Research
On-device research index

arXiv research

A locally-built, LLM-digested index of recent arXiv papers in quant finance, geometry/topology, and statistical ML — keyword search served straight from SQLite on this machine.

169,051 papers · 148 categories

Trend · papers per month

2.3%4.7%7.0%9.3% · Apr 202019922001200920182026
48 results for Anomaly-based Intrusion Detection

This paper benchmarks UNSW-NB15 as a modern alternative to KDD-99 for A-NIDS.

problem Skewed response distribution and non-stationarity in KDD-99 hamper A-NIDS performance.
method Compared UNSW-NB15 to KDD-99 and NSL-KDD using various classification models and SMOTE oversampling.
result UNSW-NB15 outperforms KDD-99 and NSL-KDD in minority class performance, suggesting it as a better benchmark.

Geometric Graph Alignment enhances IoT intrusion detection using NID data.

problem Data scarcity hinders IoT intrusion detection accuracy.
method Geometric Graph Alignment (GGA) approach to transfer knowledge between network intrusion detection and IoT intrusion detection domains.
result GGA approach boosts IoT intrusion detection performance on multiple datasets.

Paper proposes mimic learning to share intrusion detection models without private data.

problem Difficulty in obtaining labelled training data for intrusion detection models due to privacy concerns.
method Use of mimic learning to transfer knowledge from a teacher model trained on private data to a student model.
result Student model mimics teacher model without access to private data.

This paper shows diffusion models improve intrusion detection by purifying adversarial examples.

problem Adversarial examples mislead ML intrusion detection systems, leading to false alerts or evasion.
method Used diffusion models to purify adversarial examples in intrusion detection.
result Diffusion models enhance adversarial robustness in intrusion detection without significantly impacting normal performance.

Proposes SOMDAGMM for more accurate network intrusion detection.

problem Inaccurate network intrusion detection in secure network environments.
method Integrates self-organizing map with deep autoencoding Gaussian mixture model.
result SOMDAGMM outperforms state-of-the-art DAGMM with up to 15.58% improvement in F1 score.

EagerNet detects network attacks quickly with less resources.

problem Efficiently detecting network attacks with minimal resources.
method Proposes a new architecture that trades prediction speed for accuracy, evaluating only a subset of layers.
result Comparable accuracies to simple FCNNs achieved with early predictions, saving energy and computational efforts.

Study on deep learning IDS resistance against adversarial attacks.

problem Vulnerabilities in deep learning-based IDS against adversarial attacks.
method Apply min-max optimization to train IDS against adversarial samples.
result Adversarial attack methods can be used in continuous domains and boost IDS robustness.

Adversarial attacks hide cyber-physical attacks in ICS.

problem Hiding cyber-physical attacks in industrial control systems.
method Modeling an attacker compromising sensors, manipulating data, and evaluating attacks on both continuous and mixed data.
result Successfully hides cyber-physical attacks with 2.87 out of 12 sensors compromised on average.

User authentication and intrusion detection differ from standard classification problems in that while we have data generated from legitimate users, impostor or intrusion data is scarce or non-existent. We review existing techniques for dealing with this problem and propose a novel alternative based on a principled sta…

2009-10-05abs ↗pdf ↗

Bayesian coresets help reduce network intrusion detection data size.

problem Large network intrusion detection data sets hinder Bayesian learning.
method Use Bayesian coresets to reduce data size while maintaining accuracy.
result Bayesian coresets improve learning accuracy and reduce storage needs.

Active learning improves network intrusion detection with minimal labeled data.

problem Finding new attack vectors in low-volume traffic.
method Proposes an active learning framework to minimize labeled data while improving detection quality.
result Active learning with minimal labeled data significantly improves anomaly detection in network traffic.

Random Forest outperforms other IDS algorithms in smart grids.

problem Security vulnerabilities in smart grids.
method Comparison of four data mining algorithms (Random Forest, SVM, Neural Network, and KNN) in detecting attacks.
result Random Forest outperforms other algorithms in terms of detection accuracy and efficiency.

This paper improves machine learning models' robustness against evasion attacks using randomness.

problem Evasion attacks that adapt to machine learning models to avoid detection.
method Incorporates randomness into both training and application phases of machine learning models.
result The proposed randomization-based approach further improves the robustness of machine learning models, especially random forest.

Generative adversarial networks generate synthetic anomalies for host-based intrusion detection.

problem Imbalanced datasets in host-based intrusion detection.
method Cycle-GAN to generate synthetic anomalies from normal data.
result Improved anomaly detection with higher AUC and anomaly detection rate.

New online learning algorithms improve cyberattack detection in industrial control systems.

problem Detecting cyberattacks in industrial control systems with limited resources.
method Online learning algorithms to process continuous data streams and address class imbalance.
result Improved detection rate of cyberattacks in industrial control systems.

Bayesian Optimization improves machine learning for detecting network attacks.

problem Detecting network attacks to secure critical information.
method Bayesian Optimization for tuning machine learning algorithms (SVM-RBF, RF, k-NN).
result The proposed framework achieves high accuracy and low false alarms.

Many current approaches to the design of intrusion detection systems apply feature selection in a static, non-adaptive fashion. These methods often neglect the dynamic nature of network data which requires to use adaptive feature selection techniques. In this paper, we present a simple technique based on incremental le…

2018-03-01abs ↗pdf ↗

This paper studies adversarial examples in NIDS, revealing their vulnerability.

problem Vulnerability of machine learning-based NIDS to adversarial examples.
method Used evolutionary computation and deep learning to generate adversarial examples.
result Adversarial examples cause high misclassification rates in various machine learning models.

MAD-GAN detects anomalies in multivariate time series data using GANs.

problem Complex multivariate time series data requires better anomaly detection methods.
method Unsupervised anomaly detection using Generative Adversarial Networks (GANs).
result MAD-GAN effectively detects anomalies in real-world CPS systems.

Improved non-intrusive load monitoring with a novel neural network.

problem Accurately disaggregating household electricity consumption without dedicated meters.
method Developed a scale- and context-aware network with multi-scale features and contextual information.
result Significantly improved accuracy compared to state-of-the-art methods.

Paper improves anomaly detection and categorization in multi-cloud environments.

problem Differentiating among different types of attacks for better defense.
method Used supervised machine learning techniques (LR and RF) on a public dataset.
result More than 99% detection accuracy and 93.6% categorization accuracy.

DiFF-RF detects point-wise and collective anomalies using random partitioning trees.

problem Detecting anomalies in data, especially collective anomalies.
method Random partitioning binary trees with distance-based leaves and semi-supervised learning.
result DiFF-RF significantly outperforms isolation forest and one-class SVM.

Several problems such as network intrusion, community detection, and disease outbreak can be described by observations attributed to nodes or edges of a graph. In these applications presence of intrusion, community or disease outbreak is characterized by novel observations on some unknown connected subgraph. These prob…

2014-11-23abs ↗pdf ↗

This paper improves AI defenses against network attacks using ML and adversarial learning.

problem Protecting personal data from sophisticated network attacks.
method Unified multi-modal dataset, machine learning for detection, adversarial learning for synthetic data generation.
result Stable ML models for intrusion detection and high-fidelity synthetic data.

Generative adversarial networks (GANs) are able to model the complex highdimensional distributions of real-world data, which suggests they could be effective for anomaly detection. However, few works have explored the use of GANs for the anomaly detection task. We leverage recently developed GAN models for anomaly dete…

2018-02-17abs ↗pdf ↗