Multiple-Input Auto-Encoder for IoT Intrusion Detection Systems with Heterogeneous Data

Phai Vu Dinh, Dinh Thai Hoang, Nguyen Quang Uy, Diep Ngoc Nguyen, Son Pham Bao, Eryk Dutkiewicz · 2024

Machine learning is a core component of many Intrusion Detection Systems (IDS) for IoT networks. However, developing a robust machine-learning model for IDSs on IoT networks is very challenging. This is due to the diversity of IoT devices resulting in the inconsistency and high dimensions of data collected from IoT networks. In other words, in IoT environments, the training data for IDSs on IoT networks is often heterogeneous since they are collected from multiple sources with different characteristics. To tackle these problems, this paper proposes a novel neural network architecture called Multiple-Input Auto-Encoder (MIAE). MIAE has multiple sub-encoders that can process multiple input sources with different dimensions. Moreover, the MIAE model is trained in an unsupervised learning mode, and it can transfer the heterogeneous inputs into lower-dimensional representation to facilitate classifiers to distinguish between the normal samples and types of attacks. The experimental results on the three most popular benchmark IDS datasets, i.e., NSLKDD, UNSW-NB15, and IDS2017, show the superior performance of the MIAE over three groups of methods including conventional classifiers, state-of-the-art dimensionality reduction models, and unsupervised representation learning methods for multiple inputs with different dimensions. MIAE combined with the Random Forest (RF) classifier also achieves 96.2% in terms of accuracy in detecting sophisticated attacks, e.g., Slowloris. In addition, the average running time for detecting an attack sample obtained by MIAE combined with RF classifier is only roughly 5E-7 seconds, whilst the model size is lower than 1 MB. This clearly shows the effectiveness of our proposed model when deployed in practice.

Read the paper · More papers on PaperTik