AlignAD-VAE: A Variational Autoencoder with MMD-Based Dataset Alignment for Network Anomaly Detection
24th IEEE International Conference on Trust, Security and Privacy in Computing and Communications, TrustCom 2025, Guiyang, Çin, 14 - 17 Kasım 2025, ss.861-867, (Tam Metin Bildiri)
- Yayın Türü: Bildiri / Tam Metin Bildiri
- Doi Numarası: 10.1109/trustcom66490.2025.00100
- Basıldığı Şehir: Guiyang
- Basıldığı Ülke: Çin
- Sayfa Sayıları: ss.861-867
- Anahtar Kelimeler: Anomaly Detection, Cross-Dataset Generalisability, Domain Adaptation, Network Security
- Erciyes Üniversitesi Adresli: Hayır
Özet
This study addresses the persistent challenge of cross-dataset generalisability in intrusion detection systems by both assessing whether concatenating datasets improves generalisability and proposing AlignAD-VAE, a new unsupervised variational autoencoder model augmented with maximum mean discrepancy (MMD)-based alignment. The model aims to reduce the distribution shift between datasets by aligning their latent representations in a common feature space. We systematically evaluate AlignAD-VAE against modern architectures such as autoencoder and variational autoencoder baselines across multiple cross-dataset configurations using the CIC-IDS2017, CSE-CIC-IDS2018, and CIC-DDoS2019 datasets. Our experiments cover both single-dataset training and concatenated multidataset training, assessing model performance on completely unseen datasets. Concatenating training datasets improves generalisability by up to 10%, as it exposes models to a broader range of normal patterns and traffic variations, thereby reducing overfitting to dataset-specific artefacts. While all models benefit from the richer training data, AlignAD-VAE outperforms the VAE baseline by up to 2%, indicating that the integration of MMD-based domain alignment provides additional, although modest, improvements in cross-domain adaptation, as reflected in AUC-ROC, F1-score, and accuracy metrics. These findings highlight that combining diverse datasets with domain alignment can make IDS more robust to unseen network environments, a critical requirement for real-world deployment.