面向物联网受限终端的机器学习入侵检测方法综述

A survey of machine learning intrusion detection methods for internet of things restricted terminals

  • 摘要: 针对物联网(internet of things, IoT)分布式架构与终端资源受限特性导致的脆弱性问题,以及现有综述未系统剖析资源受限场景下物联网终端入侵检测核心瓶颈的缺陷,对终端资源受限IoT环境中基于机器学习的入侵检测方法开展研究。首先,解析IoT 3层架构,分析IoT终端资源受限原因并明确标注数据稀缺与类不平衡、终端计算能力不足、存储资源匮乏等核心挑战;其次,系统梳理近5年技术进展,综述了类别均衡与半监督/无监督学习如何缓解标注样本稀缺问题、模型轻量化设计与训练优化算法在降低算力需求方面的突破、数据降维及冗余特征去除技术在内存优化上的有效性,并对比各类方法的优劣;最后,提出构建真实IoT专用数据集、处理类间重叠问题等未来方向,为该领域技术深化与工程落地提供参考。

     

    Abstract: In response to the vulnerability issue arising from the distributed architecture and resource-constrained nature of internet of things (IoT) terminals, and the defects of the core bottlenecks of intrusion detection of IoT terminals in the resource-constrained scenarios that have not been systematically analyzed in the existing reviews. Firstly, the IoT three-tier architecture is analyzed to elucidate the causes of terminal resource constraints, explicitly identifying core challenges such as the scarcity of labeled data and class imbalance, insufficient terminal computing power, and limited storage resources. Secondly, this paper systematically reviews technical advancements over the past five years. It summarizes how class balancing and semi-supervised/unsupervised learning mitigate the scarcity of labeled samples, the breakthroughs of lightweight model design and training optimization algorithms in reducing computational demands, and the effectiveness of data dimensionality reduction and redundant feature removal technologies in memory optimization, while comparing the advantages and disadvantages of various methods. Future research directions, such as constructing realistic IoT-specific datasets and addressing class overlap issues are proposed, providing a reference for technological deepening and engineering implementation in this field.

     

/

返回文章
返回