The increasing adoption of the Internet has intensified cybersecurity risks such as data theft and service disruptions. Network intrusion detection is critical for identifying malicious activity, but traditional methods face limitations. Machine Learning (ML) and Deep Learning (DL) techniques often suffer from poor generalization, limiting their ability to transfer models across heterogeneous network datasets and reducing their empirical generalizability. To address this feature fragility, we propose a Multimodal Contrastive Learning approach for network intrusion detection. The key design choice lies in a multi-step training orchestration designed to stabilize latent representations under significant dataset shift.The framework integrates multimodal data for richer traffic modeling and contrastive learning to enhance latent distinction between benign and malicious traffic. To assess cross-dataset generalization, models are pre-trained on Edge-IIoT and adapted on IoT-NID and CIC-IoMT. We investigate two contrastive strategies—self-supervised and supervised—to analyze the impact of label-agnostic and label-aware learning under distribution shift. Experiments show that contrastive multimodal learning matches transfer learning in saturated regimes (F1 Score > 90%) on both IoT-NID and CIC-IoMT. On IoT-NID, specific advantages emerge: improved Recall (up to +4%) on underrepresented classes; better short-flow performance (+3% F1 Score for biflows of three or fewer packets); and a more structured latent space (0.90 vs. 1.12 DB index). On CIC-IoMT, contrastive approaches outrank transfer learning, with supervised contrastive achieving the best discriminative performance and self-supervised yielding the most compact latent space. Within the evaluated source–target setups, our findings suggest that contrastive learning is a viable alternative to transfer learning, and that latent structural quality is a meaningful generalization indicator under domain shifts.

Bovenzi, G., Guarino, I., Pescapè, A. (2026). Multimodal contrastive learning-based network intrusion detection. RESULTS IN ENGINEERING, 31, 1-20 [10.1016/j.rineng.2026.111405].

Multimodal contrastive learning-based network intrusion detection

Guarino, Idio
Secondo
;
2026

Abstract

The increasing adoption of the Internet has intensified cybersecurity risks such as data theft and service disruptions. Network intrusion detection is critical for identifying malicious activity, but traditional methods face limitations. Machine Learning (ML) and Deep Learning (DL) techniques often suffer from poor generalization, limiting their ability to transfer models across heterogeneous network datasets and reducing their empirical generalizability. To address this feature fragility, we propose a Multimodal Contrastive Learning approach for network intrusion detection. The key design choice lies in a multi-step training orchestration designed to stabilize latent representations under significant dataset shift.The framework integrates multimodal data for richer traffic modeling and contrastive learning to enhance latent distinction between benign and malicious traffic. To assess cross-dataset generalization, models are pre-trained on Edge-IIoT and adapted on IoT-NID and CIC-IoMT. We investigate two contrastive strategies—self-supervised and supervised—to analyze the impact of label-agnostic and label-aware learning under distribution shift. Experiments show that contrastive multimodal learning matches transfer learning in saturated regimes (F1 Score > 90%) on both IoT-NID and CIC-IoMT. On IoT-NID, specific advantages emerge: improved Recall (up to +4%) on underrepresented classes; better short-flow performance (+3% F1 Score for biflows of three or fewer packets); and a more structured latent space (0.90 vs. 1.12 DB index). On CIC-IoMT, contrastive approaches outrank transfer learning, with supervised contrastive achieving the best discriminative performance and self-supervised yielding the most compact latent space. Within the evaluated source–target setups, our findings suggest that contrastive learning is a viable alternative to transfer learning, and that latent structural quality is a meaningful generalization indicator under domain shifts.
2026
Bovenzi, G., Guarino, I., Pescapè, A. (2026). Multimodal contrastive learning-based network intrusion detection. RESULTS IN ENGINEERING, 31, 1-20 [10.1016/j.rineng.2026.111405].
Bovenzi, Giampaolo; Guarino, Idio; Pescapè, Antonio
File in questo prodotto:
File Dimensione Formato  
1-s2.0-S2590123026024321-main.pdf

accesso aperto

Tipo: Versione (PDF) editoriale / Version Of Record
Licenza: Licenza per Accesso Aperto. Creative Commons Attribuzione - Non commerciale - Non opere derivate (CCBYNCND)
Dimensione 3.87 MB
Formato Adobe PDF
3.87 MB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11585/1069032
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? 0
  • OpenAlex 0
social impact