [9] | Hochreiter S, Schmidhuber J. Long short-term memory[J]. Neural Computation, 1997, 9(8): 1735-1780. |
| [10] | Rumelhart D E, Hinton G E, Williams R J. Learning representations by back-propagating errors[J]. Nature, 1986, 323: 533-536. |
| [11] | 张志强, 暴亚东. 融合RF和CNN的异常流量检测算法[J]. 信息网络安全, 2024, 24(11):1655-1664. |
| [12] | 孙红哲, 王坚, 王鹏, 等. 基于Attention-BiTCN的网络入侵检测方法[J]. 信息网络安全, 2024, 24(2):309-318. |
| [13] | 刘联海, 黎汇业, 毛冬晖. 基于图像凸包特征的CBAM-CNN网络入侵检测方法[J]. 信息网络安全, 2024, 24(9):1422-1431. |
| [14] | Biyouki A, Lotfipour S, Haghi B. An enhanced deep learning framework for intrusion classification enterprise network using multi-branch CNN-attention architecture[J]. Scientific Reports, 2026, 16: 3962. |
| [15] | Zavvar M, Azar K K, Entezami M, et al. A hybrid intrusion detection method based on multi-convolutional neural networks fusion and grey wolf optimizer[J]. Journal of Cloud Computing, 2026, 15: 77. |
| [16] | 张志飞, 刘峰, 葛祎阳, 等. 一种基于深度可分离卷积和注意力机制的入侵检测方法[J]. 物联网学报, 2023, 7(1):49-59. |
| [17] | Jouhari M, Guizani M. Lightweight CNN-BiLSTM based intrusion detection systems for resource-constrained IoT devices[C]// The 20th IEEE International Wireless Communications and Mobile Computing Conference (IWCMC 2024). New York: IEEE, 2024: 1558-1563. |
| [18] | 杨毅铭, 陈世平. 不平衡数据下面向包粒度应用层负载的轻量化入侵检测模型[J]. 小型微型计算机系统, 2025, 46(2):465-473. |
| [19] | Howard A G, Zhu Menglong, Chen Bo, et al. MobileNets: efficient convolutional neural networks for mobile vision applications[C]// The IEEE Conference on Computer Vision and Pattern Recognition (CVPR). New York: IEEE, 2017: 1800-1807. |
| [20] | Chollet F. Xception: deep learning with depthwise separable convolutions[C]// The IEEE Conference on Computer Vision and Pattern Recognition (CVPR). New York: IEEE, 2017: 1251-1258. |
| [21] | He Kaiming, Zhang Xiangyu, Ren Shaoqing, et al. Deep residual learning for image recognition[C]// The IEEE Conference on Computer Vision and Pattern Recognition (CVPR). New York: IEEE, 2016: 770-778. |
| [22] | Wang Qilong, Wu Banggu, Zhu Pengfei, et al. ECA-Net: efficient channel attention for deep convolutional neural networks[C]// 2020 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). New York: IEEE, 2020: 11531-11539. |
| [23] | Hu Jie, Shen Li, Sun Gang. Squeeze-and-excitation networks[C]// The IEEE Conference on Computer Vision and Pattern Recognition (CVPR). New York: IEEE, 2018: 7132-7141. |
| [24] | Woo S, Park J, Lee J Y, et al. CBAM: convolutional block attention module[C]// The European Conference on Computer Vision (ECCV). Heidelberg: Springer, 2018: 3-19. |
| [25] | Moustafa N, Slay J. UNSW-NB15: a comprehensive data set for network intrusion detection systems[C]// 2015 Military Communications and Information Systems Conference (MilCIS). New York: IEEE, 2015: 1-6. |
| [26] | Sharafaldin I, Lashkari A H, Ghorbani A A. Toward generating a new intrusion detection dataset and intrusion traffic characterization[C]// The 4th International Conference on Information Systems Security and Privacy (ICISSP). Setubal: SciTePress, 2018: 108-116. |
| [1] | 寇亮, 屠国炫, 潘晓晨, 张纪林. 基于多视图敏感度挖掘与特征调制的恶意软件检测[J]. 信息网络安全, 2026, 26(7): 1028-1043. |
| [2] | 孙浩然, 陈杰, 刘君. 多路径特征增强的深度学习矩形攻击防御方法[J]. 信息网络安全, 2026, 26(7): 1115-1127. |
| [3] | 孙钰, 张轩瑞, 刘新宇. 高级持续性威胁检测与溯源研究进展[J]. 信息网络安全, 2026, 26(6): 833-853. |
| [4] | 杨望, 郑伟特. 基于可解释人工智能的入侵检测方法研究[J]. 信息网络安全, 2026, 26(6): 854-869. |
| [5] | 张浩, 叶骏威. 基于深度主动学习的联邦半监督入侵检测系统[J]. 信息网络安全, 2026, 26(6): 944-957. |
| [6] | 李海龙, 张运豪, 沈燮阳, 邢宇航, 崔治安. 基于机器学习的恶意软件检测方法综述[J]. 信息网络安全, 2026, 26(4): 521-541. |
| [7] | 袁小刚, 裴桓, 安德智, 万建鑫. 基于多特征感知和注意力机制的深度伪造图像检测研究[J]. 信息网络安全, 2026, 26(4): 642-653. |
| [8] | 徐衍微, 涂敏, 张亮. 深度伪造语音真实性鉴定研究综述[J]. 信息网络安全, 2026, 26(3): 367-377. |
| [9] | 秦振凯, 罗起宁, 农熏衣, 于小川, 操晓春. 融合性别与情绪强度提示特征的多层次语音情感识别模型[J]. 信息网络安全, 2026, 26(3): 420-431. |
| [10] | 徐茹枝, 武晓欣, 吕畅冉. 基于Transformer的超分辨率网络对抗样本防御方法研究[J]. 信息网络安全, 2025, 25(9): 1367-1376. |
| [11] | 陈咏豪, 蔡满春, 张溢文, 彭舒凡, 姚利峰, 朱懿. 多尺度多层次特征融合的深度伪造人脸检测方法[J]. 信息网络安全, 2025, 25(9): 1456-1464. |
| [12] | 王新猛, 陈俊雹, 杨一涛, 李文瑾, 顾杜娟. 贝叶斯优化的DAE-MLP恶意流量识别模型[J]. 信息网络安全, 2025, 25(9): 1465-1472. |
| [13] | 曹越, 方泊璎, 魏高达, 李金宇, 杨洋, 彭涛. 车载以太网环境下CAN总线入侵检测系统兼容性评估与优化[J]. 信息网络安全, 2025, 25(8): 1175-1195. |
| [14] | 李思聪, 王飞, 魏子令, 陈曙晖. 面向恶意代码检测的深度注意力网络架构[J]. 信息网络安全, 2025, 25(8): 1208-1222. |
| [15] | 金志刚, 李紫梦, 陈旭阳, 刘泽培. 面向数据不平衡的网络入侵检测系统研究综述[J]. 信息网络安全, 2025, 25(8): 1240-1253. |
| 阅读次数 | ||||||
|
全文 |
|
|||||
|
摘要 |
|
|||||