Overcoming Class Imbalance in Network Intrusion Detection: A Gaussian Mixture Model and ADASYN Augmented Deep Learning Framework
Xin Chen, Zhuoqi Gong, Dixin Huang, Nan Jiang, Yuejin Zhang · 2024
Intrusion detection in computer networks, as a critical component for maintaining network security, has become increasingly essential in the face of the widespread and evolving threats within the complex internet environment. In recent years, the widespread application of machine learning and deep learning technologies has emerged as a crucial means to counteract network threats. Despite significant advances in classification accuracy achieved by these algorithms, challenges persist in addressing the minority class problem within imbalanced datasets. This study proposes an innovative approach that combines the Adaptive Synthetic (ADASYN) sampling method with a Gaussian Mixture Model (GMM) clustering-based sampling method termed AGM. Building upon this, we enhance traditional deep learning models by adopting a comprehensive network architecture known as C3BANet, which integrates Convolutional Neural Network (CNN), Bidirectional Long Short-Term Memory (BiLSTM), and Channel-Attention mechanisms. we meticulously preprocess the UNSW-NB15 dataset to eliminate noise, inconsistencies, and incompleteness. Subsequently, the dataset undergoes carefully designed sampling using the AGM method to address the issue of poor performance on minority classes caused by the majority class prediction bias. Ultimately, we validate the effectiveness of the enhanced C3BANet model on the UNSW-NB15 dataset. Experimental results demonstrate that, after AGM sampling, the model achieves multiclass detection rates of 96.82%, respectively, on the UNSW-NB15 dataset, outperforming current mainstream intrusion detection algorithms. This research not only introduces methodological innovations but also exhibits significant advantages in practical applications.