| 講演抄録/キーワード |
| 講演名 |
2025-03-07 13:25
侵入検知システムにおける概念ドリフトに基づく継続学習手法 ○村瀬柊士・山崎 託・三好 匠(芝浦工大)・中原正隆・奥井宣広・窪田 歩(KDDI総合研究所) NS2024-254 |
| 抄録 |
(和) |
近年,IoT(Internet of Things)デバイスを標的とするサイバー攻撃が増加しており,対策として機械学習を活用した侵入検知システム(Intrusion detection system: IDS)が注目されている.
機械学習ベースのIDSは多様な攻撃を検出可能である一方,入力データ分布が時間とともに変化する概念ドリフトによって学習済みモデルの精度が低下する.
このため,定期的に再学習を行うIDSが提案されているが,過剰な学習や適応の遅延といった課題がある.
本稿では,IoTトラヒックの概念ドリフト検出に基づき,侵入検知モデルを適応的に更新する手法を提案する.
概念ドリフト下での評価実験の結果,提案手法は従来手法と比較して精度低下をより抑制できることを示した. |
| (英) |
In recent years, cyberattacks targeting IoT (Internet of Things) devices have been increasing, and intrusion detection systems (IDS) utilizing machine learning have attracted attention as a countermeasure. Machine learning-based IDS can detect various types of attacks; however, the accuracy of trained models deteriorates due to concept drift, where the input data distribution changes over time. To address this issue, IDSs that undergo periodic retraining have been proposed, but challenges such as overfitting and adaptation delays remain. This paper proposes a continual learning method based on concept drift detection in IoT traffic for intrusion detection systems. Evaluation experiments in a concept drift environment demonstrate that the proposed method suppresses model accuracy degradation more effectively than conventional methods. |
| キーワード |
(和) |
IoT / トラヒック分析 / 侵入検知 / 機械学習 / 概念ドリフト / / / |
| (英) |
IoT / traffic analysis / intrusion detection / machine learning / concept drift / / / |
| 文献情報 |
信学技報, vol. 124, no. 419, NS2024-254, pp. 345-350, 2025年3月. |
| 資料番号 |
NS2024-254 |
| 発行日 |
2025-02-27 (NS) |
| ISSN |
Online edition: ISSN 2432-6380 |
著作権に ついて |
技術研究報告に掲載された論文の著作権は電子情報通信学会に帰属します.(許諾番号:10GA0019/12GB0052/13GB0056/17GB0034/18GB0034) |
| PDFダウンロード |
NS2024-254 |