Improving Intrusion Detection with Domain-Invariant Representation Learning in Latent Space

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Roy, Padmaksha, Cody, Tyler, Singhal, Himanshu, Choi, Kevin, Jin, Ming
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912653117489152
author Roy, Padmaksha
Cody, Tyler
Singhal, Himanshu
Choi, Kevin
Jin, Ming
author_facet Roy, Padmaksha
Cody, Tyler
Singhal, Himanshu
Choi, Kevin
Jin, Ming
contents Zero-day anomaly detection is critical in industrial applications where novel, unforeseen threats can compromise system integrity and safety. Traditional detection systems often fail to identify these unseen anomalies due to their reliance on in-distribution data. Domain generalization addresses this gap by leveraging knowledge from multiple known domains to detect out-of-distribution events. In this work, we introduce a multi-task representation learning technique that fuses information across related domains into a unified latent space. By jointly optimizing classification, reconstruction, and mutual information regularization losses, our method learns a minimal(bottleneck), domain-invariant representation that discards spurious correlations. This latent space decorrelation enhances generalization, enabling the detection of anomalies in unseen domains. Our experimental results demonstrate significant improvements in zero-day or novel anomaly detection across diverse anomaly detection datasets.
format Preprint
id arxiv_https___arxiv_org_abs_2312_17300
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Improving Intrusion Detection with Domain-Invariant Representation Learning in Latent Space
Roy, Padmaksha
Cody, Tyler
Singhal, Himanshu
Choi, Kevin
Jin, Ming
Cryptography and Security
Machine Learning
Zero-day anomaly detection is critical in industrial applications where novel, unforeseen threats can compromise system integrity and safety. Traditional detection systems often fail to identify these unseen anomalies due to their reliance on in-distribution data. Domain generalization addresses this gap by leveraging knowledge from multiple known domains to detect out-of-distribution events. In this work, we introduce a multi-task representation learning technique that fuses information across related domains into a unified latent space. By jointly optimizing classification, reconstruction, and mutual information regularization losses, our method learns a minimal(bottleneck), domain-invariant representation that discards spurious correlations. This latent space decorrelation enhances generalization, enabling the detection of anomalies in unseen domains. Our experimental results demonstrate significant improvements in zero-day or novel anomaly detection across diverse anomaly detection datasets.
title Improving Intrusion Detection with Domain-Invariant Representation Learning in Latent Space
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2312.17300