Normalizing-Flow-Based Anomaly Scoring for Intelligent Network Intrusion Detection

Ahmad Ammar, Abdullah Al Bassam · 2025

We present a new approach to intrusion detection in an unsupervised mode, using the normalizing flows trained only on benign traffic data. Our technique, utilizing state-of-the-art density-estimation methods (RealNVP), includes multiple affine coupling and permutation layers that allow it to fit the distribution of benign traffic flows accurately while never having an opportunity to observe actual attack instances. Once this probabilistic model has been learned, the model gives exact likelihoods for each flow, enabling a simple mechanism to score anomalies based on negative log-likelihood. Using a detection threshold selected based on Youden's index, our model can detect a variety of attacks-perhaps in the most unified way to date-including DoS, DDoS, port scans, infiltration, and botnet activities. Our framework finds attack patterns from a comprehensive publicly available dataset containing various benign and malicious traffic for very high performance, achieving an ROC-AUC score greater than 0.97 and accuracy greater than 0.94, well above that afforded by conventional approaches of unsupervised detection. Some of its advantages lie in fully unsupervised training, interpretability through likelihood-based scores, and adaptability-great in detecting zero-day attacks and unseen network threats.

Read the paper · More papers on PaperTik