Intrusion Anomaly Detection with Multi-transformer
摘要
With the rapid growth of network scale, more network attacks have emerged, the types of network attacks have become more diverse, and the harm they cause to users has become increasingly serious, which has challenged network intrusion detection and protection methods. In order to further improve the quality of network intrusion detection, the study proposes the Multi-Transformer method, which is based on the switchable attention mechanism. It is a detection model with higher security and greater applicability and is applied to the field of network intrusion detection. The study improves the traditional Transformer model and uses self-attention(single head), multi-head attention, and convolution attention in the attention module. At the same time, in order to improve the interpretability of the model, LIME (Local interpretable Model-Agnostic Explanations) was introduced, using Multiple public datasets for testing. The results show that the detection effect of the Multi-Transformer model is better than other machine learning methods. The proposed method is more secure and applicable, and has better anti-noise ability, which has more practical significance in complex and changeable network environments.