Harnessing Unsupervised <scp>LSTM</scp> Autoencoders for Anomaly Detection in Cybersecurity Time Series
At a glance
- الاستشهادات
- 0
- المراجع
- 27
- Comments
- 0
Abstract
ABSTRACT The rapid growth of cyber threats demands effective anomaly detection systems. However, current methods often struggle with novel attacks, high false‐positive rates, and poor interpretability, especially in imbalanced environments. To address these gaps, this study proposes an unsupervised LSTM Autoencoder that learns a tightly defined baseline of normal behavior. The model was trained exclusively on the most frequent normal connection state from the CTU‐13 dataset and then tested on mixed traffic. It achieved an overall accuracy of 93.1% and an AUC of 0.87, demonstrating its effectiveness in identifying traffic that matched the learned baseline. Despite this, its performance on malicious botnet traffic was modest (F1‐score: 0.24), revealing a critical trade‐off between specialization and generalization. This work contributes a transparent anomaly detection strategy and offers clear insights into the challenge of distinguishing novel benign behaviors from genuine threats in network data.
Publication details
- DOI
- 10.1002/spy2.70118
- OpenAlex
- W4415120214
- Document type
- article
- Language
- EN
- Source
- Security and Privacy
- Last metadata update
Comments
تسجيل الدخول للانضمام إلى النقاش.