Intrusion Detection based on Non-negative Positive-unlabeled Learning

Sicai Lv,Yang Liu,Zhiyao Liu,Wang Chao,Chenrui Wu,Bailing Wang
DOI: https://doi.org/10.1109/ddcls49620.2020.9275048
2020-01-01
Abstract:Due to the diversity of network traffic flow, intrusion detection is usually studied as an anomaly detection problem. In this paper, Positive-unlabeled with Non-negative Risk Estimator(nnPU) learning is introduced for intrusion detection. The cyber attacks is treated as positive samples in PU learning. A risk estimator is raised to estimates the binary classification loss. For data imbalance in intrusion detection, we improve the risk estimator of nnPU through focal loss(FL-nnPU). The dynamic weights in focal loss is used to balance the small class prior. The experiments result show that FL-nnPU have a close performance to binary classification, and it performs better than nnPU under data imbalance problems.
What problem does this paper attempt to address?