{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/sscl-ids-enhancing-generalization-of","title":"SSCL-IDS: Enhancing Generalization of Intrusion Detection with Self-Supervised Contrastive Learning","arxiv_id":null,"date":"2024-06-10","proceeding":"IFIP Networking Conference (IFIP Networking) 2024 6","authors":["Pegah Golchin","Nima Rafiee","Mehrdad Hajizadeh","Ahmad Khalil","Ralf Kundel","Ralf Steinmetz"],"abstract":"With the increasing diversity and complexity of cyber attacks on computer networks, there is a growing demand for Intrusion Detection Systems (IDS) that can accurately categorize new unknown network flows. Machine learning- based IDS (ML-IDS) offers a potential solution by learning underlying network traffic characteristics. However, ML-IDS encounters performance degradation in predicting the traffic with a different distribution from its training dataset (i.e., new unseen data), especially for attacks that mimic benign (non- attack) traffic (e.g., multi-stage attacks). Diversity in attack types intensifies the lack of labeled attack traffic, which leads to reduced detection performance and generalization capabilities of ML-IDS. The generalization refers to the model’s capacity to identify new and unseen samples, even in cases where their distribution deviates from the training data used for the ML- IDS. To address these issues, this paper introduces SSCL- IDS, a Self-Supervised Contrastive Learning IDS designed to increase the generalization of ML-IDS. The proposed SSCL- IDS is exclusively trained on benign flows, enabling it to acquire a generic representation of benign traffic patterns and reduce the reliance on annotated network traffic datasets. The proposed SSCL-IDS demonstrates a substantial improvement in detection and generalization across diverse datasets compared to supervised (over 27%) and unsupervised (over 15%) baselines due to its ability to learn a more effective representation of benign flow attributes. Additionally, by leveraging transfer learning with SSCL-IDS as a pretrained model, we achieve AUROC scores surpassing 80% when fine-tuning with less than 20 training samples. Without fine-tuning, the average AUROC score across different datasets resembles random guessing.","url_abs":"https://ieeexplore.ieee.org/abstract/document/10619725","url_pdf":"https://www.kom.tu-darmstadt.de/en/publications/GRH24","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"sscl-ids-enhancing-generalization-of","repo_url":"https://github.com/golchinpg/ssl-ids","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":0,"framework":"pytorch","reach":null}],"tasks":[{"task_slug":"contrastive-learning","task_name":"Contrastive Learning"},{"task_slug":"diversity","task_name":"Diversity"},{"task_slug":"intrusion-detection","task_name":"Intrusion Detection"},{"task_slug":"transfer-learning","task_name":"Transfer Learning"}],"methods":[{"method_slug":"contrastive-learning","method_name":"Contrastive Learning"}],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":null,"mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}