Clustering-Based Intrusion Detection System Meets Multicritics Generative Adversarial Networks

Haofan Wang, Farah I. Kandah, Thilina Mendis, Lalith Medury · IEEE Internet of Things Journal · 2025

Network security has continuously been a major focus of research and concern on a global scale. The intrusion detection system (IDS), as a crucial defensive measure against network attacks, has undergone multiple iterations and evolutions since its inception to adapt to the ever-changing network environment. Due to the widespread issue of data imbalance in network security datasets, a single machine learning or deep learning model often struggles to effectively handle different types of attacks. In this work, we propose a multicritics generative adversarial networks (GAN) clustering-based IDS (MCGC-IDS) model to address the issue of data imbalance. The quality of the generated data is analyzed using correlation heatmaps and PCA plots, which later is used to update the dataset that is utilized for feature extraction with autoencoders (AEs). Subsequently, CNN-LSTM models are employed to analyze clusters formed by the weighted fuzzy c-means (WFCM) clustering algorithm to achieve enhanced performance for the IDS system. This model is then compared with two existing models. The results indicate that while the GAN-generated data retains the original dataset distribution, it also addresses the issue of imbalance. Moreover, the subsequent multilayered processing enables the overall model to more effectively handle various types of attacks. Finally, when this model is tested on a similar dataset, the UNSW-NB15, it continues to demonstrate superior performance, indicating its strong generalizability.

Read the paper · More papers on PaperTik