Scholay

学术搜索 · AI 审稿 · LaTeX 协作

Contextual Masking Distillation for Network Traffic Anomaly Detection

作者:Xinglin Lian, Yu Zheng, Yan Liu, Fan Zhou, Chunlei Peng, Xinbo Gao · 发表于:IEEE Transactions on Information Forensics and Security · 年份:2026 · DOI:10.1109/tifs.2026.3655514 · 被引用次数:14 · 研究领域:Network Security and Intrusion Detection、Internet Traffic Analysis and Secure E-voting、Anomaly Detection Techniques and Applications

Network traffic anomaly detection is critical for cybersecurity but faces challenges in accurately identifying malicious activities. Recent zero-positive approaches, which use only normal training data under the reconstruction paradigm, have shown progress. However, encrypted network traffic obscures normal–anomalous distinctions, causing confused modeling. In addition, the “identical shortcut” problem, where models reconstruct any input with similar fidelity, produces suboptimal representations and indistinguishable detection. To address these limitations, this paper introduces ConMD, a novel Contextual Masking Knowledge Distillation framework. ConMD features distillation paradigm for discriminative representations and then pursues two objectives: effective contextual information modeling and a comprehensive anomaly metric. Specifically, we introduce context-aware local-global attention mechanisms for the student network's backbone, which capture both intra-packet and inter-packet dependencies. Additionally, a context-enhanced masking training strategy is designed to facilitate contextual interactions in normal flows. Given the structural characteristics of network traffic, we also present a new anomaly scoring with multi-view awareness, which perceive comprehensive traffic patterns. ConMD combines insights from both packet- and flow-level views to highlight deviations in anomalous network flows, thereby improving detection accuracy. Extensive experiments on three real-world...