When using an intrusion detection system as protection against certain kind of attacks, the impact of classifying normal samples as attacks (False Positives) or attacks as normal traffic (False Negatives) is completely different. In order to prioritize the absence of one kind of error, we use reinforcement learning strategies which allow us to build a cost-sensitive meta-classifier. This classifier has been build using a DQN architecture over a MLP. While the DQN introduces extra effort during the training steps, it does not cause any penalty on the detection system. We show the feasibility of our approach for two different and commonly used datasets, achieving reductions up to 100% in the desired error by changing the rewarding strategies.
CITATION STYLE
Blanco, R., Cilla, J. J., Briongos, S., Malagón, P., & Moya, J. M. (2018). Applying Cost-Sensitive Classifiers with Reinforcement Learning to IDS. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 11314 LNCS, pp. 531–538). Springer Verlag. https://doi.org/10.1007/978-3-030-03493-1_55
Mendeley helps you to discover research relevant for your work.