Vše

Co hledáte?

Vše
Projekty
Výsledky výzkumu
Subjekty

Rychlé hledání

  • Projekty podpořené TA ČR
  • Významné projekty
  • Projekty s nejvyšší státní podporou
  • Aktuálně běžící projekty

Chytré vyhledávání

  • Takto najdu konkrétní +slovo
  • Takto z výsledků -slovo zcela vynechám
  • “Takto můžu najít celou frázi”

A Multi-Head Attention and Residual Dense Network with Dynamic Sampling for Fine-Grained Network Intrusion Classification

Identifikátory výsledku

  • Kód výsledku v IS VaVaI

    <a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F00216305%3A26220%2F26%3A0201253" target="_blank" >RIV/00216305:26220/26:0201253 - isvavai.cz</a>

  • Výsledek na webu

    <a href="http://dx.doi.org/10.1109/icumt67815.2025.11268763" target="_blank" >http://dx.doi.org/10.1109/icumt67815.2025.11268763</a>

  • DOI - Digital Object Identifier

    <a href="http://dx.doi.org/10.1109/icumt67815.2025.11268763" target="_blank" >10.1109/icumt67815.2025.11268763</a>

Alternativní jazyky

  • Jazyk výsledku

    angličtina

  • Název v původním jazyce

    A Multi-Head Attention and Residual Dense Network with Dynamic Sampling for Fine-Grained Network Intrusion Classification

  • Popis výsledku v původním jazyce

    Network Intrusion Detection Systems are essential for monitoring and analyzing network traffic to detect and prevent unauthorized access, malicious activities, and security breaches in real time. Network intrusion detection systems face persistent challenges in accurately identifying finegrained attack subcategories due to class imbalance, limited feature interactions in tabular data, and variability across different time windows. Models often struggle to capture the hidden patterns required for multi-class classification in imbalanced flow-based datasets. To overcome these limitations, this work proposes a deep learning framework that combines Multi-Head Self-Attention (MHSA) with Residual Dense Blocks (RDBs) for fine-grained intrusion classification. The MHSA layers enable the model to learn complex, non-sequential feature dependencies by attending multiple feature interactions simultaneously. The RDBs enhance depth and gradient stability, facilitating effective learning in deep networks, especially under sparse class conditions. A dynamic sampling strategy is incorporated during training, employing SMOTE for oversampling minority classes and random under-sampling of majority classes to ensure balanced learning. The model is trained and evaluated on the large dataset across four temporal resolutions (5s, 10s, 30s, 60s), targeting classification across 13 subcategories. The proposed architecture achieves a peak accuracy of 99.89% on the 10 -second window and maintains high recall across rare attack types such as recon-dns and brute force-ftp. This methodology demonstrates a robust and scalable solution for real-time, multi-class intrusion detection, offering improvements in accuracy, fairness, and adaptability over existing baseline models.

  • Název v anglickém jazyce

    A Multi-Head Attention and Residual Dense Network with Dynamic Sampling for Fine-Grained Network Intrusion Classification

  • Popis výsledku anglicky

    Network Intrusion Detection Systems are essential for monitoring and analyzing network traffic to detect and prevent unauthorized access, malicious activities, and security breaches in real time. Network intrusion detection systems face persistent challenges in accurately identifying finegrained attack subcategories due to class imbalance, limited feature interactions in tabular data, and variability across different time windows. Models often struggle to capture the hidden patterns required for multi-class classification in imbalanced flow-based datasets. To overcome these limitations, this work proposes a deep learning framework that combines Multi-Head Self-Attention (MHSA) with Residual Dense Blocks (RDBs) for fine-grained intrusion classification. The MHSA layers enable the model to learn complex, non-sequential feature dependencies by attending multiple feature interactions simultaneously. The RDBs enhance depth and gradient stability, facilitating effective learning in deep networks, especially under sparse class conditions. A dynamic sampling strategy is incorporated during training, employing SMOTE for oversampling minority classes and random under-sampling of majority classes to ensure balanced learning. The model is trained and evaluated on the large dataset across four temporal resolutions (5s, 10s, 30s, 60s), targeting classification across 13 subcategories. The proposed architecture achieves a peak accuracy of 99.89% on the 10 -second window and maintains high recall across rare attack types such as recon-dns and brute force-ftp. This methodology demonstrates a robust and scalable solution for real-time, multi-class intrusion detection, offering improvements in accuracy, fairness, and adaptability over existing baseline models.

Klasifikace

  • Druh

    O - Ostatní výsledky

  • CEP obor

  • OECD FORD obor

    20200 - Electrical engineering, Electronic engineering, Information engineering

Návaznosti výsledku

  • Projekt

    <a href="/cs/project/FW10010014" target="_blank" >FW10010014: Nová automatizace procesů řízená umělou inteligencí pro zjednodušení a zlepšení telekomunikačních procesů</a><br>

  • Návaznosti

    P - Projekt vyzkumu a vyvoje financovany z verejnych zdroju (s odkazem do CEP)

Ostatní

  • Rok uplatnění

    2025

  • Kód důvěrnosti údajů

    S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů