[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-125695-en":3,"doc-seo-125695-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},125695,16904993612988,"Olivia Brown","https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd",8,"Research & Report","A machine learning procedure to detect network attacks","Assess whether simple machine learning algorithms can infer if and how a network was attacked using graph structure alone. The approach trains k-Nearest Neighbor and Random Forest classifiers on intact and attacked Erdős–Rényi, Barabási–Albert, and Watts–Strogatz networks. Attacks are modeled as random node failures and targeted deletions based on maximum degree or maximum betweenness. Each graph is represented by four normalized topological metrics, enabling statistical separation between intact and damaged networks; targeted attacks are detectable, while random failures are not.","arXiv :2301 .06029v1 [physics .soc-ph] 15 Jan 2023  \nA machine learning procedure to detect network attacks  \nDavide Coppes 1 and Paolo Cermelli2  \n1 Department of Physics, University of Torino, Italy  \n2 Department of Mathematics, University of Torino, Italy  \nAbstract  \nThe goal of this note is to assess whether simple machine learning algorithms can be used to determine whether and how a given network has been attacked. The procedure is based on the k-Nearest Neighbor and the Random Forest classi􀀌cation schemes, using both intact and attacked Erd}os-R􀀓enyi, Barabasi-Albert and Watts-Strogatz networks to train the algorithm. The types of attacks we consider here are random failures and maximum-degree or maximum-betweenness node deletion. Each network is characterized by a list of 4 metrics, namely the normalized reciprocal maximum degree, the global clustering coe􀀎cient, the normalized average path length and the assortativity:  \na statistical analysis shows that this list of graph metrics is indeed signi􀀌cantly di􀀋erent in intact or damaged networks. We test the procedure by choosing both arti􀀌cial and real networks, performing the attacks and applying the classi􀀌cation algorithms to the resulting graphs: the procedure discussed here turns out to be able to distinguish between intact networks and those attacked by the maximum-degree of maximum-betweenness deletions, but cannot detect random failures. Our results suggest that this approach may provide a basis for the analysis and detection of network attacks.  \n1 Introduction  \nThe relevance of the study of attacks to networks was already recognized at the early stages of network science, given their importance as a substantial threat to the spread of information and the network integrity. The 􀀌rst studies in this 􀀌eld were able to identify a substantial di􀀋erence in the response to attacks in dependence of the  \nstructure of the attacked network [1, 2, 3]: in fact, networks with exponential degree distribution, such as the Erd}os-R􀀓enyi graph, are equally sensitive to random failures and targeted attacks, while scale-free networks are almost insensitive to random failures, being severely disrupted by targeted attacks. Random failures are generally understood to consist in random deletion of nodes [1, 4, 5, 6, 7], while targeted attacks are usually performed by removing nodes according to some centrality measure, such as degree centrality [1, 3, 4, 5, 6, 7, 8, 9], or betweenness centrality [3, 5, 6, 7, 8, 9], even though other types of attacks have been studied in the literature [3, 9, 10, 11] .  \nThe types of network mostly studied in the literature on the robustness of networks under attacks are the Erd}os-R􀀓enyi random graph [1, 3, 6, 7, 8, 10], with exponential degree distribution, the Barabasi{Albert model [1, 3, 7, 8], with scale-free degree distribution, and the Watts{Strogatz model [4, 8], with intermediate features.  \nIn a large body of literature the e􀀎ciency of the attack is measured in terms of the decrease of the size of the giant component [1, 3, 5, 6, 8, 9, 10], but less often more than one parameter is taken into account to measure network robustness [5] . Also, in most works the e􀀋ect of the attack is studied by comparing the damaged network with the original network [1, 3, 4, 5, 6, 7, 8, 9, 10] so that the knowledge of the latter is necessary in order to establish whether an attack has been performed.  \nIn this short note we explore a simple machine-learning procedure to establish whether and how a given network has been attacked, without requiring the knowledge of the structure of the network before the attack. In short, we characterize each graph by a list of four normalized metrics: the ratio between the average and the maximum degree, the global clustering coe􀀎cient, the ratio between the average path length and the diameter, and the assortativity. While this list is not exhaustive, we show that it has statistically signi􀀌cant di􀀋erences between intact ","cbCaitc9gew0Cvaf","https://ap.wps.com/l/cbCaitc9gew0Cvaf","pdf",460869,1,18,"English","en",105,"# Abstract\n# Introduction\n# The models","[{\"question\":\"What is the main goal of the proposed procedure?\",\"answer\":\"To determine whether a network has been attacked and to identify the attack type using simple machine learning classifiers trained on network structure.\"},{\"question\":\"Which machine learning methods are used?\",\"answer\":\"The procedure uses k-Nearest Neighbor and Random Forest classification schemes.\"},{\"question\":\"Can the method detect all attack types considered in the study?\",\"answer\":\"It can distinguish intact networks from networks attacked by maximum-degree or maximum-betweenness deletions, but it cannot detect random failures.\"}]","A machine learning procedure to detect network attacks | PDF",1785900699,45,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"a-machine-learning-procedure-to-detect-network-attacks","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/a-machine-learning-procedure-to-detect-network-attacks/125695/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-05",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What is the main goal of the proposed procedure?","Question",{"text":75,"@type":76},"To determine whether a network has been attacked and to identify the attack type using simple machine learning classifiers trained on network structure.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"Which machine learning methods are used?",{"text":80,"@type":76},"The procedure uses k-Nearest Neighbor and Random Forest classification schemes.",{"name":82,"@type":73,"acceptedAnswer":83},"Can the method detect all attack types considered in the study?",{"text":84,"@type":76},"It can distinguish intact networks from networks attacked by maximum-degree or maximum-betweenness deletions, but it cannot detect random failures.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]