<p>Distributed denial-of-service (DDoS) attacks remain a major threat to network reliability. They are especially dangerous in healthcare systems that depend on Internet of Things (IoT) devices, where rapid defensive action is essential. Traditional DDoS detection methods face challenges, including poor sample efficiency, weak feature selection, limited interpretability, class imbalance, and difficulties in hyperparameter tuning. To address these issues, this work introduces a framework that uses a two-agent architecture enhanced with an improved trust-region policy optimization (TRPO) technique. This version of TRPO includes an entropy-based regularizer to strengthen policy performance. The first agent employs active learning (AL) to identify the most informative unlabeled samples for annotation, reducing the reliance on large labeled datasets. These selected samples are then passed to the second agent, which performs DDoS detection. In this agent, local interpretable model-agnostic explanations (LIME) support more accurate feature selection, while augmented rewards for underrepresented classes mitigate data imbalance. The hyperparameters of the model are further optimized using a Homotopy-based method, which supports efficient and reliable adaptation across varying data conditions. The proposed model is evaluated on four public datasets: KDDcup99, ISCX-UNB, CICDDOS, and DARPA. It achieves accuracy/F-measure pairs of (94.953%, 93.122%), (95.629%, 93.394%), (95.659%, 94.082%), and (96.155%, 94.844%) for these datasets, respectively. Additional evaluation on the healthcare-oriented CICIoMT2024 dataset further confirms generalizability, yielding 97.164% accuracy and 94.798% F-measure. These results validate the value of our work for the healthcare security arena, with significant gains in DDoS attack detection to further improve investigative techniques in the area.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

DDoS Attack Detection in Healthcare Systems using a TRPO-based Multi Agent System Combining Active Learning and Explainable Feature Selection

  • Ahmad Kokhahi,
  • Roohallah Alizadehsani,
  • Siamak Pedrammehr

摘要

Distributed denial-of-service (DDoS) attacks remain a major threat to network reliability. They are especially dangerous in healthcare systems that depend on Internet of Things (IoT) devices, where rapid defensive action is essential. Traditional DDoS detection methods face challenges, including poor sample efficiency, weak feature selection, limited interpretability, class imbalance, and difficulties in hyperparameter tuning. To address these issues, this work introduces a framework that uses a two-agent architecture enhanced with an improved trust-region policy optimization (TRPO) technique. This version of TRPO includes an entropy-based regularizer to strengthen policy performance. The first agent employs active learning (AL) to identify the most informative unlabeled samples for annotation, reducing the reliance on large labeled datasets. These selected samples are then passed to the second agent, which performs DDoS detection. In this agent, local interpretable model-agnostic explanations (LIME) support more accurate feature selection, while augmented rewards for underrepresented classes mitigate data imbalance. The hyperparameters of the model are further optimized using a Homotopy-based method, which supports efficient and reliable adaptation across varying data conditions. The proposed model is evaluated on four public datasets: KDDcup99, ISCX-UNB, CICDDOS, and DARPA. It achieves accuracy/F-measure pairs of (94.953%, 93.122%), (95.629%, 93.394%), (95.659%, 94.082%), and (96.155%, 94.844%) for these datasets, respectively. Additional evaluation on the healthcare-oriented CICIoMT2024 dataset further confirms generalizability, yielding 97.164% accuracy and 94.798% F-measure. These results validate the value of our work for the healthcare security arena, with significant gains in DDoS attack detection to further improve investigative techniques in the area.