In time series anomaly detection systems, a prediction model plays a pivotal role in identifying anomalies. This is because the gap between the observed and predicted values contributes to determining whether a time instance is anomalous or not. Following the traditional approach of choosing the best prediction model in terms of accuracy may lead to unexpected results in the detection system. A prediction model performing well on test data due to its generalization capability might inadvertently adapt to attack data as well. Therefore, it becomes important to understand the prediction model’s properties to determine if it accurately identifies a target attack or adapts to it. To compare the behavior of these prediction models under attacks, we propose a framework for analyzing prediction responses to specific inputs, similar to control system analysis. We identify four model responses that can be used to assess five prediction models- MLP, LSTM, GRU, TCN and CNN-LSTM, and gain insights into their behavior. Our results show that each prediction model has distinct behavior and choosing a model by the prediction accuracy alone is insufficient. It emphasizes the need for nuanced model selection and highlights the potential for developing more effective anomaly detection systems.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Characterizing Prediction Model Responses to Attack Inputs: A Study with Time-Series Power Consumption Data

  • Srinidhi Madabhushi,
  • Rinku Dewri

摘要

In time series anomaly detection systems, a prediction model plays a pivotal role in identifying anomalies. This is because the gap between the observed and predicted values contributes to determining whether a time instance is anomalous or not. Following the traditional approach of choosing the best prediction model in terms of accuracy may lead to unexpected results in the detection system. A prediction model performing well on test data due to its generalization capability might inadvertently adapt to attack data as well. Therefore, it becomes important to understand the prediction model’s properties to determine if it accurately identifies a target attack or adapts to it. To compare the behavior of these prediction models under attacks, we propose a framework for analyzing prediction responses to specific inputs, similar to control system analysis. We identify four model responses that can be used to assess five prediction models- MLP, LSTM, GRU, TCN and CNN-LSTM, and gain insights into their behavior. Our results show that each prediction model has distinct behavior and choosing a model by the prediction accuracy alone is insufficient. It emphasizes the need for nuanced model selection and highlights the potential for developing more effective anomaly detection systems.