用于入侵检测的对决深度Q学习
Dueling Deep Q-Learning for Intrusion Detection
浏览论文内容
中文总结 AI 辅助
本研究针对入侵检测系统难以适配新型攻击的问题,提出对决深度Q学习模型,结合CIC-IDS2018数据集训练,准确率达99.68%,并集成SHAP提升预测可解释性。
中文摘要 AI 辅助
入侵检测系统(IDS,用于检测和报告网络威胁的自动化系统)通常采用监督机器学习方法处理,这类模型虽有效,但难以有效适配新型攻击类型。本研究提出一种基于奖励的对决Q学习模型用于IDS,在多类攻击中实现了99.68%的平均准确率。该模型采用对决网络架构,将预测拆分为价值流和优势流,可提升学习效率与稳定性。模型在基于真实入侵检测场景的基准数据集CIC-IDS2018上训练,该数据集包含DDoS、僵尸网络、暴力破解等多类攻击;此外,研究还将可解释人工智能(XAI,具体为SHAP即SHapley Additive exPlanations)集成到训练与评估过程中,以提供模型预测的可解释性。
英文摘要
Intrusion detection systems (IDS) and automated systems for detecting and reporting cyber threats, are commonly handled via supervised machine learning methods. Though effective, these models struggle to effectively adapt to new attack types. This study proposes a novel approach by employing a reward-based, dueling Q-learning model for IDS, achieving an average accuracy of 99.68% across multiple attack classes. The proposed model has a dueling network architecture which separates its predictions into value and advantage streams. This has the benefit of improving learning efficiency and stability. The model was trained on the CIC-IDS2018, a benchmark dataset based on real-world intrusion detection scenarios, having multiple attack classes such as DDoS, botnets, and brute-force attacks. Furthermore, Explainable AI (XAI), specifically SHAP (SHapley Additive exPlanations), was also integrated into the training and evaluation process to provide interpretability into the model's predictions.
发表机构
- Georgia Institute of Technology(佐治亚理工学院)
- School of Computer Science, College of Computing, Georgia Institute of Technology(佐治亚理工学院计算学院计算机学院)
机构由 AI 辅助整理,请以论文原文为准。