<p>Machine learning techniques have been increasingly applied to network intrusion detection. Class imbalance and adversarial attacks are two pivotal challenges that hinder the accuracy and robustness of machine learning-based network traffic detection models. However, current research efforts focus solely on addressing one of these issues, which limits the improvement of detection performance. To jointly tackle these challenges, we propose a dynamic ensemble learning method called ADHS-EL. Specifically, a novel sampling mechanism is integrated into the Boosting ensemble framework, providing a balanced data subset mixed with adversarial samples for each iteration to yield a strong ensemble. This sampling mechanism includes dynamic hybrid sampling for balancing benign and malicious traffic, as well as boundary malicious traffic adversarial augmentation for introducing adversarial samples to the training dataset. A boundary samples importance enhancement strategy is adopted in hybrid sampling and adversarial augmentation, which contributes to improving intrusion detection accuracy and preventing robust overfitting. Experimental evaluations on two public datasets demonstrate that the proposed method exhibits significant advantages in terms of accuracy and robustness. In the non-adversarial test, ADHS-EL obtains the highest F1 score on both datasets. In the adversarial test involving four types of adversarial attacks, ADHS-EL achieves the average detection rates of 74.35% and 80.30% on the two datasets, respectively, marking improvements of 10.63% and 13.26% over the optimal baseline methods.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

ADHS-EL: Dynamic ensemble learning with adversarial augmentation for accurate and robust network intrusion detection

  • Huajuan Ren,
  • Yonghe Tang,
  • Shuai Ren,
  • Ruimin Wang,
  • Weiyu Dong

摘要

Machine learning techniques have been increasingly applied to network intrusion detection. Class imbalance and adversarial attacks are two pivotal challenges that hinder the accuracy and robustness of machine learning-based network traffic detection models. However, current research efforts focus solely on addressing one of these issues, which limits the improvement of detection performance. To jointly tackle these challenges, we propose a dynamic ensemble learning method called ADHS-EL. Specifically, a novel sampling mechanism is integrated into the Boosting ensemble framework, providing a balanced data subset mixed with adversarial samples for each iteration to yield a strong ensemble. This sampling mechanism includes dynamic hybrid sampling for balancing benign and malicious traffic, as well as boundary malicious traffic adversarial augmentation for introducing adversarial samples to the training dataset. A boundary samples importance enhancement strategy is adopted in hybrid sampling and adversarial augmentation, which contributes to improving intrusion detection accuracy and preventing robust overfitting. Experimental evaluations on two public datasets demonstrate that the proposed method exhibits significant advantages in terms of accuracy and robustness. In the non-adversarial test, ADHS-EL obtains the highest F1 score on both datasets. In the adversarial test involving four types of adversarial attacks, ADHS-EL achieves the average detection rates of 74.35% and 80.30% on the two datasets, respectively, marking improvements of 10.63% and 13.26% over the optimal baseline methods.