Modern computer networks are increasingly complex, heterogeneous, and exposed to a growing spectrum of cyber threats, making robust network anomaly detection (NAD) a critical challenge. While machine learning (ML) has significantly improved detection accuracy, most existing NAD systems remain tightly coupled to the datasets on which they are trained, leading to poor generalization across diverse infrastructures and evolving traffic patterns. To fill this gap, we present MERGE, a NAD solution that shifts from dataset-specific optimization toward architectural unification. We address dataset heterogeneity by training a single unified autoencoder and a shared classifier that operate across multiple data sources, establishing a universal latent space and decision boundary for anomaly detection. Unlike standard approaches that rely on environment-specific calibration, MERGE leverages eXplainable AI (XAI) as an architectural optimization tool to identify a universal feature set. This enables distilling multiple specialized pipelines into a single, compact model instance. Experimental results over three benchmarks (enterprise, IoT, and hybrid traffic) demonstrate that MERGE achieves near-parity with dataset-specific baselines, exhibiting only a 1-2% difference in F1-Score. Crucially, this unification reduces model management overhead and parameter footprint by a factor of M (where M is the number of datasets), providing a scalable and interpretable solution for large-scale network environments.

MERGE: Multi-Scenario Embedding for Robust Generalization in Network Anomaly Detection / Colella, C., Serra, C., Sacco, A., Marchetto, G.. - ELETTRONICO. - (2026), pp. 463-468. (IEEE NetSoft 2026 - 5th International Workshop on Edge Network Softwarization Berlin (DEU) 29 June - 03 July 2026) [10.1109/netsoft70012.2026.11603479].

MERGE: Multi-Scenario Embedding for Robust Generalization in Network Anomaly Detection

Colella, Christian;Serra, Cristiano;Sacco, Alessio;Marchetto, Guido
2026

Abstract

Modern computer networks are increasingly complex, heterogeneous, and exposed to a growing spectrum of cyber threats, making robust network anomaly detection (NAD) a critical challenge. While machine learning (ML) has significantly improved detection accuracy, most existing NAD systems remain tightly coupled to the datasets on which they are trained, leading to poor generalization across diverse infrastructures and evolving traffic patterns. To fill this gap, we present MERGE, a NAD solution that shifts from dataset-specific optimization toward architectural unification. We address dataset heterogeneity by training a single unified autoencoder and a shared classifier that operate across multiple data sources, establishing a universal latent space and decision boundary for anomaly detection. Unlike standard approaches that rely on environment-specific calibration, MERGE leverages eXplainable AI (XAI) as an architectural optimization tool to identify a universal feature set. This enables distilling multiple specialized pipelines into a single, compact model instance. Experimental results over three benchmarks (enterprise, IoT, and hybrid traffic) demonstrate that MERGE achieves near-parity with dataset-specific baselines, exhibiting only a 1-2% difference in F1-Score. Crucially, this unification reduces model management overhead and parameter footprint by a factor of M (where M is the number of datasets), providing a scalable and interpretable solution for large-scale network environments.
2026
979-8-3315-6382-0
File in questo prodotto:
File Dimensione Formato  
MERGE_Multi-Scenario_Embedding_for_Robust_Generalization_in_Network_Anomaly_Detection.pdf

accesso riservato

Tipologia: 2a Post-print versione editoriale / Version of Record
Licenza: Non Pubblico - Accesso privato/ristretto
Dimensione 432.02 kB
Formato Adobe PDF
432.02 kB Adobe PDF   Visualizza/Apri   Richiedi una copia
MERGE_2026.pdf

accesso aperto

Tipologia: 2. Post-print / Author's Accepted Manuscript
Licenza: Pubblico - Tutti i diritti riservati
Dimensione 377.06 kB
Formato Adobe PDF
377.06 kB Adobe PDF Visualizza/Apri
Pubblicazioni consigliate

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11583/3013596