{"title":"Collaborative Multi-agent Reinforcement Learning for Intrusion Detection","authors":"Guochen Shi, Gang He","doi":"10.1109/IC-NIDC54101.2021.9660402","DOIUrl":null,"url":null,"abstract":"Network intrusion detection system (NIDS) is the essential component of cyber security infrastructure to ensure the security of communication and information systems. In this paper, a collaborative multi-agent reinforcement learning, Major-Minor-RL, is proposed to make the detection more efficient. The model consists of one major agent and several minor agents. The role of major agent is to predict whether the traffic is normal or abnormal, while minor agents are auxiliary to the major agent and help it to correct errors. If the action of major agent is different fro m the behavior of most minor agents, the final action will be determined by minor agents, while in most cases, the final action is equal to the major one. In this paper, the model has been trained on NSL-KDD dataset and the results are boosted. After comparing with the existing models, we observed much better classification performance in Major-Minor-RL intrusion detection system.","PeriodicalId":264468,"journal":{"name":"2021 7th IEEE International Conference on Network Intelligence and Digital Content (IC-NIDC)","volume":"38 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-11-17","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 7th IEEE International Conference on Network Intelligence and Digital Content (IC-NIDC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/IC-NIDC54101.2021.9660402","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4
Abstract
Network intrusion detection system (NIDS) is the essential component of cyber security infrastructure to ensure the security of communication and information systems. In this paper, a collaborative multi-agent reinforcement learning, Major-Minor-RL, is proposed to make the detection more efficient. The model consists of one major agent and several minor agents. The role of major agent is to predict whether the traffic is normal or abnormal, while minor agents are auxiliary to the major agent and help it to correct errors. If the action of major agent is different fro m the behavior of most minor agents, the final action will be determined by minor agents, while in most cases, the final action is equal to the major one. In this paper, the model has been trained on NSL-KDD dataset and the results are boosted. After comparing with the existing models, we observed much better classification performance in Major-Minor-RL intrusion detection system.