🤖 AI Summary
This work addresses the challenge of anomaly detection in unlabeled network traffic within IT/OT convergence scenarios by proposing an unsupervised approach based on β-variational autoencoders (β-VAE). It presents the first systematic comparison between two detection mechanisms: latent space distance and reconstruction error. Experimental evaluation on the NSL-KDD dataset demonstrates that measuring the distance from test samples to the training data distribution in the latent space significantly outperforms conventional reconstruction error–based methods, yielding notably higher detection accuracy under fully unsupervised conditions. The findings highlight the critical advantage of leveraging latent space structure for unsupervised network anomaly detection and offer a novel direction for future research in this domain.
📝 Abstract
As Operational Technology increasingly integrates with Information Technology, the need for Intrusion Detection Systems becomes more important. This paper explores an unsupervised approach to anomaly detection in network traffic using $β$-Variational Autoencoders on the NSL-KDD dataset. We investigate two methods: leveraging the latent space structure by measuring distances from test samples to the training data projections, and using the reconstruction error as a conventional anomaly detection metric. By comparing these approaches, we provide insights into their respective advantages and limitations in an unsupervised setting. Experimental results highlight the effectiveness of latent space exploitation for classification tasks.