Anomaly Based Intrusion Detection Using Large Language Models

Zineb Maasaoui, Mheni Merzouki, Abdella Battou, Ahmed Lbath · 2024

In the context of modern networks where cyber-attacks are increasingly complex and frequent, traditional Intrusion Detection Systems (IDS) often struggle to manage the vast volume of data and fail to detect novel attacks. Leveraging Artificial Intelligence, specifically Natural Language Processing with transformer architectures, offers a promising solution. This study applies the Bidirectional Encoder Representations from Transformers (BERT) model, enhanced by a Byte-level Byte-pair tokenizer (BBPE), to effectively identify network-based attacks within IoT systems. Experiments on three datasets-UNSW-NB15, TON-IoT, and Edge-IIoT-show that our approach substantially outperforms traditional methods in multi-class classification tasks. Notably, we achieved near-perfect classification accuracy on the Edge-IIoT dataset, with significant improvements in F1 scores and reduction in validation losses across all datasets, demonstrating the efficacy of pre-trained Large Language Models (LLMs) in network security.

Read the paper · More papers on PaperTik