A journal of IEEE and CAA , publishes high-quality papers in English on original theoretical/experimental research and development in all areas of automation
Volume 13 Issue 9
Sep.  2026

IEEE/CAA Journal of Automatica Sinica

  • JCR Impact Factor: 18.3, Top 1 (SCI Q1)
    CiteScore: 28.2, Top 1% (Q1)
    Google Scholar h5-index: 95, TOP 5
Turn off MathJax
Article Contents
Y. Lai, Z. Wang, J. Dong, Y. Xiao, Z. Li, and Q. Ye, “Towards efficient intrusion detection: A Bayesian nonparametric model with gamma distributions,” IEEE/CAA J. Autom. Sinica, vol. 13, no. 9, pp. 2132–2145, Sep. 2026. doi: 10.1109/JAS.2026.125927
Citation: Y. Lai, Z. Wang, J. Dong, Y. Xiao, Z. Li, and Q. Ye, “Towards efficient intrusion detection: A Bayesian nonparametric model with gamma distributions,” IEEE/CAA J. Autom. Sinica, vol. 13, no. 9, pp. 2132–2145, Sep. 2026. doi: 10.1109/JAS.2026.125927

Towards Efficient Intrusion Detection: A Bayesian Nonparametric Model With Gamma Distributions

doi: 10.1109/JAS.2026.125927
Funds:  This work was supported in part by the National Natural Science Foundation of China (62272051, 62572074) and National Grid Corporation of China Science and Technology (B7182025Z044)
More Information
  • With the continuous development and widespread application of internet technology, network security issues have become increasingly complex and dynamic. To address these challenges, intrusion detection technology has emerged as a research hotspot in cyberspace security. Finite mixture models have been widely adopted for network intrusion detection; however, existing studies have predominantly focused on parameter estimation, while often neglecting the effects of model selection and data imbalance, which can lead to suboptimal detection performance. To address this limitation, in this paper, we first employ oversampling approaches to generate a rebalanced training set. Subsequently, a Dirichlet process mixture of gamma distributions based on a stick-breaking representation is utilized to model the underlying distributions of normal and suspicious activities. The proposed model is then trained using the extended stochastic variational inference framework, through which an analytically tractable solution for Bayesian estimation is developed. This learning strategy enables the simultaneous estimation of model complexity and parameters within a unified Bayesian framework. The effectiveness and performance of the proposed method are validated on three publicly available datasets, namely, UNSW-NB 15, CICIoT2023, and ISCX-IDS-2012. In comparison with several well-established finite mixture models, as well as machine learning and deep learning algorithms, the proposed approach not only achieves comparable or superior detection performance in terms of precision, recall, F1 score, and AUC values, but also significantly reduces training and detection time.

     

  • loading
  • [1]
    Z. Xi, Y. Zhou, D. Zhang, K. Gao, C. Sun, J. Cao, Y. Wang, M. Xu, and J. Wu, “Newton: Intent-driven network traffic monitoring,” IEEE/ACM Trans. Netw., vol. 30, no. 2, pp. 939−952, Apr. 2022. doi: 10.1109/TNET.2021.3128557
    [2]
    Q. Yang, C. Wang, H. Yuan, J. Cui, H. Teng, X. Chen, and C. Jiang, “Approaching the information-theoretic limit of privacy disclosure with utility guarantees,” IEEE Trans. Inform. Foren. Secur., vol. 19, pp. 3339−3352, Jan. 2024. doi: 10.1109/TIFS.2024.3354412
    [3]
    C. Wang, H. Zhu, and B. Yang, “Composite behavioral modeling for identity theft detection in online social networks,” IEEE Trans. Comput. Soc. Syst., vol. 9, no. 2, pp. 428−439, Apr. 2022. doi: 10.1109/TCSS.2021.3092007
    [4]
    M. Zhou and J. Liu, “A two-phase multiobjective evolutionary algorithm for enhancing the robustness of scale-free networks against multiple malicious attacks,” IEEE Trans. Cybern., vol. 47, no. 2, pp. 539−552, Feb. 2017. doi: 10.1109/tcyb.2016.2520477
    [5]
    M. A. Ferrag, L. Shu, O. Friha, and X. Yang, “Cyber security intrusion detection for agriculture 4.0: Machine learning-based solutions, datasets, and future directions,” IEEE/CAA J. Autom. Sinica, vol. 9, no. 3, pp. 407−436, Mar. 2022. doi: 10.1109/JAS.2021.1004344
    [6]
    T. E. T. Djaidja, B. Brik, S. Mohammed Senouci, A. Boualouache, and Y. Ghamri-Doudane, “Early network intrusion detection enabled by attention mechanisms and RNNs,” IEEE Trans. Inform. Foren. Secur., vol. 19, pp. 7783−7793, Jan. 2024. doi: 10.1109/TIFS.2024.3441862
    [7]
    P. Mishra, V. Varadharajan, U. Tupakula, and E. S. Pilli, “A detailed investigation and analysis of using machine learning techniques for intrusion detection,” IEEE Commun. Surv. Tutorials, vol. 21, no. 1, pp. 686−728, 2019.
    [8]
    N. Moustafa, G. Misra, and J. Slay, “Generalized outlier Gaussian mixture technique based on automated association features for simulating and detecting web application attacks,” IEEE Trans. Sustain. Comput., vol. 6, no. 2, pp. 245−256, Apr.−Jun. 2021. doi: 10.1109/TSUSC.2018.2808430
    [9]
    W. He, X. Cai, Y. Lai, and X. Yuan, “ESVI-GAMM: A fast network intrusion detection approach based on the Bayesian gamma mixture model,” Inform. Sci., vol. 678, Art. no. 121001, Sep. 2024. doi: 10.1016/j.ins.2024.121001
    [10]
    N. Moustafa, J. Slay, and G. Creech, “Novel geometric area analysis technique for anomaly detection using trapezoidal area estimation on large-scale networks,” IEEE Trans. Big Data, vol. 5, no. 4, pp. 481−494, Dec. 2019. doi: 10.1109/TBDATA.2017.2715166
    [11]
    N. Moustafa, K.-K. R. Choo, I. Radwan, and S. Camtepe, “Outlier Dirichlet mixture mechanism: Adversarial statistical learning for anomaly detection in the fog,” IEEE Trans. Inform. Foren. Secur., vol. 14, no. 8, pp. 1975−1987, Aug. 2019. doi: 10.1109/TIFS.2018.2890808
    [12]
    Y. Lai, W. Guan, L. Luo, Y. Guo, H. Song, and H. Meng, “Bayesian estimation of inverted beta mixture models with extended stochastic variational inference for positive vector classification,” IEEE Trans. Neural Netw. Learning Syst., vol. 35, no. 5, pp. 6948−6962, May 2024. doi: 10.1109/TNNLS.2022.3213518
    [13]
    Y. Lai, Y. Yu, W. Guan, L. Luo, J. Fan, N. Zhou, and Y. Ping, “A lightweight intrusion detection system using a finite Dirichlet mixture model with extended stochastic variational inference,” IEEE Trans. Netw. Serv. Manage., vol. 21, no. 4, pp. 4701−4712, Aug. 2024. doi: 10.1109/TNSM.2024.3391250
    [14]
    G. Douzas, F. Bacao, and F. Last, “Improving imbalanced learning through a heuristic oversampling method based on K-means and SMOTE,” Inform. Sci., vol. 465, pp. 1−20, Oct. 2018. doi: 10.1016/j.ins.2018.06.056
    [15]
    C. Long, Y. Zhang, J. Wei, W. Wan, J. Zhao, and G. Du, “A hybrid intrusion detection algorithm based on Gaussian mixture model and nearest neighbors,” in Proc. IEEE 44th Conf. Local Computer Networks, Osnabrueck, Germany, 2019, pp. 117−120.
    [16]
    R. Blanco, P. Malagón, S. Briongos, and J. M. Moya, “Anomaly detection using Gaussian mixture probability model to implement intrusion detection system,” in Proc. 14th Int. Conf. Hybrid Artificial Intelligent Systems. León, Spain, 2019, pp. 648−659.
    [17]
    N. Moustafa, G. Creech, and J. Slay, “Anomaly detection system using beta mixture models and outlier detection,” in Proc. Progress in Computing, Analytics and Networking, Singapore, Singapore, 2018, pp. 125−135.
    [18]
    W. Fan, L. Yang, and N. Bouguila, “Grouped spherical data modeling through hierarchical nonparametric Bayesian models and its application to fMRI data analysis,” IEEE Trans. Neural Netw. Learning Syst., vol. 35, no. 4, pp. 5566−5576, Apr. 2024. doi: 10.1109/TNNLS.2022.3208202
    [19]
    W. Alhakami, A. Alharbi, S. Bourouis, R. Alroobaea, and N. Bouguila, “Network anomaly intrusion detection using a nonparametric Bayesian approach and feature selection,” IEEE Access, vol. 7, pp. 52181−52190, 2019.
    [20]
    M. Zheng, X. Hu, Y. Hu, X. Zheng, and Y. Luo, “Fed-UGI: Federated undersampling learning framework with Gini impurity for imbalanced network intrusion detection,” IEEE Trans. Inform. Foren. Secur., vol. 20, pp. 1262−1277, Jan. 2025. doi: 10.1109/TIFS.2024.3516547
    [21]
    H. Ding, Y. Sun, N. Huang, Z. Shen, and X. Cui, “TMG-GAN: Generative adversarial networks-based imbalanced learning for network intrusion detection,” IEEE Trans. Inform. Foren. Secur., vol. 19, pp. 1156−1167, Jan. 2024. doi: 10.1109/TIFS.2023.3331240
    [22]
    S. Wang, L. L. Minku, and X. Yao, “Resampling-based ensemble methods for online class imbalance learning,” IEEE Trans. Knowl. Data Eng., vol. 27, no. 5, pp. 1356−1368, May 2015. doi: 10.1109/TKDE.2014.2345380
    [23]
    N. V. Chawla, K. W. Bowyer, L. O. Hall, and W. P. Kegelmeyer, “SMOTE: Synthetic minority over-sampling technique,” J. Artif. Intell. Res., vol. 16, no. 1, pp. 321−35, Jun. 2002.
    [24]
    Z. Xu, D. Shen, T. Nie, Y. Kou, N. Yin, and X. Han, “A cluster-based oversampling algorithm combining SMOTE and K-means for imbalanced medical data,” Inform. Sci., vol. 572, pp. 574−589, Sep. 2021. doi: 10.1016/j.ins.2021.02.056
    [25]
    H. Han, W.-Y. Wang, and B.-H. Mao, “Borderline-SMOTE: A new over-sampling method in imbalanced data sets learning,” in Proc. Int. Conf. Intelligent Computing on Advances in Intelligent Computing, Hefei, China, 2005, pp. 878−887.
    [26]
    M. Lamari, N. Azizi, N. E. Hammami, A. Boukhamla, S. Cheriguene, N. Dendani, and N. E. Benzebouchi, “SMOTE-ENN-based data sampling and improved dynamic ensemble selection for imbalanced medical data classification,” in Proc. ICACIn 2020 on Advances on Smart and Soft Computing, Singapore, Singapore, 2020, pp. 37−49.
    [27]
    H. Sain and S. W. Purnami, “Combine sampling support vector machine for imbalanced data classification,” Procedia Comput. Sci. vol. 72, pp. 59−66, 2015.
    [28]
    P. Vuttipittayamongkol and E. Elyan, “Neighbourhood-based undersampling approach for handling imbalanced and overlapped data,” Inform. Sci., vol. 509, pp. 47−70, Jan. 2020. doi: 10.1016/j.ins.2019.08.062
    [29]
    M. Bach, “New undersampling method based on the kNN approach,” Procedia Comput. Sci., vol. 207, pp. 3403−3412, Jan. 2022. doi: 10.1016/j.procs.2022.09.399
    [30]
    Y. Lai, H. Cao, L. Luo, Y. Zhang, F. Bi, X. Gui, and Y. Ping, “Extended variational inference for gamma mixture model in positive vectors modeling,” Neurocomputing, vol. 432, pp. 145−158, Apr. 2021. doi: 10.1016/j.neucom.2020.12.042
    [31]
    C. M. Bishop, Pattern Recognition and Machine Learning. New York, USA: Springer, 2006.
    [32]
    N. J. Foti and S. A. Williamson, “A survey of non-exchangeable priors for Bayesian nonparametric models,” IEEE Trans. Pattern Anal. Mach. Intell., vol. 37, no. 2, pp. 359−371, Feb. 2015. doi: 10.1109/TPAMI.2013.224
    [33]
    S. Sun and X. Xu, “Variational inference for infinite mixtures of Gaussian processes with applications to traffic flow prediction,” IEEE Trans. Intell. Transport. Syst., vol. 12, no. 2, pp. 466−475, Jun. 2011. doi: 10.1109/TITS.2010.2093575
    [34]
    X. Wei and C. Li, “The student’s t-hidden Markov model with truncated stick-breaking priors,” IEEE Signal Process. Lett., vol. 18, no. 6, pp. 355−358, Jun. 2011. doi: 10.1109/LSP.2011.2138695
    [35]
    Z. Ma and A. Leijon, “Bayesian estimation of beta mixture models with variational inference,” IEEE Trans. Pattern Anal. Mach. Intell., vol. 33, no. 11, pp. 2160−2173, Nov. 2011. doi: 10.1109/TPAMI.2011.63
    [36]
    M. D. Hoffman, D. M. Blei, C. Wang, and J. Paisley, “Stochastic variational inference,” J. Mach. Learn. Res., vol. 14, pp. 1303−1347, 2013.
    [37]
    C. Liu, H.-C. Li, K. Fu, F. Zhang, M. Datcu, and W. J. Emery, “Bayesian estimation of generalized gamma mixture model based on variational EM algorithm,” Pattern Recogn., vol. 87, pp. 269−284, Mar. 2019. doi: 10.1016/j.patcog.2018.10.025
    [38]
    J. Huang and C. X. Ling, “Using AUC and accuracy in evaluating learning algorithms,” IEEE Trans. Knowl. Data Eng., vol. 17, no. 3, pp. 299−310, Mar. 2005. doi: 10.1109/TKDE.2005.50
    [39]
    N. Bouguila and D. Ziou, “A Dirichlet process mixture of generalized Dirichlet distributions for proportional data modeling,” IEEE Trans. Neural Netw., vol. 21, no. 1, pp. 107−122, Jan. 2010. doi: 10.1109/TNN.2009.2034851
    [40]
    H. He, Y. Bai, E. A. Garcia, and S. Li, “ADASYN: Adaptive synthetic sampling approach for imbalanced learning,” in Proc. IEEE Int. Joint Conf. Neural Networks (IEEE World Congr. on Computational Intelligence), Hong Kong, China, 2008, pp. 1322−1328.
    [41]
    F. Kamalov, H.-H. Leung, and A. K. Cherukuri, “Keep it simple: Random oversampling for imbalanced data,” in Proc. Advances in Science and Engineering Technology Int. Conferences, Dubai, United Arab Emirates, 2023, pp. 1−4.
    [42]
    L. Van Der Maaten and G. Hinton, “Visualizing data using t-SNE,” J. Mach. Learning Res., vol. 9, no. 86, pp. 2579−2605, 2008.
    [43]
    Y. Liao and V. R. Vemuri, “Use of K-nearest neighbor classifier for intrusion detection,” Comput. Secur., vol. 21, no. 5, pp. 439−448, Oct. 2002. doi: 10.1016/S0167-4048(02)00514-X
    [44]
    B. S. Sharmila and R. Nagapadma, “Intrusion detection system using naive Bayes algorithm,” in Proc. IEEE Int. WIE Conf. Electrical and Computer Engineering, Bangalore, India, 2019, pp. 1−4.
    [45]
    W. Hu, W. Hu, and S. Maybank, “AdaBoost-based algorithm for network intrusion detection,” IEEE Trans. Syst., Man, Cybern., Part B (Cybern.), vol. 38, no. 2, pp. 577−583, Apr. 2008. doi: 10.1109/TSMCB.2007.914695
    [46]
    R.-E. Fan, K.-W. Chang, C.-J. Hsieh, X.-R. Wang, and C.-J. Lin, “LIBLINEAR: A library for large linear classification,” J. Mach. Learning Res., vol. 9, pp. 1871−1874, Jun. 2008.
    [47]
    N. Yang, J. Xiong, C. Guo, S. Guo, and G. Li, “Reflection coefficients inversion based on the bidirectional long short-term memory network,” IEEE Geosci. Remote Sens. Lett., vol. 19, Art. no. 3008605, 2022.
    [48]
    G. Andresini, A. Appice, and D. Malerba, “Autoencoder-based deep metric learning for network intrusion detection,” Inform. Sci., vol. 569, pp. 706−727, Aug. 2021. doi: 10.1016/j.ins.2021.05.016
    [49]
    G. E. Hinton, S. Osindero, and Y.-W. Teh, “A fast learning algorithm for deep belief nets,” Neural Comput., vol. 18, no. 7, pp. 1527−1554, Jul. 2006. doi: 10.1162/neco.2006.18.7.1527
    [50]
    T.-N. Dao and H. Lee, “Stacked autoencoder-based probabilistic feature extraction for on-device network intrusion detection,” IEEE Internet Things J., vol. 9, no. 16, pp. 14438−14451, Aug. 2022. doi: 10.1109/JIOT.2021.3078292

Catalog

    通讯作者: 陈斌, bchen63@163.com
    • 1. 

      沈阳化工大学材料科学与工程学院 沈阳 110142

    1. 本站搜索
    2. 百度学术搜索
    3. 万方数据库搜索
    4. CNKI搜索

    Figures(8)  / Tables(7)

    Article Metrics

    Article views (17) PDF downloads(1) Cited by()

    /

    DownLoad:  Full-Size Img  PowerPoint
    Return
    Return