Authors
Nico Görnitz, Marius Kloft, Konrad Rieck, Ulf Brefeld
Publication date
2009/11/9
Book
Proceedings of the 2nd ACM workshop on Security and artificial intelligence
Pages
47-54
Description
Anomaly detection for network intrusion detection is usually considered an unsupervised task. Prominent techniques, such as one-class support vector machines, learn a hypersphere enclosing network data, mapped to a vector space, such that points outside of the ball are considered anomalous. However, this setup ignores relevant information such as expert and background knowledge. In this paper, we rephrase anomaly detection as an active learning task. We propose an effective active learning strategy to query low-confidence observations and to expand the data basis with minimal labeling effort. Our empirical evaluation on network intrusion detection shows that our approach consistently outperforms existing methods in relevant scenarios.
Total citations
20092010201120122013201420152016201720182019202020212022202320241115658410781112961
Scholar articles
N Görnitz, M Kloft, K Rieck, U Brefeld - Proceedings of the 2nd ACM workshop on Security and …, 2009