EAAI Journal 2025 Journal Article
Dual replay memory reinforcement learning framework for minority attack detection
- Ankit Sharma
- Manjeet Singh
Cyberattacks are becoming more frequent as the number of systems connected to the Internet has grown significantly. Intrusion detection systems based on machine learning have become essential to cyber security because they can evaluate and find patterns in huge amounts of data. A branch of machine learning called reinforcement learning has shown promise in identifying new types of cyberattacks, but the class imbalance problem remains unresolved. Addressing this gap, this work presents a novel offline reinforcement learning framework that significantly enhances the capabilities of traditional Deep Q-network based reinforcement learning models for network intrusion detection. The innovation lies in using dual replay memory, which prioritizes learning minority attack classes. Experiments with and without dual-replay memory on the same offline reinforcement learning framework highlighted the significant improvements in evaluation metrics like accuracy, precision, recall and F1-Score. The research investigated the influence of various ratios of replay memories on learning through the grid search method. It evaluated their performance for each class using receiver operating characteristics and area under the curve. Experimental results using the one-vs-rest and aggregated approaches demonstrated the effectiveness of handling the class imbalance problem with high accuracy. Compared to existing methods, the technique performs better in detecting attacks and reducing false positive rates. The proposed model represents significant progress in intrusion detection, offering a robust and highly effective solution for detecting common and minority network intrusions.