Journal of Information Security Reserach ›› 2026, Vol. 12 ›› Issue (6): 566-.

Previous Articles     Next Articles

A Network Traffic Anomaly Detection Model Based on Semisupervised  Twochannel Multiscale Gating Fusion

Chen Ying1, Fan Runchun1, and Wen Feng2   

  1. 1(Department of Cryptography and Science Technology, Beijing Electronic Science & Technology Institute, Beijing 100070)
    2(Beijing Trust & Far Technology Co., Ltd., Beijing 100080)
  • Online:2026-06-07 Published:2026-06-07

一种基于半监督的双通道多尺度门控融合的 网络流量异常检测模型

陈颖1范润椿1文锋2   

  1. 1(北京电子科技学院密码科学与技术系北京100070)
    2(北京银信长远科技股份有限公司北京100080)
  • 通讯作者: 文锋 工程师.主要研究方向为通信网络、平台运营、ICT系统集成. 3256161900@qq.com
  • 作者简介:陈颖 博士,教授.主要研究方向为数据挖掘、密码算法和信息安全. ychen@besti.edu.cn 范润椿 硕士.主要研究方向为网络安全. 1003211455@qq.com 文锋 工程师.主要研究方向为通信网络、平台运营、ICT系统集成. 3256161900@qq.com

Abstract: With the increasing number of network attacks, network traffic anomaly detection is becoming more and more important for maintaining network security and stability. However, existing methods are often difficult to effectively capture both static statistical features and dynamic temporal features of network traffic during feature extraction, resulting in limited detection performance in complex and evolving network environments. To address these issues, this paper proposes a twochannel multiscale gated fusion anomaly detection model (MSAD) based on semisupervised learning. The model first extracts  static statistical features of the traffic, including the number of packets, total bytes, etc., through a multiscale convolutional neural network. Secondly, the temporal features of network traffic data are captured through a bidirectional GRU network and combined with a multihead attention mechanism. Finally, adaptive fusion of different modal features is performed through gated fusion mechanism. Meanwhile, for the problem of insufficient credibility of pseudolabel generation in semisupervised learning, a twostage adversarial pseudolabel generation strategy is proposed, which effectively improves the robustness of pseudolabels. The experimental results show that under the condition of limited labeled data, the model proposed in this paper achieves 99.63%, 99.54%, 99.9% and 99.72% of accuracy, precision, recall and F1 value on the CICIDS 2017 dataset, which is significantly better than traditional machine learning and deep learning methods.

Key words: anomaly detection, semisupervised learning, multiscale convolutional neural networks, bidirectional GRU networks, gated fusion mechanisms

摘要: 随着网络攻击的日益增多,网络流量异常检测对于维护网络安全稳定也越来越重要.然而,现有方法在特征提取方面往往难以同时有效捕捉网络流量的静态统计特征和动态时序特征,导致在复杂多变的网络环境下检测性能受限.为解决这些问题,提出了一种基于半监督学习的双通道多尺度门控融合异常检测模型(MSAD).该模型首先通过多尺度卷积神经网络提取流量的静态统计特征,包括包数量、总字节数等.其次,通过双向GRU网络并结合多头注意力机制对网络流量数据的时序特征进行捕捉.最后通过门控融合机制对不同模态特征进行自适应融合.同时,针对半监督学习中伪标签生成可信度不足的问题,提出了一种双阶段对抗性伪标签生成策略,有效提升了伪标签的鲁棒性.实验结果表明,在标注数据有限的条件下,该模型在CICIDS2017数据集上准确率、精确率、召回率和F1分数分别达到99.63%,99.54%,99.9%和99.72%,显著优于传统机器学习和深度学习方法.

关键词: 异常检测, 半监督学习, 多尺度卷积神经网络, 双向GRU网络, 门控融合机制

CLC Number: