{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,30]],"date-time":"2025-12-30T15:36:15Z","timestamp":1767108975008,"version":"build-2065373602"},"reference-count":52,"publisher":"MDPI AG","issue":"8","license":[{"start":{"date-parts":[[2021,8,9]],"date-time":"2021-08-09T00:00:00Z","timestamp":1628467200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62071056"],"award-info":[{"award-number":["62071056"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"the action plan project of Beijing University of Posts and Telecommunications","award":["No.2020XD-A03-1"],"award-info":[{"award-number":["No.2020XD-A03-1"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Symmetry"],"abstract":"<jats:p>Deep learning has been applied in the field of network intrusion detection and has yielded good results. In malicious network traffic classification tasks, many studies have achieved good performance with respect to the accuracy and recall rate of classification through self-designed models. In deep learning, the design of the model architecture greatly influences the results. However, the design of the network model architecture usually requires substantial professional knowledge. At present, the focus of research in the field of traffic monitoring is often directed elsewhere. Therefore, in the classification task of the network intrusion detection field, there is much room for improvement in the design and optimization of the model architecture. A neural architecture search (NAS) can automatically search the architecture of the model under the premise of a given optimization goal. For this reason, we propose a model that can perform NAS in the field of network traffic classification and search for the optimal architecture suitable for traffic detection based on the network traffic dataset. Each layer of our depth model is constructed according to the principle of maximum coding rate attenuation, which has strong consistency and symmetry in structure. Compared with some manually designed network architectures, classification indicators, such as Top-1 accuracy and F1 score, are also greatly improved while ensuring the lightweight nature of the model. In addition, we introduce a surrogate model in the search task. Compared to using the traditional NAS model to search the network traffic classification model, our NAS model greatly improves the search efficiency under the premise of ensuring that the results are not substantially different. We also manually adjust some operations in the search space of the architecture search to find a set of model operations that are more suitable for traffic classification. Finally, we apply the searched model to other traffic datasets to verify the universality of the model. Compared with several common network models in the traffic field, the searched model (NAS-Net) performs better, and the classification effect is more accurate.<\/jats:p>","DOI":"10.3390\/sym13081453","type":"journal-article","created":{"date-parts":[[2021,8,9]],"date-time":"2021-08-09T09:03:53Z","timestamp":1628499833000},"page":"1453","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":21,"title":["Network Intrusion Detection Based on an Efficient Neural Architecture Search"],"prefix":"10.3390","volume":"13","author":[{"given":"Renjian","family":"Lyu","sequence":"first","affiliation":[{"name":"School of Computer Science, Beijing University of Posts and Telecommunications, Beijing 100876, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2896-4595","authenticated-orcid":false,"given":"Mingshu","family":"He","sequence":"additional","affiliation":[{"name":"School of Electronic Engineering, Beijing University of Posts and Telecommunications, Beijing 100876, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yu","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Electronic Engineering, Beijing University of Posts and Telecommunications, Beijing 100876, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4855-2464","authenticated-orcid":false,"given":"Lei","family":"Jin","sequence":"additional","affiliation":[{"name":"School of Computer Science, Beijing University of Posts and Telecommunications, Beijing 100876, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xinlei","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Electronic Engineering, Beijing University of Posts and Telecommunications, Beijing 100876, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2021,8,9]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Dong, Y.-N., and Liang, G.-S. (2019, January 8\u201310). Research and Discussion on Image Recognition and Classification Algorithm Based on Deep Learning. Proceedings of the 2019 International Conference on Machine Learning, Big Data and Business Intelligence (MLBDBI), Taiyuan, China.","DOI":"10.1109\/MLBDBI48998.2019.00061"},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Wang, P. (2020, January 10\u201312). Research and Design of Smart Home Speech Recognition System Based on Deep Learning. Proceedings of the 2020 International Conference on Computer Vision, Image and Deep Learning (CVIDL), Chongqing, China.","DOI":"10.1109\/CVIDL51233.2020.00-98"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Goularas, D., and Kamis, S. (2019, January 26\u201328). Evaluation of Deep Learning Techniques in Sentiment Analysis from Twitter Data. Proceedings of the 2019 International Conference on Deep Learning and Machine Learning in Emerging Applications (Deep-ML), Istanbul, Turkey.","DOI":"10.1109\/Deep-ML.2019.00011"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Xin, M., and Wang, Y. (2020, January 15\u201319). Research on Feature Selection of Intrusion Detection Based on Deep Learning. Proceedings of the 2020 International Wireless Communications and Mobile Computing (IWCMC), Limassol, Cyprus.","DOI":"10.1109\/IWCMC48107.2020.9148217"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Wang, X., Chen, S., and Su, J. (2020, January 6\u20139). App-Net: A Hybrid Neural Network for Encrypted Mobile Traffic Classification. Proceedings of the IEEE INFOCOM 2020\u2014IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS), Toronto, ON, Canada.","DOI":"10.1109\/INFOCOMWKSHPS50562.2020.9162891"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"45182","DOI":"10.1109\/ACCESS.2019.2908225","article-title":"Deep-Full-Range: A Deep Learning Based Network Encrypted Traffic Classification and Intrusion Detection Framework","volume":"7","author":"Zeng","year":"2019","journal-title":"IEEE Access"},{"key":"ref_7","unstructured":"Krizhevsky, A., Sutskever, I., and Hinton, G. (2012). ImageNet Classification with Deep Convolutional Neural Networks. Advances in Neural Information Processing Systems, Curran Associates Inc."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Szegedy, C., Liu, W., Jia, Y., Sermanet, P., Reed, S., Anguelov, D., Erhan, D., Vanhoucke, V., and Rabinovich, A. (2015, January 7\u201312). Going Deeper with Convolutions. Proceedings of the 2015 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), Boston, MA, USA.","DOI":"10.1109\/CVPR.2015.7298594"},{"key":"ref_9","unstructured":"Howard, A.G., Zhu, M., Chen, B., Kalenichenko, D., Wang, W., Weyand, T., Andreetto, M., and Adam, H. (2017). MobileNets: Efficient Convolutional Neural Networks for Mobile Vision Applications. arXiv."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"You, J. (2020, January 11\u201313). A Genetic Algorithm-based AutoML Approach for Large-scale Traffic Speed Prediction. Proceedings of the 2020 IEEE 5th International Conference on Intelligent Transportation Engineering (ICITE), Beijing, China.","DOI":"10.1109\/ICITE50838.2020.9231486"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Dyrmishi, S., Elshawi, R., and Sakr, S. (2019, January 8\u201311). A Decision Support Framework for AutoML Systems: A Meta-Learning Approach. Proceedings of the 2019 International Conference on Data Mining Workshops (ICDMW), Beijing, China.","DOI":"10.1109\/ICDMW.2019.00025"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Nagarajah, T., and Poravi, G. (2019, January 29\u201331). A Review on Automated Machine Learning (AutoML) Systems. Proceedings of the 2019 IEEE 5th International Conference for Convergence in Technology (I2CT), Bombay, India.","DOI":"10.1109\/I2CT45611.2019.9033810"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"182","DOI":"10.1109\/4235.996017","article-title":"A fast and elitist multiobjective genetic algorithm: NSGA-II","volume":"6","author":"Deb","year":"2002","journal-title":"IEEE Trans. Evol. Comput."},{"key":"ref_14","unstructured":"Pham, H., Guan, M., Zoph, B., Le, Q., and Dean, J. (2018, January 10\u201315). Efficient Neural Architecture Search via Parameter Sharing. Proceedings of the International Conference on Machine Learning, Stockholm, Sweden."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Chen, Z., and Li, B. (2020, January 19\u201324). Efficient Evolution for Neural Architecture Search. Proceedings of the 2020 International Joint Conference on Neural Networks (IJCNN), Glasgow, UK.","DOI":"10.1109\/IJCNN48605.2020.9207545"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Liu, C., Zoph, B., Neumann, M., Shlens, J., Hua, W., Li, L., Li, F., Yuille, A., Huang, J., and Murphy, K. (2018, January 8\u201314). Progressive Neural Architecture Search. Proceedings of the European Conference on Computer Vision, Munich, Germany.","DOI":"10.1007\/978-3-030-01246-5_2"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Lu, Z., Deb, K., Goodman, E., Banzhaf, W., and Boddeti, V.N. (2020, January 23\u201328). NSGANetV2: Evolutionary Multi-Objective Surrogate-Assisted Neural Architecture Search. Proceedings of the European Conference on Computer Vision, Glasgow, UK.","DOI":"10.1007\/978-3-030-58452-8_3"},{"key":"ref_18","unstructured":"Anish, H.A., and Sundarakantham, K. (2019, January 23\u201325). Machine Learning Based Intrusion Detection System. Proceedings of the 2019 3rd International Conference on Trends in Electronics and Informatics (ICOEI), Tirunelveli, India."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"151","DOI":"10.23919\/JCC.2020.05.013","article-title":"FEW-NNN: A fuzzy entropy weighted natural nearest neighbor method for flow-based network traffic attack detection","volume":"17","author":"Chen","year":"2020","journal-title":"China Commun."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Waskle, S., Parashar, L., and Singh, U. (2020, January 2\u20134). Intrusion Detection System Using PCA with Random Forest Approach. Proceedings of the 2020 International Conference on Electronics and Sustainable Communication Systems (ICESC), Coimbatore, India.","DOI":"10.1109\/ICESC48915.2020.9155656"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Liu, J., and Chung, S.S. (2019, January 19\u201323). Automatic Feature Extraction and Selection For Machine Learning Based Intrusion Detection. Proceedings of the 2019 IEEE SmartWorld, Ubiquitous Intelligence & Computing, Advanced & Trusted Computing, Scalable Computing & Communications, Cloud & Big Data Computing, Internet of People and Smart City Innovation (SmartWorld\/SCALCOM\/UIC\/ATC\/CBDCom\/IOP\/SCI), Leicester, UK.","DOI":"10.1109\/SmartWorld-UIC-ATC-SCALCOM-IOP-SCI.2019.00254"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"He, M., Wang, X., Zhou, J., Xi, Y., Jin, L., and Wang, X. (2021). Deep-Feature-Based Autoencoder Network for Few-Shot Malicious Traffic Detection. Secur. Commun. Netw., 2021.","DOI":"10.1155\/2021\/6659022"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Zhang, F., Shang, T., and Liu, J. (2020, January 2\u20136). Imbalanced Encrypted Traffic Classification Scheme Using Random Forest. Proceedings of the 2020 International Conferences on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData) and IEEE Congress on Cybermatics (Cybermatics), Rhodes, Greece.","DOI":"10.1109\/iThings-GreenCom-CPSCom-SmartData-Cybermatics50389.2020.00142"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"605","DOI":"10.1109\/TDSC.2019.2907946","article-title":"Resource-Aware Detection and Defense System against Multi-Type Attacks in the Cloud: Repeated Bayesian Stackelberg Game","volume":"18","author":"Wahab","year":"2021","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Wahab, O.A., Bentahar, J., Otrok, H., and Mourad, A. (July, January 27). How to Distribute the Detection Load among Virtual Machines to Maximize the Detection of Distributed Attacks in the Cloud. Proceedings of the 2016 IEEE International Conference on Services Computing (SCC), San Francisco, CA, USA.","DOI":"10.1109\/SCC.2016.48"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Mehmood, T., and Rais, H.B.M. (2016, January 15\u201317). Machine learning algorithms in context of intrusion detection. Proceedings of the 2016 3rd International Conference on Computer and Information Sciences (ICCOINS), Kuala Lumpur, Malaysia.","DOI":"10.1109\/ICCOINS.2016.7783243"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"82512","DOI":"10.1109\/ACCESS.2019.2923640","article-title":"An Adaptive Ensemble Machine Learning Model for Intrusion Detection","volume":"7","author":"Gao","year":"2019","journal-title":"IEEE Access"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"2735","DOI":"10.1007\/s10489-018-01408-x","article-title":"A new hybrid approach for intrusion detection using machine learning methods","volume":"49","author":"Cavusoglu","year":"2019","journal-title":"Appl. Intell."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Shaaban, A.R., Abd-Elwanis, E., and Hussein, M. (2019, January 8\u201310). DDoS attack detection and classification via Convolutional Neural Network (CNN). Proceedings of the 2019 Ninth International Conference on Intelligent Computing and Information Systems (ICICIS), Cairo, Egypt.","DOI":"10.1109\/ICICIS46948.2019.9014826"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Park, S.H., Park, H.J., and Choi, Y. (2020, January 19\u201321). RNN-based Prediction for Network Intrusion Detection. Proceedings of the 2020 International Conference on Artificial Intelligence in Information and Communication (ICAIIC), Fukuoka, Japan.","DOI":"10.1109\/ICAIIC48513.2020.9065249"},{"key":"ref_31","first-page":"34","article-title":"Web log classification framework with data augmentation based on GANs","volume":"27","author":"He","year":"2020","journal-title":"J. China Univ. Posts Telecommun."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"181","DOI":"10.26599\/BDMA.2020.9020003","article-title":"Applying big data based deep learning system to intrusion detection","volume":"3","author":"Zhong","year":"2020","journal-title":"Big Data Min. Anal."},{"key":"ref_33","first-page":"941","article-title":"A Network Traffic Classification Model Based on Metric Learning","volume":"64","author":"Chen","year":"2020","journal-title":"Comput. Mater. Contin."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Lim, H., Kim, J., Heo, J., Kim, K., Hong, Y., and Han, Y. (2019, January 11\u201313). Packet-based Network Traffic Classification Using Deep Learning. Proceedings of the 2019 International Conference on Artificial Intelligence in Information and Communication (ICAIIC), Okinawa, Japan.","DOI":"10.1109\/ICAIIC.2019.8669045"},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Saleh, I., and Hao, J. (2020, January 6\u20138). Network Traffic Images: A Deep Learning Approach to the Challenge of Internet Traffic Classification. Proceedings of the 2020 10th Annual Computing and Communication Workshop and Conference (CCWC), Las Vegas, NV, USA.","DOI":"10.1109\/CCWC47524.2020.9031260"},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Zhong, Z., Yan, J., Wu, W., Shao, J., and Liu, C. (2018, January 18\u201323). Practical Block-Wise Neural Network Architecture Generation. Proceedings of the 2018 IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Salt Lake City, UT, USA.","DOI":"10.1109\/CVPR.2018.00257"},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., and Sun, J. (2016, January 27\u201330). Deep Residual Learning for Image Recognition. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Las Vegas, NV, USA.","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Szegedy, C., Ioffe, S., Vanhoucke, V., and Alemi, A.A. (2017, January 4\u20139). Inception-v4, Inception-ResNet and the Impact of Residual Connections on Learning. Proceedings of the Thirty-First AAAI Conference on Artificial Intelligence, San Francisco, CA, USA.","DOI":"10.1609\/aaai.v31i1.11231"},{"key":"ref_39","unstructured":"Zoph, B., and Le, Q.V. (2016). Neural Architecture Search with Reinforcement Learning. Science of the Total Environment. arXiv."},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"277","DOI":"10.1109\/TEVC.2020.3024708","article-title":"Multi-Objective Evolutionary Design of Deep Convolutional Neural Networks for Image Classification","volume":"25","author":"Lu","year":"2020","journal-title":"IEEE Trans. Evol. Comput."},{"key":"ref_41","unstructured":"Liu, H., Simonyan, K., and Yang, Y. (2018). Darts: Differentiable architecture search. arXiv."},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Zhang, C., Liu, X., Wang, G., and Cai, Z. (October, January 26). Particle Swarm Optimization Based Deep Learning Architecture Search for Hyperspectral Image Classification. Proceedings of the IGARSS 2020\u20142020 IEEE International Geoscience and Remote Sensing Symposium, Waikoloa, HI, USA.","DOI":"10.1109\/IGARSS39084.2020.9324463"},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Hu, K., Tian, S., Guo, S., Li, N., Luo, L., and Wang, L. (2020, January 19\u201324). Recurrent Neural Architecture Search based on Randomness-Enhanced Tabu Algorithm. Proceedings of the 2020 International Joint Conference on Neural Networks (IJCNN), Glasgow, UK.","DOI":"10.1109\/IJCNN48605.2020.9207393"},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"350","DOI":"10.1109\/TEVC.2019.2924461","article-title":"Surrogate-Assisted Evolutionary Deep Learning Using an End-to-End Random Forest-Based Performance Predictor","volume":"24","author":"Sun","year":"2019","journal-title":"IEEE Trans. Evol. Comput."},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Dai, X., Zhang, P., Wu, B., Yin, H., Sun, F., Wang, Y., Dukhan, M., Hu, Y., Wu, Y., and Jia, Y. (2019, January 15\u201320). ChamNet: Towards Efficient Network Design Through Platform-Aware Model Adaptation. Proceedings of the 2019 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), Long Beach, CA, USA.","DOI":"10.1109\/CVPR.2019.01166"},{"key":"ref_46","unstructured":"(2021, August 08). USTC-TK2016. Available online: https:\/\/github.com\/yungshenglu\/USTC-TK2016\/."},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"69680","DOI":"10.1109\/ACCESS.2021.3078065","article-title":"An Efficient IDS Framework for DDoS Attacks in SDN Environment","volume":"9","author":"Varghese","year":"2021","journal-title":"IEEE Access"},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Le, T.T.H., Kim, Y., and Kim, H. (2019). Network intrusion detection based on novel feature selection model and various recurrent neural networks. Appl. Sci., 9.","DOI":"10.3390\/app9071392"},{"key":"ref_49","doi-asserted-by":"crossref","unstructured":"Siddiqi, M.A., and Pak, W. (2020). Optimizing Filter-Based Feature Selection Method Flow for Intrusion Detection System. Electronics, 9.","DOI":"10.3390\/electronics9122114"},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"100172","DOI":"10.1109\/ACCESS.2020.2997939","article-title":"Artificial immune systems and fuzzy logic to detect flooding attacks in software-defined networks","volume":"8","author":"Scaranti","year":"2020","journal-title":"IEEE Access"},{"key":"ref_51","first-page":"655","article-title":"DoS and DDoS attack detection using deep learning and IDS","volume":"17","author":"Shurman","year":"2020","journal-title":"Int. Arab J. Inf. Technol."},{"key":"ref_52","doi-asserted-by":"crossref","unstructured":"Babi\u0107, I., Miljkovi\u0107, A., \u010cabarkapa, M., Nikoli\u0107, V., \u0110or\u0111evi\u0107, A., Ran\u0111elovi\u0107, M., and Ran\u0111elovi\u0107, D. (2021). Triple Modular Redundancy Optimization for Threshold Determination in Intrusion Detection Systems. Symmetry, 13.","DOI":"10.3390\/sym13040557"}],"container-title":["Symmetry"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2073-8994\/13\/8\/1453\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T06:42:52Z","timestamp":1760164972000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2073-8994\/13\/8\/1453"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,8,9]]},"references-count":52,"journal-issue":{"issue":"8","published-online":{"date-parts":[[2021,8]]}},"alternative-id":["sym13081453"],"URL":"https:\/\/doi.org\/10.3390\/sym13081453","relation":{},"ISSN":["2073-8994"],"issn-type":[{"type":"electronic","value":"2073-8994"}],"subject":[],"published":{"date-parts":[[2021,8,9]]}}}