Search arXivSearch

arXiv · 2301.06029

A machine learning procedure to detect network attacks

Abstract

The goal of this note is to assess whether simple machine learning algorithms can be used to determine whether and how a given network has been attacked. The procedure is based on the $k$-Nearest Neighbor and the Random Forest classification schemes, using both intact and attacked Erdős-Rényi, Barabasi-Albert and Watts-Strogatz networks to train the algorithm. The types of attacks we consider here are random failures and maximum-degree or maximum-betweenness node deletion. Each network is characterized by a list of 4 metrics, namely the normalized reciprocal maximum degree, the global clustering coefficient, the normalized average path length and the assortativity: a statistical analysis shows that this list of graph metrics is indeed significantly different in intact or damaged networks. We test the procedure by choosing both artificial and real networks, performing the attacks and applying the classification algorithms to the resulting graphs: the procedure discussed here turns out to be able to distinguish between intact networks and those attacked by the maximum-degree of maximum-betweenness deletions, but cannot detect random failures. Our results suggest that this approach may provide a basis for the analysis and detection of network attacks.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Davide Coppes, Paolo Cermelli. 2023-01-15. A machine learning procedure to detect network attacks. https://doi.org/10.1093/comnet%2Fcnad017

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Self-Reference in Large Language Models: The Introspection Threshold for Recursive Self-Improvement

The pursuit of self-evolving AI raises a critical question: when is autonomous self-improvement sustainable rather than degenerative? Drawing an analogy to von Neumann's complexity threshold for self-reproducing automata, we argue that sustainable recursive self-improvement in Large Language Models (LLMs) requires a functional analogue: introspection -- the system's capacity to simulate its own operations and target modifications. Grounded in Kleene's Second Recursion Theorem, we demonstrate the theoretical existence of such introspective programs. However, an empirical review reveals that while current LLMs exhibit quasi-introspection (e.g., partial metacognition), they fall short of true introspection due to structural bottlenecks: a lack of complete self-access, the feedforward nature of the Transformer, and computational class constraints that prevent fixed-point iteration. We conclude by outlining architectural paths to cross this complexity threshold and discussing the associated safety implications.

physics.soc-ph

Multilayer Analysis of the Global Trade Network

Global trade is more than a single network of aggregate flows. Beneath the observable exchange of products among economies lies a complex multilayer structure, formed by thousands of product-specific trade relationships that differ in their similarity, interdependence, and temporal evolution. Using the CEPII's BACI database, which records bilateral product-level trade flows between economies, we represent the global trade network from 1995 to 2024 as a temporal multilayer network, with economies as nodes and directed weighted trade flows as edges. To investigate product-level organisation and cross-layer similarity, temporal structural change, and the structural role of individual economies, we introduce a random-walk-based similarity measure that provides a unified framework for comparing weighted and directed trade layers. Our results show that the global trade network remains relatively stable over short periods but undergoes gradual structural change over longer timescales. We also find that similarity-based product communities only partially align with the official product taxonomy, indicating that products assigned to the same official category do not necessarily exhibit similar trade-network structures. Finally, we show that an economy's structural influence is not always determined by its trade volume. These results highlight the value of multilayer network analysis for revealing patterns in global trade that remain hidden at the aggregate level.

physics.soc-ph

Detectability limits of scaling laws

Power law scaling relations between size and output are central to quantitative theories of cities, organisms, and other complex systems. Competing theories predict scaling exponents that differ by small fractions, but there is no existing theory for verifying whether a given dataset can even distinguish exponents at the required resolution to address such discrepancies. Here we derive a resolution limit for scaling exponents, giving the smallest exponent difference that any method of analysis can detect. We find that the Hurst exponents governing the evolution of systems' sizes and deviations from the scaling law determine how long a record of growing systems must be before it can separate competing scaling theories. Empirical results suggest that many available data panels are insufficient for reliable scaling model selection.

physics.soc-ph