Intrusion Detection based on Non-negative Positive-unlabeled Learning
Sicai Lv, Yang Liu, Zhiyao Liu, Chao Wang, Chenrui Wu, Bailing Wang · 2020 IEEE 9th Data Driven Control and Learning Systems Conference (DDCLS) · 2020
Due to the diversity of network traffic flow, intrusion detection is usually studied as an anomaly detection problem. In this paper, Positive-unlabeled with Non-negative Risk Estimator(nnPU) learning is introduced for intrusion detection. The cyber attacks is treated as positive samples in PU learning. A risk estimator is raised to estimates the binary classification loss. For data imbalance in intrusion detection, we improve the risk estimator of nnPU through focal loss(FL-nnPU). The dynamic weights in focal loss is used to balance the small class prior. The experiments result show that FL-nnPU have a close performance to binary classification, and it performs better than nnPU under data imbalance problems.