This paper introduces a transformer-based Network Intrusion Detection System (NIDS). Addressing a common oversight in current NIDSs that often neglect networks’ long-term behavior and characteristics, our proposed model capitalizes on transformer models to effectively identify these features. Our proposed model enables adaptability across diverse flow-based network datasets by offering various transformer components, including the classification head, transformer, and data preprocessing. We leveraged our proposed model with different transformer architectures, such as shallow encoder transformer, shallow decoder transformer, and GPT 2.0, on three widely used NIDS benchmark datasets, including those specific to IoT environments. The evaluation covers key metrics like accuracy, F1 score, precision, and recall, with a notable finding emphasizing the pivotal role of classification head selection in determining model performance. Our proposed model provides crucial insights into optimizing transformer architectures for enhanced accuracy, efficiency, and applicability in the domain of network intrusion detection.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Transformer-Based Model for Network Intrusion Detection: Architecture, Classification Heads, and Transformer Blocks

  • Nourhan Ibrahim,
  • Sarama Shehmir,
  • Aman Yadav,
  • Rasha Kashef

摘要

This paper introduces a transformer-based Network Intrusion Detection System (NIDS). Addressing a common oversight in current NIDSs that often neglect networks’ long-term behavior and characteristics, our proposed model capitalizes on transformer models to effectively identify these features. Our proposed model enables adaptability across diverse flow-based network datasets by offering various transformer components, including the classification head, transformer, and data preprocessing. We leveraged our proposed model with different transformer architectures, such as shallow encoder transformer, shallow decoder transformer, and GPT 2.0, on three widely used NIDS benchmark datasets, including those specific to IoT environments. The evaluation covers key metrics like accuracy, F1 score, precision, and recall, with a notable finding emphasizing the pivotal role of classification head selection in determining model performance. Our proposed model provides crucial insights into optimizing transformer architectures for enhanced accuracy, efficiency, and applicability in the domain of network intrusion detection.