IP Library › Granted Patent US 12,634,305
Granted Patent B2
US 12,634,305 · App. 18/563,272 · Granted May 19, 2026

Unsupervised GAN-based intrusion detection system using temporal convolutional networks, self-attention, and transformers

Inventors: Paulo Freitas De Araujo Filho (Recife, BR); Mohamed Naili (Montreal, CA); Georges Kaddoum (Laval, CA); Emmanuel Thepie Fapi (Cote-Saint-Luc, CA); Zhongwen Zhu (Saint-Laurent, CA)
Assignee: Telefonaktiebolaget LM Ericsson (publ)
H04L63/1416G06N3/088H04L63/1425H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,634,305
App. No.
18/563,272
Granted
May 19, 2026
Kind
B2
Abstract

There is provided a method for detecting cyber-attacks at edge servers. The method comprises receiving network traffic. The method comprises extracting and normalizing network flow features from the network traffic to produce a data pattern for evaluation. The method comprises computing an anomaly detection score for the data pattern for evaluation. The method comprises comparing the anomaly detection score with a threshold and determining if the network traffic corresponds to normal traffic or to an anomaly. The method comprises, upon determining that the network traffic corresponds to an anomaly, mitigating malicious network traffic by triggering a mitigation strategy and sending an anomaly message to an anomaly classifier. A method for classifying cyber-attacks at a cloud server is also provided.

Claims (36)

1 . A method for detecting cyber-attacks at edge servers, comprising:

receiving network traffic;

extracting and normalizing network flow features from the network traffic to produce a data pattern for evaluation;

computing an anomaly detection score for the data pattern for evaluation;

comparing the anomaly detection score with a threshold and determining if the network traffic corresponds to normal traffic or to an anomaly;

upon determining that the network traffic corresponds to an anomaly, mitigating malicious network traffic by triggering a mitigation strategy and sending an anomaly message to an anomaly classifier;

retraining the anomaly detector, using federated learning, when triggered by a cloud server running the anomaly classifier upon obtention of new datasets of network traffic;

receiving a new training dataset with normal traffic data from the cloud server;

retraining a generative adversarial network (GAN) generator neural network and a GAN discriminator neural network of the anomaly detector;

periodically sending weights of the neural networks of the generator and discriminator to the cloud server;

receiving average generator weights and average discriminator weights from the cloud server;

updating the weights of the neural networks of the generator and discriminator using the average generator weights and average discriminator weights received from the cloud server, and resuming training; and

replacing the current GAN generator neural network and the GAN discriminator neural network with the retrained GAN generator neural network and GAN discriminator neural network.

2 . The method of claim 1 , wherein the generator learns a probabilistic distribution of a training set, enabling production, by the generator, of data similar to the training set and wherein the discriminator learns how to distinguish between real data and data produced by the generator.

3 . The method of claim 2 , wherein the training set comprises only data corresponding to normal traffic, thereby enabling the discriminator to distinguish between the learned normal traffic and anomalies without requiring labeled data corresponding to anomalies.

4 . The method of claim 1 , wherein the GAN comprises at least one of each of a temporal convolutional network (TCN) block, a self-attention block, and a transformer block.

5 . The method of claim 1 , wherein the extracting and normalizing network flow features from the network traffic, comprises extracting and normalizing flow duration, total number of packets, number of flow packets per second, and number of flow bytes per second.

6 . The method of claim 1 , wherein the mitigation strategy is selected among any one or more of temporarily dropping packets, resetting connections, deviating traffic, and notifying network hosts.

7 . The method of claim 1 , wherein the anomaly message comprises a geographical location, a timestamp, normalized network flow features, and a computed anomaly detection score value.

8 . The method of claim 1 , wherein the threshold is defined during the training of the GAN and is updated when the GAN is updated.

9 . An edge server running an anomaly detector for detecting cyber-attacks comprising processing circuits and a memory, the memory containing instructions executable by the processing circuits whereby the edge server running the anomaly detector is operative to:

receive network traffic;

extract and normalize network flow features from the network traffic to produce a data pattern for evaluation;

compute an anomaly detection score for the data pattern for evaluation;

compare the anomaly detection score with a threshold and determine if the network traffic corresponds to normal traffic or to an anomaly;

determine that the network traffic corresponds to an anomaly and mitigate malicious network traffic by triggering mitigation strategies and send an anomaly message to an anomaly classifier;

retrain the anomaly detector, using federated learning, when triggered by a cloud server running the anomaly classifier upon obtention of new datasets of network traffic;

receive a new training dataset with normal traffic data from the cloud server;

start retraining a GAN generator neural network and a GAN discriminator neural network of the anomaly detector;

periodically send weights of the neural networks of the generator and discriminator to the cloud server;

receive average generator weights and average discriminator weights from the cloud server;

update the weights of the neural networks of the generator and discriminator using the average generator weights and average discriminator weights received from the cloud server, and resume training; and

replace the current GAN generator neural network and the GAN discriminator neural network with the retrained GAN generator neural network and GAN discriminator neural network.

10 . The edge server of claim 9 , wherein the edge server is further operative to:

receive a validation dataset from the cloud server; and

detect anomalies in the received validation dataset and send back a report with an anomaly detection score computed for each of a plurality of data sample of the validation dataset.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2026
From: NAILI, MOHAMED; THEPIE FAPI, EMMANUEL; ZHU, ZHONGWEN
To: TELEFONAKTIEBOLOGAT LM ERICSSON (PUBL)
Reel/Frame 074378/0675 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2026
From: ECOLE DE TECHNOLOGIE SUPERIEURE
To: TELEFONAKTIEBOLOGAT LM ERICSSON (PUBL)
Reel/Frame 074379/0038 →
Continuity (2)
Provisional Application 63197571 · Jun 7, 2021
Related Publication 20240250963A1 · Jul 25, 2024
References Cited (41)
US 8418249B1 · Nucci · 2013 [cited by examiner]
US 10956808B1 · Bhardwaj · 2021 [cited by examiner]
US 11481637B2 · Malaya · 2022 [cited by examiner]
US 11611588B2 · Vasu · 2023 [cited by examiner]
US 11936667B2 · Salji · 2024 [cited by examiner]
US 11960978B2 · Crabtree · 2024 [cited by examiner]
US 20220014554A1 · Vasu · 2022 [cited by examiner]
US 20220383071A1 · Sun · 2022 [cited by examiner]
A. A. Diro et al., Deep Learning: The Frontier for Distributed Attack Detection in Fog-to-Things Computing, IEEE Communications Magazine ⋅ Feb. 2018. [cited by applicant]
A. Creswell et al., Generative Adversarial Networks, Digital Object Identifier 10.1109/MSP.2017.2765202 Date of publication: Jan. 9, 2018. [cited by applicant]
A. Ferdowsi et al., Generative Adversarial Networks for Distributed Intrusion Detection in the Internet of Things, 2019 IEEE. [cited by applicant]
A. Nisioti et al., From Intrusion Detection to Attacker Attribution: A Comprehensive Survey of Unsupervised Methods, IEEE Communications Surveys & Tutorials, vol. 20, No. 4, Fourth Quarter 2018. [cited by applicant]
A. Sharma et al., Analysis of Security Data from a Large Computing Organization, 2011 IEEE. [cited by applicant]
A. Vaswani et al., Attention Is All You Need, arXiv:1706.03762v5 [cs.CL] Dec. 6, 2017. [cited by applicant]
D. Ding et al., A survey on security control and attack detection for industrial cyber-physical systems, Neurocomputing vol. 275, Jan. 31, 2018, pp. 1674-1683. [cited by applicant]
D. Li et al., Anomaly Detection with Generative Adversarial Networks for Multivariate Time Series, arXiv:1809.04758v3 [cs.LG] Jan. 15, 2019. [cited by applicant]
H. Choi et al., Unsupervised learning approach for network intrusion detection system using autoencoders, The Journal of Supercomputing (2019) 75:5597-5621, https://doi.org/10.1007/s11227-019-02805-w. [cited by applicant]
H. Zenati et al., Adversarially Learned Anomaly Detection, 2018 IEEE International Conference on Data Mining. [cited by applicant]
I. V. Tetko et al., Artificial Neural Networks and Machine Learning, ICANN 2019. [cited by applicant]
L. Kaiser et al., “Tensor2Tensor Transformers New Deep Models for NLP”, 2017. [cited by applicant]
M. Abdel-Basset et al: “Semi-Supervised Spatiotemporal Deep Learning for Intrusions Detection in IoT Networks”, IEEE Internet of Things Journal, IEEE, USA, vol. 8, No. 15, Feb. 19, 2021. [cited by applicant]
M. Arjovsky et al., “Wasserstein Generative Adversarial Networks”, Proceedings of the 34th. International Conference on Machine Learning, Sydney, Australia, PMLR 70, 2017. Copyright 2017 by the author(s). [cited by applicant]
M. S. Haghighi et al., “A Machine Learning-based Approach to Build Zero False-Positive IPSs for Industrial IoT and CPS with a Case Study on Power Grids Security”, 0093-9994 (c) 2020 IEEE. Personal use is permitted, but … [cited by applicant]
M. Tan et al., “A Neural Attention Model for Real-Time Network Intrusion Detection”, 2019 IEEE. [cited by applicant]
N. Chaabouni et al., “Network Intrusion Detection for IoT Security Based on Learning Techniques”, IEEE Communications Surveys & Tutorials, vol. 21, No. 3, Third Quarter 2019. [cited by applicant]
P. Freitas De Araujo-Filho et al: “Intrusion Detection for Cyber-Physical Systems Using Generative Adversarial Networks in Fog Environment”, IEEE Internet of Things Journal, IEEE, USA, vol. 8, No. 8, Sep. 18, 2020. [cited by applicant]
P. Freitas et al., Intrusion Detection for Cyber-Physical Systems Using Generative Adversarial Networks in Fog Environment, IEEE Internet of Things Journal, vol. 8, No. 8, Apr. 15, 2021. [cited by applicant]
P. Illy et al., “Securing Fog-to-Things Environment Using Intrusion Detection System Based on Ensemble Learning”, 2019 IEEE Wireless Communications and Networking Conference (WCNC). [cited by applicant]
R. Alguliyev et al., “Cyber-physical systems and their security issues, Computers in Industry”, vol. 100, Sep. 2018, pp. 212-223. [cited by applicant]
S. Bai et al., “An Empirical Evaluation of Generic Convolutional and Recurrent Networks for Sequence Modeling”, arXiv:1803.01271v2 [cs.LG], 14 pages, Apr. 19, 2018. [cited by applicant]
S. Han et al., “Intrusion Detection in Cyber-Physical Systems: Techniques and Challenges”, IEEE Systems Journal, vol. 8, No. 4, Dec. 2014. [cited by applicant]
S. Huang et al., “HitAnomaly: Hierarchical Transformers for Anomaly Detection in System Log”, IEEE Transactions on Network and Service Management, vol. 17, No. 4, Dec. 2020. [cited by applicant]
S. Prabavathy et al., “Design of Cognitive Fog Computing for Intrusion Detection in Internet of Things”, Journal of Communications and Networks, vol. 20 , No. 3, Jun. 2018. [cited by applicant]
S. Y. Ozgumus, “Adversarially Learned Anomaly Detection Using Generative Adversarial Networks”, Department of Electronics, Informatics and Bioengineering M.Sc. course of Computer Science and Engineering, 2019. [cited by applicant]
S.E. Yi et al., “A Comparison of LSTMs and Attention Mechanisms for Forecasting Financial Time Series”, arXiv:1812.07699v1 [cs.LG] Dec. 18, 2018. [cited by applicant]
T. N. Duc et al., “Convolutional Neural Networks for Continuous QoE Prediction in Video Streaming Services”, Received May 4, 2020, accepted Jun. 11, 2020, date of publication Jun. 22, 2020, date of current version Jul. … [cited by applicant]
T. Schlegl et al., f-AnoGAN: “Fast unsupervised anomaly detection with generative adversarial networks”, Medical Image Analysis, vol. 54, May 2019, pp. 30-44. [cited by applicant]
Y. Jia et al., “FlowGuard: An Intelligent Edge Defense Mechanism Against IoT DDoS Attacks”, IEEE Internet of Things Journal, vol. 7, No. 10, Oct. 2020. [cited by applicant]
Y. Li et al., “Detecting Anomalies in Intelligent Vehicle Charging and Station Power Supply Systems With Multi-Head Attention Models”, IEEE Transactions on Intelligent Transportation Systems, vol. 22, No. 1, Jan. 2021. [cited by applicant]
Y. Yang et al., “A Survey on Security and Privacy Issues in Internet-of-Things”, IEEE Internet of Things Journal, vol. 4, No. 5, Oct. 2017. [cited by applicant]
International Search Report for PCT/IB2022/055261, mailing date of Sep. 12, 2022, 11 pages. [cited by applicant]