Deep Reinforcement Learning based Network Intrusion Classification
Loading...
Date
Authors
Journal Title
Journal ISSN
Volume Title
Publisher
UIU
DOI
Abstract
Network intrusion classification referred to the process of monitoring and analyzing network traffic to identify suspicious activities or attacks. In this work, author proposed a novel approach to classify network intrusion by utilizing deep reinforcement learning
(DRL), integrating a hybrid deep learning model architecture that combined Deep Neural Network (DNN) and Long Short-Term Memory (LSTM) networks. A DRL-based approach improved upon traditional deep learning by adapting dynamically to novel/unknown and evolving attack patterns. Unlike static models, DRL continuously learned optimal strategies through interaction with the environment, allowing for better detection of previously unseen threats in real-time. To address the class imbalance often encountered in network intrusion datasets, I evaluated the performance of several advanced data balancing
techniques, including Borderline-SMOTE, SMOTE-ENN, ADYSN, and K-means SMOTE. The findings demonstrated that the K-means-based data balancing method outperformed other techniques, resulting in the most robust performance across various metrics. Author conducted multi-dataset validation to ensure robustness across different network flow data. For adaptive modeling testing, author excluded some attack types from training data and included them in testing data (e.g., DoS attacks were excluded from the training data but included in the testing data). The proposed approach enhanced the accuracy and
reliability of intrusion detection, making it a viable solution for securing modern network infrastructures.
