A Dual-Head Model for Host based Intrusion Detection on System-Call traces
DOI:
https://doi.org/10.64552/wipiec.v12i2.143Keywords:
host-based intrusion detection, anomaly detection, deep learning, convolutional neural networks, zero-day attacksAbstract
Host-based intrusion detection systems (HIDS) need to detect both unseen exploits from day one and recurring known attack families. Maintaining separate anomaly-detection and supervised-classification frameworks increases the computational and operational footprint — a cost that only a few embedded or edge devices can carry. To satisfy both requirements without increasing deployment overhead, we propose a single dual-head Convolutional Neural Network (CNN) operating over a sliding window of embedded system-call tokens. Head 1 is an autoregressive next-token prediction module that emits sequence-level anomaly scores derived from token-wise negative log-likelihood (NLL) estimates, while Head 2 is a supervised attack-classification module using a shared latent representation. The two heads jointly support concurrent anomaly detection and supervised attack classification within a single model.
The proposed framework is evaluated using the ADFA-LD Linux system-call benchmark [1]. The proposed framework achieves mean AUROC scores of 0.916 in the unsupervised setting and 0.979 in the supervised setting, outperforming the baselines reported in [2] under the reshuffled evaluation protocol in both settings. These results demonstrate that unified sequential representation learning can simultaneously support both zero-day anomaly detection and supervised attack classification refinement within a single operational HIDS framework, thereby reducing the operational complexity of practical HIDS deployments.
References
G. Creech and J. Hu, “Generation of a new IDS test dataset: Time to retire the KDD collection,” in Proc. IEEE Wireless Commun. Netw. Conf. (WCNC), 2013, pp. 4487–4492.
C. Kim, M. Jang, S. Seo, K. Park, and P. Kang, “Intrusion detection based on sequential information preserving log embedding methods and anomaly detection algorithms,” IEEE Access, vol. 9, pp. 58 088–58 101, 2021.
S. Forrest, S. A. Hofmeyr, A. Somayaji, and T. A. Longstaff, “A sense of self for Unix processes,” in Proc. IEEE Symp. Security and Privacy, 1996, pp. 120–128.
C. Warrender, S. Forrest, and B. Pearlmutter, “Detecting intrusions using system calls: Alternative data models,” in Proc. IEEE Symp. Security and Privacy, 1999, pp. 133–145.
R. A. Bridges, T. R. Glass-Vanderlan, M. D. Iannacone, M. S. Vincent, and Q. Chen, “A survey of intrusion detection systems leveraging host data,” ACM Computing Surveys, vol. 52, no. 6, pp. 128:1–128:35, 2019.
S. A. Abdulkareem, C. H. Foh, M. Shojafar, F. Carrez, and K. Moessner, “Network intrusion detection: An IoT and non IoT-related survey,” IEEE Access, vol. 12, pp. 144 608–144 636, 2024.
A. Milenkoski, M. Vieira, S. Kounev, A. Avritzer, and B. D. Payne, “Evaluating computer intrusion detection systems: A survey of common practices,” ACM Comput. Surv., vol. 48, no. 1, Sep. 2015. [Online]. Available: https://doi.org/10.1145/2808691
M. Grimmer, T. Kaelble, F. Nirsberger, E. Schulze, T. Rucks, J. Hoffmann, and E. Rahm, “Lid-ds 2021,” in CRITIS Conference Proceedings, 2021.
M. Landauer, F. Skopik, and M. Wurzenberger, “A critical review of common log data sets used for evaluation of sequence-based anomaly detection techniques,” Proc. ACM Softw. Eng., vol. 1, no. FSE, p. Article 61, 2024.
J. He, C. Tang, W. Li, T. Li, L. Chen, and X. Lan, “BR-HIDF: An anti-sparsity and effective host intrusion detection framework based on multi-granularity feature extraction,” IEEE Transactions on Information Forensics and Security, vol. 19, pp. 485–499, 2024.
N. Shamim, M. Asim, A. I. Awad, and M. K. Khan, “Anomaly detection in Internet of Things system calls using a centroid-based vector-space model,” IEEE Internet of Things Journal, vol. 12, no. 14, pp. 26 868–26 881, 2025.
Q. Le and T. Mikolov, “Distributed representations of sentences and documents,” in Proc. Int. Conf. Machine Learning (ICML), 2014, pp. 1188–1196.
O. Gungor, I. Kale, J. Zhou, and T. Rosing, “Light-hids: A lightweight and effective machine learning-based framework for robust host intrusion detection,” 2025. [Online]. Available: https://arxiv.org/abs/2509.13464
T. Li, X. Zhang, H. Zhao, J. Xu, Y. Chang, and S. Yang, “A dual-head output network attack detection and classification approach for multi-energy systems,” Frontiers in Energy Research, vol. 12, p. 1367199, 2024.
H. Kamal and M. Mashaly, “Ae-dtnn: Autoencoder–dense–transformer neural network model for efficient anomaly-based intrusion detection systems,” Machine Learning and Knowledge Extraction, vol. 7, no. 3, p. 78, 2025.
Z. Cao, Z. Zhao, W. Shang, and S. Ai, “VAEMax: Open-set intrusion detection based on OpenMax and variational autoencoder,” arXiv preprint arXiv:2403.04193, 2024.
M. Baz, “SEHIDS: Self evolving host-based intrusion detection system for IoT networks,” Sensors, vol. 22, no. 17, p. 6505, 2022.
T. Fawcett, “An introduction to roc analysis,” Pattern Recognition Letters, vol. 27, no. 8, pp. 861–874, 2006, rOC Analysis in Pattern Recognition. [Online]. Available: https://www.sciencedirect.com/science/article/pii/S016786550500303X
I. Ring, John H., C. M. Van Oort, S. Durst, V. White, J. P. Near, and C. Skalka, “Methods for host-based intrusion detection with deep learning,” Digital Threats: Research and Practice, vol. 2, no. 4, pp. 26:1–26:29, Oct. 2021.
D. P. Kingma and J. Ba, “Adam: A method for stochastic optimization,” in Proc. Int. Conf. Learning Representations (ICLR), 2015.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Matthias Dippold, Sofia Maragkou, Matthias Wess, Thilo Sauter, Grigorios Chrysos, Sotiris Ioannidis

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
License Terms:
Except where otherwise noted, content on this website is lincesed under a Creative Commons Attribution Non-Commercial License (CC BY NC)
![]()
Use, distribution and reproduction in any medium, provided the original work is properly cited and is not used for commercial purposes, is permitted.
Copyright to any article published by WiPiEC retained by the author(s). Authors grant WiPiEC Journal a license to publish the article and identify itself as the original publisher. Authors also grant any third party the right to use the article freely as long as it is not used for commercial purposes and its original authors, citation details, and publisher are identified, in accordance with CC BY NC license. Fore more information on license terms, click here.