acceptodds
Under review as a conference paper at ICLR 2027

FlowGuard: A Machine Learning System for DDoS Mitigation via LLM-Augmented In-Switch Classification

Abstract

Distributed denial-of-service (DDoS) attacks remain a severe threat to network availability. Programmable switches enable line-rate DDoS mitigation, but their limited computational and memory resources restrict in-switch classifiers to lightweight models, which are both less accurate on attack traffic that resembles legitimate flows and quickly outdated as attack patterns evolve. To address these challenges, we present FlowGuard, a closed-loop hybrid DDoS mitigation framework that combines line-rate in-switch classification with LLM-assisted out-of-switch analysis and classifier adaptation. In the switch data plane, a lightweight decision tree performs line-rate flow classification and enables immediate mitigation. Outside the switch, an LLM analyzes compact window-level traffic statistics to produce risk assessments, victim subnets, and rationales for flagged windows, from which FlowGuard derives flow-level weak labels. When statistical drift is detected, a second LLM stage determines whether retraining is warranted. If retraining is approved, FlowGuard trains a new decision tree from these weak labels together with the original labeled data, and deploys it only after it passes a safety gate. Through this closed-loop design, FlowGuard combines line-rate DDoS mitigation with the ability to adapt to evolving traffic patterns. Experiments on CIC-DDoS2019 and IoT-23 show that FlowGuard achieves an F1 score of 0.968, representing relative improvements of 24.6% and 43.8% over our static in-switch decision-tree and the in-network baseline SISTAR, respectively. Code and data are available at https://anonymous.4open.science/r/FlowGuard.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.