A METHOD FOR DETECTING COMPUTER ATTACKS BASED ON H-DDPM NETWORK TRAFFIC DATA AUGMENTATION MODEL
Abstract
This paper examines the problem of improving the detection of computer attacks (CA) by an intrusion detection system (IDS) under conditions of significant network traffic data imbalance. Based on an analysis of methods for reducing data imbalance, it is concluded that classical methods of balancing and generative augmentation do not preserve the statistical structure of multidimensional tabular data, including their fractal properties and self-similarity, which reduces the quality of classifier training. This paper proposes a method for detecting computer attacks (CA) based on the H-DDPM data augmentation model, a modification of the DDPM diffusion probabilistic model, in which the variance of the added Gaussian noise in the forward process depends on the Hurst exponent H for each CA class. The method includes data preprocessing, the formation of time series using sliding windows, H estimation using DFA and R/S methods, and the generation of synthetic data for training the LSTM classifier. The method is evaluated using the general performance metrics Accuracy, Recall, F1, ROC-AUC, and G-means, as well as Precision, Recall, and F1-score for each class. Experiments were conducted on the CSE-CSE-CIC-IDS2018 and UNSW-NB15 datasets. A comparison was made with other methods, such as SMOTE, GAN, and DDPM. The experimental results show that H-DDPM improves the efficiency of CA detection, outperforming similar methods in terms of imbalance-sensitive metrics. Furthermore, experimental validations demonstrate that directly using the Hurst H exponent for CA classes in the H-DDPM model improves the recall and balanced quality of CA detection. It is noted that H-DDPM has an impact on CA classification, manifested by an increase in false positives and a decrease in the ROC-AUC metric, which requires additional tuning of the classifier model hyperparameters and filtering of synthetic data
##article.references##
1. Check Point Research. Kiberugrozy za 2025 god: issledovanie mirovykh kiberatak za vtoroy kvartal 2025 [Check Point Research. Cyber Threats for 2025: a study of global cyberattacks in second quarter 2025]. Available at: https://www.itsec.ru/news/check-point-research-iberataka-za-2025-predstavil-issledovaniye-mirovih-kiberatak-za-vtoroy-kvartal-2025 (accessed 17 March 2025).
2. Positive Technologies. Aktual'nye kiberugrozy: IV kvartal 2024 goda i I kvartal 2025 goda [Positive Technologies. Current cyber threats: fourth quarter of 2024 and first quarter of 2025. Available at: https://ptsecurity.com/research/analytics/aktualnye-kiberugrozy-iv-kvartal-2024-goda-i-kvartal-2025-goda/ (accessed 17 March 2025).
3. Shelukhin O.I., Sakalema D.Zh., Filinova A.S. Obnaruzhenie vtorzheniy v komp'yuternye seti (setevye anomalii): ucheb. posobie [Network intrusion detection (network anomalies): a textbook], ed. by
O.I. Shelukhina. Moscow: Goryachaya liniya-Telekom, 2018, 220 p. ISBN 978-5-9912-0323-4. Lan': el-ektronno-bibliotechnaya sistema. Available at: https://e.lanbook.com/book/111119.
4. Abdelkhalek A., Mashaly M. Addressing the class imbalance problem in network intrusion detection sys-tems using data resampling and deep learning, J Supercomput, 2023, 79, pp. 10611-10644. Available at: https://doi.org/10.1007/s11227-023-05073-x.
5. Zhang Y., Muniyandi R.C., Qamar F. A Review of Deep Learning Applications in Intrusion Detection Systems: Overcoming Challenges in Spatiotemporal Feature Extraction and Data Imbalance, Appl. Sci., 2025, 15, 1552. Available at: https://doi.org/10.3390/app15031552.
6. Leevy J.L., Khoshgoftaar T.M., Bauder R.A. et al. A survey on addressing high-class imbalance in big data, J Big Data, 2018, 5, 42. Available at: https://doi.org/10.1186/s40537-018-0151-6.
7. Wang Z. et al. A Comprehensive Survey on Data Augmentation, in IEEE Transactions on Knowledge and Data Engineering. doi: 10.1109/TKDE.2025.3622600.
8. Yunhao Chen, Zihui Yan, Yunjie Zhu. A comprehensive survey for generative data augmentation, Neuro-computing, 2024, Vol. 600, 128167. ISSN 0925-2312. Available at: https://doi.org/10.1016/ j.neucom.2024.128167. https://www.sciencedirect.com/science/article/pii/S092523122400938X.
9. G. Charbel N. Kindji, Lina M. Rojas-Barahona, Elisa Fromont, Tanguy Urvoy. Tabular data generation models: An in-depth survey and performance benchmarks with extensive tuning, Neurocomputing, 2025, Vol. 658, 131655. ISSN 0925-2312. Available at: https://doi.org/10.1016/ j.neucom.2025.131655.
10. Tang B., Lu Y., Li Q., Bai Y., Yu J., Yu, X. A Diffusion Model Based on Network Intrusion Detection Method for Industrial Cyber-Physical Systems, Sensors, 2023, 23, 1141. Available at: https://doi.org/ 10.3390/s23031141.
11. Yang Y., Tang X., Liu Z., Cheng J., Fang H., and Zhang C. Diff-IDS: A Network Intrusion Detection Model Based on Diffusion Model for Imbalanced Data Samples, Comput. Mater. Contin., 2025, Vol. 82, No. 3, pp. 4389-4408. Available at: https://doi.org/10.32604/cmc.2025.060357.
12. Saihua Cai, Yingwei Zhao, Jiaao Lyu, Shengran Wang, Yikai Hu, Mengya Cheng, Guofeng Zhang. DDP-DAR: Network intrusion detection based on denoising diffusion probabilistic model and dual-attention re-sidual network, Neural Networks, 2025, Vol. 184, 107064. ISSN 0893-6080. Available at: https://doi.org/10.1016/j.neunet.2024.107064.
13. Wang Z., Guan Z., Liu X., Qiao M., Sun X., Li J. Diffusion–Attention Traffic Generation: Traffic Genera-tion Based on the Fusion of a Diffusion Model and a Self-Attention Mechanism, Electronics, 2025, 14, 1977. Available at: https://doi.org/10.3390/electronics14101977.
14. Kotenko I., Saenko I., Lauta O., Kribel' A. Metod rannego obnaruzheniya kiberatak na osnove integratsii fraktal'nogo analiza i statisticheskikh metodov [Method of early detection of cyberattacks based on the in-tegration of fractal analysis and statistical methods], Pervaya milya [First Mile], 2021, No. 6 (98),
pp. 64-71. DOI 10.22184/2070-8963.2021.98.6.64.70. EDN KRIUAD.
15. Jonathan Ho, Ajay Jain, and Pieter Abbeel. Denoising diffusion probabilistic models, In Proceedings of the 34th International Conference on Neural Information Processing Systems (NIPS '20). Curran Asso-ciates Inc., Red Hook, NY, USA, 2020, Article 574, pp. 6840-6851.
16. Yang Song and Stefano Ermon. Generative modeling by estimating gradients of the data distribution, Pro-ceedings of the 33rd International Conference on Neural Information Processing Systems. Curran Asso-ciates Inc., Red Hook, NY, USA, 2019, Article 1067, pp. 11918-11930.
17. Leevy J.L., Khoshgoftaar T.M. A survey and analysis of intrusion detection models based on CSE-CSE-CIC-IDS2018 Big Data, J Big Data, 2020, 7, 104. Available at: https://doi.org/10.1186/s40537-020-00382-x.
18. Moustafa N., Slay J. The evaluation of Network Anomaly Detection Systems: Statistical analysis of the UNSW-NB15 data set and the comparison with the KDD99 data set, Inf. Secur. J. A Glob. Perspect, 2016, 25, pp. 18-31.
19. Kadam V., & Verma R. A Critical Review of Performance Metrics in Intrusion Detection Systems, Jour-nal of Engineering Science and Technology Review, 2025, 18 (1), pp. 199-209.
20. Morehead A., Cheng J. Geometry-complete diffusion for 3D molecule generation and optimization, Com-mun Chem, 2024, 7, 150. Available at: https://doi.org/10.1038/s42004-024-01233-z.








