DeepAID: Interpreting and Improving Deep Learning-based Anomaly Detection in Security Applications

09/23/2021
by   Dongqi Han, et al.
0

Unsupervised Deep Learning (DL) techniques have been widely used in various security-related anomaly detection applications, owing to the great promise of being able to detect unforeseen threats and superior performance provided by Deep Neural Networks (DNN). However, the lack of interpretability creates key barriers to the adoption of DL models in practice. Unfortunately, existing interpretation approaches are proposed for supervised learning models and/or non-security domains, which are unadaptable for unsupervised DL models and fail to satisfy special requirements in security domains. In this paper, we propose DeepAID, a general framework aiming to (1) interpret DL-based anomaly detection systems in security domains, and (2) improve the practicality of these systems based on the interpretations. We first propose a novel interpretation method for unsupervised DNNs by formulating and solving well-designed optimization problems with special constraints for security domains. Then, we provide several applications based on our Interpreter as well as a model-based extension Distiller to improve security systems by solving domain-specific problems. We apply DeepAID over three types of security-related anomaly detection systems and extensively evaluate our Interpreter with representative prior works. Experimental results show that DeepAID can provide high-quality interpretations for unsupervised DL models while meeting the special requirements of security domains. We also provide several use cases to show that DeepAID can help security operators to understand model decisions, diagnose system mistakes, give feedback to models, and reduce false positives.

READ FULL TEXT

page 3

page 19

research
12/04/2020

Deep Learning for Medical Anomaly Detection – A Survey

Machine learning-based medical anomaly detection is an important problem...
research
10/09/2019

Explaining Deep Learning-Based Networked Systems

While deep learning (DL)-based networked systems have shown great potent...
research
03/14/2021

A new interpretable unsupervised anomaly detection method based on residual explanation

Despite the superior performance in modeling complex patterns to address...
research
09/25/2018

A Framework for Data-Driven Physical Security and Insider Threat Detection

This paper presents PS0, an ontological framework and a methodology for ...
research
01/07/2021

Corner case data description and detection

As the major factors affecting the safety of deep learning models, corne...
research
06/22/2022

Human-AI communication for human-human communication: Applying interpretable unsupervised anomaly detection to executive coaching

In this paper, we discuss the potential of applying unsupervised anomaly...

Please sign up or login with your details

Forgot password? Click here to reset