Security in cloud computing has become a major concern due to several factors such as layered cloud architectures, dynamic environments, and exposure to unseen or zero-day attacks. Moreover, intrusion detection systems (IDS) typically operate at specific layers and rely heavily on machine learning models, which often perform well in experimental settings but fail to sustain performance in real cloud deployments. In this work, we implement a confidence-aware multilevel intrusion detection system using reinforcement learning tailored for cloud environments. The system secures three distinct layers: network, host, and hypervisor. Machine learning models at each layer detect known attack patterns, while prediction confidence distinguishes reliable decisions from uncertain outcomes. Within the multi-gate flow, low-confidence events pass through a learned-threshold confidence gate (Gate-1), followed by a Chroma memory-matching gate (Gate-2), with unresolved events escalated to a large language model (LLM) for semantic analysis and explanation. Final attack promotion at Gate-3 uses calibrated LLM confidence or weighted-fusion fallback, while uncertain events are retained in a review bucket to avoid forced classification. Generated explanations and confirmed knowledge are stored in ChromaDB to support future analysis and retraining. The approach is first evaluated using static thresholds, establishing a baseline for comparison. Results show that the proposed system learns adaptive thresholds and reduces LLM escalation by 58.78%, lowering cost while maintaining strong performance (88.68% accuracy, 85.29% precision, 84.72% recall, 85.00% F1). The network and hypervisor layers achieve 98.02% and 97.08% accuracy, demonstrating a balanced and efficient detection system.


翻译:云计算安全已成为重大关切,这主要源于分层云架构、动态环境以及未知或零日攻击暴露等多重因素。此外,入侵检测系统通常在特定层级运作,且高度依赖机器学习模型,这些模型在实验场景中表现良好,但在实际云部署中难以维持性能。本文针对云环境实现了一种基于强化学习的置信感知多层次入侵检测系统。该系统对网络层、主机层和虚拟机监控层三个不同层级进行安全防护。每层的机器学习模型用于检测已知攻击模式,而预测置信度则用以区分可靠决策与不确定结果。在多门控流程中,低置信度事件依次通过基于学习阈值的置信门控(门控-1)和Chroma记忆匹配门控(门控-2),未决事件则升级至大语言模型进行语义分析与解释。在门控-3处,最终攻击判定采用经校准的LLM置信度或加权融合回退机制,同时将不确定事件保留于审查存储桶中,以避免强制分类。生成的解释与已确认知识存储至ChromaDB,以支撑后续分析与重训练。该方法首先通过静态阈值进行评估,建立比较基准。结果表明,所提系统能够学习自适应阈值,并将LLM升级量降低58.78%,在降低成本的同时保持强劲性能(准确率88.68%,精确率85.29%,召回率84.72%,F1值85.00%)。网络层与虚拟机监控层分别达到98.02%和97.08%的准确率,展现了均衡高效的检测系统。

0
下载
关闭预览

相关内容

《用于建模系统攻击路径的强化学习环境》
专知会员服务
23+阅读 · 3月5日
基于深度学习的入侵检测系统:综述
专知会员服务
16+阅读 · 2025年4月11日
《用于边缘云异常检测的机器学习》博士论文
专知会员服务
25+阅读 · 2025年1月20日
《边缘云异常检测的机器学习》最新博士论文
专知会员服务
28+阅读 · 2024年8月8日
对抗机器学习在网络入侵检测领域的应用
专知会员服务
35+阅读 · 2022年1月4日
Distributional Soft Actor-Critic (DSAC)强化学习算法的设计与验证
深度强化学习实验室
20+阅读 · 2020年8月11日
支持个性化学习的行为大数据可视化研究
联邦学习或将助力IoT走出“数据孤岛”?
中国计算机学会
20+阅读 · 2019年3月16日
【边缘智能】边缘计算驱动的深度学习加速技术
产业智能官
20+阅读 · 2019年2月8日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
4+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
8+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
2+阅读 · 2014年12月31日
国家自然科学基金
4+阅读 · 2014年12月31日
VIP会员
最新内容
从采集到决策:美军视角下的战术情报范式重构
专知会员服务
0+阅读 · 47分钟前
《履带式无人地面战车技术发展现状》
专知会员服务
2+阅读 · 今天1:46
《无人机脆弱性利用:网络空间力量的新域》
专知会员服务
2+阅读 · 8月1日
美空军如何将人工智能从战场部署至后方机关
专知会员服务
11+阅读 · 7月31日
《史诗怒火行动:多域前瞻评估》49页报告
专知会员服务
7+阅读 · 7月31日
《英国防部:未来空战系统数字化战略》33页
专知会员服务
5+阅读 · 7月31日
《面向自主飞行网络的智能体人工智能架构》
专知会员服务
7+阅读 · 7月31日
相关基金
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
4+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
8+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
2+阅读 · 2014年12月31日
国家自然科学基金
4+阅读 · 2014年12月31日
Top
微信扫码咨询专知VIP会员