Unsupervised Real-Time In-Kernel Intrusion Detection System Using Autoencoders and eBPF

Hotaka Taguchi, Takanori Hara, Shoji Kasahara · IEICE Transactions on Communications · 2025

Traditional intrusion detection systems (IDSs), leveraging machine learning (ML) algorithms, have improved the detection accuracy of unknown attacks by continuously updating ML models but have underestimated the context switching overhead between kernel and user spaces. To address this issue, existing studies have implemented real-time IDSs using neural networks (NNs) in the kernel space by offloading the quantized models trained with post-training quantization (PTQ) to extended Berkeley Packet Filter (eBPF). However, they cannot fine-tune the model parameters through the additional training because the PTQ applies the quantization to the trained model. In addition, their IDSs are based on supervised learning, which requires a large amount of labeled data. In this paper, we propose a real-time in-kernel IDS leveraging eBPF, unsupervised learning, and quantization-aware training (QAT) to enhance continuous learning. Evaluation results demonstrate that the proposed in-kernel IDS exhibits almost the same detection accuracy as the traditional user-space IDS. From the viewpoint of the packet processing speed, the proposed in-kernel IDS can serve 224 K packets per second while the user-space IDS can only serve 3.2K packets per second.

Read the paper · More papers on PaperTik