Netinfo Security ›› 2026, Vol. 26 ›› Issue (8): 1264-1276.doi: 10.3969/j.issn.1671-1122.2026.08.008

Previous Articles     Next Articles

Argus6: an IPv6 DDoS threat detection model

Zhang Hongtao1,2, Wang Qingtao1,2, Zhang Liancheng3(), Wang Jichang3   

  1. 1 School of Cyber Science and Engineering, Zhengzhou University, Zhengzhou 450002, China
    2 Network Management Center, Zhengzhou University, Zhengzhou 450001, China
    3 School of Cyberspace Security, Cyberspace Force Information Engineering University, Zhengzhou 450001, China
  • Received:2025-12-25 Online:2026-08-10 Published:2026-09-23
  • Contact: Zhang Liancheng E-mail:liancheng17@aliyun.com

Abstract:

This paper presented a hybrid deep-learning method, Argus6, for IPv6 DDoS threat detection under limited labeled data. The method parallelized a transformer-based branch to capture global temporal dependencies and a Mamba state-space branch to model long-sequence dynamics efficiently. Ablation studied on two benchmark datasets showed that the proposed method significantly outperformed its single-branch variants. On Dataset 1, it achieved an F1-Score of 0.9874 and an AUC of 0.9986; on Dataset 2, it obtained an F1-Score of 0.9926 and an AUC of 0.9995, with false positive and false negative rates reduced to 1.19% and 0.84%, respectively. In K-shot experiments, the method demonstrated strong data efficiency: with only 10 labeled samples per class, it yielded an F1-Score of approximately 0.78 and an AUC of approximately 0.81; when the number of samples per class exceeded 100, the F1-Score and AUC reached approximately 0.91 and 0.96, respectively. On the full IPv6 DDoS threat dataset, the method surpasses 1D-CNN, CNN-LSTM, MF-Net, and classical baselines in accuracy, F1-Score, AUC, and error-rate metrics, which confirms its robustness and data efficiency for large-scale DDoS threat defense.

Key words: IPv6, DDoS threat, transformer, mamba

CLC Number: