<p>Intrusion Detection Systems (IDS) take on the important task of defending against network attacks and play a vital role in network security, but the data imbalance problem in intrusion detection data seriously affects the identification of abnormal data. Traditional oversampling algorithms are limited to the local information of data, which lead to low-quality of generated data, and cannot solve the problem of multiple classifications in intrusion detection. In contrast, Generative Adversarial Network (GAN) can learn the distributions of real data and effectively expand the number of samples for minority classes, but suffer from the problems of pattern collapse and training instability. To solve the above problems, we propose an oversampling algorithm based on Conditional Wasserstein GAN-Gradient Penalty (CWGAN-GP) to generate minority class samples for improving the classification results of network attack data in imbalanced intrusion detection datasets. The proposed algorithm uses Wasserstein distance to evaluate the quality of generated samples, resulting in a more stable training process, and applies a gradient penalty to the discriminator for overcoming the gradient disappearance problem of GAN; in addition, the auxiliary label information is introduced to generate the controllable data and multi-class data samples; finally, the proposed algorithm is experimented on 2 intrusion detection datasets and compared with some oversampling algorithms, and the results show that the proposed algorithm has better performance in the intrusion detection classification.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

An intrusion detection imbalanced data classification algorithm based on CWGAN-GP oversampling

  • Qinglei Yao,
  • Xiaoqiang Zhao

摘要

Intrusion Detection Systems (IDS) take on the important task of defending against network attacks and play a vital role in network security, but the data imbalance problem in intrusion detection data seriously affects the identification of abnormal data. Traditional oversampling algorithms are limited to the local information of data, which lead to low-quality of generated data, and cannot solve the problem of multiple classifications in intrusion detection. In contrast, Generative Adversarial Network (GAN) can learn the distributions of real data and effectively expand the number of samples for minority classes, but suffer from the problems of pattern collapse and training instability. To solve the above problems, we propose an oversampling algorithm based on Conditional Wasserstein GAN-Gradient Penalty (CWGAN-GP) to generate minority class samples for improving the classification results of network attack data in imbalanced intrusion detection datasets. The proposed algorithm uses Wasserstein distance to evaluate the quality of generated samples, resulting in a more stable training process, and applies a gradient penalty to the discriminator for overcoming the gradient disappearance problem of GAN; in addition, the auxiliary label information is introduced to generate the controllable data and multi-class data samples; finally, the proposed algorithm is experimented on 2 intrusion detection datasets and compared with some oversampling algorithms, and the results show that the proposed algorithm has better performance in the intrusion detection classification.