نموذج كشف التسلل الشبكي باستخدام اختيار الميزات القائم على الغلاف ومحولات الانتباه متعددة الرؤوس
Network intrusion detection model using wrapper based feature selection and multi head attention transformers

شارك:
المجلة: Scientific Reports، المجلد: 15، العدد: 1
DOI: https://doi.org/10.1038/s41598-025-11348-5
PMID: https://pubmed.ncbi.nlm.nih.gov/40769994
تاريخ النشر: 2025-08-06
المؤلف: Muhammad Fahad Umer وآخرون
الموضوع الرئيسي: أمن الشبكات وكشف التسلل

نظرة عامة

تناقش الورقة البحثية زيادة تعرض الأنظمة المترابطة عبر مختلف القطاعات، مثل الرعاية الصحية والنقل، للهجمات الإلكترونية. تكافح تدابير الأمان التقليدية للتعامل مع التعقيد المتزايد وتنوع هذه التهديدات. لمعالجة هذا التحدي، يقترح المؤلفون نموذج كشف اقتحام جديد يستخدم مجموعة بيانات UNSW-NB15. يستخدم هذا النموذج تقنية اختيار الميزات القائمة على الغلاف لتحديد الميزات الأكثر صلة، والتي تتم معالجتها بعد ذلك من خلال محول يعتمد على الانتباه متعدد الرؤوس. تظهر مقاييس التقييم—الدقة، الدقة، الاسترجاع، ودرجة F1—تحسينات كبيرة في أداء الكشف.

في الختام، يبرز المؤلفون فعالية إطارهم المعتمد على المحولات المحسّنة، حيث حققوا دقة بنسبة 93%، ودقة بنسبة 91%، واسترجاع بنسبة 92%، ودرجة F1 بنسبة 92%. يعزز دمج آلية الانتباه متعدد الرؤوس قدرة النموذج على تحليل جوانب متعددة من بيانات الإدخال، بينما تعالج تقنيات مثل SMOTE قضايا عدم توازن البيانات. بالإضافة إلى ذلك، يتم استخدام تقنيات تقليل الأبعاد وطبقات الإسقاط للتخفيف من الإفراط في التكيف. تشير النتائج إلى أن الجمع بين اختيار الميزات المتقدم مع هياكل المحولات يمكن أن يتعامل بفعالية مع التحديات الأمنية المعقدة. قد تستكشف الأعمال المستقبلية دمج آليات انتباه أكثر تعقيدًا وطرق هجينة، مثل الجمع بين المحولات والشبكات التنافسية التوليدية (GANs) أو طرق التجميع، لتعزيز أداء النموذج بشكل أكبر.

طرق

تحدد هذه القسم منهجية لكشف الاقتحامات الشبكية باستخدام تقنيات التعلم الآلي، مع التركيز بشكل خاص على اختيار الميزات ونماذج المحولات. تهدف هذه الطريقة إلى تعزيز أداء هذه النماذج من خلال تحسين عمليات اختيار الميزات. يتضمن التصميم التجريبي عدة مراحل: جمع البيانات، المعالجة المسبقة، اختيار الميزات، تدريب النموذج، والتقييم، مع تقديم توضيحات مفصلة في الشكل 2 والخوارزمية 1.

استخدم الإعداد التجريبي Google Colab للتنفيذ بلغة بايثون، مع الاستعانة بمكتبات مثل TensorFlow وKeras وScikit-learn وPandas. تم اختبار طرق مختلفة لمعالجة عدم توازن الفئات، بما في ذلك العينة الزائدة العشوائية، العينة الناقصة العشوائية، وتقنية العينة الزائدة للأقليات الاصطناعية (SMOTE). تشير النتائج، الملخصة في الجدول 5، إلى أن SMOTE يتفوق بشكل كبير على الطرق الأخرى، محققًا دقة بنسبة 92.7% ودرجة F1 بنسبة 92%. في المقابل، حققت العينة الزائدة العشوائية دقة بنسبة 91.5%، بينما أدت العينة الناقصة العشوائية إلى أدنى دقة عند 88.3%. تشير النتائج إلى أن قدرة SMOTE على توليد عينات اصطناعية بناءً على فضاءات ميزات الفئة الأقل تعزز قابلية الفصل بين الفئات وأداء النموذج بشكل عام، مما يوفر حلاً أكثر فعالية لمشكلة عدم توازن الفئات في كشف الاقتحامات الشبكية.

نتائج

في هذا القسم، يتم تقييم النموذج المقترح باستخدام مجموعة بيانات UNSW-NB15، مع تنظيم النتائج بشكل منهجي بما يتماشى مع الأهداف البحثية المحددة. يبرز التحليل أداء النموذج عبر مقاييس مختلفة، مما يوفر رؤى حول فعاليته في معالجة المشكلة المذكورة. يتم تقديم مقارنات مفصلة للنتائج، مما يسهل فهمًا شاملاً لقدرات النموذج وقيوده في سياق مجموعة البيانات.

مناقشة

يوفر قسم المناقشة في الورقة البحثية نظرة شاملة على دمج تقنيات التعلم الآلي (ML)، والتعلم العميق (DL)، والنهج المعتمدة على المحولات في أنظمة كشف الاقتحام (IDS) عبر مجموعات بيانات مختلفة. يبرز فعالية تقنيات التعلم الآلي، مثل Fuzzy C-Means وK-Means clustering، في تحسين معدلات الكشف مع إدارة الإيجابيات الكاذبة. ومن الجدير بالذكر أن نموذج Random Forest (RF) أظهر دقة متفوقة مقارنة بأشجار القرار ومصنفات Naïve Bayes عند تقييمه على مجموعة بيانات UNSW-NB15. بالإضافة إلى ذلك، أظهرت طرق التجميع، بما في ذلك AdaBoost والنماذج الهجينة التي تجمع بين مصنفات مختلفة، نتائج واعدة في تعزيز دقة الكشف ومعالجة عدم توازن الفئات من خلال تقنيات مثل تقنية العينة الزائدة للأقليات الاصطناعية (SMOTE).

يستكشف القسم أيضًا صعود طرق التعلم العميق، التي تتفوق في التعامل مع البيانات عالية الأبعاد والتفاعلات المعقدة بين الميزات. تم استخدام هياكل مختلفة، بما في ذلك الذاكرة طويلة وقصيرة المدى (LSTM) والشبكات العصبية التلافيفية (CNN)، مع الإبلاغ عن بعض الدراسات عن دقة تتجاوز 90% على مجموعات بيانات معيارية. كما أن نماذج المحولات تكتسب زخمًا، حيث تعالج التحديات مثل وقت التدريب وتصنيف الفئات المتعددة من خلال تقنيات مبتكرة مثل تضمين الموضع والهياكل الهجينة. تؤكد الورقة على إمكانيات المحولات في تحسين أداء IDS، لا سيما من خلال تحسين استخراج الميزات والاحتفاظ بالمعلومات السياقية، مما يضع أساسًا للبحوث المستقبلية في هذا المجال.

Journal: Scientific Reports, Volume: 15, Issue: 1
DOI: https://doi.org/10.1038/s41598-025-11348-5
PMID: https://pubmed.ncbi.nlm.nih.gov/40769994
Publication Date: 2025-08-06
Author(s): Muhammad Fahad Umer et al.
Primary Topic: Network Security and Intrusion Detection

Overview

The research paper discusses the increasing vulnerability of interconnected systems across various sectors, such as healthcare and transportation, to cyberattacks. Traditional security measures struggle to cope with the growing complexity and diversity of these threats. To address this challenge, the authors propose a novel intrusion detection model that utilizes the UNSW-NB15 dataset. This model employs a wrapper-based feature selection technique to identify the most relevant features, which are then processed through a Multi-Head Attention-based transformer. The evaluation metrics—accuracy, precision, recall, and F1-score—demonstrate significant improvements in detection performance.

In the conclusion, the authors highlight the effectiveness of their optimized transformer-based framework, achieving an accuracy of 93%, precision of 91%, recall of 92%, and an F1-score of 92%. The integration of the multi-head attention mechanism enhances the model’s ability to analyze multiple aspects of the input data, while techniques such as SMOTE address data imbalance issues. Additionally, dimensionality reduction and dropout layers are employed to mitigate overfitting. The findings suggest that combining advanced feature selection with transformer architectures can effectively tackle complex security challenges. Future work may explore the integration of more sophisticated attention mechanisms and hybrid approaches, such as combining transformers with generative adversarial networks (GANs) or ensemble methods, to further enhance model performance.

Methods

The section outlines a methodology for detecting network intrusions using machine learning techniques, particularly focusing on feature selection and transformer models. The approach aims to enhance the performance of these models by optimizing feature selection processes. The experimental design includes several phases: data collection, pre-processing, feature selection, model training, and evaluation, with detailed illustrations provided in Figure 2 and Algorithm 1.

The experimental setup utilized Google Colab for implementation in Python, employing libraries such as TensorFlow, Keras, Scikit-learn, and Pandas. Various methods for addressing class imbalance were tested, including random oversampling, random undersampling, and the Synthetic Minority Over-sampling Technique (SMOTE). Results, summarized in Table 5, indicate that SMOTE significantly outperforms the other methods, achieving an accuracy of 92.7% and an F1-score of 92%. In contrast, random oversampling yielded an accuracy of 91.5%, while random undersampling resulted in the lowest accuracy at 88.3%. The findings suggest that SMOTE’s ability to generate synthetic samples based on minority class feature spaces enhances class separability and overall model performance, thereby providing a more effective solution for class imbalance in network intrusion detection.

Results

In this section, the evaluation of the proposed model is conducted using the UNSW-NB15 dataset, with findings systematically organized in alignment with the defined research objectives. The analysis highlights the model’s performance across various metrics, providing insights into its effectiveness in addressing the stated problem. Detailed comparisons of results are presented, facilitating a comprehensive understanding of the model’s capabilities and limitations in the context of the dataset.

Discussion

The discussion section of the research paper provides a comprehensive overview of the integration of machine learning (ML), deep learning (DL), and transformer-based approaches in intrusion detection systems (IDS) across various datasets. It highlights the effectiveness of ML techniques, such as Fuzzy C-Means and K-Means clustering, in improving detection rates while managing false positives. Notably, the Random Forest (RF) model demonstrated superior accuracy compared to Decision Trees and Naïve Bayes classifiers when evaluated on the UNSW-NB15 dataset. Additionally, ensemble methods, including AdaBoost and hybrid models combining different classifiers, have shown promising results in enhancing detection accuracy and addressing class imbalance through techniques like Synthetic Minority Oversampling Technique (SMOTE).

The section further explores the rise of DL methods, which excel in handling high-dimensional data and complex feature interactions. Various architectures, including Long Short-Term Memory (LSTM) and Convolutional Neural Networks (CNN), have been employed, with some studies reporting accuracies exceeding 90% on standard datasets. Transformer-based models are also gaining traction, addressing challenges such as training time and multi-class classification through innovative techniques like position embedding and hybrid architectures. The paper emphasizes the potential of transformers in improving IDS performance, particularly through enhanced feature extraction and contextual information retention, thereby setting a foundation for future research in this domain.

شارك: