Trustworthy and Temporally Robust Web Attack Detection for Autonomous Edge Network Security
Abstract
Trustworthy security at the network edge demands fine-grained and temporally robust web attack detection to support autonomous threat response under the latency and communication constraints of distributed networked systems. Existing data-driven methods fail to deliver high-performance attack type classification as they either process HTTP fields independently or treat the entire request as a flat unstructured sequence, obscuring field-specific attack semantics. Moreover, the critical challenge of temporal distribution shift in dynamic network environments has received no systematic treatment in prior web attack detection work. To address both challenges, we propose DAMF-Net, a Domain-Adversarial Multi-Field Network that independently encodes HTTP fields via a shared SecureBERT encoder and fuses their representations through a field-aware attention mechanism that adaptively weights each field per sample, providing interpretable field-level evidence to support trustworthy autonomous threat response. An adversarial multi-source domain generalization module further promotes temporally invariant representations across multiple data periods. To support fine-grained evaluation and temporal robustness validation, we construct TMF-HAD, a 13-month real-world HTTP attack log dataset with fine-grained labels for seven attack categories from a production cloud Web Application Firewall (WAF) platform. Extensive experiments demonstrate that DAMF-Net achieves an average intra-domain accuracy of 98.19% and a macro-averaged F1 of 97.82% over 13 months, ranking first or co-first in 9 of 13 accuracy evaluations and 6 of 13 macro-F1 evaluations, while consistently outperforming the unadapted baseline under severe temporal drift. On three public benchmarks, DAMF-Net matches or surpasses prior state-of-the-art methods.