Reconstruction-based Network Intrusion Detection

This project develops a reconstruction-based anomaly detection system for network intrusions, utilizing autoencoders with attention mechanism to identify intrusions by analyzing the loss in reconstructing network traffic data. This approach works better than classical classifiers, which need to be trained on every possible attack type, and fail to detect novel attacks. Attention mechanism also allows it to capture time dependencies across packets.

Sparse Coding and Autoencoders

Cite

@inproceedings{rangamani_sparse_2018,
abstract = {In this work we study the landscape of squared loss of an Autoencoder when the data generative model is that of “Sparse Coding”/“Dictionary Learning”. The neural net considered is an \$\mathbbR\textasciicircumn\rightarrow \mathbbR\textasciicircumn\$ mapping and has a single ReLU activation layer of size \$h \textgreater n\$. The net has access to vectors \$yın \mathbbR\textasciicircumn\$ obtained as \$y=A\textasciicircum\astx\textasciicircum\ast\$ where \$x\textasciicircum\astın \mathbbR\textasciicircumh\$ are sparse high dimensional vectors and \$A\textasciicircum\astın \mathbbR\textasciicircumn\times h$^\textrm\ast\$$, we prove that the norm of the expected gradient of the squared loss function is asymptotically (in sparse code dimension) negligible for all points in a small neighborhood of $^\textrm\ast\$$. This is supported with experimental evidence using synthetic data. We conduct experiments to suggest that $^\textrm\ast\$$ sits at the bottom of a well in the landscape and we also give experiments showing that gradient descent on this loss function gets columnwise very close to the original dictionary even with far enough initialization. Along the way we prove that a layer of ReLU gates can be set up to automatically recover the support of the sparse codes. Since this property holds independent of the loss function we believe that it could be of independent interest. A full version of this paper is accessible at: https://arxiv.org/abs/1708.03735},
author = {Rangamani, Akshay and Mukherjee, Anirbit and Basu, Amitabh and Arora, Ashish and Ganapathi, Tejaswini and Chin, Sang and Tran, Trac D.},
booktitle = {2018 IEEE International Symposium on Information Theory (ISIT)},
doi = {10.1109/ISIT.2018.8437533},
month = {June},
note = {ISSN: 2157-8117},
pages = {36–40},
title = {Sparse Coding and Autoencoders},
year = {2018}
}