arrow
返回

Machine learning-based intrusion detection: feature selection versus feature extraction

delete2023-07-05
delete9
PRE
AI
V
Vu-Duc Ngo
T
Tuan-Cuong Vuong
T
Thien Van Luong
H
Hung Tran *
DOI:10.1007/s10586-023-04089-5delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Internet of Things (IoTs) has been playing an important role in many sectors, such as smart cities, smart agriculture, smart healthcare, and smart manufacturing. However, IoT devices are highly vulnerable to cyber-attacks, which may result in security breaches and data leakages. To effectively prevent these attacks, a variety of machine learning-based network intrusion detection methods for IoT networks have been developed, which often rely on either feature extraction or feature selection techniques for reducing the dimension of input data before being fed into machine learning models. This aims to make the detection complexity low enough for real-time operations, which is particularly vital in any intrusion detection systems. This paper provides a comprehensive comparison between these two feature reduction methods of intrusion detection in terms of various performance metrics, namely, precision rate, recall rate, detection accuracy, as well as runtime complexity, in the presence of the modern UNSW-NB15 dataset as well as both binary and multiclass classification. For example, in general, the feature selection method not only provides better detection performance but also lower training and inference time compared to its feature extraction counterpart, especially when the number of reduced features K increases. However, the feature extraction method is much more reliable than its selection counterpart, particularly when K is very small, such as K = 4. Additionally, feature extraction is less sensitive to changing the number of reduced features K than feature selection, and this holds true for both binary and multiclass classifications. Based on this comparison, we provide a useful guideline for selecting a suitable intrusion detection type for each specific scenario, as detailed in Table 14 at the end of Sect. 4. Note that such the comparison between feature selection and feature extraction over UNSW-NB15 as well as theoretical guideline have been overlooked in the literature.
Keyword:
Intrusion detection
UNSW-NB15
Feature selection
Feature extraction
PCA
Machine learning
Internet of Things
Runtime
Binary
multiclass classification
NIDS
IoT

期刊

C
Cluster Computing-The Journal of Networks Software Tools and Applications
IF:
4.1
论文数:
5.1K
被引数:
7.5K

机构

H
hanoi university of science & technology (hust)
学者数:
3.3K
论文数: 2.2K
被引数: 1
引用论文

引用论文

Dual Regularized Unsupervised Feature Selection Based on Matrix Factorization and Minimum Redundancy with application in gene selection
err2022-11-01
err59
errOAAI
errSaberi-Movahed, Farid; Rostami, Mehrdad; Berahmand, Kamal; Karami, Saeed; Tiwari, Prayag; Oussalah, Mourad; Band, Shahab S.
err分享
err收藏
Variational LSTM Enhanced Anomaly Detection for Industrial Big Data
err2021-05-01
err269
errOAAI
errZhou, Xiaokang; Hu, Yiyong; Liang, Wei; Ma, Jianhua; Jin, Qun
err分享
err收藏
TSE-IDS: A Two-Stage Classifier Ensemble for Intelligent Anomaly-Based Intrusion Detection System
err2019-01-01
err227
errOAAI
errTama, Bayu Adhi; Comuzzi, Marco; Rhee, Kyung-Hyune
err分享
err收藏
err分享
err收藏
学者 查看更多内容