A Dual-Head Model for Host based Intrusion Detection on System-Call traces

Authors

  • Matthias Dippold Institute of Computer Technology (ICT), TU Wien
  • Sofia Maragkou Institute of Computer Technology (ICT), TU Wien
  • Matthias Wess Institute of Computer Technology (ICT), TU Wien
  • Thilo Sauter Institute of Computer Technology (ICT), TU Wien
  • Grigorios Chrysos Dept. of Electrical and Computer Engineering (ECE), Technical University of Crete
  • Sotiris Ioannidis Dept. of Electrical and Computer Engineering (ECE), Technical University of Crete

DOI:

https://doi.org/10.64552/wipiec.v12i2.143

Keywords:

host-based intrusion detection, anomaly detection, deep learning, convolutional neural networks, zero-day attacks

Abstract

Host-based intrusion detection systems (HIDS) need to detect both unseen exploits from day one and recurring known attack families. Maintaining separate anomaly-detection and supervised-classification frameworks increases the computational and operational footprint — a cost that only a few embedded or edge devices can carry. To satisfy both requirements without increasing deployment overhead, we propose a single dual-head Convolutional Neural Network (CNN) operating over a sliding window of embedded system-call tokens. Head 1 is an autoregressive next-token prediction module that emits sequence-level anomaly scores derived from token-wise negative log-likelihood (NLL) estimates, while Head 2 is a supervised attack-classification module using a shared latent representation. The two heads jointly support concurrent anomaly detection and supervised attack classification within a single model.
The proposed framework is evaluated using the ADFA-LD Linux system-call benchmark [1]. The proposed framework achieves mean AUROC scores of 0.916 in the unsupervised setting and 0.979 in the supervised setting, outperforming the baselines reported in [2] under the reshuffled evaluation protocol in both settings. These results demonstrate that unified sequential representation learning can simultaneously support both zero-day anomaly detection and supervised attack classification refinement within a single operational HIDS framework, thereby reducing the operational complexity of practical HIDS deployments.

Author Biographies

Matthias Dippold, Institute of Computer Technology (ICT), TU Wien

Institute of Computer Technology (ICT), TU Wien, Vienna, Austria.

Sofia Maragkou, Institute of Computer Technology (ICT), TU Wien

Institute of Computer Technology (ICT), TU Wien, Vienna, Austria.

Matthias Wess, Institute of Computer Technology (ICT), TU Wien

Institute of Computer Technology (ICT), TU Wien, Vienna, Austria.

Thilo Sauter, Institute of Computer Technology (ICT), TU Wien

Institute of Computer Technology (ICT), TU Wien, Vienna, Austria.

Grigorios Chrysos, Dept. of Electrical and Computer Engineering (ECE), Technical University of Crete

Dept. of Electrical and Computer Engineering (ECE), Technical University of Crete, Chania, Greece.

Sotiris Ioannidis, Dept. of Electrical and Computer Engineering (ECE), Technical University of Crete

Dept. of Electrical and Computer Engineering (ECE), Technical University of Crete, Chania, Greece.

References

G. Creech and J. Hu, “Generation of a new IDS test dataset: Time to retire the KDD collection,” in Proc. IEEE Wireless Commun. Netw. Conf. (WCNC), 2013, pp. 4487–4492.

C. Kim, M. Jang, S. Seo, K. Park, and P. Kang, “Intrusion detection based on sequential information preserving log embedding methods and anomaly detection algorithms,” IEEE Access, vol. 9, pp. 58 088–58 101, 2021.

S. Forrest, S. A. Hofmeyr, A. Somayaji, and T. A. Longstaff, “A sense of self for Unix processes,” in Proc. IEEE Symp. Security and Privacy, 1996, pp. 120–128.

C. Warrender, S. Forrest, and B. Pearlmutter, “Detecting intrusions using system calls: Alternative data models,” in Proc. IEEE Symp. Security and Privacy, 1999, pp. 133–145.

R. A. Bridges, T. R. Glass-Vanderlan, M. D. Iannacone, M. S. Vincent, and Q. Chen, “A survey of intrusion detection systems leveraging host data,” ACM Computing Surveys, vol. 52, no. 6, pp. 128:1–128:35, 2019.

S. A. Abdulkareem, C. H. Foh, M. Shojafar, F. Carrez, and K. Moessner, “Network intrusion detection: An IoT and non IoT-related survey,” IEEE Access, vol. 12, pp. 144 608–144 636, 2024.

A. Milenkoski, M. Vieira, S. Kounev, A. Avritzer, and B. D. Payne, “Evaluating computer intrusion detection systems: A survey of common practices,” ACM Comput. Surv., vol. 48, no. 1, Sep. 2015. [Online]. Available: https://doi.org/10.1145/2808691

M. Grimmer, T. Kaelble, F. Nirsberger, E. Schulze, T. Rucks, J. Hoffmann, and E. Rahm, “Lid-ds 2021,” in CRITIS Conference Proceedings, 2021.

M. Landauer, F. Skopik, and M. Wurzenberger, “A critical review of common log data sets used for evaluation of sequence-based anomaly detection techniques,” Proc. ACM Softw. Eng., vol. 1, no. FSE, p. Article 61, 2024.

J. He, C. Tang, W. Li, T. Li, L. Chen, and X. Lan, “BR-HIDF: An anti-sparsity and effective host intrusion detection framework based on multi-granularity feature extraction,” IEEE Transactions on Information Forensics and Security, vol. 19, pp. 485–499, 2024.

N. Shamim, M. Asim, A. I. Awad, and M. K. Khan, “Anomaly detection in Internet of Things system calls using a centroid-based vector-space model,” IEEE Internet of Things Journal, vol. 12, no. 14, pp. 26 868–26 881, 2025.

Q. Le and T. Mikolov, “Distributed representations of sentences and documents,” in Proc. Int. Conf. Machine Learning (ICML), 2014, pp. 1188–1196.

O. Gungor, I. Kale, J. Zhou, and T. Rosing, “Light-hids: A lightweight and effective machine learning-based framework for robust host intrusion detection,” 2025. [Online]. Available: https://arxiv.org/abs/2509.13464

T. Li, X. Zhang, H. Zhao, J. Xu, Y. Chang, and S. Yang, “A dual-head output network attack detection and classification approach for multi-energy systems,” Frontiers in Energy Research, vol. 12, p. 1367199, 2024.

H. Kamal and M. Mashaly, “Ae-dtnn: Autoencoder–dense–transformer neural network model for efficient anomaly-based intrusion detection systems,” Machine Learning and Knowledge Extraction, vol. 7, no. 3, p. 78, 2025.

Z. Cao, Z. Zhao, W. Shang, and S. Ai, “VAEMax: Open-set intrusion detection based on OpenMax and variational autoencoder,” arXiv preprint arXiv:2403.04193, 2024.

M. Baz, “SEHIDS: Self evolving host-based intrusion detection system for IoT networks,” Sensors, vol. 22, no. 17, p. 6505, 2022.

T. Fawcett, “An introduction to roc analysis,” Pattern Recognition Letters, vol. 27, no. 8, pp. 861–874, 2006, rOC Analysis in Pattern Recognition. [Online]. Available: https://www.sciencedirect.com/science/article/pii/S016786550500303X

I. Ring, John H., C. M. Van Oort, S. Durst, V. White, J. P. Near, and C. Skalka, “Methods for host-based intrusion detection with deep learning,” Digital Threats: Research and Practice, vol. 2, no. 4, pp. 26:1–26:29, Oct. 2021.

D. P. Kingma and J. Ba, “Adam: A method for stochastic optimization,” in Proc. Int. Conf. Learning Representations (ICLR), 2015.

Downloads

Published

2026-08-25

How to Cite

Dippold, M., Maragkou, S., Wess, M., Sauter, T., Chrysos, G., & Ioannidis, S. (2026). A Dual-Head Model for Host based Intrusion Detection on System-Call traces. WiPiEC Journal - Works in Progress in Embedded Computing Journal, 12(2), 8. https://doi.org/10.64552/wipiec.v12i2.143