{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,14]],"date-time":"2026-07-14T07:11:15Z","timestamp":1784013075224,"version":"3.55.0"},"reference-count":42,"publisher":"MDPI AG","issue":"7","license":[{"start":{"date-parts":[[2024,3,26]],"date-time":"2024-03-26T00:00:00Z","timestamp":1711411200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>The network intrusion detection system (NIDS) plays a crucial role as a security measure in addressing the increasing number of network threats. The majority of current research relies on feature-ready datasets that heavily depend on feature engineering. Conversely, the increasing complexity of network traffic and the ongoing evolution of attack techniques lead to a diminishing distinction between benign and malicious network behaviors. In this paper, we propose a novel end-to-end intrusion detection framework based on a contrastive learning approach. We design a hierarchical Convolutional Neural Network (CNN) and Gated Recurrent Unit (GRU) model to facilitate the automated extraction of spatiotemporal features from raw traffic data. The integration of contrastive learning amplifies the distinction between benign and malicious network traffic in the representation space. The proposed method exhibits enhanced detection capabilities for unknown attacks in comparison to the approaches trained using the cross-entropy loss function. Experiments are carried out on the public datasets CIC-IDS2017 and CSE-CIC-IDS2018, demonstrating that our method can attain a detection accuracy of 99.9% for known attacks, thus achieving state-of-the-art performance. For unknown attacks, a weighted recall rate of 95% can be achieved.<\/jats:p>","DOI":"10.3390\/s24072122","type":"journal-article","created":{"date-parts":[[2024,3,26]],"date-time":"2024-03-26T11:05:33Z","timestamp":1711451133000},"page":"2122","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":16,"title":["End-to-End Network Intrusion Detection Based on Contrastive Learning"],"prefix":"10.3390","volume":"24","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7390-3647","authenticated-orcid":false,"given":"Longlong","family":"Li","sequence":"first","affiliation":[{"name":"College of Electronic Engineering, National University of Defense Technology, Hefei 230037, China"},{"name":"Anhui Province Key Laboratory of Cyberspace Security Situation Awareness and Evaluation, Hefei 230037, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuliang","family":"Lu","sequence":"additional","affiliation":[{"name":"College of Electronic Engineering, National University of Defense Technology, Hefei 230037, China"},{"name":"Anhui Province Key Laboratory of Cyberspace Security Situation Awareness and Evaluation, Hefei 230037, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Guozheng","family":"Yang","sequence":"additional","affiliation":[{"name":"College of Electronic Engineering, National University of Defense Technology, Hefei 230037, China"},{"name":"Anhui Province Key Laboratory of Cyberspace Security Situation Awareness and Evaluation, Hefei 230037, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xuehu","family":"Yan","sequence":"additional","affiliation":[{"name":"College of Electronic Engineering, National University of Defense Technology, Hefei 230037, China"},{"name":"Anhui Province Key Laboratory of Cyberspace Security Situation Awareness and Evaluation, Hefei 230037, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2024,3,26]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"353","DOI":"10.1016\/j.cose.2011.05.008","article-title":"Data Preprocessing for Anomaly Based Network Intrusion Detection: A Review","volume":"30","author":"Davis","year":"2011","journal-title":"Comput. Secur."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Sommer, R., and Paxson, V. (2010, January 16\u201319). Outside the Closed World: On Using Machine Learning for Network Intrusion Detection. Proceedings of the 2010 IEEE Symposium on Security and Privacy, Oakland, CA, USA.","DOI":"10.1109\/SP.2010.25"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1016\/j.cose.2008.08.003","article-title":"Anomaly-Based Network Intrusion Detection: Techniques, Systems and Challenges","volume":"28","year":"2009","journal-title":"Comput. Secur."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"6882","DOI":"10.1109\/JIOT.2020.2970501","article-title":"Passban IDS: An Intelligent Anomaly-Based Intrusion Detection System for IoT Edge Devices","volume":"7","author":"Eskandari","year":"2020","journal-title":"IEEE Internet Things J."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"102675","DOI":"10.1016\/j.cose.2022.102675","article-title":"A Systematic Literature Review of Methods and Datasets for Anomaly-Based Network Intrusion Detection","volume":"116","author":"Yang","year":"2022","journal-title":"Comput. Secur."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"1781","DOI":"10.1109\/JSAC.2006.877131","article-title":"Fast and Scalable Pattern Matching for Network Intrusion Detection Systems","volume":"24","author":"Dharmapurikar","year":"2006","journal-title":"IEEE J. Sel. Areas Commun."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"14753","DOI":"10.1007\/s00521-020-04830-w","article-title":"DeNNeS: Deep Embedded Neural Network Expert System for Detecting Cyber Attacks","volume":"32","author":"Mahdavifar","year":"2020","journal-title":"Neural Comput. Appl."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Liu, J., Yin, L., Hu, Y., Lv, S., and Sun, L. (2018, January 17\u201319). A Novel Intrusion Detection Algorithm for Industrial Control Systems Based on CNN and Process State Transition. Proceedings of the 2018 IEEE 37th International Performance Computing and Communications Conference (IPCCC), Orlando, FL, USA.","DOI":"10.1109\/PCCC.2018.8710993"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"108","DOI":"10.1109\/JAS.2017.7510730","article-title":"SVM-DT-Based Adaptive and Collaborative Intrusion Detection","volume":"5","author":"Teng","year":"2018","journal-title":"IEEE\/CAA J. Autom. Sin."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"220","DOI":"10.1504\/IJSN.2010.037661","article-title":"Efficient Decision Tree for Protocol Analysis in Intrusion Detection","volume":"5","author":"Abbes","year":"2010","journal-title":"Int. J. Secur. Netw."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"5156","DOI":"10.1007\/s11227-018-2413-7","article-title":"NBC-MAIDS: Na\u00efve Bayesian Classification Technique in Multi-Agent System-Enriched IDS for Securing IoT against DDoS Attacks","volume":"74","author":"Mehmood","year":"2018","journal-title":"J. Supercomput."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"101851","DOI":"10.1016\/j.cose.2020.101851","article-title":"Building Auto-Encoder Intrusion Detection System Based on Random Forest Feature Selection","volume":"95","author":"Li","year":"2020","journal-title":"Comput. Secur."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"107049","DOI":"10.1016\/j.comnet.2019.107049","article-title":"HELAD: A Novel Network Anomaly Detection Model Based on Heterogeneous Ensemble Learning","volume":"169","author":"Zhong","year":"2020","journal-title":"Comput. Netw."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Alzubi, J.A., Alzubi, O.A., Qiqieh, I., and Singh, A. (2024). A Blended Deep Learning Intrusion Detection Framework For Consumable Edge-Centric IoMT Industry. IEEE Trans. Consum. Electron.","DOI":"10.1109\/TCE.2024.3350231"},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"1792","DOI":"10.1109\/ACCESS.2017.2780250","article-title":"HAST-IDS: Learning Hierarchical Spatial-Temporal Features Using Deep Neural Networks to Improve Intrusion Detection","volume":"6","author":"Wang","year":"2018","journal-title":"IEEE Access"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"108117","DOI":"10.1016\/j.comnet.2021.108117","article-title":"PBCNN: Packet Bytes-Based Convolutional Neural Network for Network Intrusion Detection","volume":"194","author":"Yu","year":"2021","journal-title":"Comput. Netw."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"1294","DOI":"10.1109\/TNET.2021.3137084","article-title":"Adversarial Attacks Against Deep Learning-Based Network Intrusion Detection Systems and Defense Mechanisms","volume":"30","author":"Zhang","year":"2022","journal-title":"IEEE\/ACM Trans. Netw."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"538","DOI":"10.1109\/COMST.2022.3233793","article-title":"Adversarial Machine Learning for Network Intrusion Detection Systems: A Comprehensive Survey","volume":"25","author":"He","year":"2023","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Sharafaldin, I., Habibi Lashkari, A., and Ghorbani, A.A. (2018, January 22\u201324). Toward Generating a New Intrusion Detection Dataset and Intrusion Traffic Characterization. Proceedings of the 4th International Conference on Information Systems Security and Privacy, Funchal, Madeira, Portugal.","DOI":"10.5220\/0006639801080116"},{"key":"ref_20","unstructured":"(2024, March 21). A Realistic Cyber Defense Dataset (CSE-CIC-IDS2018)\u2013Registry of Open Data on AWS. Available online: https:\/\/registry.opendata.aws\/cse-cic-ids2018\/."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Mirsky, Y., Doitshman, T., Elovici, Y., and Shabtai, A. (2018, January 18\u201321). Kitsune: An Ensemble of Autoencoders for Online Network Intrusion Detection. Proceedings of the 2018 Network and Distributed System Security Symposium, San Diego, CA, USA.","DOI":"10.14722\/ndss.2018.23204"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"48697","DOI":"10.1109\/ACCESS.2018.2867564","article-title":"An Intrusion Detection System Using a Deep Neural Network With Gated Recurrent Units","volume":"6","author":"Xu","year":"2018","journal-title":"IEEE Access"},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"103143","DOI":"10.1016\/j.cose.2023.103143","article-title":"Feature Mining for Encrypted Malicious Traffic Detection with Deep Learning and Other Machine Learning Algorithms","volume":"128","author":"Wang","year":"2023","journal-title":"Comput. Secur."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Wang, W., Zhu, M., Wang, J., Zeng, X., and Yang, Z. (2017, January 22\u201324). End-to-End Encrypted Traffic Classification with One-Dimensional Convolution Neural Networks. Proceedings of the 2017 IEEE International Conference on Intelligence and Security Informatics (ISI), Beijing, China.","DOI":"10.1109\/ISI.2017.8004872"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"107974","DOI":"10.1016\/j.comnet.2021.107974","article-title":"TSCRNN: A Novel Classification Scheme of Encrypted Traffic Based on Flow Spatiotemporal Features for Efficient Management of IIoT","volume":"190","author":"Lin","year":"2021","journal-title":"Comput. Netw."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Shapira, T., and Shavitt, Y. (May, January 29). FlowPic: Encrypted Internet Traffic Classification Is as Easy as Image Recognition. Proceedings of the IEEE INFOCOM 2019\u2013IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS), Paris, France.","DOI":"10.1109\/INFCOMW.2019.8845315"},{"key":"ref_27","unstructured":"Chen, T., Kornblith, S., Norouzi, M., and Hinton, G. (2020). A Simple Framework for Contrastive Learning of Visual Representations. arXiv."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"He, K., Fan, H., Wu, Y., Xie, S., and Girshick, R. (2020, January 13\u201319). Momentum Contrast for Unsupervised Visual Representation Learning. Proceedings of the 2020 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), Seattle, WA, USA.","DOI":"10.1109\/CVPR42600.2020.00975"},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Gao, T., Yao, X., and Chen, D. (2021, January 7\u201311). SimCSE: Simple Contrastive Learning of Sentence Embeddings. Proceedings of the 2021 Conference on Empirical Methods in Natural Language Processing, Online and Punta Cana, Dominican Republic.","DOI":"10.18653\/v1\/2021.emnlp-main.552"},{"key":"ref_30","unstructured":"Khosla, P., Teterwak, P., Wang, C., Sarna, A., Tian, Y., Isola, P., Maschinot, A., Liu, C., and Krishnan, D. (2021). Supervised Contrastive Learning. arXiv."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Wang, N., Chen, Y., Hu, Y., Lou, W., and Hou, Y.T. (2022, January 2\u20135). FeCo: Boosting Intrusion Detection Capability in IoT Networks via Contrastive Learning. Proceedings of the IEEE INFOCOM 2022\u2013IEEE Conference on Computer Communications, London, UK.","DOI":"10.1109\/INFOCOM48880.2022.9796926"},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"200","DOI":"10.1016\/j.inffus.2021.09.014","article-title":"Supervised Contrastive Learning over Prototype-Label Embeddings for Network Intrusion Detection","volume":"79","author":"Arribas","year":"2022","journal-title":"Inf. Fusion"},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"4232","DOI":"10.1109\/TNSM.2022.3218843","article-title":"Contrastive Learning Enhanced Intrusion Detection","volume":"19","author":"Yue","year":"2022","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"1218","DOI":"10.1109\/TNSM.2021.3071441","article-title":"FlowPic: A Generic Representation for Encrypted Traffic Classification and Applications Identification","volume":"18","author":"Shapira","year":"2021","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"35","DOI":"10.1109\/MNET.2012.6135854","article-title":"Issues and Future Directions in Traffic Classification","volume":"26","author":"Dainotti","year":"2012","journal-title":"IEEE Netw."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"6659022","DOI":"10.1155\/2021\/6659022","article-title":"Deep-Feature-Based Autoencoder Network for Few-Shot Malicious Traffic Detection","volume":"2021","author":"He","year":"2021","journal-title":"Secur. Commun. Netw."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"1735","DOI":"10.1162\/neco.1997.9.8.1735","article-title":"Long Short-Term Memory","volume":"9","author":"Hochreiter","year":"1997","journal-title":"Neural Comput."},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Cho, K., van Merrienboer, B., Gulcehre, C., Bahdanau, D., Bougares, F., Schwenk, H., and Bengio, Y. (2014). Learning Phrase Representations Using RNN Encoder-Decoder for Statistical Machine Translation. arXiv.","DOI":"10.3115\/v1\/D14-1179"},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"901","DOI":"10.1016\/j.ins.2022.06.013","article-title":"Efficient Density and Cluster Based Incremental Outlier Detection in Data Streams","volume":"607","author":"Degirmenci","year":"2022","journal-title":"Inf. Sci."},{"key":"ref_40","unstructured":"Paszke, A., Gross, S., Massa, F., Lerer, A., Bradbury, J., Chanan, G., Killeen, T., Lin, Z., Gimelshein, N., and Antiga, L. (2019, January 8\u201314). PyTorch: An Imperative Style, High-Performance Deep Learning Library. Proceedings of the Advances in Neural Information Processing Systems 32 (NeurIPS 2019), Vancouver, BC, Canada."},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Liu, L., Engelen, G., Lynar, T., Essam, D., and Joosen, W. (2022, January 3\u20135). Error Prevalence in NIDS Datasets: A Case Study on CIC-IDS-2017 and CSE-CIC-IDS-2018. Proceedings of the 2022 IEEE Conference on Communications and Network Security (CNS), Austin, TX, USA.","DOI":"10.1109\/CNS56114.2022.9947235"},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Wang, F., and Liu, H. (2021, January 20\u201325). Understanding the Behaviour of Contrastive Loss. Proceedings of the 2021 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), Nashville, TN, USA.","DOI":"10.1109\/CVPR46437.2021.00252"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/24\/7\/2122\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T14:18:55Z","timestamp":1760105935000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/24\/7\/2122"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,3,26]]},"references-count":42,"journal-issue":{"issue":"7","published-online":{"date-parts":[[2024,4]]}},"alternative-id":["s24072122"],"URL":"https:\/\/doi.org\/10.3390\/s24072122","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,3,26]]}}}