paper-with-me

홈 › Papers

One-class Collective Anomaly Detection based on Long Short-Term Memory Recurrent Neural Networks

2018-01-31 · Nga Nguyen Thi, Van Loi Cao, Nhien-An Le-Khac

Intrusion detection for computer network systems has been becoming one of the most critical tasks for network administrators today. It has an important role for organizations, governments and our society due to the valuable resources hosted on computer networks. Traditional misuse detection strategies are unable to detect new and unknown intrusion types. In contrast, anomaly detection in network security aims to distinguish between illegal or malicious events and normal behavior of network systems. Anomaly detection can be considered as a classification problem where it builds models of normal network behavior, of which it uses to detect new patterns that significantly deviate from the model. Most of the current approaches on anomaly detection is based on the learning of normal behavior and anomalous actions. They do not include memory that is they do not take into account previous events classify new ones. In this paper, we propose a one class collective anomaly detection model based on neural network learning. Normally a Long Short Term Memory Recurrent Neural Network (LSTM RNN) is trained only on normal data, and it is capable of predicting several time steps ahead of an input. In our approach, a LSTM RNN is trained on normal time series data before performing a prediction for each time step. Instead of considering each time-step separately, the observation of prediction errors from a certain number of time-steps is now proposed as a new idea for detecting collective anomalies. The prediction errors of a certain number of the latest time-steps above a threshold will indicate a collective anomaly. The model is evaluated on a time series version of the KDD 1999 dataset. The experiments demonstrate that the proposed model is capable to detect collective anomaly efficiently

📄 PDF Abstract BibTeX arXiv:1802.00324

Code (0)

등록된 구현이 없습니다.

Tasks

Anomaly DetectionIntrusion DetectionTime SeriesTime Series Analysis

Methods 이 논문이 사용한 방법론

Sigmoid Activation 설명 없음
Tanh Activation 설명 없음
LSTM An LSTM is a type of recurrent neural network that addresses the vanishing gradient problem in vanilla…

Similar Papers 제목 키워드 기반

Collective Anomaly Detection based on Long Short Term Memory Recurrent Neural Network

2017-03-28 · Loic Bontemps, Van Loi Cao, James McDermott, Nhien-An Le-Khac

Intrusion detection for computer network systems becomes one of the most critical tasks for network administrators today. It has an important role for organizations, governments and our society due to its valuable resour…

Anomaly DetectionIntrusion DetectionTime SeriesTime Series Analysis

CoBAD: Modeling Collective Behaviors for Human Mobility Anomaly Detection

2025-08-13 · Haomin Wen, Shurui Cao, Leman Akoglu arxiv

Detecting anomalies in human mobility is essential for applications such as public safety and urban planning. While traditional anomaly detection methods primarily focus on individual movement patterns (e.g., a child sho…

Anomaly Detection

Big data analysis and distributed deep learning for next-generation intrusion detection system optimization

2022-09-28 · Khloud Al Jallad, Mohamad Aljnidi, Mohammad Said Desouki

With the growing use of information technology in all life domains, hacking has become more negatively effective than ever before. Also with developing technologies, attacks numbers are growing exponentially every few mo…

Anomaly DetectionChatbotIntrusion Detection

Is Task-Specific Training Necessary for Anomaly Detection?

2026-01-30 · Xingwu Zhang, Guanxuan Li, Paul Henderson, Gerardo Aragon-Camarasa 외 arxiv

Current state-of-the-art multi-class unsupervised anomaly detection (MUAD) methods rely on training encoder--decoder models to reconstruct anomaly-free features. However, we argue that such task-specific training is cost…

Unsupervised Anomaly Detection

Holistic Features For Real-Time Crowd Behaviour Anomaly Detection

2016-06-16 · M. Marsden, K. McGuinness, S. Little, N. E. O'Connor

This paper presents a new approach to crowd behaviour anomaly detection that uses a set of efficiently computed, easily interpretable, scene-level holistic features. This low-dimensional descriptor combines two features …

Anomaly DetectionBinary ClassificationGeneral ClassificationOutlier Detection