Multi-Agent Reinforcement Learning for Intrusion Detection: A Case Study and Evaluation

  • Authors:
  • Arturo Servin;Daniel Kudenko

  • Affiliations:
  • Department of Computer Science, University of York, Heslington, York, United Kingdom YO10 5DD;Department of Computer Science, University of York, Heslington, York, United Kingdom YO10 5DD

  • Venue:
  • MATES '08 Proceedings of the 6th German conference on Multiagent System Technologies
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper we propose a novel approach to train Multi-Agent Reinforcement Learning(MARL) agents to cooperate to detect intrusions in the form of normal and abnormal states in the network. We present an architecture of distributed sensor and decision agents that learn how to identify normal and abnormal states of the network using Reinforcement Learning(RL). Sensor agents extract network-state information using tile-coding as a function approximation technique and send communication signals in the form of actions to decision agents. By means of an on line process, sensor and decision agents learn the semantics of the communication actions. In this paper we detail the learning process and the operation of the agent architecture. We also present tests and results of our research work in an intrusion detection case study, using a realistic network simulation where sensor and decision agents learn to identify normal and abnormal states of the network.