基于集成学习与异常流量检测的物联网恶意威胁检测
作者:
作者单位:

1安徽财经大学图书与信息中心,安徽 蚌埠 233030;2安徽建筑大学电子与信息工程学院, 安徽 合肥 230601

作者简介:

通讯作者:

基金项目:

2021年安徽省高等学校自然科学研究项目(KJ2021A0476)。


Detection of Malicious Threats on the Internet of Things Based on Ensemble Learning and Abnormal Traffic
Author:
Affiliation:

1School of Library & Information Center, Anhui University of Finance & Economics, Bengbu 233030, Anhui, China;2School of Electronics and Information Engineering, Anhui Jianzhu University, Hefei 230601, Anhui, China

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
    摘要:

    伴随着越来越多的物联网终端接入到网络空间之中,恶意流量也在不断地变换自身伪装形式及形态种类;由于其体积庞大且属性特征较多、多维度,在使用传统检测方法来解决此类难题的过程中经常会遇到准确性不高、计算量过大等问题。在此背景下,提出了基于多尺度特征提取与高效的卷积运算恶意流量检测方法。首先,在模型的设计上,利用集成学习思想引入Inception模块实现了多尺度特征的并行抽取;其次,采用轻量化卷积代替全连接层构建轻量化主干网络,兼顾检测精度与运算速度;再次,为避免多通道输入导致的关键特征被稀释,将通道注意力和空间注意力相结合后加入模型中,更好地强化模型对关键特征的挖掘能力;最后,通过Softmax输出攻击类型判断结果。实验结果表明:该模型各项性能指标均能实现突破,检测准确率达到0.94,精确率及召回率分别为0.92和0.91,均方根误差低于0.07,误报率、漏报率分别为0.08和0.09,平均检测延时为15 ms,模型参数量约为6.1 M。该方法具有较强的实时性、较好的部署灵活性,在复杂的物联网环境下也能为终端设备提供一种较为可行的安全防护方法。

    Abstract:

    With the widespread popularity and application of internet of things devices, malicious threats in network environments are becoming increasingly frequent. Traditional detection methods are inadequate in dealing with high-dimensional traffic characteristics and multi-scale pattern recognition, and there is an urgent need to build efficient and accurate detection models. Therefore, a malicious traffic detection method combining multi-scale feature extraction and efficient convolution strategy has been proposed. Firstly, introduces the idea of ensemble learning combined with inception structure to construct a network traffic classification model. Secondly, efficient convolutional neural network architectures are adopted to construct a lightweight detection model. Thirdly, channel and spatial attention mechanisms are integrated to enhance feature weighting. Finally, the malicious traffic recognition result is output through the Softmax classifier. The experimental results show that the proposed model is significantly better than the comparative methods in terms of accuracy, precision, and recall. The accuracy reaches 0.94, and the precision and recall are 0.92 and 0.91, respectively. The root mean square error is reduced to 0.07, and the false positive and false negative rates are 0.08 and 0.09, respectively. The average detection delay is controlled at 15 ms, and the parameter count is 6.1 M, demonstrating excellent computational efficiency and stability. The research results indicate that the proposed integrated model can achieve high-precision and low false alarm malicious traffic detection in the internet of things environment, providing reliable support for real-time security protection of intelligent terminals.

    参考文献
    相似文献
    引证文献
引用本文

杨磊,景然.基于集成学习与异常流量检测的物联网恶意威胁检测[J].西昌学院学报(自然科学版),2026,40(2):93-99.

复制
文章指标
  • 点击次数:
  • 下载次数:
历史
  • 收稿日期:2025-08-29
  • 最后修改日期:2025-10-22
  • 录用日期:2025-10-27
  • 在线发布日期: 2026-07-08