A Two-Layer Soft-Voting Ensemble Learning Model for Network Intrusion Detection.

Wenbin Yao,Yingying Hou,Longcan Hu,Xiaoyong Li
DOI: https://doi.org/10.1109/dsn-w54100.2022.00034
2022-01-01
Abstract:Network intrusion detection is a real-time technology to protect the network from attack, which plays a major role in the server system and network security. However, network intrusion detection still faces multiple challenges, such as inconsistent data distribution between training and testing dataset, imbalanced data categories and low accuracy rate. To solve these problems, a two-layer soft-voting ensemble learning model with RF, lightGBM and XGBoost as base classifiers is proposed in this paper. Firstly, the model uses the adversarial validate algorithm to test the consistency of data distribution in training and testing dataset to determine whether the dataset needs re-splitting. Secondly, the model adopts the Synthetic Minority Oversampling Technique (SMOTE) to synthesize samples of minority classes, which helps improve the accuracy rate of minority classes. Finally, the experimental results show that the soft-voting ensemble learning model has a higher accuracy rate in both binary and multi-classification than other single models, which proves to be both feasible and efficient. In particular, the recall rate of DoS, ShellCode, Worms and Reconnaissance is significantly increased in multi-classification.
What problem does this paper attempt to address?