Novelty detection with CANDIES: a holistic technique based on probabilistic models

Novelty detection with CANDIES: a holistic technique based on probabilistic models
复制标题

DOI:
10.1007/s13042-016-0618-8
复制
发表时间:
2016-11
影响因子:
5.6
通讯作者:
Christian Gruhl;B. Sick
Christian Gruhl;B. Sick
中科院分区:
计算机科学3区
文献类型:
--
作者:
Christian Gruhl;B. Sick

文献摘要

被引文献

相似文献

在这篇文章中,我们提出了在智能嵌入式系统(CANSYS)中的新奇检测的组合方法,这是一种新的技术系统中新奇检测的方法。我们假设一个技术系统观察到一个可以被视为由几个过程组成的环境。当用传感器观察这些过程时,从传感器信号中提取特征,并且我们能够用概率模型对特征空间中的样本分布进行建模。在理想情况下,我们使用的参数混合密度模型的组件对应于真实的世界中的过程。最终,例如,在不可预测的失败的情况下,新的过程出现。因此,观察到需要模型适应的新类型的样本。在特征空间的低密度和高密度区域中的新奇检测需要不同的检测策略。我们介绍了一种新的技术来检测novelprocesses在高密度区域通过一个快速的在线拟合优度测试。对于低密度区域的检测,我们使用2SND(两阶段新颖性检测器),这是我们在前期工作中提出的一种方法。有了CANCELLS,我们联合收割机结合了这两种技术,提供了一个整体的方法来检测新颖性。使用人工数据和基准数据在计算机网络中的入侵检测领域的CANNER的属性进行评估。
In this article, we propose Combined Approach for Novelty Detection in Intelligent Embedded Systems (CANDIES), a new approach to novelty detection in technical systems. We assume that a technical system observes an environment that can be regarded as being composed of several processes. When observing these processes with sensors, features are extracted from sensor signals and we are able to model the sample distribution in feature space with a probabilistic model. In an ideal case, the components of the parametric mixture density model we use correspond to the processes in the real world. Eventually, e.g., in the case of an unpredictable failure,novelprocesses emerge. As a consequence, new kinds of samples are observed that require an adaptation of the model. Novelty detection in low- and high-density regions of the feature space require different detection strategies. We introduce a new technique to detectnovelprocesses in high-density regions by means of a fast online goodness-of-fit test. For detection in low-density regions we use 2SND (Two-Stage-Novelty-Detector), an approach we presented in preliminary work. With CANDIES, we combine both techniques to provide a holistic method to detectnovelty. The properties of CANDIES are evaluated using artificial data and benchmark data from the field of intrusion detection in computer networks.