Published August 1, 2021 | Version v1
Journal article Open

Accelerating the update of a DL-based IDS for IoT using deep transfer learning

  • 1. MATSI Research Lab., ESTO, Mohammed First University, Oujda, Morocco

Description

Deep learning (DL) models are nowadays broadly applied and have shown outstanding performance in a variety of fields, including our focus topic of "IoT cybersecurity". Deep learning-based intrusion detection system (DL-IDS) models are more fixated and depended on the trained dataset. This poses a problem for these DL-IDS, especially with the known mutation and behavior changes of attacks, which can render them undetected. As a result, the DL-IDS has become outdated. In this work, we present a solution for updating DL-IDS employing a transfer learning technique that allows us to retrain and fine-tune pre-trained models on small datasets with new attack behaviors. In our experiments, we built CNN-based IDS on the Bot-IoT dataset, and updated it on small data from a new dataset named TON-IoT. We obtained promising results in multiple metrics regarding the detection rate and the training between the initial training for the original model and the updated one, in the matter of detecting new attacks behaviors and improving the detection rate for some classes by overcoming the lack of their labeled data.

Files

48 25630.pdf

Files (636.9 kB)

Name Size Download all
md5:b1e904a2c95125488479d37f7993b64a
636.9 kB Preview Download