Deep Q-Learning based Reinforcement Learning Approach for Network Intrusion Detection

  • 2021-11-27 20:18:00
  • Hooman Alavizadeh, Julian Jang-Jaccard, Hootan Alavizadeh
  • 2

Abstract

The rise of the new generation of cyber threats demands more sophisticatedand intelligent cyber defense solutions equipped with autonomous agents capableof learning to make decisions without the knowledge of human experts. Severalreinforcement learning methods (e.g., Markov) for automated network intrusiontasks have been proposed in recent years. In this paper, we introduce a newgeneration of network intrusion detection methods that combines aQ-learning-based reinforcement learning with a deep-feed forward neural networkmethod for network intrusion detection. Our proposed Deep Q-Learning (DQL)model provides an ongoing auto-learning capability for a network environmentthat can detect different types of network intrusions using an automatedtrial-error approach and continuously enhance its detection capabilities. Weprovide the details of fine-tuning different hyperparameters involved in theDQL model for more effective self-learning. According to our extensiveexperimental results based on the NSL-KDD dataset, we confirm that the lowerdiscount factor which is set as 0.001 under 250 episodes of training yields thebest performance results. Our experimental results also show that our proposedDQL is highly effective in detecting different intrusion classes andoutperforms other similar machine learning approaches.

 

Quick Read (beta)

loading the full paper ...