Intrusion Detection Using Convolutional Neural Network: A Color Mapping Approach on NSL-KDD Dataset
Md. Abrar Faiaz, Dipankar Mitra, Ranat Das Prangon · 2024
Converting any kind of data to image data can make the dataset suitable for Convolutional Neural Networks (CNNs). In this study, the NSL-KDD dataset was converted to image data using the color mapping technique and using CNN a good accuracy of 98.91% and aggregated f1 score of 0.91 was achieved. Here an image representation of each row was generated using both Hue-Saturation-Value (HSV) and Viridis colormap. Though some attack types were misclassified by the model, no attack sample of the validation dataset was classified as normal. For model training, five CNN architectures were evaluated by transfer learning from their pre-trained weights. It was found that ResNet18 performs best among all the five architectures evaluated. ResNet18 uses 1x1 convolution to reduce the number of parameters used. It means that for the classification of the colormap of this dataset complex CNN architectures are not necessary. Fine-tuning of the ResNet18, the best-performing architecture, was done using 50 epochs using an optimal learning rate. However, the accuracy mentioned above was found only after 4 epochs demonstrating good efficiency of the model training. The NSL-KDD dataset contains information about network intrusion in tabular format. Hence, this model can be used for intrusion detection purposes.