OpenCADP: Open-Set Intrusion Detection with a Cluster Anomaly Detection Plugin

Guolou Ping
DOI: https://doi.org/10.1109/smc53992.2023.10393991
2023-01-01
Abstract:Open-set recognition has gained significant attention in intrusion detection due to its ability to classify known attacks and identify novel attacks. However, current approaches based solely on discriminative features may fail to identify new data with non-discriminative feature differences and are prone to adversarial attacks. To overcome these limitations, this paper proposes an open-set intrusion detection framework that incorporates a cluster anomaly detection plugin to identify non-discriminative unknown classes by introducing primitive features and detecting adversarial examples through cluster design. Specifically, 1) we use the anomaly detection plugin trained with primitive features from the raw data to discover unseen data. Samples rejected by either deep discriminative classifiers or detection plugins are considered unknown. 2) We design the plugin as a cluster of one-class anomaly detectors. This approach effectively isolates adversarial examples carefully crafted to deceive the deep classifier. 3) We provide theoretical evidence of the proposed framework's ability to detect non-discriminative unknown classes and adversarial examples. Extensive experiments demonstrate the effectiveness of our approach when applied to open-set intrusion detection.
What problem does this paper attempt to address?