article

Harnessing Unsupervised <scp>LSTM</scp> Autoencoders for Anomaly Detection in Cybersecurity Time Series

  • Security and Privacy
  • Wiley
Research footprint

At a glance

الاستشهادات
0
المراجع
27
Comments
0
Paper overview

Abstract

ABSTRACT The rapid growth of cyber threats demands effective anomaly detection systems. However, current methods often struggle with novel attacks, high false‐positive rates, and poor interpretability, especially in imbalanced environments. To address these gaps, this study proposes an unsupervised LSTM Autoencoder that learns a tightly defined baseline of normal behavior. The model was trained exclusively on the most frequent normal connection state from the CTU‐13 dataset and then tested on mixed traffic. It achieved an overall accuracy of 93.1% and an AUC of 0.87, demonstrating its effectiveness in identifying traffic that matched the learned baseline. Despite this, its performance on malicious botnet traffic was modest (F1‐score: 0.24), revealing a critical trade‐off between specialization and generalization. This work contributes a transparent anomaly detection strategy and offers clear insights into the challenge of distinguishing novel benign behaviors from genuine threats in network data.

Record transparency

Publication details

DOI
10.1002/spy2.70118
OpenAlex
W4415120214
Document type
article
Language
EN
Source
Security and Privacy
Last metadata update
المجتمع

Comments

تسجيل الدخول للانضمام إلى النقاش.

  1. لا توجد تعليقات بعد. ابدأ النقاش.