A New Intrusion Detection Model Transformer_KAN
Yufei Ji, Lihong Guo, Tiancheng Hu, Jinao Wei · 2024
With the rapid development of network technology, the type and scale of network cyberattacks are also evolving, and the network security problem is becoming increasingly serious. In this paper, we propose a new intrusion detection model, Transformer_KAN, which combines the advantages of the KAN and Transformer models to efficiently handle large-scale and multi-dimensional network traffic data. In this model, the univariate spline function of the KAN model is used instead of the linear weights in the traditional MLP, which fully uses of the nonlinear correlation between features and improves the feature representation capability. In addition, with the powerful sequence modeling capability of the Transformer model, the potential dependencies in the time series are effectively captured to improve the system’s ability to identify complex attack patterns. To verify the performance of the new model, we tested it on the CIC-IDS2017 dataset. Results show that the Transformer_KAN model achieves significant improvement in the accuracy rate, loss value, and other metrics compared with the traditional machine learning and a single deep learning model, and especially performs excellently in detecting a few classes of attack samples. The proposed model provides an efficient and widely applicable solution for the development of IDS.