PANACEA: a neural model ensemble for cyber-threat detection

被引:7
作者
AL-Essa, Malik [1 ,2 ]
Andresini, Giuseppina [1 ,2 ]
Appice, Annalisa [1 ,2 ]
Malerba, Donato [1 ,2 ]
机构
[1] Univ Bari Aldo Moro, Dept Comp Sci, Via Orabona 4, I-70125 Bari, Italy
[2] Consorzio Interuniv Nazl Informat, Via Orabona 4, I-70125 Bari, Italy
关键词
Ensemble learning; Adversarial training; Explainable artificial intelligence; Cyber-threat detection; NETWORK; IMBALANCE;
D O I
10.1007/s10994-023-06470-2
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Ensemble learning is a strategy commonly used to fuse different base models by creating a model ensemble that is expected more accurate on unseen data than the base models. This study describes a new cyber-threat detection method, called PANACEA, that uses ensemble learning coupled with adversarial training in deep learning, in order to gain accuracy with neural models trained in cybersecurity problems. The selection of the base models is one of the main challenges to handle, in order to train accurate ensembles. This study describes a model ensemble pruning approach based on eXplainable AI (XAI) to increase the ensemble diversity and gain accuracy in ensemble classification. We base on the idea that being able to identify base models that give relevance to different input feature sub-spaces may help in improving the accuracy of an ensemble trained to recognise different signatures of different cyber-attack patterns. To this purpose, we use a global XAI technique to measure the ensemble model diversity with respect to the effect of the input features on the accuracy of the base neural models combined in the ensemble. Experiments carried out on four benchmark cybersecurity datasets (three network intrusion detection datasets and one malware detection dataset) show the beneficial effects of the proposed combination of adversarial training, ensemble learning and XAI on the accuracy of multi-class classifications of cyber-data achieved by the neural model ensemble.
引用
收藏
页码:5379 / 5422
页数:44
相关论文
共 75 条
[1]  
Al-Essa Malik, 2022, 2022 IEEE Intl Conf on Dependable, Autonomic and Secure Computing
[2]  
Intl Conf on Pervasive Intelligence and Computing
[3]  
Intl Conf on Cloud and Big Data Computing
[4]   An XAI-based adversarial training approach for cyber-threat detection [J].
Al-Essa, Malik ;
Andresini, Giuseppina ;
Appice, Annalisa ;
Malerba, Donato .
2022 IEEE INTL CONF ON DEPENDABLE, AUTONOMIC AND SECURE COMPUTING, INTL CONF ON PERVASIVE INTELLIGENCE AND COMPUTING, INTL CONF ON CLOUD AND BIG DATA COMPUTING, INTL CONF ON CYBER SCIENCE AND TECHNOLOGY CONGRESS (DASC/PICOM/CBDCOM/CYBERSCITECH), 2022, :806-813
[5]   A Convolutional Neural Network for Improved Anomaly-Based Network Intrusion Detection [J].
Al-Turaiki, Isra ;
Altwaijry, Najwa .
BIG DATA, 2021, 9 (03) :233-252
[6]  
Andresini G., 2021, Mach. Intell. Big Data Anal. Cybersecur. Appl., P105
[7]   INSOMNIA: Towards Concept-Drift Robustness in Network Intrusion Detection [J].
Andresini, Giuseppina ;
Pendlebury, Feargus ;
Pierazzi, Fabio ;
Loglisci, Corrado ;
Appice, Annalisa ;
Cavallaro, Lorenzo .
PROCEEDINGS OF THE 14TH ACM WORKSHOP ON ARTIFICIAL INTELLIGENCE AND SECURITY, AISEC 2021, 2021, :111-122
[8]   ROULETTE: A neural attention multi-output model for explainable Network Intrusion Detection [J].
Andresini, Giuseppina ;
Appice, Annalisa ;
Caforio, Francesco Paolo ;
Malerba, Donato ;
Vessio, Gennaro .
EXPERT SYSTEMS WITH APPLICATIONS, 2022, 201
[9]   GAN augmentation to deal with imbalance in imaging-based intrusion detection [J].
Andresini, Giuseppina ;
Appice, Annalisa ;
De Rose, Luca ;
Malerba, Donato .
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2021, 123 (123) :108-127
[10]   Autoencoder-based deep metric learning for network intrusion detection [J].
Andresini, Giuseppina ;
Appice, Annalisa ;
Malerba, Donato .
INFORMATION SCIENCES, 2021, 569 (569) :706-727