Next Article in Journal
Securing Cloud-Based Internet of Things: Challenges and Mitigations
Previous Article in Journal
BA-ATEMNet: Bayesian Learning and Multi-Head Self-Attention for Theoretical Denoising of Airborne Transient Electromagnetic Signals
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

EM-AUC: A Novel Algorithm for Evaluating Anomaly Based Network Intrusion Detection Systems

1
Independent Researcher, Westwood, MA 02090, USA
2
Department of Engineering Management and Systems Engineering, George Washington University, Washington, DC 20052, USA
*
Author to whom correspondence should be addressed.
Sensors 2025, 25(1), 78; https://doi.org/10.3390/s25010078
Submission received: 24 November 2024 / Revised: 19 December 2024 / Accepted: 25 December 2024 / Published: 26 December 2024
(This article belongs to the Section Sensor Networks)

Abstract

Effective network intrusion detection using anomaly scores from unsupervised machine learning models depends on the performance of the models. Although unsupervised models do not require labels during the training and testing phases, the assessment of their performance metrics during the evaluation phase still requires comparing anomaly scores against labels. In real-world scenarios, the absence of labels in massive network datasets makes it infeasible to calculate performance metrics. Therefore, it is valuable to develop an algorithm that calculates robust performance metrics without using labels. In this paper, we propose a novel algorithm, Expectation Maximization-Area Under the Curve (EM-AUC), to derive the Area Under the ROC Curve (AUC-ROC) and the Area Under the Precision-Recall Curve (AUC-PR) by treating the unavailable labels as missing data and replacing them through their posterior probabilities. This algorithm was applied to two network intrusion datasets, yielding robust results. To the best of our knowledge, this is the first time AUC-ROC and AUC-PR, derived without labels, have been used to evaluate network intrusion detection systems. The EM-AUC algorithm enables model training, testing, and performance evaluation to proceed without comprehensive labels, offering a cost-effective and scalable solution for selecting the most effective models for network intrusion detection.
Keywords: network intrusion detection; unsupervised machine learning models; EM-AUC algorithm; missing data inference; Area Under the Roc Curve; Area Under the Precision-Recall Curve network intrusion detection; unsupervised machine learning models; EM-AUC algorithm; missing data inference; Area Under the Roc Curve; Area Under the Precision-Recall Curve

Share and Cite

MDPI and ACS Style

Bai, K.Z.; Fossaceca, J.M. EM-AUC: A Novel Algorithm for Evaluating Anomaly Based Network Intrusion Detection Systems. Sensors 2025, 25, 78. https://doi.org/10.3390/s25010078

AMA Style

Bai KZ, Fossaceca JM. EM-AUC: A Novel Algorithm for Evaluating Anomaly Based Network Intrusion Detection Systems. Sensors. 2025; 25(1):78. https://doi.org/10.3390/s25010078

Chicago/Turabian Style

Bai, Kevin Z., and John M. Fossaceca. 2025. "EM-AUC: A Novel Algorithm for Evaluating Anomaly Based Network Intrusion Detection Systems" Sensors 25, no. 1: 78. https://doi.org/10.3390/s25010078

APA Style

Bai, K. Z., & Fossaceca, J. M. (2025). EM-AUC: A Novel Algorithm for Evaluating Anomaly Based Network Intrusion Detection Systems. Sensors, 25(1), 78. https://doi.org/10.3390/s25010078

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop