MANomaly: Mutual adversarial networks for semi-supervised anomaly detection

被引:25
作者
Zhang, Lianming [1 ]
Xie, Xiaowei [1 ]
Xiao, Kai [1 ]
Bai, Wenji [1 ]
Liu, Kui [1 ]
Dong, Pingping [1 ]
机构
[1] Hunan Normal Univ, Coll Informat Sci & Engn, Changsha 410081, Peoples R China
关键词
Network intrusion detection; Anomaly detection; Mutual adversarial network; Mutual adversarial training; High anomaly suppression; VEHICLES;
D O I
10.1016/j.ins.2022.08.033
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In network intrusion detection, since the available attack traffic is much less than normal traffic, detecting attacks and intrusions from these unbalanced traffic can be a problem of semi-supervised learning, i.e., finding outliers (anomalies) from a data population that obeys a certain distribution. In this paper, we design a novel network model named the mutual adversarial network (MAN), which has two identical reconstruction autoencoder (RecAE) subnetworks. In training, these two subnetworks use the proposed mutual adver-sarial training to learn the data distribution of normal traffic samples. In detection, we identify anomalies based on the residual values obtained after different samples are recon-structed by MAN. In addition, we devise a novel method to identify anomalies from anom-aly scores named the high anomaly suppression (HAS) determination mechanism, which uses the mean values to suppress the effect of noisy data in the test sample. Then, we con-struct a novel semi-supervised reconstruction anomaly detection framework named MANomaly by combining MAN with the HAS determination mechanism. Meanwhile, we design three different mutual adversarial training approaches to MANomaly and evaluate them on two publicly available network traffic datasets: NSL-KDD and UNSW-NB15. Experimental results show that our method achieves excellent performance by using only 5% of normal training data. (c) 2022 Elsevier Inc. All rights reserved.
引用
收藏
页码:65 / 80
页数:16
相关论文
共 44 条
[1]   Skip-GANomaly: Skip Connected and Adversarially Trained Encoder-Decoder Anomaly Detection [J].
Akcay, Samet ;
Atapour-Abarghouei, Amir ;
Breckon, Toby P. .
2019 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2019,
[2]   GANomaly: Semi-supervised Anomaly Detection via Adversarial Training [J].
Akcay, Samet ;
Atapour-Abarghouei, Amir ;
Breckon, Toby P. .
COMPUTER VISION - ACCV 2018, PT III, 2019, 11363 :622-637
[3]  
Arjovsky M, 2017, PR MACH LEARN RES, V70
[4]   Fuzziness based semi-supervised learning approach for intrusion detection system [J].
Ashfaq, Rana Aamir Raza ;
Wang, Xi-Zhao ;
Huang, Joshua Zhexue ;
Abbas, Haider ;
He, Yu-Lin .
INFORMATION SCIENCES, 2017, 378 :484-497
[5]   Deep Autoencoding Models for Unsupervised Anomaly Segmentation in Brain MR Images [J].
Baur, Christoph ;
Wiestler, Benedikt ;
Albarqouni, Shadi ;
Navab, Nassir .
BRAINLESION: GLIOMA, MULTIPLE SCLEROSIS, STROKE AND TRAUMATIC BRAIN INJURIES, BRAINLES 2018, PT I, 2019, 11383 :161-169
[6]   Network Intrusion Detection System Using Neural Network and Condensed Nearest Neighbors with Selection of NSL-KDD Influencing Features [J].
Belgrana, Fatima Zohra ;
Benamrane, Nacera ;
Hamaida, Mohamed Amine ;
Chaabani, Abdellah Mohamed ;
Taleb-Ahmed, Abdelmalik .
2020 IEEE INTERNATIONAL CONFERENCE ON INTERNET OF THINGS AND INTELLIGENCE SYSTEM (IOTAIS), 2021, :23-29
[7]   Multi-scale Self-Organizing Map assisted Deep Autoencoding Gaussian Mixture Model for unsupervised intrusion detection [J].
Chen, Yang ;
Ashizawa, Nami ;
Yeo, Chai Kiat ;
Yanai, Naoto ;
Yean, Seanglidet .
KNOWLEDGE-BASED SYSTEMS, 2021, 224
[8]   Wavelet-Based EEG Processing for Epilepsy Detection Using Fuzzy Entropy and Associative Petri Net [J].
Chiang, Hsiu-Sen ;
Chen, Mu-Yen ;
Huang, Yu-Jhih .
IEEE ACCESS, 2019, 7 :103255-103262
[9]   Convergent newton method and neural network for the electric energy usage prediction [J].
de Jesus Rubio, Jose ;
Antonio Islas, Marco ;
Ochoa, Genaro ;
Ricardo Cruz, David ;
Garcia, Enrique ;
Pacheco, Jaime .
INFORMATION SCIENCES, 2022, 585 :89-112
[10]  
DERUBIO JJ, 2020, IEEE T NEUR NET LEAR, P3510